VirtualBox

Ticket #16292: VBoxHardening.log

File VBoxHardening.log, 390.4 KB (added by cepal, 8 years ago)
Line 
12ad8.2ae4: Log file opened: 5.1.10r112026 g_hStartupLog=0000000000000014 g_uNtVerCombined=0x611db110
22ad8.2ae4: \SystemRoot\System32\ntdll.dll:
32ad8.2ae4: CreationTime: 2016-12-06T13:54:13.996612500Z
42ad8.2ae4: LastWriteTime: 2016-10-07T15:35:29.838228900Z
52ad8.2ae4: ChangeTime: 2016-12-06T14:34:54.832632500Z
62ad8.2ae4: FileAttributes: 0x20
72ad8.2ae4: Size: 0x1a7100
82ad8.2ae4: NT Headers: 0xe0
92ad8.2ae4: Timestamp: 0x57f7c06e
102ad8.2ae4: Machine: 0x8664 - amd64
112ad8.2ae4: Timestamp: 0x57f7c06e
122ad8.2ae4: Image Version: 6.1
132ad8.2ae4: SizeOfImage: 0x1aa000 (1744896)
142ad8.2ae4: Resource Dir: 0x14e000 LB 0x5a028
152ad8.2ae4: ProductName: Microsoft® Windows® Operating System
162ad8.2ae4: ProductVersion: 6.1.7601.23569
172ad8.2ae4: FileVersion: 6.1.7601.23569 (win7sp1_ldr.161007-0600)
182ad8.2ae4: FileDescription: NT Layer DLL
192ad8.2ae4: \SystemRoot\System32\kernel32.dll:
202ad8.2ae4: CreationTime: 2016-12-06T13:54:13.154207100Z
212ad8.2ae4: LastWriteTime: 2016-10-07T15:32:25.787000000Z
222ad8.2ae4: ChangeTime: 2016-12-06T14:34:58.686906700Z
232ad8.2ae4: FileAttributes: 0x20
242ad8.2ae4: Size: 0x11c000
252ad8.2ae4: NT Headers: 0xe0
262ad8.2ae4: Timestamp: 0x57f7c0b3
272ad8.2ae4: Machine: 0x8664 - amd64
282ad8.2ae4: Timestamp: 0x57f7c0b3
292ad8.2ae4: Image Version: 6.1
302ad8.2ae4: SizeOfImage: 0x11f000 (1175552)
312ad8.2ae4: Resource Dir: 0x116000 LB 0x528
322ad8.2ae4: ProductName: Microsoft® Windows® Operating System
332ad8.2ae4: ProductVersion: 6.1.7601.23569
342ad8.2ae4: FileVersion: 6.1.7601.23569 (win7sp1_ldr.161007-0600)
352ad8.2ae4: FileDescription: Windows NT BASE API Client DLL
362ad8.2ae4: \SystemRoot\System32\KernelBase.dll:
372ad8.2ae4: CreationTime: 2016-12-06T13:54:42.513595300Z
382ad8.2ae4: LastWriteTime: 2016-10-07T15:32:25.802000000Z
392ad8.2ae4: ChangeTime: 2016-12-06T14:34:58.640105800Z
402ad8.2ae4: FileAttributes: 0x20
412ad8.2ae4: Size: 0x66800
422ad8.2ae4: NT Headers: 0xe8
432ad8.2ae4: Timestamp: 0x57f7c0b4
442ad8.2ae4: Machine: 0x8664 - amd64
452ad8.2ae4: Timestamp: 0x57f7c0b4
462ad8.2ae4: Image Version: 6.1
472ad8.2ae4: SizeOfImage: 0x6a000 (434176)
482ad8.2ae4: Resource Dir: 0x68000 LB 0x530
492ad8.2ae4: ProductName: Microsoft® Windows® Operating System
502ad8.2ae4: ProductVersion: 6.1.7601.23569
512ad8.2ae4: FileVersion: 6.1.7601.23569 (win7sp1_ldr.161007-0600)
522ad8.2ae4: FileDescription: Windows NT BASE API Client DLL
532ad8.2ae4: \SystemRoot\System32\apisetschema.dll:
542ad8.2ae4: CreationTime: 2016-12-06T13:54:39.346775000Z
552ad8.2ae4: LastWriteTime: 2016-10-07T15:32:20.717000000Z
562ad8.2ae4: ChangeTime: 2016-12-06T14:34:54.598628000Z
572ad8.2ae4: FileAttributes: 0x20
582ad8.2ae4: Size: 0x1a00
592ad8.2ae4: NT Headers: 0xc0
602ad8.2ae4: Timestamp: 0x57f7c04d
612ad8.2ae4: Machine: 0x8664 - amd64
622ad8.2ae4: Timestamp: 0x57f7c04d
632ad8.2ae4: Image Version: 6.1
642ad8.2ae4: SizeOfImage: 0x50000 (327680)
652ad8.2ae4: Resource Dir: 0x30000 LB 0x3f8
662ad8.2ae4: ProductName: Microsoft® Windows® Operating System
672ad8.2ae4: ProductVersion: 6.1.7601.23569
682ad8.2ae4: FileVersion: 6.1.7601.23569 (win7sp1_ldr.161007-0600)
692ad8.2ae4: FileDescription: ApiSet Schema DLL
702ad8.2ae4: Found driver mfewfpk (0x20)
712ad8.2ae4: Found driver mfehidk (0x20)
722ad8.2ae4: Found driver mfeavfk (0x20)
732ad8.2ae4: Found driver mfefirek (0x20)
742ad8.2ae4: supR3HardenedWinFindAdversaries: 0x20
752ad8.2ae4: \SystemRoot\System32\drivers\mfeavfk.sys:
762ad8.2ae4: CreationTime: 2016-10-22T05:17:09.511250000Z
772ad8.2ae4: LastWriteTime: 2016-10-22T05:16:44.230000000Z
782ad8.2ae4: ChangeTime: 2016-11-10T18:19:49.912409800Z
792ad8.2ae4: FileAttributes: 0x20
802ad8.2ae4: Size: 0x55328
812ad8.2ae4: NT Headers: 0xe8
822ad8.2ae4: Timestamp: 0x56b28095
832ad8.2ae4: Machine: 0x8664 - amd64
842ad8.2ae4: Timestamp: 0x56b28095
852ad8.2ae4: Image Version: 0.0
862ad8.2ae4: SizeOfImage: 0x57000 (356352)
872ad8.2ae4: Resource Dir: 0x55000 LB 0x758
882ad8.2ae4: ProductName: SYSCORE
892ad8.2ae4: ProductVersion: 15.4.0.811
902ad8.2ae4: FileVersion: SYSCORE.15.4.0.811
912ad8.2ae4: PrivateBuild: SYSCORE.15.4.0.811 F15,F16,F19
922ad8.2ae4: FileDescription: Anti-Virus File System Filter Driver
932ad8.2ae4: \SystemRoot\System32\drivers\mfefirek.sys:
942ad8.2ae4: CreationTime: 2016-10-22T05:17:35.042500000Z
952ad8.2ae4: LastWriteTime: 2016-10-22T05:16:45.058125000Z
962ad8.2ae4: ChangeTime: 2016-11-10T18:19:49.943789600Z
972ad8.2ae4: FileAttributes: 0x20
982ad8.2ae4: Size: 0x78728
992ad8.2ae4: NT Headers: 0xe8
1002ad8.2ae4: Timestamp: 0x56b280ed
1012ad8.2ae4: Machine: 0x8664 - amd64
1022ad8.2ae4: Timestamp: 0x56b280ed
1032ad8.2ae4: Image Version: 0.0
1042ad8.2ae4: SizeOfImage: 0x7b000 (503808)
1052ad8.2ae4: Resource Dir: 0x77000 LB 0x388
1062ad8.2ae4: ProductName: SYSCORE
1072ad8.2ae4: ProductVersion: 15.4.0.811
1082ad8.2ae4: FileVersion: SYSCORE.15.4.0.811
1092ad8.2ae4: PrivateBuild: SYSCORE.15.4.0.811 F17,F18
1102ad8.2ae4: FileDescription: McAfee Core Firewall Engine Driver
1112ad8.2ae4: \SystemRoot\System32\drivers\mfehidk.sys:
1122ad8.2ae4: CreationTime: 2016-10-22T05:17:07.526875000Z
1132ad8.2ae4: LastWriteTime: 2016-10-22T05:16:44.464375000Z
1142ad8.2ae4: ChangeTime: 2016-11-10T18:19:49.990579600Z
1152ad8.2ae4: FileAttributes: 0x20
1162ad8.2ae4: Size: 0xcd528
1172ad8.2ae4: NT Headers: 0x100
1182ad8.2ae4: Timestamp: 0x56b28053
1192ad8.2ae4: Machine: 0x8664 - amd64
1202ad8.2ae4: Timestamp: 0x56b28053
1212ad8.2ae4: Image Version: 0.0
1222ad8.2ae4: SizeOfImage: 0xd9000 (888832)
1232ad8.2ae4: Resource Dir: 0xd5000 LB 0x758
1242ad8.2ae4: ProductName: SYSCORE
1252ad8.2ae4: ProductVersion: 15.4.0.811
1262ad8.2ae4: FileVersion: SYSCORE.15.4.0.811
1272ad8.2ae4: PrivateBuild: SYSCORE.15.4.0.811 F14,F15,F16,F18,F20
1282ad8.2ae4: FileDescription: McAfee Link Driver
1292ad8.2ae4: \SystemRoot\System32\drivers\mfewfpk.sys:
1302ad8.2ae4: CreationTime: 2016-10-22T05:16:57.245625000Z
1312ad8.2ae4: LastWriteTime: 2016-10-22T05:16:44.636250000Z
1322ad8.2ae4: ChangeTime: 2016-11-10T18:19:50.021832500Z
1332ad8.2ae4: FileAttributes: 0x20
1342ad8.2ae4: Size: 0x3b728
1352ad8.2ae4: NT Headers: 0xf0
1362ad8.2ae4: Timestamp: 0x56b28063
1372ad8.2ae4: Machine: 0x8664 - amd64
1382ad8.2ae4: Timestamp: 0x56b28063
1392ad8.2ae4: Image Version: 0.0
1402ad8.2ae4: SizeOfImage: 0x59000 (364544)
1412ad8.2ae4: Resource Dir: 0x57000 LB 0x380
1422ad8.2ae4: ProductName: SYSCORE
1432ad8.2ae4: ProductVersion: 15.4.0.811
1442ad8.2ae4: FileVersion: SYSCORE.15.4.0.811
1452ad8.2ae4: PrivateBuild: SYSCORE.15.4.0.811 F17,F18
1462ad8.2ae4: FileDescription: Anti-Virus Mini-Firewall Driver
1472ad8.2ae4: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\local\apps\Virtualbox'
1482ad8.2ae4: Calling main()
1492ad8.2ae4: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
1502ad8.2ae4: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume2\local\apps\Virtualbox'
1512ad8.2ae4: SUPR3HardenedMain: Respawn #1
1522ad8.2ae4: System32: \Device\HarddiskVolume2\Windows\System32
1532ad8.2ae4: WinSxS: \Device\HarddiskVolume2\Windows\winsxs
1542ad8.2ae4: KnownDllPath: C:\WINDOWS\system32
1552ad8.2ae4: '\Device\HarddiskVolume2\local\apps\Virtualbox\VirtualBox.exe' has no imports
1562ad8.2ae4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\local\apps\Virtualbox\VirtualBox.exe)
1572ad8.2ae4: supR3HardNtEnableThreadCreation:
1582ad8.2ae4: supR3HardNtDisableThreadCreation: pvLdrInitThunk=0000000077a7a360 pvNtTerminateThread=0000000077a9c260
1592ad8.2ae4: supR3HardenedWinDoReSpawn(1): New child 2af0.2ae8 [kernel32].
1602ad8.2ae4: supR3HardNtChildGatherData: PebBaseAddress=000007fffffdd000 cbPeb=0x380
1612ad8.2ae4: supR3HardNtPuChFindNtdll: uNtDllParentAddr=0000000077a50000 uNtDllChildAddr=0000000077a50000
1622ad8.2ae4: supR3HardenedWinSetupChildInit: uLdrInitThunk=0000000077a7a360
1632ad8.2ae4: supR3HardenedWinSetupChildInit: Start child.
1642ad8.2ae4: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
1652ad8.2ae4: supR3HardNtChildPurify: Startup delay kludge #1/0: 515 ms, 33 sleeps
1662ad8.2ae4: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
1672ad8.2ae4: *0000000000000000-fffffffffffeffff 0x0001/0x0000 0x0000000
1682ad8.2ae4: *0000000000010000-fffffffffffeffff 0x0004/0x0004 0x0020000
1692ad8.2ae4: *0000000000030000-000000000002bfff 0x0002/0x0002 0x0040000
1702ad8.2ae4: 0000000000034000-0000000000027fff 0x0001/0x0000 0x0000000
1712ad8.2ae4: *0000000000040000-000000000003efff 0x0004/0x0004 0x0020000
1722ad8.2ae4: 0000000000041000-fffffffffff21fff 0x0001/0x0000 0x0000000
1732ad8.2ae4: *0000000000160000-0000000000063fff 0x0000/0x0004 0x0020000
1742ad8.2ae4: 000000000025c000-0000000000259fff 0x0104/0x0004 0x0020000
1752ad8.2ae4: 000000000025e000-000000000025bfff 0x0004/0x0004 0x0020000
1762ad8.2ae4: 0000000000260000-ffffffff88a6ffff 0x0001/0x0000 0x0000000
1772ad8.2ae4: *0000000077a50000-0000000077a50fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
1782ad8.2ae4: 0000000077a51000-0000000077b4dfff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
1792ad8.2ae4: 0000000077b4e000-0000000077b7cfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
1802ad8.2ae4: 0000000077b7d000-0000000077b86fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
1812ad8.2ae4: 0000000077b87000-0000000077b87fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
1822ad8.2ae4: 0000000077b88000-0000000077b8afff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
1832ad8.2ae4: 0000000077b8b000-0000000077bf9fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
1842ad8.2ae4: 0000000077bfa000-0000000070813fff 0x0001/0x0000 0x0000000
1852ad8.2ae4: *000000007efe0000-000000007dfdffff 0x0000/0x0002 0x0020000
1862ad8.2ae4: *000000007ffe0000-000000007ffdefff 0x0002/0x0002 0x0020000
1872ad8.2ae4: 000000007ffe1000-000000007ffd1fff 0x0000/0x0002 0x0020000
1882ad8.2ae4: 000000007fff0000-ffffffffc0ccffff 0x0001/0x0000 0x0000000
1892ad8.2ae4: *000000013f310000-000000013f310fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\local\apps\Virtualbox\VirtualBox.exe
1902ad8.2ae4: 000000013f311000-000000013f37ffff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\local\apps\Virtualbox\VirtualBox.exe
1912ad8.2ae4: 000000013f380000-000000013f380fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume2\local\apps\Virtualbox\VirtualBox.exe
1922ad8.2ae4: 000000013f381000-000000013f3c5fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\local\apps\Virtualbox\VirtualBox.exe
1932ad8.2ae4: 000000013f3c6000-000000013f3c6fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\local\apps\Virtualbox\VirtualBox.exe
1942ad8.2ae4: 000000013f3c7000-000000013f3c7fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\local\apps\Virtualbox\VirtualBox.exe
1952ad8.2ae4: 000000013f3c8000-000000013f3ccfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\local\apps\Virtualbox\VirtualBox.exe
1962ad8.2ae4: 000000013f3cd000-000000013f3cdfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\local\apps\Virtualbox\VirtualBox.exe
1972ad8.2ae4: 000000013f3ce000-000000013f3cefff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\local\apps\Virtualbox\VirtualBox.exe
1982ad8.2ae4: 000000013f3cf000-000000013f3d2fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\local\apps\Virtualbox\VirtualBox.exe
1992ad8.2ae4: 000000013f3d3000-000000013f41afff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\local\apps\Virtualbox\VirtualBox.exe
2002ad8.2ae4: 000000013f41b000-fffff8037eac5fff 0x0001/0x0000 0x0000000
2012ad8.2ae4: *000007feffd70000-000007feffd70fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\apisetschema.dll
2022ad8.2ae4: 000007feffd71000-000007fdffb31fff 0x0001/0x0000 0x0000000
2032ad8.2ae4: *000007fffffb0000-000007fffff8cfff 0x0002/0x0002 0x0040000
2042ad8.2ae4: 000007fffffd3000-000007fffffc8fff 0x0001/0x0000 0x0000000
2052ad8.2ae4: *000007fffffdd000-000007fffffdbfff 0x0004/0x0004 0x0020000
2062ad8.2ae4: *000007fffffde000-000007fffffdbfff 0x0004/0x0004 0x0020000
2072ad8.2ae4: *000007fffffe0000-000007fffffcffff 0x0001/0x0002 0x0020000
2082ad8.2ae4: apisetschema.dll: timestamp 0x57f7c04d (rc=VINF_SUCCESS)
2092ad8.2ae4: VirtualBox.exe: timestamp 0x58332496 (rc=VINF_SUCCESS)
2102ad8.2ae4: '\Device\HarddiskVolume2\local\apps\Virtualbox\VirtualBox.exe' has no imports
2112ad8.2ae4: '\Device\HarddiskVolume2\Windows\System32\apisetschema.dll' has no imports
2122ad8.2ae4: '\Device\HarddiskVolume2\Windows\System32\ntdll.dll' has no imports
2132ad8.2ae4: supR3HardNtChildPurify: Done after 530 ms and 0 fixes (loop #0).
2142ad8.2ae4: supR3HardNtEnableThreadCreation:
2152af0.2ae8: Log file opened: 5.1.10r112026 g_hStartupLog=0000000000000004 g_uNtVerCombined=0x611db100
2162af0.2ae8: supR3HardenedVmProcessInit: uNtDllAddr=0000000077a50000 g_uNtVerCombined=0x611db100
2172af0.2ae8: ntdll.dll: timestamp 0x57f7c06e (rc=VINF_SUCCESS)
2182af0.2ae8: New simple heap: #1 0000000000260000 LB 0x400000 (for 1744896 allocation)
2192af0.2ae8: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\local\apps\Virtualbox'
2202af0.2ae8: System32: \Device\HarddiskVolume2\Windows\System32
2212af0.2ae8: WinSxS: \Device\HarddiskVolume2\Windows\winsxs
2222af0.2ae8: KnownDllPath: C:\WINDOWS\system32
2232af0.2ae8: supR3HardenedVmProcessInit: Opening vboxdrv stub...
2242af0.2ae8: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
2252af0.2ae8: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
2262af0.2ae8: Registered Dll notification callback with NTDLL.
2272af0.2ae8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\kernel32.dll)
2282af0.2ae8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\kernel32.dll
2292af0.2ae8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
2302af0.2ae8: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
2312af0.2ae8: supR3HardenedDllNotificationCallback: load 0000000077930000 LB 0x0011f000 C:\WINDOWS\system32\kernel32.dll [fFlags=0x0]
2322af0.2ae8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
2332af0.2ae8: supR3HardenedDllNotificationCallback: load 000007fefd910000 LB 0x0006a000 C:\WINDOWS\system32\KERNELBASE.dll [fFlags=0x0]
2342af0.2ae8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\KernelBase.dll)
2352af0.2ae8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\KernelBase.dll
2362af0.2ae8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077930000 'C:\WINDOWS\system32\kernel32.dll'
2372af0.2ae8: supR3HardNtDisableThreadCreation: pvLdrInitThunk=0000000077a7a360 pvNtTerminateThread=0000000077a9c260
2382ad8.2ae4: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 16 ms.
2392af0.2ae8: \SystemRoot\System32\ntdll.dll:
2402af0.2ae8: CreationTime: 2016-12-06T13:54:13.996612500Z
2412af0.2ae8: LastWriteTime: 2016-10-07T15:35:29.838228900Z
2422af0.2ae8: ChangeTime: 2016-12-06T14:34:54.832632500Z
2432af0.2ae8: FileAttributes: 0x20
2442af0.2ae8: Size: 0x1a7100
2452af0.2ae8: NT Headers: 0xe0
2462af0.2ae8: Timestamp: 0x57f7c06e
2472af0.2ae8: Machine: 0x8664 - amd64
2482af0.2ae8: Timestamp: 0x57f7c06e
2492af0.2ae8: Image Version: 6.1
2502af0.2ae8: SizeOfImage: 0x1aa000 (1744896)
2512af0.2ae8: Resource Dir: 0x14e000 LB 0x5a028
2522af0.2ae8: ProductName: Microsoft® Windows® Operating System
2532af0.2ae8: ProductVersion: 6.1.7601.23569
2542af0.2ae8: FileVersion: 6.1.7601.23569 (win7sp1_ldr.161007-0600)
2552af0.2ae8: FileDescription: NT Layer DLL
2562af0.2ae8: \SystemRoot\System32\kernel32.dll:
2572af0.2ae8: CreationTime: 2016-12-06T13:54:13.154207100Z
2582af0.2ae8: LastWriteTime: 2016-10-07T15:32:25.787000000Z
2592af0.2ae8: ChangeTime: 2016-12-06T14:34:58.686906700Z
2602af0.2ae8: FileAttributes: 0x20
2612af0.2ae8: Size: 0x11c000
2622af0.2ae8: NT Headers: 0xe0
2632af0.2ae8: Timestamp: 0x57f7c0b3
2642af0.2ae8: Machine: 0x8664 - amd64
2652af0.2ae8: Timestamp: 0x57f7c0b3
2662af0.2ae8: Image Version: 6.1
2672af0.2ae8: SizeOfImage: 0x11f000 (1175552)
2682af0.2ae8: Resource Dir: 0x116000 LB 0x528
2692af0.2ae8: ProductName: Microsoft® Windows® Operating System
2702af0.2ae8: ProductVersion: 6.1.7601.23569
2712af0.2ae8: FileVersion: 6.1.7601.23569 (win7sp1_ldr.161007-0600)
2722af0.2ae8: FileDescription: Windows NT BASE API Client DLL
2732af0.2ae8: \SystemRoot\System32\KernelBase.dll:
2742af0.2ae8: CreationTime: 2016-12-06T13:54:42.513595300Z
2752af0.2ae8: LastWriteTime: 2016-10-07T15:32:25.802000000Z
2762af0.2ae8: ChangeTime: 2016-12-06T14:34:58.640105800Z
2772af0.2ae8: FileAttributes: 0x20
2782af0.2ae8: Size: 0x66800
2792af0.2ae8: NT Headers: 0xe8
2802af0.2ae8: Timestamp: 0x57f7c0b4
2812af0.2ae8: Machine: 0x8664 - amd64
2822af0.2ae8: Timestamp: 0x57f7c0b4
2832af0.2ae8: Image Version: 6.1
2842af0.2ae8: SizeOfImage: 0x6a000 (434176)
2852af0.2ae8: Resource Dir: 0x68000 LB 0x530
2862af0.2ae8: ProductName: Microsoft® Windows® Operating System
2872af0.2ae8: ProductVersion: 6.1.7601.23569
2882af0.2ae8: FileVersion: 6.1.7601.23569 (win7sp1_ldr.161007-0600)
2892af0.2ae8: FileDescription: Windows NT BASE API Client DLL
2902af0.2ae8: \SystemRoot\System32\apisetschema.dll:
2912af0.2ae8: CreationTime: 2016-12-06T13:54:39.346775000Z
2922af0.2ae8: LastWriteTime: 2016-10-07T15:32:20.717000000Z
2932af0.2ae8: ChangeTime: 2016-12-06T14:34:54.598628000Z
2942af0.2ae8: FileAttributes: 0x20
2952af0.2ae8: Size: 0x1a00
2962af0.2ae8: NT Headers: 0xc0
2972af0.2ae8: Timestamp: 0x57f7c04d
2982af0.2ae8: Machine: 0x8664 - amd64
2992af0.2ae8: Timestamp: 0x57f7c04d
3002af0.2ae8: Image Version: 6.1
3012af0.2ae8: SizeOfImage: 0x50000 (327680)
3022af0.2ae8: Resource Dir: 0x30000 LB 0x3f8
3032af0.2ae8: ProductName: Microsoft® Windows® Operating System
3042af0.2ae8: ProductVersion: 6.1.7601.23569
3052af0.2ae8: FileVersion: 6.1.7601.23569 (win7sp1_ldr.161007-0600)
3062af0.2ae8: FileDescription: ApiSet Schema DLL
3072af0.2ae8: Found driver mfewfpk (0x20)
3082af0.2ae8: Found driver mfehidk (0x20)
3092af0.2ae8: Found driver mfeavfk (0x20)
3102af0.2ae8: Found driver mfefirek (0x20)
3112af0.2ae8: supR3HardenedWinFindAdversaries: 0x20
3122af0.2ae8: \SystemRoot\System32\drivers\mfeavfk.sys:
3132af0.2ae8: CreationTime: 2016-10-22T05:17:09.511250000Z
3142af0.2ae8: LastWriteTime: 2016-10-22T05:16:44.230000000Z
3152af0.2ae8: ChangeTime: 2016-11-10T18:19:49.912409800Z
3162af0.2ae8: FileAttributes: 0x20
3172af0.2ae8: Size: 0x55328
3182af0.2ae8: NT Headers: 0xe8
3192af0.2ae8: Timestamp: 0x56b28095
3202af0.2ae8: Machine: 0x8664 - amd64
3212af0.2ae8: Timestamp: 0x56b28095
3222af0.2ae8: Image Version: 0.0
3232af0.2ae8: SizeOfImage: 0x57000 (356352)
3242af0.2ae8: Resource Dir: 0x55000 LB 0x758
3252af0.2ae8: ProductName: SYSCORE
3262af0.2ae8: ProductVersion: 15.4.0.811
3272af0.2ae8: FileVersion: SYSCORE.15.4.0.811
3282af0.2ae8: PrivateBuild: SYSCORE.15.4.0.811 F15,F16,F19
3292af0.2ae8: FileDescription: Anti-Virus File System Filter Driver
3302af0.2ae8: \SystemRoot\System32\drivers\mfefirek.sys:
3312af0.2ae8: CreationTime: 2016-10-22T05:17:35.042500000Z
3322af0.2ae8: LastWriteTime: 2016-10-22T05:16:45.058125000Z
3332af0.2ae8: ChangeTime: 2016-11-10T18:19:49.943789600Z
3342af0.2ae8: FileAttributes: 0x20
3352af0.2ae8: Size: 0x78728
3362af0.2ae8: NT Headers: 0xe8
3372af0.2ae8: Timestamp: 0x56b280ed
3382af0.2ae8: Machine: 0x8664 - amd64
3392af0.2ae8: Timestamp: 0x56b280ed
3402af0.2ae8: Image Version: 0.0
3412af0.2ae8: SizeOfImage: 0x7b000 (503808)
3422af0.2ae8: Resource Dir: 0x77000 LB 0x388
3432af0.2ae8: ProductName: SYSCORE
3442af0.2ae8: ProductVersion: 15.4.0.811
3452af0.2ae8: FileVersion: SYSCORE.15.4.0.811
3462af0.2ae8: PrivateBuild: SYSCORE.15.4.0.811 F17,F18
3472af0.2ae8: FileDescription: McAfee Core Firewall Engine Driver
3482af0.2ae8: \SystemRoot\System32\drivers\mfehidk.sys:
3492af0.2ae8: CreationTime: 2016-10-22T05:17:07.526875000Z
3502af0.2ae8: LastWriteTime: 2016-10-22T05:16:44.464375000Z
3512af0.2ae8: ChangeTime: 2016-11-10T18:19:49.990579600Z
3522af0.2ae8: FileAttributes: 0x20
3532af0.2ae8: Size: 0xcd528
3542af0.2ae8: NT Headers: 0x100
3552af0.2ae8: Timestamp: 0x56b28053
3562af0.2ae8: Machine: 0x8664 - amd64
3572af0.2ae8: Timestamp: 0x56b28053
3582af0.2ae8: Image Version: 0.0
3592af0.2ae8: SizeOfImage: 0xd9000 (888832)
3602af0.2ae8: Resource Dir: 0xd5000 LB 0x758
3612af0.2ae8: ProductName: SYSCORE
3622af0.2ae8: ProductVersion: 15.4.0.811
3632af0.2ae8: FileVersion: SYSCORE.15.4.0.811
3642af0.2ae8: PrivateBuild: SYSCORE.15.4.0.811 F14,F15,F16,F18,F20
3652af0.2ae8: FileDescription: McAfee Link Driver
3662af0.2ae8: \SystemRoot\System32\drivers\mfewfpk.sys:
3672af0.2ae8: CreationTime: 2016-10-22T05:16:57.245625000Z
3682af0.2ae8: LastWriteTime: 2016-10-22T05:16:44.636250000Z
3692af0.2ae8: ChangeTime: 2016-11-10T18:19:50.021832500Z
3702af0.2ae8: FileAttributes: 0x20
3712af0.2ae8: Size: 0x3b728
3722af0.2ae8: NT Headers: 0xf0
3732af0.2ae8: Timestamp: 0x56b28063
3742af0.2ae8: Machine: 0x8664 - amd64
3752af0.2ae8: Timestamp: 0x56b28063
3762af0.2ae8: Image Version: 0.0
3772af0.2ae8: SizeOfImage: 0x59000 (364544)
3782af0.2ae8: Resource Dir: 0x57000 LB 0x380
3792af0.2ae8: ProductName: SYSCORE
3802af0.2ae8: ProductVersion: 15.4.0.811
3812af0.2ae8: FileVersion: SYSCORE.15.4.0.811
3822af0.2ae8: PrivateBuild: SYSCORE.15.4.0.811 F17,F18
3832af0.2ae8: FileDescription: Anti-Virus Mini-Firewall Driver
3842af0.2ae8: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\local\apps\Virtualbox'
3852af0.2ae8: Calling main()
3862af0.2ae8: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
3872af0.2ae8: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume2\local\apps\Virtualbox'
3882af0.2ae8: '\Device\HarddiskVolume2\local\apps\Virtualbox\VirtualBox.exe' has no imports
3892af0.2ae8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\local\apps\Virtualbox\VirtualBox.exe)
3902af0.2ae8: SUPR3HardenedMain: Respawn #2
3912af0.2ae8: supR3HardNtEnableThreadCreation:
3922af0.2ae8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\apphelp.dll)
3932af0.2ae8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\apphelp.dll
3942af0.2ae8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\apphelp.dll (rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
3952af0.2ae8: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\apphelp.dll [lacks WinVerifyTrust]
3962af0.2ae8: supR3HardenedDllNotificationCallback: load 000007fefd560000 LB 0x00057000 C:\WINDOWS\system32\apphelp.dll [fFlags=0x0]
3972af0.2ae8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\apphelp.dll [lacks WinVerifyTrust]
3982af0.2ae8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd560000 'C:\WINDOWS\system32\apphelp.dll'
3992af0.2ae8: supR3HardNtDisableThreadCreation: pvLdrInitThunk=0000000077a7a360 pvNtTerminateThread=0000000077a9c260
4002af0.2ae8: supR3HardenedWinDoReSpawn(2): New child 28f8.2aa4 [kernel32].
4012af0.2ae8: supR3HardNtChildGatherData: PebBaseAddress=000007fffffdf000 cbPeb=0x380
4022af0.2ae8: supR3HardNtPuChFindNtdll: uNtDllParentAddr=0000000077a50000 uNtDllChildAddr=0000000077a50000
4032af0.2ae8: supR3HardenedWinSetupChildInit: uLdrInitThunk=0000000077a7a360
4042af0.2ae8: supR3HardenedWinSetupChildInit: Start child.
4052af0.2ae8: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
4062af0.2ae8: supR3HardNtChildPurify: Startup delay kludge #1/0: 515 ms, 33 sleeps
4072af0.2ae8: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
4082af0.2ae8: *0000000000000000-fffffffffffeffff 0x0001/0x0000 0x0000000
4092af0.2ae8: *0000000000010000-fffffffffffeffff 0x0004/0x0004 0x0020000
4102af0.2ae8: *0000000000030000-000000000002bfff 0x0002/0x0002 0x0040000
4112af0.2ae8: 0000000000034000-0000000000027fff 0x0001/0x0000 0x0000000
4122af0.2ae8: *0000000000040000-000000000003efff 0x0004/0x0004 0x0020000
4132af0.2ae8: 0000000000041000-fffffffffff41fff 0x0001/0x0000 0x0000000
4142af0.2ae8: *0000000000140000-0000000000043fff 0x0000/0x0004 0x0020000
4152af0.2ae8: 000000000023c000-0000000000239fff 0x0104/0x0004 0x0020000
4162af0.2ae8: 000000000023e000-000000000023bfff 0x0004/0x0004 0x0020000
4172af0.2ae8: 0000000000240000-ffffffff88a2ffff 0x0001/0x0000 0x0000000
4182af0.2ae8: *0000000077a50000-0000000077a50fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
4192af0.2ae8: 0000000077a51000-0000000077b4dfff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
4202af0.2ae8: 0000000077b4e000-0000000077b7cfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
4212af0.2ae8: 0000000077b7d000-0000000077b86fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
4222af0.2ae8: 0000000077b87000-0000000077b87fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
4232af0.2ae8: 0000000077b88000-0000000077b8afff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
4242af0.2ae8: 0000000077b8b000-0000000077bf9fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
4252af0.2ae8: 0000000077bfa000-0000000070813fff 0x0001/0x0000 0x0000000
4262af0.2ae8: *000000007efe0000-000000007dfdffff 0x0000/0x0002 0x0020000
4272af0.2ae8: *000000007ffe0000-000000007ffdefff 0x0002/0x0002 0x0020000
4282af0.2ae8: 000000007ffe1000-000000007ffd1fff 0x0000/0x0002 0x0020000
4292af0.2ae8: 000000007fff0000-ffffffffc0ccffff 0x0001/0x0000 0x0000000
4302af0.2ae8: *000000013f310000-000000013f310fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\local\apps\Virtualbox\VirtualBox.exe
4312af0.2ae8: 000000013f311000-000000013f37ffff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\local\apps\Virtualbox\VirtualBox.exe
4322af0.2ae8: 000000013f380000-000000013f380fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume2\local\apps\Virtualbox\VirtualBox.exe
4332af0.2ae8: 000000013f381000-000000013f3c5fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\local\apps\Virtualbox\VirtualBox.exe
4342af0.2ae8: 000000013f3c6000-000000013f3c6fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\local\apps\Virtualbox\VirtualBox.exe
4352af0.2ae8: 000000013f3c7000-000000013f3c7fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\local\apps\Virtualbox\VirtualBox.exe
4362af0.2ae8: 000000013f3c8000-000000013f3ccfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\local\apps\Virtualbox\VirtualBox.exe
4372af0.2ae8: 000000013f3cd000-000000013f3cdfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\local\apps\Virtualbox\VirtualBox.exe
4382af0.2ae8: 000000013f3ce000-000000013f3cefff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\local\apps\Virtualbox\VirtualBox.exe
4392af0.2ae8: 000000013f3cf000-000000013f3d2fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\local\apps\Virtualbox\VirtualBox.exe
4402af0.2ae8: 000000013f3d3000-000000013f41afff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\local\apps\Virtualbox\VirtualBox.exe
4412af0.2ae8: 000000013f41b000-fffff8037eac5fff 0x0001/0x0000 0x0000000
4422af0.2ae8: *000007feffd70000-000007feffd70fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\apisetschema.dll
4432af0.2ae8: 000007feffd71000-000007fdffb31fff 0x0001/0x0000 0x0000000
4442af0.2ae8: *000007fffffb0000-000007fffff8cfff 0x0002/0x0002 0x0040000
4452af0.2ae8: 000007fffffd3000-000007fffffc8fff 0x0001/0x0000 0x0000000
4462af0.2ae8: *000007fffffdd000-000007fffffdafff 0x0004/0x0004 0x0020000
4472af0.2ae8: *000007fffffdf000-000007fffffddfff 0x0004/0x0004 0x0020000
4482af0.2ae8: *000007fffffe0000-000007fffffcffff 0x0001/0x0002 0x0020000
4492af0.2ae8: apisetschema.dll: timestamp 0x57f7c04d (rc=VINF_SUCCESS)
4502af0.2ae8: VirtualBox.exe: timestamp 0x58332496 (rc=VINF_SUCCESS)
4512af0.2ae8: '\Device\HarddiskVolume2\local\apps\Virtualbox\VirtualBox.exe' has no imports
4522af0.2ae8: '\Device\HarddiskVolume2\Windows\System32\apisetschema.dll' has no imports
4532af0.2ae8: '\Device\HarddiskVolume2\Windows\System32\ntdll.dll' has no imports
4542af0.2ae8: supR3HardNtChildPurify: Done after 562 ms and 0 fixes (loop #0).
4552af0.2ae8: supR3HardenedEarlyCompact: Removed heap 1 (0x00000000260000 LB 0x400000)
45628f8.2aa4: Log file opened: 5.1.10r112026 g_hStartupLog=0000000000000004 g_uNtVerCombined=0x611db100
45728f8.2aa4: supR3HardenedVmProcessInit: uNtDllAddr=0000000077a50000 g_uNtVerCombined=0x611db100
4582af0.2ae8: supR3HardNtEnableThreadCreation:
45928f8.2aa4: ntdll.dll: timestamp 0x57f7c06e (rc=VINF_SUCCESS)
46028f8.2aa4: New simple heap: #1 0000000000340000 LB 0x400000 (for 1744896 allocation)
46128f8.2aa4: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\local\apps\Virtualbox'
46228f8.2aa4: System32: \Device\HarddiskVolume2\Windows\System32
46328f8.2aa4: WinSxS: \Device\HarddiskVolume2\Windows\winsxs
46428f8.2aa4: KnownDllPath: C:\WINDOWS\system32
46528f8.2aa4: supR3HardenedVmProcessInit: Opening vboxdrv...
46628f8.2aa4: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
46728f8.2aa4: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
46828f8.2aa4: Registered Dll notification callback with NTDLL.
46928f8.2aa4: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\kernel32.dll)
47028f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\kernel32.dll
47128f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
47228f8.2aa4: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
47328f8.2aa4: supR3HardenedDllNotificationCallback: load 0000000077930000 LB 0x0011f000 C:\WINDOWS\system32\kernel32.dll [fFlags=0x0]
47428f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
47528f8.2aa4: supR3HardenedDllNotificationCallback: load 000007fefd910000 LB 0x0006a000 C:\WINDOWS\system32\KERNELBASE.dll [fFlags=0x0]
47628f8.2aa4: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\KernelBase.dll)
47728f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\KernelBase.dll
47828f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077930000 'C:\WINDOWS\system32\kernel32.dll'
47928f8.2aa4: supR3HardNtDisableThreadCreation: pvLdrInitThunk=0000000077a7a360 pvNtTerminateThread=0000000077a9c260
4802af0.2ae8: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 31 ms.
48128f8.2aa4: \SystemRoot\System32\ntdll.dll:
48228f8.2aa4: CreationTime: 2016-12-06T13:54:13.996612500Z
48328f8.2aa4: LastWriteTime: 2016-10-07T15:35:29.838228900Z
48428f8.2aa4: ChangeTime: 2016-12-06T14:34:54.832632500Z
48528f8.2aa4: FileAttributes: 0x20
48628f8.2aa4: Size: 0x1a7100
48728f8.2aa4: NT Headers: 0xe0
48828f8.2aa4: Timestamp: 0x57f7c06e
48928f8.2aa4: Machine: 0x8664 - amd64
49028f8.2aa4: Timestamp: 0x57f7c06e
49128f8.2aa4: Image Version: 6.1
49228f8.2aa4: SizeOfImage: 0x1aa000 (1744896)
49328f8.2aa4: Resource Dir: 0x14e000 LB 0x5a028
49428f8.2aa4: ProductName: Microsoft® Windows® Operating System
49528f8.2aa4: ProductVersion: 6.1.7601.23569
49628f8.2aa4: FileVersion: 6.1.7601.23569 (win7sp1_ldr.161007-0600)
49728f8.2aa4: FileDescription: NT Layer DLL
49828f8.2aa4: \SystemRoot\System32\kernel32.dll:
49928f8.2aa4: CreationTime: 2016-12-06T13:54:13.154207100Z
50028f8.2aa4: LastWriteTime: 2016-10-07T15:32:25.787000000Z
50128f8.2aa4: ChangeTime: 2016-12-06T14:34:58.686906700Z
50228f8.2aa4: FileAttributes: 0x20
50328f8.2aa4: Size: 0x11c000
50428f8.2aa4: NT Headers: 0xe0
50528f8.2aa4: Timestamp: 0x57f7c0b3
50628f8.2aa4: Machine: 0x8664 - amd64
50728f8.2aa4: Timestamp: 0x57f7c0b3
50828f8.2aa4: Image Version: 6.1
50928f8.2aa4: SizeOfImage: 0x11f000 (1175552)
51028f8.2aa4: Resource Dir: 0x116000 LB 0x528
51128f8.2aa4: ProductName: Microsoft® Windows® Operating System
51228f8.2aa4: ProductVersion: 6.1.7601.23569
51328f8.2aa4: FileVersion: 6.1.7601.23569 (win7sp1_ldr.161007-0600)
51428f8.2aa4: FileDescription: Windows NT BASE API Client DLL
51528f8.2aa4: \SystemRoot\System32\KernelBase.dll:
51628f8.2aa4: CreationTime: 2016-12-06T13:54:42.513595300Z
51728f8.2aa4: LastWriteTime: 2016-10-07T15:32:25.802000000Z
51828f8.2aa4: ChangeTime: 2016-12-06T14:34:58.640105800Z
51928f8.2aa4: FileAttributes: 0x20
52028f8.2aa4: Size: 0x66800
52128f8.2aa4: NT Headers: 0xe8
52228f8.2aa4: Timestamp: 0x57f7c0b4
52328f8.2aa4: Machine: 0x8664 - amd64
52428f8.2aa4: Timestamp: 0x57f7c0b4
52528f8.2aa4: Image Version: 6.1
52628f8.2aa4: SizeOfImage: 0x6a000 (434176)
52728f8.2aa4: Resource Dir: 0x68000 LB 0x530
52828f8.2aa4: ProductName: Microsoft® Windows® Operating System
52928f8.2aa4: ProductVersion: 6.1.7601.23569
53028f8.2aa4: FileVersion: 6.1.7601.23569 (win7sp1_ldr.161007-0600)
53128f8.2aa4: FileDescription: Windows NT BASE API Client DLL
53228f8.2aa4: \SystemRoot\System32\apisetschema.dll:
53328f8.2aa4: CreationTime: 2016-12-06T13:54:39.346775000Z
53428f8.2aa4: LastWriteTime: 2016-10-07T15:32:20.717000000Z
53528f8.2aa4: ChangeTime: 2016-12-06T14:34:54.598628000Z
53628f8.2aa4: FileAttributes: 0x20
53728f8.2aa4: Size: 0x1a00
53828f8.2aa4: NT Headers: 0xc0
53928f8.2aa4: Timestamp: 0x57f7c04d
54028f8.2aa4: Machine: 0x8664 - amd64
54128f8.2aa4: Timestamp: 0x57f7c04d
54228f8.2aa4: Image Version: 6.1
54328f8.2aa4: SizeOfImage: 0x50000 (327680)
54428f8.2aa4: Resource Dir: 0x30000 LB 0x3f8
54528f8.2aa4: ProductName: Microsoft® Windows® Operating System
54628f8.2aa4: ProductVersion: 6.1.7601.23569
54728f8.2aa4: FileVersion: 6.1.7601.23569 (win7sp1_ldr.161007-0600)
54828f8.2aa4: FileDescription: ApiSet Schema DLL
54928f8.2aa4: Found driver mfewfpk (0x20)
55028f8.2aa4: Found driver mfehidk (0x20)
55128f8.2aa4: Found driver mfeavfk (0x20)
55228f8.2aa4: Found driver mfefirek (0x20)
55328f8.2aa4: supR3HardenedWinFindAdversaries: 0x20
55428f8.2aa4: \SystemRoot\System32\drivers\mfeavfk.sys:
55528f8.2aa4: CreationTime: 2016-10-22T05:17:09.511250000Z
55628f8.2aa4: LastWriteTime: 2016-10-22T05:16:44.230000000Z
55728f8.2aa4: ChangeTime: 2016-11-10T18:19:49.912409800Z
55828f8.2aa4: FileAttributes: 0x20
55928f8.2aa4: Size: 0x55328
56028f8.2aa4: NT Headers: 0xe8
56128f8.2aa4: Timestamp: 0x56b28095
56228f8.2aa4: Machine: 0x8664 - amd64
56328f8.2aa4: Timestamp: 0x56b28095
56428f8.2aa4: Image Version: 0.0
56528f8.2aa4: SizeOfImage: 0x57000 (356352)
56628f8.2aa4: Resource Dir: 0x55000 LB 0x758
56728f8.2aa4: ProductName: SYSCORE
56828f8.2aa4: ProductVersion: 15.4.0.811
56928f8.2aa4: FileVersion: SYSCORE.15.4.0.811
57028f8.2aa4: PrivateBuild: SYSCORE.15.4.0.811 F15,F16,F19
57128f8.2aa4: FileDescription: Anti-Virus File System Filter Driver
57228f8.2aa4: \SystemRoot\System32\drivers\mfefirek.sys:
57328f8.2aa4: CreationTime: 2016-10-22T05:17:35.042500000Z
57428f8.2aa4: LastWriteTime: 2016-10-22T05:16:45.058125000Z
57528f8.2aa4: ChangeTime: 2016-11-10T18:19:49.943789600Z
57628f8.2aa4: FileAttributes: 0x20
57728f8.2aa4: Size: 0x78728
57828f8.2aa4: NT Headers: 0xe8
57928f8.2aa4: Timestamp: 0x56b280ed
58028f8.2aa4: Machine: 0x8664 - amd64
58128f8.2aa4: Timestamp: 0x56b280ed
58228f8.2aa4: Image Version: 0.0
58328f8.2aa4: SizeOfImage: 0x7b000 (503808)
58428f8.2aa4: Resource Dir: 0x77000 LB 0x388
58528f8.2aa4: ProductName: SYSCORE
58628f8.2aa4: ProductVersion: 15.4.0.811
58728f8.2aa4: FileVersion: SYSCORE.15.4.0.811
58828f8.2aa4: PrivateBuild: SYSCORE.15.4.0.811 F17,F18
58928f8.2aa4: FileDescription: McAfee Core Firewall Engine Driver
59028f8.2aa4: \SystemRoot\System32\drivers\mfehidk.sys:
59128f8.2aa4: CreationTime: 2016-10-22T05:17:07.526875000Z
59228f8.2aa4: LastWriteTime: 2016-10-22T05:16:44.464375000Z
59328f8.2aa4: ChangeTime: 2016-11-10T18:19:49.990579600Z
59428f8.2aa4: FileAttributes: 0x20
59528f8.2aa4: Size: 0xcd528
59628f8.2aa4: NT Headers: 0x100
59728f8.2aa4: Timestamp: 0x56b28053
59828f8.2aa4: Machine: 0x8664 - amd64
59928f8.2aa4: Timestamp: 0x56b28053
60028f8.2aa4: Image Version: 0.0
60128f8.2aa4: SizeOfImage: 0xd9000 (888832)
60228f8.2aa4: Resource Dir: 0xd5000 LB 0x758
60328f8.2aa4: ProductName: SYSCORE
60428f8.2aa4: ProductVersion: 15.4.0.811
60528f8.2aa4: FileVersion: SYSCORE.15.4.0.811
60628f8.2aa4: PrivateBuild: SYSCORE.15.4.0.811 F14,F15,F16,F18,F20
60728f8.2aa4: FileDescription: McAfee Link Driver
60828f8.2aa4: \SystemRoot\System32\drivers\mfewfpk.sys:
60928f8.2aa4: CreationTime: 2016-10-22T05:16:57.245625000Z
61028f8.2aa4: LastWriteTime: 2016-10-22T05:16:44.636250000Z
61128f8.2aa4: ChangeTime: 2016-11-10T18:19:50.021832500Z
61228f8.2aa4: FileAttributes: 0x20
61328f8.2aa4: Size: 0x3b728
61428f8.2aa4: NT Headers: 0xf0
61528f8.2aa4: Timestamp: 0x56b28063
61628f8.2aa4: Machine: 0x8664 - amd64
61728f8.2aa4: Timestamp: 0x56b28063
61828f8.2aa4: Image Version: 0.0
61928f8.2aa4: SizeOfImage: 0x59000 (364544)
62028f8.2aa4: Resource Dir: 0x57000 LB 0x380
62128f8.2aa4: ProductName: SYSCORE
62228f8.2aa4: ProductVersion: 15.4.0.811
62328f8.2aa4: FileVersion: SYSCORE.15.4.0.811
62428f8.2aa4: PrivateBuild: SYSCORE.15.4.0.811 F17,F18
62528f8.2aa4: FileDescription: Anti-Virus Mini-Firewall Driver
62628f8.2aa4: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\local\apps\Virtualbox'
62728f8.2aa4: Calling main()
62828f8.2aa4: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
62928f8.2aa4: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume2\local\apps\Virtualbox'
63028f8.2aa4: '\Device\HarddiskVolume2\local\apps\Virtualbox\VirtualBox.exe' has no imports
63128f8.2aa4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\local\apps\Virtualbox\VirtualBox.exe)
63228f8.2aa4: SUPR3HardenedMain: Final process, opening VBoxDrv...
63328f8.2aa4: supR3HardenedEarlyCompact: Removed heap 1 (0x00000000340000 LB 0x400000)
63428f8.2aa4: supR3HardNtEnableThreadCreation:
63528f8.2aa4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\local\apps\Virtualbox\VBoxSupLib.dll)
63628f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxSupLib.dll
63728f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\local\apps\Virtualbox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000023b781:<flags> [calling]
63828f8.2aa4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxSupLib.dll [lacks WinVerifyTrust]
63928f8.2aa4: supR3HardenedDllNotificationCallback: load 000007fefa310000 LB 0x00005000 C:\local\apps\Virtualbox\VBoxSupLib.DLL [fFlags=0x0]
64028f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxSupLib.dll [lacks WinVerifyTrust]
64128f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxSupLib.dll [lacks WinVerifyTrust]
64228f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\local\apps\Virtualbox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000238f01:<flags> [calling]
64328f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa310000 'C:\local\apps\Virtualbox\VBoxSupLib.DLL'
64428f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxSupLib.dll [lacks WinVerifyTrust]
64528f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\local\apps\Virtualbox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000238f01:<flags> [calling]
64628f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa310000 'C:\local\apps\Virtualbox\VBoxSupLib.DLL'
64728f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa310000 'C:\local\apps\Virtualbox\VBoxSupLib.DLL'
64828f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
64928f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'crypt32.dll'.
65028f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msasn1.dll'.
65128f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
65228f8.2aa4: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\wintrust.dll)
65328f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wintrust.dll
65428f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
65528f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
65628f8.2aa4: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll)
65728f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
65828f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
65928f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume2\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
66028f8.2aa4: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\msasn1.dll)
66128f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msasn1.dll
66228f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
66328f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume2\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
66428f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
66528f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msasn1.dll'.
66628f8.2aa4: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\crypt32.dll)
66728f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\crypt32.dll
66828f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
66928f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
67028f8.2aa4: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\msvcrt.dll)
67128f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
67228f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
67328f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume2\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
67428f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
67528f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
67628f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
67728f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
67828f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000023d591:<flags> [calling]
67928f8.2aa4: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
68028f8.2aa4: supR3HardenedDllNotificationCallback: load 000007fefd890000 LB 0x0003b000 C:\WINDOWS\system32\Wintrust.dll [fFlags=0x0]
68128f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
68228f8.2aa4: supR3HardenedDllNotificationCallback: load 000007fefde20000 LB 0x0009f000 C:\WINDOWS\system32\msvcrt.dll [fFlags=0x0]
68328f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
68428f8.2aa4: supR3HardenedDllNotificationCallback: load 000007fefd9b0000 LB 0x0016d000 C:\WINDOWS\system32\CRYPT32.dll [fFlags=0x0]
68528f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
68628f8.2aa4: supR3HardenedDllNotificationCallback: load 000007fefd790000 LB 0x0000f000 C:\WINDOWS\system32\MSASN1.dll [fFlags=0x0]
68728f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
68828f8.2aa4: supR3HardenedDllNotificationCallback: load 000007feffbb0000 LB 0x0012d000 C:\WINDOWS\system32\RPCRT4.dll [fFlags=0x0]
68928f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
69028f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd890000 'C:\WINDOWS\system32\Wintrust.dll'
69128f8.2aa4: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\bcrypt.dll)
69228f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\bcrypt.dll
69328f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\bcrypt.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000023d591:<flags> [calling]
69428f8.2aa4: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
69528f8.2aa4: supR3HardenedDllNotificationCallback: load 000007fefd0b0000 LB 0x00022000 C:\WINDOWS\system32\bcrypt.dll [fFlags=0x0]
69628f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
69728f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd0b0000 'C:\WINDOWS\system32\bcrypt.dll'
69828f8.2aa4: bcrypt.dll loaded at 000007fefd0b0000, BCryptOpenAlgorithmProvider at 000007fefd0b2640, preloading providers:
69928f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'advapi32.dll'.
70028f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'bcrypt.dll'.
70128f8.2aa4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll)
70228f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll
70328f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
70428f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume2\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
70528f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
70628f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
70728f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
70828f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
70928f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'rpcrt4.dll'.
71028f8.2aa4: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\advapi32.dll)
71128f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\advapi32.dll
71228f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
71328f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
71428f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
71528f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
71628f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
71728f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
71828f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\bcryptprimitives.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000023d581:<flags> [calling]
71928f8.2aa4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
72028f8.2aa4: supR3HardenedDllNotificationCallback: load 000007fefcba0000 LB 0x0004c000 C:\WINDOWS\system32\bcryptprimitives.dll [fFlags=0x0]
72128f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
72228f8.2aa4: supR3HardenedDllNotificationCallback: load 000007fefe940000 LB 0x000db000 C:\WINDOWS\system32\ADVAPI32.dll [fFlags=0x0]
72328f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
72428f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msvcrt.dll'.
72528f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'rpcrt4.dll'.
72628f8.2aa4: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\sechost.dll)
72728f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\sechost.dll
72828f8.2aa4: supR3HardenedDllNotificationCallback: load 000007fefdf40000 LB 0x0001f000 C:\WINDOWS\SYSTEM32\sechost.dll [fFlags=0x0]
72928f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\sechost.dll [lacks WinVerifyTrust]
73028f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcba0000 'C:\WINDOWS\system32\bcryptprimitives.dll'
73128f8.2aa4: BCryptOpenAlgorithmProvider(,'MD2',0,0) -> 0x0 (hAlgo=000000000081c600)
73228f8.2aa4: BCryptOpenAlgorithmProvider(,'MD4',0,0) -> 0x0 (hAlgo=000000000081ce90)
73328f8.2aa4: BCryptOpenAlgorithmProvider(,'MD5',0,0) -> 0x0 (hAlgo=000000000081cfb0)
73428f8.2aa4: BCryptOpenAlgorithmProvider(,'SHA1',0,0) -> 0x0 (hAlgo=000000000081d1c0)
73528f8.2aa4: BCryptOpenAlgorithmProvider(,'SHA256',0,0) -> 0x0 (hAlgo=000000000081d2e0)
73628f8.2aa4: BCryptOpenAlgorithmProvider(,'SHA512',0,0) -> 0x0 (hAlgo=000000000081d400)
73728f8.2aa4: BCryptOpenAlgorithmProvider(,'RSA',0,0) -> 0x0 (hAlgo=000000000081d640)
73828f8.2aa4: BCryptOpenAlgorithmProvider(,'DSA',0,0) -> 0x0 (hAlgo=000000000081d760)
73928f8.2aa4: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\cryptsp.dll)
74028f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cryptsp.dll
74128f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
74228f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
74328f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
74428f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
74528f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
74628f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
74728f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\CRYPTSP.dll (Input=CRYPTSP.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000023d0e1:<flags> [calling]
74828f8.2aa4: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptsp.dll [lacks WinVerifyTrust]
74928f8.2aa4: supR3HardenedDllNotificationCallback: load 000007fefcf60000 LB 0x00018000 C:\WINDOWS\system32\CRYPTSP.dll [fFlags=0x0]
75028f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptsp.dll [lacks WinVerifyTrust]
75128f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcf60000 'C:\WINDOWS\system32\CRYPTSP.dll'
75228f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
75328f8.2aa4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\rsaenh.dll)
75428f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\rsaenh.dll
75528f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
75628f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
75728f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
75828f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000023d071:<flags> [calling]
75928f8.2aa4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
76028f8.2aa4: supR3HardenedDllNotificationCallback: load 000007fefcc60000 LB 0x00047000 C:\WINDOWS\system32\rsaenh.dll [fFlags=0x0]
76128f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
76228f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcc60000 'C:\WINDOWS\system32\rsaenh.dll'
76328f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
76428f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\ADVAPI32.dll (Input=ADVAPI32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000023c901:<flags> [calling]
76528f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe940000 'C:\WINDOWS\system32\ADVAPI32.dll'
76628f8.2aa4: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\cryptbase.dll)
76728f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cryptbase.dll
76828f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\CRYPTBASE.dll (Input=CRYPTBASE.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000023cc81:<flags> [calling]
76928f8.2aa4: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptbase.dll [lacks WinVerifyTrust]
77028f8.2aa4: supR3HardenedDllNotificationCallback: load 000007fefd5c0000 LB 0x0000f000 C:\WINDOWS\system32\CRYPTBASE.dll [fFlags=0x0]
77128f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptbase.dll [lacks WinVerifyTrust]
77228f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd5c0000 'C:\WINDOWS\system32\CRYPTBASE.dll'
77328f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
77428f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000023c6b1:<flags> [calling]
77528f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077930000 'C:\WINDOWS\system32\kernel32.dll'
77628f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
77728f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\WINTRUST.DLL (Input=WINTRUST.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000023d041:<flags> [calling]
77828f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd890000 'C:\WINDOWS\system32\WINTRUST.DLL'
77928f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
78028f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\CRYPT32.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=000000000023ce71:<flags> [calling]
78128f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd9b0000 'C:\WINDOWS\system32\CRYPT32.dll'
78228f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
78328f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'advapi32.dll'.
78428f8.2aa4: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\imagehlp.dll)
78528f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\imagehlp.dll
78628f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
78728f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
78828f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
78928f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
79028f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
79128f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
79228f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\imagehlp.dll (Input=imagehlp.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000023cec1:<flags> [calling]
79328f8.2aa4: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\imagehlp.dll [lacks WinVerifyTrust]
79428f8.2aa4: supR3HardenedDllNotificationCallback: load 000007feffa90000 LB 0x00019000 C:\WINDOWS\system32\imagehlp.dll [fFlags=0x0]
79528f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\imagehlp.dll [lacks WinVerifyTrust]
79628f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feffa90000 'C:\WINDOWS\system32\imagehlp.dll'
79728f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptsp.dll [lacks WinVerifyTrust]
79828f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\CRYPTSP.dll (Input=CRYPTSP.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000023d011:<flags> [calling]
79928f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcf60000 'C:\WINDOWS\system32\CRYPTSP.dll'
80028f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
80128f8.2aa4: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\user32.dll)
80228f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\user32.dll
80328f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
80428f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
80528f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
80628f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'lpk.dll'.
80728f8.2aa4: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\gdi32.dll)
80828f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\gdi32.dll
80928f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'lpk.dll'...
81028f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'lpk.dll' -> '\Device\HarddiskVolume2\Windows\System32\lpk.dll' [rcNtRedir=0xc0150008]
81128f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'gdi32.dll'.
81228f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'user32.dll'.
81328f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'usp10.dll'.
81428f8.2aa4: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\lpk.dll)
81528f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\lpk.dll
81628f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
81728f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
81828f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
81928f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'usp10.dll'...
82028f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'usp10.dll' -> '\Device\HarddiskVolume2\Windows\System32\usp10.dll' [rcNtRedir=0xc0150008]
82128f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
82228f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
82328f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'gdi32.dll'.
82428f8.2aa4: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\usp10.dll)
82528f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\usp10.dll
82628f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
82728f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
82828f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
82928f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
83028f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
83128f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
83228f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
83328f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
83428f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
83528f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
83628f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
83728f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
83828f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
83928f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
84028f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
84128f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\USER32.dll (Input=USER32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000023cb41:<flags> [calling]
84228f8.2aa4: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
84328f8.2aa4: supR3HardenedDllNotificationCallback: load 0000000077830000 LB 0x000fa000 C:\WINDOWS\system32\USER32.dll [fFlags=0x0]
84428f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
84528f8.2aa4: supR3HardenedDllNotificationCallback: load 000007fefea60000 LB 0x00067000 C:\WINDOWS\system32\GDI32.dll [fFlags=0x0]
84628f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
84728f8.2aa4: supR3HardenedDllNotificationCallback: load 000007fefe630000 LB 0x0000e000 C:\WINDOWS\system32\LPK.dll [fFlags=0x0]
84828f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\lpk.dll [lacks WinVerifyTrust]
84928f8.2aa4: supR3HardenedDllNotificationCallback: load 000007fefe640000 LB 0x000ca000 C:\WINDOWS\system32\USP10.dll [fFlags=0x0]
85028f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\usp10.dll [lacks WinVerifyTrust]
85128f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
85228f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\gdi32.dll (Input=gdi32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000023c041:<flags> [calling]
85328f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefea60000 'C:\WINDOWS\system32\gdi32.dll'
85428f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'user32.dll'.
85528f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
85628f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msctf.dll'.
85728f8.2aa4: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\imm32.dll)
85828f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\imm32.dll
85928f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msctf.dll'...
86028f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msctf.dll' -> '\Device\HarddiskVolume2\Windows\System32\msctf.dll' [rcNtRedir=0xc0150008]
86128f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
86228f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
86328f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'gdi32.dll'.
86428f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'imm32.dll'.
86528f8.2aa4: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\msctf.dll)
86628f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msctf.dll
86728f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
86828f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
86928f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
87028f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
87128f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
87228f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
87328f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
87428f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume2\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
87528f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\imm32.dll [lacks WinVerifyTrust]
87628f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
87728f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
87828f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
87928f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
88028f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
88128f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
88228f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
88328f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
88428f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
88528f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\IMM32.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000023b981:<flags> [calling]
88628f8.2aa4: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\imm32.dll [lacks WinVerifyTrust]
88728f8.2aa4: supR3HardenedDllNotificationCallback: load 000007fefea20000 LB 0x0002e000 C:\WINDOWS\system32\IMM32.DLL [fFlags=0x0]
88828f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\imm32.dll [lacks WinVerifyTrust]
88928f8.2aa4: supR3HardenedDllNotificationCallback: load 000007fefe250000 LB 0x00109000 C:\WINDOWS\system32\MSCTF.dll [fFlags=0x0]
89028f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msctf.dll [lacks WinVerifyTrust]
89128f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefea20000 'C:\WINDOWS\system32\IMM32.DLL'
89228f8.2aa4: supHardenedWinVerifyImageByHandle: -> -23303 (\Device\HarddiskVolume2\Windows\System32\nvinitx.dll)
89328f8.2aa4: Error (rc=0):
89428f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: rc=Unknown Status -23303 (0xffffa4f9) fImage=1 fProtect=0x0 fAccess=0x0 \Device\HarddiskVolume2\Windows\System32\nvinitx.dll: fKeyUsage=0x0, missing 0x1: \Device\HarddiskVolume2\Windows\System32\nvinitx.dll
89528f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\nvinitx.dll
89628f8.2aa4: Error (rc=0):
89728f8.2aa4: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\WINDOWS\system32\nvinitx.dll' (C:\WINDOWS\system32\nvinitx.dll): rcNt=0xc0000190
89828f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\WINDOWS\system32\nvinitx.dll'
89928f8.2aa4: \Device\HarddiskVolume2\Windows\System32\AMInit64.dll: Owner is administrators group.
90028f8.2aa4: supHardenedWinVerifyImageByHandle: -> -23021 (\Device\HarddiskVolume2\Windows\System32\AMInit64.dll)
90128f8.2aa4: Error (rc=0):
90228f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: rc=Unknown Status -23021 (0xffffa613) fImage=1 fProtect=0x0 fAccess=0x0 \Device\HarddiskVolume2\Windows\System32\AMInit64.dll: None of the 1 path(s) have a trust anchor.: \Device\HarddiskVolume2\Windows\System32\AMInit64.dll
90328f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\AMInit64.dll
90428f8.2aa4: Error (rc=0):
90528f8.2aa4: supR3HardenedMonitor_LdrLoadDll: rejecting 'C:\WINDOWS\system32\AMINIT64.DLL': rcNt=0xc0000190
90628f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\WINDOWS\system32\AMINIT64.DLL'
90728f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077830000 'C:\WINDOWS\system32\USER32.dll'
90828f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'bcrypt.dll'.
90928f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
91028f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msasn1.dll'.
91128f8.2aa4: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\ncrypt.dll)
91228f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ncrypt.dll
91328f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
91428f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume2\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
91528f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
91628f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
91728f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
91828f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
91928f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
92028f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume2\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
92128f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
92228f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\ncrypt.dll (Input=ncrypt.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000023ce41:<flags> [calling]
92328f8.2aa4: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\ncrypt.dll [lacks WinVerifyTrust]
92428f8.2aa4: supR3HardenedDllNotificationCallback: load 000007fefd0e0000 LB 0x00050000 C:\WINDOWS\system32\ncrypt.dll [fFlags=0x0]
92528f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\ncrypt.dll [lacks WinVerifyTrust]
92628f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd0e0000 'C:\WINDOWS\system32\ncrypt.dll'
92728f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
92828f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\bcrypt.dll (Input=bcrypt.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000023cc31:<flags> [calling]
92928f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd0b0000 'C:\WINDOWS\system32\bcrypt.dll'
93028f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
93128f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'rpcrt4.dll'.
93228f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'profapi.dll'.
93328f8.2aa4: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\userenv.dll)
93428f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\userenv.dll
93528f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'profapi.dll'...
93628f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'profapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\profapi.dll' [rcNtRedir=0xc0150008]
93728f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
93828f8.2aa4: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\profapi.dll)
93928f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\profapi.dll
94028f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
94128f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
94228f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
94328f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
94428f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
94528f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
94628f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
94728f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
94828f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
94928f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\USERENV.dll (Input=USERENV.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000023c5c1:<flags> [calling]
95028f8.2aa4: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\userenv.dll [lacks WinVerifyTrust]
95128f8.2aa4: supR3HardenedDllNotificationCallback: load 000007fefd7b0000 LB 0x0001e000 C:\WINDOWS\system32\USERENV.dll [fFlags=0x0]
95228f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\userenv.dll [lacks WinVerifyTrust]
95328f8.2aa4: supR3HardenedDllNotificationCallback: load 000007fefd780000 LB 0x0000f000 C:\WINDOWS\system32\profapi.dll [fFlags=0x0]
95428f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\profapi.dll [lacks WinVerifyTrust]
95528f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd7b0000 'C:\WINDOWS\system32\USERENV.dll'
95628f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=000000000023c321:<flags> [calling]
95728f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdf40000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
95828f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=000000000023c6b1:<flags> [calling]
95928f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdf40000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
96028f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
96128f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'rpcrt4.dll'.
96228f8.2aa4: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\gpapi.dll)
96328f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\gpapi.dll
96428f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
96528f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
96628f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
96728f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
96828f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
96928f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
97028f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\GPAPI.dll (Input=GPAPI.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000023c8e1:<flags> [calling]
97128f8.2aa4: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gpapi.dll [lacks WinVerifyTrust]
97228f8.2aa4: supR3HardenedDllNotificationCallback: load 000007fefc9d0000 LB 0x0001b000 C:\WINDOWS\system32\GPAPI.dll [fFlags=0x0]
97328f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gpapi.dll [lacks WinVerifyTrust]
97428f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc9d0000 'C:\WINDOWS\system32\GPAPI.dll'
97528f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-Management-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=000000000023c831:<flags> [calling]
97628f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdf40000 'API-MS-WIN-Service-Management-L1-1-0.dll'
97728f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
97828f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rpcrt4.dll (Input=rpcrt4.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000023bf31:<flags> [calling]
97928f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feffbb0000 'C:\WINDOWS\system32\rpcrt4.dll'
98028f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-Management-L2-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=000000000023c811:<flags> [calling]
98128f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdf40000 'API-MS-WIN-Service-Management-L2-1-0.dll'
98228f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=000000000023c821:<flags> [calling]
98328f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdf40000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
98428f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
98528f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'advapi32.dll'.
98628f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'crypt32.dll'.
98728f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'wldap32.dll'.
98828f8.2aa4: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\cryptnet.dll)
98928f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cryptnet.dll
99028f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wldap32.dll'...
99128f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'wldap32.dll' -> '\Device\HarddiskVolume2\Windows\System32\wldap32.dll' [rcNtRedir=0xc0150008]
99228f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
99328f8.2aa4: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\Wldap32.dll)
99428f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\Wldap32.dll
99528f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
99628f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume2\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
99728f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
99828f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
99928f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
100028f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
100128f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
100228f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
100328f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
100428f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
100528f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
100628f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
100728f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\cryptnet.dll (Input=cryptnet.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000023c321:<flags> [calling]
100828f8.2aa4: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
100928f8.2aa4: supR3HardenedDllNotificationCallback: load 000007fef9230000 LB 0x00027000 C:\WINDOWS\system32\cryptnet.dll [fFlags=0x0]
101028f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
101128f8.2aa4: supR3HardenedDllNotificationCallback: load 000007feffb50000 LB 0x00052000 C:\WINDOWS\system32\WLDAP32.dll [fFlags=0x0]
101228f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\Wldap32.dll [lacks WinVerifyTrust]
101328f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
101428f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=000000000023b551:<flags> [calling]
101528f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef9230000 'C:\WINDOWS\system32\cryptnet.dll'
101628f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
101728f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=000000000023b551:<flags> [calling]
101828f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef9230000 'C:\WINDOWS\system32\cryptnet.dll'
101928f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
102028f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=000000000023b551:<flags> [calling]
102128f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef9230000 'C:\WINDOWS\system32\cryptnet.dll'
102228f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
102328f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=000000000023b551:<flags> [calling]
102428f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef9230000 'C:\WINDOWS\system32\cryptnet.dll'
102528f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
102628f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=000000000023b551:<flags> [calling]
102728f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef9230000 'C:\WINDOWS\system32\cryptnet.dll'
102828f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
102928f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=000000000023b551:<flags> [calling]
103028f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef9230000 'C:\WINDOWS\system32\cryptnet.dll'
103128f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
103228f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef9230000 'C:\WINDOWS\system32\cryptnet.dll'
103328f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
103428f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef9230000 'C:\WINDOWS\system32\cryptnet.dll'
103528f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
103628f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef9230000 'C:\WINDOWS\system32\cryptnet.dll'
103728f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
103828f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef9230000 'C:\WINDOWS\system32\cryptnet.dll'
103928f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
104028f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef9230000 'C:\WINDOWS\system32\cryptnet.dll'
104128f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef9230000 'C:\WINDOWS\system32\cryptnet.dll'
104228f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
104328f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef9230000 'C:\WINDOWS\system32\cryptnet.dll'
104428f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=000000000023bc41:<flags> [calling]
104528f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdf40000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
104628f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\profapi.dll [lacks WinVerifyTrust]
104728f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\profapi.dll (Input=profapi.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000023bc41:<flags> [calling]
104828f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd780000 'C:\WINDOWS\system32\profapi.dll'
104928f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
105028f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
105128f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msvcrt.dll'.
105228f8.2aa4: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\shlwapi.dll)
105328f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\shlwapi.dll
105428f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
105528f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
105628f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
105728f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
105828f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
105928f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
106028f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
106128f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
106228f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
106328f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\SHLWAPI.dll (Input=SHLWAPI.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000023b6d1:<flags> [calling]
106428f8.2aa4: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll [lacks WinVerifyTrust]
106528f8.2aa4: supR3HardenedDllNotificationCallback: load 000007feffce0000 LB 0x00071000 C:\WINDOWS\system32\SHLWAPI.dll [fFlags=0x0]
106628f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll [lacks WinVerifyTrust]
106728f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feffce0000 'C:\WINDOWS\system32\SHLWAPI.dll'
106828f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000000 pwszName=\SystemRoot\System32\ntdll.dll
106928f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: New context 000000000082a990
107028f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
107128f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=9D7B2AF2FE56517E2ACF949E036476CC240908FE
107228f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=000000000023c601:<flags> [calling]
107328f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdf40000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
107428f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-Management-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=000000000023c161:<flags> [calling]
107528f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdf40000 'API-MS-WIN-Service-Management-L1-1-0.dll'
107628f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-winsvc-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=000000000023c161:<flags> [calling]
107728f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdf40000 'API-MS-WIN-Service-winsvc-L1-1-0.dll'
107828f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
107928f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\ADVAPI32.dll (Input=ADVAPI32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000023c601:<flags> [calling]
108028f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe940000 'C:\WINDOWS\system32\ADVAPI32.dll'
108128f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-LSALookup-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=000000000023c5b1:<flags> [calling]
108228f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdf40000 'API-MS-Win-Security-LSALookup-L1-1-0.dll'
108328f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-LSALookup-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=000000000023c2a1:<flags> [calling]
108428f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdf40000 'API-MS-Win-Security-LSALookup-L1-1-0.dll'
108528f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_139_for_KB3197868~31bf3856ad364e35~amd64~~6.1.1.5.cat'; file='\SystemRoot\System32\ntdll.dll'
108628f8.2aa4: g_pfnWinVerifyTrust=000007fefd891010
108728f8.2aa4: supR3HardenedScreenImage/preload: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [redoing WinVerifyTrust]
108828f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000e0 pwszName=\Device\HarddiskVolume2\Windows\System32\crypt32.dll
108928f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
109028f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
109128f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=3AF990F37D753AA60690FC7939ADB03EE893B58C
109228f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_300_for_KB3197868~31bf3856ad364e35~amd64~~6.1.1.5.cat'; file='\Device\HarddiskVolume2\Windows\System32\crypt32.dll'
109328f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
109428f8.2aa4: supR3HardenedScreenImage/preload: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\crypt32.dll'
109528f8.2aa4: supR3HardenedScreenImage/preload: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [redoing WinVerifyTrust]
109628f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000d4 pwszName=\Device\HarddiskVolume2\Windows\System32\wintrust.dll
109728f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
109828f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
109928f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=C8A284C43D9CD4E55273B385170EFA8FC455EB8C
110028f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_139_for_KB3197868~31bf3856ad364e35~amd64~~6.1.1.5.cat'; file='\Device\HarddiskVolume2\Windows\System32\wintrust.dll'
110128f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
110228f8.2aa4: supR3HardenedScreenImage/preload: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\wintrust.dll'
110328f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000003cc pwszName=\Device\HarddiskVolume2\Windows\System32\shlwapi.dll
110428f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
110528f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
110628f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=0AB8D9C9D3E1FC95D01F9A984B16ED031BB40CD8
110728f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\shlwapi.dll'
110828f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
110928f8.2aa4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll'
111028f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000003c0 pwszName=\Device\HarddiskVolume2\Windows\System32\Wldap32.dll
111128f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
111228f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
111328f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=87E73086F2528CF31D3AD5F0D71E04F8B942D5D8
111428f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\Wldap32.dll'
111528f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
111628f8.2aa4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\Wldap32.dll'
111728f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000003bc pwszName=\Device\HarddiskVolume2\Windows\System32\cryptnet.dll
111828f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
111928f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
112028f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=67EE3A294226F707ED5FD1E644414962E2DF2864
112128f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_139_for_KB3197868~31bf3856ad364e35~amd64~~6.1.1.5.cat'; file='\Device\HarddiskVolume2\Windows\System32\cryptnet.dll'
112228f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
112328f8.2aa4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\cryptnet.dll'
112428f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000027c pwszName=\Device\HarddiskVolume2\Windows\System32\gpapi.dll
112528f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
112628f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
112728f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=EBDAA16C3FD93DFF9C20BA3B2689DFF4C8D31061
112828f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_115_for_KB3159398~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\gpapi.dll'
112928f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
113028f8.2aa4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\gpapi.dll'
113128f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000001e8 pwszName=\Device\HarddiskVolume2\Windows\System32\profapi.dll
113228f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
113328f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
113428f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2449672745D9BA339420451D13FA0380AA768231
113528f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\profapi.dll'
113628f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
113728f8.2aa4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\profapi.dll'
113828f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000001e4 pwszName=\Device\HarddiskVolume2\Windows\System32\userenv.dll
113928f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
114028f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
114128f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=D3E1A2CC7367F751C19EBF4E6EDF5E9A10E47313
114228f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\userenv.dll'
114328f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
114428f8.2aa4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\userenv.dll'
114528f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000001c0 pwszName=\Device\HarddiskVolume2\Windows\System32\ncrypt.dll
114628f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
114728f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
114828f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=6BB6B4B9063A10A5AC1EDE35F603A79C0421DC1D
114928f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_139_for_KB3197868~31bf3856ad364e35~amd64~~6.1.1.5.cat'; file='\Device\HarddiskVolume2\Windows\System32\ncrypt.dll'
115028f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
115128f8.2aa4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\ncrypt.dll'
115228f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000001a8 pwszName=\Device\HarddiskVolume2\Windows\System32\msctf.dll
115328f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
115428f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
115528f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=6D141A0C50E469CDD81DC8293CF8B3635FE0240E
115628f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_139_for_KB3197868~31bf3856ad364e35~amd64~~6.1.1.5.cat'; file='\Device\HarddiskVolume2\Windows\System32\msctf.dll'
115728f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
115828f8.2aa4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\msctf.dll'
115928f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000001a4 pwszName=\Device\HarddiskVolume2\Windows\System32\imm32.dll
116028f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
116128f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
116228f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=6EEE1AB3B6D79AFF857940FF5F51ED27698153EC
116328f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\imm32.dll'
116428f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
116528f8.2aa4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\imm32.dll'
116628f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000001a0 pwszName=\Device\HarddiskVolume2\Windows\System32\usp10.dll
116728f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
116828f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
116928f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=31498ABFB06219E83141E0AA8B2A55C4CECFD033
117028f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3108670~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\Windows\System32\usp10.dll'
117128f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
117228f8.2aa4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\usp10.dll'
117328f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000019c pwszName=\Device\HarddiskVolume2\Windows\System32\lpk.dll
117428f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
117528f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
117628f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=6476128ECFCCBBE98E9D88478BD4355574A990C2
117728f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_139_for_KB3197868~31bf3856ad364e35~amd64~~6.1.1.5.cat'; file='\Device\HarddiskVolume2\Windows\System32\lpk.dll'
117828f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
117928f8.2aa4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\lpk.dll'
118028f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000198 pwszName=\Device\HarddiskVolume2\Windows\System32\gdi32.dll
118128f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
118228f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
118328f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=C26B6C5525D45228994D185B3C08A3BC03FF6AFF
118428f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3164035~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\gdi32.dll'
118528f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
118628f8.2aa4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\gdi32.dll'
118728f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000194 pwszName=\Device\HarddiskVolume2\Windows\System32\user32.dll
118828f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
118928f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
119028f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=A50DB67CFDA2B98A4E5A869EC667DB8F8F0786A5
119128f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3185911~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\Windows\System32\user32.dll'
119228f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
119328f8.2aa4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\user32.dll'
119428f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000190 pwszName=\Device\HarddiskVolume2\Windows\System32\imagehlp.dll
119528f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
119628f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
119728f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2702EE05F1B717B0F2CE0FBE32784A47B8419DCA
119828f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_2_for_KB2893294~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\imagehlp.dll'
119928f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
120028f8.2aa4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\imagehlp.dll'
120128f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000134 pwszName=\Device\HarddiskVolume2\Windows\System32\cryptbase.dll
120228f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
120328f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
120428f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=0E413B883493D97795E0B55A38CBE79167A5930B
120528f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_139_for_KB3197868~31bf3856ad364e35~amd64~~6.1.1.5.cat'; file='\Device\HarddiskVolume2\Windows\System32\cryptbase.dll'
120628f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
120728f8.2aa4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\cryptbase.dll'
120828f8.2aa4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\rsaenh.dll'
120928f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000130 pwszName=\Device\HarddiskVolume2\Windows\System32\cryptsp.dll
121028f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
121128f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
121228f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=CECCA98E04985A576883E9A9AD8AF2140526B576
121328f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_139_for_KB3197868~31bf3856ad364e35~amd64~~6.1.1.5.cat'; file='\Device\HarddiskVolume2\Windows\System32\cryptsp.dll'
121428f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
121528f8.2aa4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\cryptsp.dll'
121628f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000120 pwszName=\Device\HarddiskVolume2\Windows\System32\sechost.dll
121728f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
121828f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
121928f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=CB669FA8DB80F8E50A29D055BB8D558E10E5E6B4
122028f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_85_for_KB3068708~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\Windows\System32\sechost.dll'
122128f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
122228f8.2aa4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\sechost.dll'
122328f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000011c pwszName=\Device\HarddiskVolume2\Windows\System32\advapi32.dll
122428f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
122528f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
122628f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=E4EE697F80E721EB7360DB40DCE1F1FD473FD915
122728f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_303_for_KB3197868~31bf3856ad364e35~amd64~~6.1.1.5.cat'; file='\Device\HarddiskVolume2\Windows\System32\advapi32.dll'
122828f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
122928f8.2aa4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\advapi32.dll'
123028f8.2aa4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll'
123128f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000104 pwszName=\Device\HarddiskVolume2\Windows\System32\bcrypt.dll
123228f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
123328f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
123428f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=62E377A1F0AD0C2EDC0A73CB3EFF841FF18D00D2
123528f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\bcrypt.dll'
123628f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
123728f8.2aa4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\bcrypt.dll'
123828f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000e4 pwszName=\Device\HarddiskVolume2\Windows\System32\msvcrt.dll
123928f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
124028f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
124128f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2CA2FD632B264C063162F71474266E3615B6420C
124228f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB2654428~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\Windows\System32\msvcrt.dll'
124328f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
124428f8.2aa4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll'
124528f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000dc pwszName=\Device\HarddiskVolume2\Windows\System32\msasn1.dll
124628f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
124728f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
124828f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=F2FF57DC30D774F93061607060DAA0DD15E39CCE
124928f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\msasn1.dll'
125028f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
125128f8.2aa4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\msasn1.dll'
125228f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000d8 pwszName=\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
125328f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
125428f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
125528f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=CB69D2586C4D23312076E677AE166F560B92B6EE
125628f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_139_for_KB3197868~31bf3856ad364e35~amd64~~6.1.1.5.cat'; file='\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll'
125728f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
125828f8.2aa4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll'
125928f8.2aa4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\local\apps\Virtualbox\VBoxSupLib.dll'
126028f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000028 pwszName=\Device\HarddiskVolume2\Windows\System32\KernelBase.dll
126128f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
126228f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
126328f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=6DDE3D8D254B3D658CFEA97EBCA8B1609224CF94
126428f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_139_for_KB3197868~31bf3856ad364e35~amd64~~6.1.1.5.cat'; file='\Device\HarddiskVolume2\Windows\System32\KernelBase.dll'
126528f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
126628f8.2aa4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\KernelBase.dll'
126728f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000020 pwszName=\Device\HarddiskVolume2\Windows\System32\kernel32.dll
126828f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
126928f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
127028f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=7A6110AE55384DC5D9B4DD697AE74FC7E61FF36D
127128f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_139_for_KB3197868~31bf3856ad364e35~amd64~~6.1.1.5.cat'; file='\Device\HarddiskVolume2\Windows\System32\kernel32.dll'
127228f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
127328f8.2aa4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\kernel32.dll'
127428f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll
127528f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\crypt32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000023c0b1:<flags> [calling]
127628f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd9b0000 'C:\WINDOWS\system32\crypt32.dll'
127728f8.2aa4: supR3HardenedWinIsDesiredRootCA: Adding 0x78cb9f45f57dbc00 CN=WSUS Publishers Self-signed
127828f8.2aa4: supR3HardenedWinIsDesiredRootCA: Adding 0x5ad46780fa5df300 DC=com, DC=microsoft, CN=Microsoft Root Certificate Authority
127928f8.2aa4: supR3HardenedWinIsDesiredRootCA: Adding 0xea5386456178582b C=ZA, ST=Western Cape, L=Durbanville, O=Thawte, OU=Thawte Certification, CN=Thawte Timestamping CA
128028f8.2aa4: supR3HardenedWinIsDesiredRootCA: Adding 0x3be670c1bd02a900 OU=Copyright (c) 1997 Microsoft Corp., OU=Microsoft Corporation, CN=Microsoft Root Authority
128128f8.2aa4: supR3HardenedWinIsDesiredRootCA: Adding 0x2fb3137a2f3fd32f C=US, O=OpenDNS Global Network, CN=OpenDNS 2016 CA
128228f8.2aa4: supR3HardenedWinIsDesiredRootCA: Adding 0x4d3835aa4180b200 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2011
128328f8.2aa4: supR3HardenedWinIsDesiredRootCA: Adding 0x6ded11c97009a300 CN=BSkyB Root CA
128428f8.2aa4: supR3HardenedWinIsDesiredRootCA: Adding 0x646e3fe3ba08df00 C=US, O=MSFT, CN=Microsoft Authenticode(tm) Root Authority
128528f8.2aa4: supR3HardenedWinIsDesiredRootCA: Adding 0x3304182dc45346cd C=US, O=OpenDNS Global Network, CN=OpenDNS 2015 CA
128628f8.2aa4: supR3HardenedWinIsDesiredRootCA: Adding 0x566d870f5916c400 C=US, O=OpenDNS Global Network, CN=OpenDNS CA
128728f8.2aa4: supR3HardenedWinIsDesiredRootCA: Adding 0xece4e4289e08b900 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010
128828f8.2aa4: supR3HardenedWinIsDesiredRootCA: Adding 0x43a9cc371ff5385a O=Microsoft Trust Network, OU=Microsoft Corporation, OU=Microsoft Time Stamping Service Root, OU=Copyright (c) 1997 Microsoft Corp.
128928f8.2aa4: supR3HardenedWinIsDesiredRootCA: Adding 0x2e2d2c7c68f0202e O=VeriSign Trust Network, OU=VeriSign, Inc., OU=VeriSign Time Stamping Service Root, OU=NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.
129028f8.2aa4: supR3HardenedWinIsDesiredRootCA: Adding 0xd8dbfb2c27bfb200 C=US, O=thawte, Inc., OU=Certification Services Division, OU=(c) 2008 thawte, Inc. - For authorized use only, CN=thawte Primary Root CA - G3
129128f8.2aa4: supR3HardenedWinIsDesiredRootCA: Adding 0x61a3a33f81aace00 C=US, ST=UT, L=Salt Lake City, O=The USERTRUST Network, OU=http://www.usertrust.com, CN=UTN-USERFirst-Object
129228f8.2aa4: supR3HardenedWinIsDesiredRootCA: Adding 0x57ba5395b561bf00 C=BM, O=QuoVadis Limited, OU=Root Certification Authority, CN=QuoVadis Root Certification Authority
129328f8.2aa4: supR3HardenedWinIsDesiredRootCA: Adding 0xf4fd306318ccda00 C=US, O=GeoTrust Inc., CN=GeoTrust Global CA
129428f8.2aa4: supR3HardenedWinIsDesiredRootCA: Adding 0x83085097e9afdf00 O=Digital Signature Trust Co., CN=DST Root CA X3
129528f8.2aa4: supR3HardenedWinIsDesiredRootCA: Adding 0x780679907625cc00 OU=GlobalSign Root CA - R3, O=GlobalSign, CN=GlobalSign
129628f8.2aa4: supR3HardenedWinIsDesiredRootCA: Adding 0x3d98ab22bb04a300 C=IE, O=Baltimore, OU=CyberTrust, CN=Baltimore CyberTrust Root
129728f8.2aa4: supR3HardenedWinIsDesiredRootCA: Adding 0xa0ee62086758b15d C=US, O=Equifax, OU=Equifax Secure Certificate Authority
129828f8.2aa4: supR3HardenedWinIsDesiredRootCA: Adding 0xd944bca189a00 C=BM, O=QuoVadis Limited, CN=QuoVadis Root CA 2
129928f8.2aa4: supR3HardenedWinIsDesiredRootCA: Adding 0x8ff6fc03c1edbd00 C=US, ST=Arizona, L=Scottsdale, O=Starfield Technologies, Inc., CN=Starfield Root Certificate Authority - G2
130028f8.2aa4: supR3HardenedWinIsDesiredRootCA: Adding 0xc6fa4243b695b600 C=US, O=Entrust, Inc., OU=www.entrust.net/CPS is incorporated by reference, OU=(c) 2006 Entrust, Inc., CN=Entrust Root Certification Authority
130128f8.2aa4: supR3HardenedWinIsDesiredRootCA: Adding 0xa3ce8d99e60eda00 C=BE, O=GlobalSign nv-sa, OU=Root CA, CN=GlobalSign Root CA
130228f8.2aa4: supR3HardenedWinIsDesiredRootCA: Adding 0x560ad29254e89100 C=GB, ST=Greater Manchester, L=Salford, O=COMODO CA Limited, CN=COMODO RSA Certification Authority
130328f8.2aa4: supR3HardenedWinIsDesiredRootCA: Adding 0xa671e9fec832b700 C=US, O=Starfield Technologies, Inc., OU=Starfield Class 2 Certification Authority
130428f8.2aa4: supR3HardenedWinIsDesiredRootCA: Adding 0xa8de7211e13be200 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root CA
130528f8.2aa4: supR3HardenedWinIsDesiredRootCA: Adding 0x7ae89c50f0b6a00f C=US, O=GTE Corporation, OU=GTE CyberTrust Solutions, Inc., CN=GTE CyberTrust Global Root
130628f8.2aa4: supR3HardenedWinIsDesiredRootCA: Adding 0xd45980fbf0a0ac00 C=US, O=thawte, Inc., OU=Certification Services Division, OU=(c) 2006 thawte, Inc. - For authorized use only, CN=thawte Primary Root CA
130728f8.2aa4: supR3HardenedWinIsDesiredRootCA: Adding 0xc9edb72b684ba00 C=US, O=Entrust, Inc., OU=See www.entrust.net/legal-terms, OU=(c) 2009 Entrust, Inc. - for authorized use only, CN=Entrust Root Certification Authority - G2
130828f8.2aa4: supR3HardenedWinIsDesiredRootCA: Adding 0xf5cd95e581a4ab00 C=US, O=SecureTrust Corporation, CN=SecureTrust CA
130928f8.2aa4: supR3HardenedWinIsDesiredRootCA: Adding 0x14018a1bf29e595c C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority
131028f8.2aa4: supR3HardenedWinIsDesiredRootCA: Adding 0x9e5bc2d78b6a3636 C=ZA, ST=Western Cape, L=Cape Town, O=Thawte Consulting cc, OU=Certification Services Division, CN=Thawte Premium Server CA, Email=premium-server@thawte.com
131128f8.2aa4: supR3HardenedWinIsDesiredRootCA: Adding 0x7c4fd32ec1b1ce00 C=PL, O=Unizeto Sp. z o.o., CN=Certum CA
131228f8.2aa4: supR3HardenedWinIsDesiredRootCA: Adding 0xd4fbe673e5ccc600 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA
131328f8.2aa4: supR3HardenedWinIsDesiredRootCA: Adding 0x16e64d2a56ccf200 C=US, ST=Arizona, L=Scottsdale, O=Starfield Technologies, Inc., OU=http://certificates.starfieldtech.com/repository/, CN=Starfield Services Root Certificate Authority
131428f8.2aa4: supR3HardenedWinIsDesiredRootCA: Adding 0xb28612a94b4dad00 O=Entrust.net, OU=www.entrust.net/CPS_2048 incorp. by ref. (limits liab.), OU=(c) 1999 Entrust.net Limited, CN=Entrust.net Certification Authority (2048)
131528f8.2aa4: supR3HardenedWinIsDesiredRootCA: Adding 0x357a29080824af00 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2006 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G5
131628f8.2aa4: supR3HardenedWinIsDesiredRootCA: Adding 0x59faf1086271bf00 C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com, Inc., CN=Go Daddy Root Certificate Authority - G2
131728f8.2aa4: supR3HardenedWinIsDesiredRootCA: Adding 0x466cbc09db88c100 C=IL, O=StartCom Ltd., OU=Secure Digital Certificate Signing, CN=StartCom Certification Authority
131828f8.2aa4: supR3HardenedWinIsDesiredRootCA: Adding 0x3401b15e3761c700 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2008 VeriSign, Inc. - For authorized use only, CN=VeriSign Universal Root Certification Authority
131928f8.2aa4: supR3HardenedWinIsDesiredRootCA: Adding 0x7cd4ff7b15b8be00 C=US, O=GeoTrust Inc., CN=GeoTrust Primary Certification Authority
132028f8.2aa4: supR3HardenedWinIsDesiredRootCA: Adding 0x491857ead79dde00 C=US, O=The Go Daddy Group, Inc., OU=Go Daddy Class 2 Certification Authority
132128f8.2aa4: supR3HardenedWinIsDesiredRootCA: Adding 0xc2ba72a37dfbe300 C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Trusted Network CA
132228f8.2aa4: supR3HardenedWinIsDesiredRootCA: Adding 0x8043e4ce150ead00 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID Root CA
132328f8.2aa4: supR3HardenedWinIsDesiredRootCA: Adding 0x331d58625ee2dc00 C=US, O=GeoTrust Inc., OU=(c) 2008 GeoTrust Inc. - For authorized use only, CN=GeoTrust Primary Certification Authority - G3
132428f8.2aa4: supR3HardenedWinIsDesiredRootCA: Adding 0xf2e6331af7b700 C=SE, O=AddTrust AB, OU=AddTrust External TTP Network, CN=AddTrust External CA Root
132528f8.2aa4: supR3HardenedWinIsDesiredRootCA: Adding 0x6ded11c97009a300 CN=BSkyB Root CA
132628f8.2aa4: supR3HardenedWinIsDesiredRootCA: Adding 0xe22ff11422069400 C=GB, O=SkyBet, OU=PKI, CN=SBROOTCA
132728f8.2aa4: supR3HardenedWinIsDesiredRootCA: Adding 0x6ded11c97009a300 CN=BSkyB Root CA
132828f8.2aa4: supR3HardenedWinIsDesiredRootCA: Adding 0x7594ebb1f606bb00 CN=NEW-BSKYB-ROOTCA
132928f8.2aa4: supR3HardenedWinRetrieveTrustedRootCAs: cAdded=52
133028f8.2aa4: SUPR3HardenedMain: Load Runtime...
133128f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
133228f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
133328f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ws2_32.dll'.
133428f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'rpcrt4.dll'.
133528f8.2aa4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\local\apps\Virtualbox\VBoxRT.dll) WinVerifyTrust
133628f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxRT.dll
133728f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
133828f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
133928f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
134028f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
134128f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
134228f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000468 pwszName=\Device\HarddiskVolume2\Windows\System32\ws2_32.dll
134328f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
134428f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
134528f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=901DCB8172024F14E25295BF5692180F12FC8C18
134628f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3161949~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\Windows\System32\ws2_32.dll'
134728f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
134828f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
134928f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'rpcrt4.dll'.
135028f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'nsi.dll'.
135128f8.2aa4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ws2_32.dll) WinVerifyTrust
135228f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
135328f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
135428f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\msvcp100.dll' [rcNtRedir=0xc0150008]
135528f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
135628f8.2aa4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\local\apps\Virtualbox\msvcp100.dll) WinVerifyTrust
135728f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\local\apps\Virtualbox\msvcp100.dll
135828f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
135928f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
136028f8.2aa4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\local\apps\Virtualbox\msvcr100.dll) WinVerifyTrust
136128f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\local\apps\Virtualbox\msvcr100.dll
136228f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
136328f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
136428f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\msvcr100.dll
136528f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
136628f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume2\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
136728f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000046c pwszName=\Device\HarddiskVolume2\Windows\System32\nsi.dll
136828f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
136928f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
137028f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=7AFD8538945F2D05BC1AF949B9B19B7D2D9FBBF8
137128f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\nsi.dll'
137228f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
137328f8.2aa4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\nsi.dll) WinVerifyTrust
137428f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\nsi.dll
137528f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
137628f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
137728f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
137828f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
137928f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
138028f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
138128f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\local\apps\Virtualbox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000023c3d1:<flags> [calling]
138228f8.2aa4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxRT.dll
138328f8.2aa4: supR3HardenedDllNotificationCallback: load 000007fee7fe0000 LB 0x00527000 C:\local\apps\Virtualbox\VBoxRT.dll [fFlags=0x0]
138428f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxRT.dll
138528f8.2aa4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\msvcr100.dll
138628f8.2aa4: supR3HardenedDllNotificationCallback: load 0000000051a70000 LB 0x000d2000 C:\local\apps\Virtualbox\MSVCR100.dll [fFlags=0x0]
138728f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\msvcr100.dll
138828f8.2aa4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\msvcp100.dll
138928f8.2aa4: supR3HardenedDllNotificationCallback: load 00000000519d0000 LB 0x00098000 C:\local\apps\Virtualbox\MSVCP100.dll [fFlags=0x0]
139028f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\msvcp100.dll
139128f8.2aa4: supR3HardenedDllNotificationCallback: load 000007fefead0000 LB 0x0004d000 C:\WINDOWS\system32\WS2_32.dll [fFlags=0x0]
139228f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
139328f8.2aa4: supR3HardenedDllNotificationCallback: load 000007fefea50000 LB 0x00008000 C:\WINDOWS\system32\NSI.dll [fFlags=0x0]
139428f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\nsi.dll
139528f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxRT.dll
139628f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\local\apps\Virtualbox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000239b11:<flags> [calling]
139728f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7fe0000 'C:\local\apps\Virtualbox\VBoxRT.dll'
139828f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxRT.dll
139928f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\local\apps\Virtualbox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000239b11:<flags> [calling]
140028f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7fe0000 'C:\local\apps\Virtualbox\VBoxRT.dll'
140128f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxRT.dll
140228f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\local\apps\Virtualbox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000239b11:<flags> [calling]
140328f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7fe0000 'C:\local\apps\Virtualbox\VBoxRT.dll'
140428f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxRT.dll
140528f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\local\apps\Virtualbox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000239b11:<flags> [calling]
140628f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7fe0000 'C:\local\apps\Virtualbox\VBoxRT.dll'
140728f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxRT.dll
140828f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\local\apps\Virtualbox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000239b11:<flags> [calling]
140928f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7fe0000 'C:\local\apps\Virtualbox\VBoxRT.dll'
141028f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxRT.dll
141128f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\local\apps\Virtualbox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000239b11:<flags> [calling]
141228f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7fe0000 'C:\local\apps\Virtualbox\VBoxRT.dll'
141328f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7fe0000 'C:\local\apps\Virtualbox\VBoxRT.dll'
141428f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7fe0000 'C:\local\apps\Virtualbox\VBoxRT.dll'
141528f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7fe0000 'C:\local\apps\Virtualbox\VBoxRT.dll'
141628f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7fe0000 'C:\local\apps\Virtualbox\VBoxRT.dll'
141728f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7fe0000 'C:\local\apps\Virtualbox\VBoxRT.dll'
141828f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7fe0000 'C:\local\apps\Virtualbox\VBoxRT.dll'
141928f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7fe0000 'C:\local\apps\Virtualbox\VBoxRT.dll'
142028f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxRT.dll
142128f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\local\apps\Virtualbox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000239b11:<flags> [calling]
142228f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7fe0000 'C:\local\apps\Virtualbox\VBoxRT.dll'
142328f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7fe0000 'C:\local\apps\Virtualbox\VBoxRT.dll'
142428f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7fe0000 'C:\local\apps\Virtualbox\VBoxRT.dll'
142528f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7fe0000 'C:\local\apps\Virtualbox\VBoxRT.dll'
142628f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7fe0000 'C:\local\apps\Virtualbox\VBoxRT.dll'
142728f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7fe0000 'C:\local\apps\Virtualbox\VBoxRT.dll'
142828f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7fe0000 'C:\local\apps\Virtualbox\VBoxRT.dll'
142928f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7fe0000 'C:\local\apps\Virtualbox\VBoxRT.dll'
143028f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7fe0000 'C:\local\apps\Virtualbox\VBoxRT.dll'
143128f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7fe0000 'C:\local\apps\Virtualbox\VBoxRT.dll'
143228f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7fe0000 'C:\local\apps\Virtualbox\VBoxRT.dll'
143328f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7fe0000 'C:\local\apps\Virtualbox\VBoxRT.dll'
143428f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7fe0000 'C:\local\apps\Virtualbox\VBoxRT.dll'
143528f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7fe0000 'C:\local\apps\Virtualbox\VBoxRT.dll'
143628f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7fe0000 'C:\local\apps\Virtualbox\VBoxRT.dll'
143728f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7fe0000 'C:\local\apps\Virtualbox\VBoxRT.dll'
143828f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxRT.dll
143928f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\local\apps\Virtualbox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000239b11:<flags> [calling]
144028f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7fe0000 'C:\local\apps\Virtualbox\VBoxRT.dll'
144128f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7fe0000 'C:\local\apps\Virtualbox\VBoxRT.dll'
144228f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7fe0000 'C:\local\apps\Virtualbox\VBoxRT.dll'
144328f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7fe0000 'C:\local\apps\Virtualbox\VBoxRT.dll'
144428f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll
144528f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000023df31:<flags> [calling]
144628f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd890000 'C:\WINDOWS\system32\Wintrust.dll'
144728f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll
144828f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\crypt32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000023ca91:<flags> [calling]
144928f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd9b0000 'C:\WINDOWS\system32\crypt32.dll'
145028f8.2aa4: SUPR3HardenedMain: Load TrustedMain...
145128f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'opengl32.dll'.
145228f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
145328f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msvcp100.dll'.
145428f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcr100.dll'.
145528f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qt5corevbox.dll'.
145628f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'qt5guivbox.dll'.
145728f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'qt5widgetsvbox.dll'.
145828f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'qt5printsupportvbox.dll'.
145928f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'qt5openglvbox.dll'.
146028f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'user32.dll'.
146128f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'advapi32.dll'.
146228f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'shell32.dll'.
146328f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'ole32.dll'.
146428f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'oleaut32.dll'.
146528f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #15 'winmm.dll'.
146628f8.2aa4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\local\apps\Virtualbox\VirtualBox.dll) WinVerifyTrust
146728f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\local\apps\Virtualbox\VirtualBox.dll
146828f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
146928f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
147028f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004d0 pwszName=\Device\HarddiskVolume2\Windows\System32\winmm.dll
147128f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
147228f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
147328f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=82E2B2A7826F88BEB98FFF0540C9BDB0A12F001A
147428f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\winmm.dll'
147528f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
147628f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
147728f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
147828f8.2aa4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\winmm.dll) WinVerifyTrust
147928f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\winmm.dll
148028f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
148128f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
148228f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004b0 pwszName=\Device\HarddiskVolume2\Windows\System32\oleaut32.dll
148328f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
148428f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
148528f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=6C3B3967CA9D3D145651C5098BAF1C0EA892DB24
148628f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_139_for_KB3197868~31bf3856ad364e35~amd64~~6.1.1.5.cat'; file='\Device\HarddiskVolume2\Windows\System32\oleaut32.dll'
148728f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
148828f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ole32.dll'.
148928f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
149028f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
149128f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'user32.dll'.
149228f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'gdi32.dll'.
149328f8.2aa4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\oleaut32.dll) WinVerifyTrust
149428f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
149528f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
149628f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
149728f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004c4 pwszName=\Device\HarddiskVolume2\Windows\System32\ole32.dll
149828f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
149928f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
150028f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=796B1965C19A0614793EA3630408324B2CFA32D2
150128f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_87_for_KB3146706~31bf3856ad364e35~amd64~~6.1.1.2.cat'; file='\Device\HarddiskVolume2\Windows\System32\ole32.dll'
150228f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
150328f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
150428f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
150528f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'user32.dll'.
150628f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'rpcrt4.dll'.
150728f8.2aa4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ole32.dll) WinVerifyTrust
150828f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ole32.dll
150928f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
151028f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
151128f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004dc pwszName=\Device\HarddiskVolume2\Windows\System32\shell32.dll
151228f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
151328f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
151428f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=F13C2B4E594038A8834146A1D81AAE9B43ED8649
151528f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_41_for_KB3184143~31bf3856ad364e35~amd64~~6.1.1.4.cat'; file='\Device\HarddiskVolume2\Windows\System32\shell32.dll'
151628f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
151728f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
151828f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #21 'shlwapi.dll'.
151928f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'user32.dll'.
152028f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #24 'gdi32.dll'.
152128f8.2aa4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\shell32.dll) WinVerifyTrust
152228f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\shell32.dll
152328f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
152428f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
152528f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
152628f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
152728f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
152828f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5openglvbox.dll'...
152928f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5openglvbox.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\qt5openglvbox.dll' [rcNtRedir=0xc0150008]
153028f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'qt5widgetsvbox.dll'.
153128f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'qt5guivbox.dll'.
153228f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5corevbox.dll'.
153328f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcr100.dll'.
153428f8.2aa4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\local\apps\Virtualbox\Qt5OpenGLVBox.dll) WinVerifyTrust
153528f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\local\apps\Virtualbox\Qt5OpenGLVBox.dll
153628f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5printsupportvbox.dll'...
153728f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5printsupportvbox.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\qt5printsupportvbox.dll' [rcNtRedir=0xc0150008]
153828f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
153928f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
154028f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5widgetsvbox.dll'.
154128f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qt5guivbox.dll'.
154228f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qt5corevbox.dll'.
154328f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'winspool.drv'.
154428f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'comdlg32.dll'.
154528f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'msvcr100.dll'.
154628f8.2aa4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\local\apps\Virtualbox\Qt5PrintSupportVBox.dll) WinVerifyTrust
154728f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\local\apps\Virtualbox\Qt5PrintSupportVBox.dll
154828f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
154928f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
155028f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
155128f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
155228f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5guivbox.dll'.
155328f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qt5corevbox.dll'.
155428f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'shell32.dll'.
155528f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcp100.dll'.
155628f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msvcr100.dll'.
155728f8.2aa4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\local\apps\Virtualbox\Qt5WidgetsVBox.dll) WinVerifyTrust
155828f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\local\apps\Virtualbox\Qt5WidgetsVBox.dll
155928f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
156028f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
156128f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ole32.dll'.
156228f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'opengl32.dll'.
156328f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
156428f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
156528f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qt5corevbox.dll'.
156628f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcp100.dll'.
156728f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msvcr100.dll'.
156828f8.2aa4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\local\apps\Virtualbox\Qt5GuiVBox.dll) WinVerifyTrust
156928f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\local\apps\Virtualbox\Qt5GuiVBox.dll
157028f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
157128f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
157228f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
157328f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'shell32.dll'.
157428f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ole32.dll'.
157528f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
157628f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ws2_32.dll'.
157728f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'mpr.dll'.
157828f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'msvcp100.dll'.
157928f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'msvcr100.dll'.
158028f8.2aa4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\local\apps\Virtualbox\Qt5CoreVBox.dll) WinVerifyTrust
158128f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\local\apps\Virtualbox\Qt5CoreVBox.dll
158228f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
158328f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
158428f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\msvcr100.dll
158528f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
158628f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\msvcp100.dll' [rcNtRedir=0xc0150008]
158728f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\msvcp100.dll
158828f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
158928f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\vboxrt.dll' [rcNtRedir=0xc0150008]
159028f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
159128f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
159228f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000508 pwszName=\Device\HarddiskVolume2\Windows\System32\opengl32.dll
159328f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
159428f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
159528f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=608AC397FCC42B9FBAE25CB8C25EAF4C19AA384D
159628f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\opengl32.dll'
159728f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
159828f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
159928f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
160028f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'gdi32.dll'.
160128f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'glu32.dll'.
160228f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'ddraw.dll'.
160328f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'user32.dll'.
160428f8.2aa4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\opengl32.dll) WinVerifyTrust
160528f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\opengl32.dll
160628f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
160728f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
160828f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ddraw.dll'...
160928f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ddraw.dll' -> '\Device\HarddiskVolume2\Windows\System32\ddraw.dll' [rcNtRedir=0xc0150008]
161028f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004fc pwszName=\Device\HarddiskVolume2\Windows\System32\ddraw.dll
161128f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
161228f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
161328f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=24C763EA54CD792A0F1618411061DC356EE31FF6
161428f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\ddraw.dll'
161528f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
161628f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
161728f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
161828f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'dciman32.dll'.
161928f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
162028f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'setupapi.dll'.
162128f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'dwmapi.dll'.
162228f8.2aa4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ddraw.dll) WinVerifyTrust
162328f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ddraw.dll
162428f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'glu32.dll'...
162528f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'glu32.dll' -> '\Device\HarddiskVolume2\Windows\System32\glu32.dll' [rcNtRedir=0xc0150008]
162628f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000500 pwszName=\Device\HarddiskVolume2\Windows\System32\glu32.dll
162728f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
162828f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
162928f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=60E45AB914E06A11F44EA76C6EF750AF892F9EA2
163028f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\glu32.dll'
163128f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
163228f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
163328f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'opengl32.dll'.
163428f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
163528f8.2aa4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\glu32.dll) WinVerifyTrust
163628f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\glu32.dll
163728f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
163828f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
163928f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll
164028f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
164128f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
164228f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
164328f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
164428f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
164528f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
164628f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
164728f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\msvcr100.dll
164828f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
164928f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\msvcp100.dll' [rcNtRedir=0xc0150008]
165028f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\msvcp100.dll
165128f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mpr.dll'...
165228f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'mpr.dll' -> '\Device\HarddiskVolume2\Windows\System32\mpr.dll' [rcNtRedir=0xc0150008]
165328f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000518 pwszName=\Device\HarddiskVolume2\Windows\System32\mpr.dll
165428f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
165528f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
165628f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=F84FE9BA047B24E7694C9E0C349B48B9FD5F925B
165728f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\mpr.dll'
165828f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
165928f8.2aa4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\mpr.dll) WinVerifyTrust
166028f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\mpr.dll
166128f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
166228f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
166328f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
166428f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
166528f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
166628f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
166728f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
166828f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
166928f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
167028f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
167128f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
167228f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
167328f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
167428f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
167528f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
167628f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
167728f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\msvcr100.dll
167828f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
167928f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\msvcp100.dll' [rcNtRedir=0xc0150008]
168028f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\msvcp100.dll
168128f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
168228f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
168328f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\Qt5CoreVBox.dll
168428f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
168528f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
168628f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
168728f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
168828f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
168928f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
169028f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
169128f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
169228f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
169328f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
169428f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
169528f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
169628f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\msvcr100.dll
169728f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
169828f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\msvcp100.dll' [rcNtRedir=0xc0150008]
169928f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\msvcp100.dll
170028f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
170128f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
170228f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
170328f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
170428f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
170528f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\Qt5CoreVBox.dll
170628f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
170728f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
170828f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\Qt5GuiVBox.dll
170928f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
171028f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
171128f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
171228f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
171328f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
171428f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
171528f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\msvcr100.dll
171628f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comdlg32.dll'...
171728f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'comdlg32.dll' -> '\Device\HarddiskVolume2\Windows\System32\comdlg32.dll' [rcNtRedir=0xc0150008]
171828f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000524 pwszName=\Device\HarddiskVolume2\Windows\System32\comdlg32.dll
171928f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
172028f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
172128f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=66EE5BDFFA413AEA9E1FE7838A08646E94136DA5
172228f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\comdlg32.dll'
172328f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
172428f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
172528f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'shlwapi.dll'.
172628f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
172728f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'gdi32.dll'.
172828f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'comctl32.dll'.
172928f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'shell32.dll'.
173028f8.2aa4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\comdlg32.dll) WinVerifyTrust
173128f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\comdlg32.dll
173228f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winspool.drv'...
173328f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'winspool.drv' -> '\Device\HarddiskVolume2\Windows\System32\winspool.drv' [rcNtRedir=0xc0150008]
173428f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000528 pwszName=\Device\HarddiskVolume2\Windows\System32\winspool.drv
173528f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
173628f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
173728f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=C89A2ED7B99A056D78CA6BAC9CCAB8B1FF119A14
173828f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\winspool.drv'
173928f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
174028f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
174128f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
174228f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
174328f8.2aa4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\winspool.drv) WinVerifyTrust
174428f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\winspool.drv
174528f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
174628f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
174728f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\Qt5CoreVBox.dll
174828f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
174928f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
175028f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\Qt5GuiVBox.dll
175128f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
175228f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
175328f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\Qt5WidgetsVBox.dll
175428f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
175528f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
175628f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
175728f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
175828f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
175928f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
176028f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
176128f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
176228f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\Qt5CoreVBox.dll
176328f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
176428f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
176528f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\Qt5GuiVBox.dll
176628f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
176728f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
176828f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\Qt5WidgetsVBox.dll
176928f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
177028f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
177128f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
177228f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
177328f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
177428f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
177528f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll
177628f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
177728f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
177828f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
177928f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
178028f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
178128f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
178228f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll
178328f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
178428f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
178528f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
178628f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
178728f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
178828f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
178928f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
179028f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
179128f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
179228f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
179328f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
179428f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
179528f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
179628f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
179728f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
179828f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
179928f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
180028f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
180128f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
180228f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
180328f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
180428f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
180528f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
180628f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
180728f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
180828f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
180928f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
181028f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
181128f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comctl32.dll'...
181228f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'comctl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\comctl32.dll' [rcNtRedir=0x0]
181328f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000051c pwszName=\Device\HarddiskVolume2\Windows\System32\comctl32.dll
181428f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
181528f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
181628f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=761964761EE466757E306124E042F4C2ACBEA092
181728f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3059317~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\Windows\System32\comctl32.dll'
181828f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
181928f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'advapi32.dll'.
182028f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
182128f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
182228f8.2aa4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\comctl32.dll) WinVerifyTrust
182328f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\comctl32.dll
182428f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
182528f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
182628f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll
182728f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
182828f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
182928f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
183028f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
183128f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll
183228f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
183328f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
183428f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
183528f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
183628f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
183728f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
183828f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
183928f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
184028f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
184128f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dwmapi.dll'...
184228f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'dwmapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\dwmapi.dll' [rcNtRedir=0xc0150008]
184328f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000530 pwszName=\Device\HarddiskVolume2\Windows\System32\dwmapi.dll
184428f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
184528f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
184628f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=F3F3D4867E9140896E0742D7EE8AE1D01FE85ECE
184728f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3078667~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\Windows\System32\dwmapi.dll'
184828f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
184928f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
185028f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
185128f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
185228f8.2aa4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\dwmapi.dll) WinVerifyTrust
185328f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\dwmapi.dll
185428f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
185528f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
185628f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000052c pwszName=\Device\HarddiskVolume2\Windows\System32\setupapi.dll
185728f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
185828f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
185928f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=1499C4FEA6E143F9BEC35B4FFA098917D3A6EBF2
186028f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\setupapi.dll'
186128f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
186228f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'cfgmgr32.dll'.
186328f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msvcrt.dll'.
186428f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'gdi32.dll'.
186528f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
186628f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'user32.dll'.
186728f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'oleaut32.dll'.
186828f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'devobj.dll'.
186928f8.2aa4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\setupapi.dll) WinVerifyTrust
187028f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\setupapi.dll
187128f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
187228f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
187328f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dciman32.dll'...
187428f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'dciman32.dll' -> '\Device\HarddiskVolume2\Windows\System32\dciman32.dll' [rcNtRedir=0xc0150008]
187528f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000540 pwszName=\Device\HarddiskVolume2\Windows\System32\dciman32.dll
187628f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
187728f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
187828f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=31A74D9F0CD6EDF8FC5A0A644C3B997ABF30083E
187928f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_139_for_KB3197868~31bf3856ad364e35~amd64~~6.1.1.5.cat'; file='\Device\HarddiskVolume2\Windows\System32\dciman32.dll'
188028f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
188128f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
188228f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'gdi32.dll'.
188328f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
188428f8.2aa4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\dciman32.dll) WinVerifyTrust
188528f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\dciman32.dll
188628f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
188728f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
188828f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
188928f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
189028f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
189128f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
189228f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
189328f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
189428f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
189528f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
189628f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'devobj.dll'...
189728f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'devobj.dll' -> '\Device\HarddiskVolume2\Windows\System32\devobj.dll' [rcNtRedir=0xc0150008]
189828f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000548 pwszName=\Device\HarddiskVolume2\Windows\System32\devobj.dll
189928f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
190028f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
190128f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B410A095222E69F0ECE7D66E4AC27A7125D2EB5A
190228f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\devobj.dll'
190328f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
190428f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
190528f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'cfgmgr32.dll'.
190628f8.2aa4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\devobj.dll) WinVerifyTrust
190728f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\devobj.dll
190828f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
190928f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
191028f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
191128f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
191228f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
191328f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
191428f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
191528f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
191628f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
191728f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
191828f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
191928f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
192028f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
192128f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000053c pwszName=\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll
192228f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
192328f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
192428f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=8F731777EFC4BC982C1E1467FBF29A74CC14D93A
192528f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll'
192628f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
192728f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
192828f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'rpcrt4.dll'.
192928f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
193028f8.2aa4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll) WinVerifyTrust
193128f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll
193228f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
193328f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
193428f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
193528f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
193628f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
193728f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
193828f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
193928f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
194028f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
194128f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
194228f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
194328f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
194428f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
194528f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
194628f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
194728f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
194828f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
194928f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
195028f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
195128f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
195228f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll
195328f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
195428f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
195528f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\local\apps\Virtualbox\VirtualBox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000023c3e1:<flags> [calling]
195628f8.2aa4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\VirtualBox.dll
195728f8.2aa4: supR3HardenedDllNotificationCallback: load 000007fed9070000 LB 0x008e6000 C:\local\apps\Virtualbox\VirtualBox.dll [fFlags=0x0]
195828f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\VirtualBox.dll
195928f8.2aa4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
196028f8.2aa4: supR3HardenedDllNotificationCallback: load 000007fee5d90000 LB 0x0011d000 C:\WINDOWS\system32\OPENGL32.dll [fFlags=0x0]
196128f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
196228f8.2aa4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\glu32.dll
196328f8.2aa4: supR3HardenedDllNotificationCallback: load 000007fee7ee0000 LB 0x0002d000 C:\WINDOWS\system32\GLU32.dll [fFlags=0x0]
196428f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\glu32.dll
196528f8.2aa4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ddraw.dll
196628f8.2aa4: supR3HardenedDllNotificationCallback: load 000007fee5c90000 LB 0x000f1000 C:\WINDOWS\system32\DDRAW.dll [fFlags=0x0]
196728f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ddraw.dll
196828f8.2aa4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dciman32.dll
196928f8.2aa4: supR3HardenedDllNotificationCallback: load 000007fee7f30000 LB 0x00008000 C:\WINDOWS\system32\DCIMAN32.dll [fFlags=0x0]
197028f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dciman32.dll
197128f8.2aa4: supR3HardenedDllNotificationCallback: load 000007fefeb20000 LB 0x001d7000 C:\WINDOWS\system32\SETUPAPI.dll [fFlags=0x0]
197228f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\setupapi.dll
197328f8.2aa4: supR3HardenedDllNotificationCallback: load 000007fefd8d0000 LB 0x00036000 C:\WINDOWS\system32\CFGMGR32.dll [fFlags=0x0]
197428f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll
197528f8.2aa4: supR3HardenedDllNotificationCallback: load 000007fefe170000 LB 0x000da000 C:\WINDOWS\system32\OLEAUT32.dll [fFlags=0x0]
197628f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
197728f8.2aa4: supR3HardenedDllNotificationCallback: load 000007fefdf60000 LB 0x00203000 C:\WINDOWS\system32\ole32.dll [fFlags=0x0]
197828f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
197928f8.2aa4: supR3HardenedDllNotificationCallback: load 000007fefd990000 LB 0x0001a000 C:\WINDOWS\system32\DEVOBJ.dll [fFlags=0x0]
198028f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\devobj.dll
198128f8.2aa4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dwmapi.dll
198228f8.2aa4: supR3HardenedDllNotificationCallback: load 000007fefb420000 LB 0x00018000 C:\WINDOWS\system32\dwmapi.dll [fFlags=0x0]
198328f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dwmapi.dll
198428f8.2aa4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\Qt5CoreVBox.dll
198528f8.2aa4: supR3HardenedDllNotificationCallback: load 0000000051460000 LB 0x00566000 C:\local\apps\Virtualbox\Qt5CoreVBox.dll [fFlags=0x0]
198628f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\Qt5CoreVBox.dll
198728f8.2aa4: supR3HardenedDllNotificationCallback: load 000007fefed00000 LB 0x00d8a000 C:\WINDOWS\system32\SHELL32.dll [fFlags=0x0]
198828f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
198928f8.2aa4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\mpr.dll
199028f8.2aa4: supR3HardenedDllNotificationCallback: load 000007fef41d0000 LB 0x00018000 C:\WINDOWS\system32\MPR.dll [fFlags=0x0]
199128f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\mpr.dll
199228f8.2aa4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\Qt5GuiVBox.dll
199328f8.2aa4: supR3HardenedDllNotificationCallback: load 000007fed8a70000 LB 0x005f7000 C:\local\apps\Virtualbox\Qt5GuiVBox.dll [fFlags=0x0]
199428f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\Qt5GuiVBox.dll
199528f8.2aa4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\Qt5WidgetsVBox.dll
199628f8.2aa4: supR3HardenedDllNotificationCallback: load 0000000050ef0000 LB 0x00561000 C:\local\apps\Virtualbox\Qt5WidgetsVBox.dll [fFlags=0x0]
199728f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\Qt5WidgetsVBox.dll
199828f8.2aa4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\Qt5PrintSupportVBox.dll
199928f8.2aa4: supR3HardenedDllNotificationCallback: load 000007fee8940000 LB 0x00051000 C:\local\apps\Virtualbox\Qt5PrintSupportVBox.dll [fFlags=0x0]
200028f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\Qt5PrintSupportVBox.dll
200128f8.2aa4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winspool.drv
200228f8.2aa4: supR3HardenedDllNotificationCallback: load 000007fefad70000 LB 0x00071000 C:\WINDOWS\system32\WINSPOOL.DRV [fFlags=0x0]
200328f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winspool.drv
200428f8.2aa4: supR3HardenedDllNotificationCallback: load 000007feffab0000 LB 0x00097000 C:\WINDOWS\system32\COMDLG32.dll [fFlags=0x0]
200528f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\comdlg32.dll
200628f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'advapi32.dll'.
200728f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
200828f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
200928f8.2aa4: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll)
201028f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll
201128f8.2aa4: supR3HardenedDllNotificationCallback: load 000007fefadf0000 LB 0x000a0000 C:\WINDOWS\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\COMCTL32.dll [fFlags=0x0]
201228f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll [avoiding WinVerifyTrust]
201328f8.2aa4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\Qt5OpenGLVBox.dll
201428f8.2aa4: supR3HardenedDllNotificationCallback: load 0000000050e90000 LB 0x00054000 C:\local\apps\Virtualbox\Qt5OpenGLVBox.dll [fFlags=0x0]
201528f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\Qt5OpenGLVBox.dll
201628f8.2aa4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
201728f8.2aa4: supR3HardenedDllNotificationCallback: load 000007fefae90000 LB 0x0003b000 C:\WINDOWS\system32\WINMM.dll [fFlags=0x0]
201828f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
201928f8.2aa4: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume2\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll'.
202028f8.2aa4: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll' [rescheduled]
202128f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\imm32.dll
202228f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
202328f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
202428f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
202528f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
202628f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
202728f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
202828f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\imm32.dll (Input=imm32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000023b9b1:<flags> [calling]
202928f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefea20000 'C:\WINDOWS\system32\imm32.dll'
203028f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe940000 'C:\WINDOWS\system32\ADVAPI32.DLL'
203128f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cryptbase.dll
203228f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\cryptbase.dll (Input=cryptbase.dll, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
203328f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd5c0000 'C:\WINDOWS\system32\cryptbase.dll'
203428f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fed9070000 'C:\local\apps\Virtualbox\VirtualBox.dll'
203528f8.2aa4: SUPR3HardenedMain: Calling TrustedMain (000007fed9071610)...
203628f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
203728f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\ole32.dll (Input=ole32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000023dce1:<flags> [calling]
203828f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdf60000 'C:\WINDOWS\system32\ole32.dll'
203928f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe940000 'C:\WINDOWS\system32\ADVAPI32.dll'
204028f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\profapi.dll
204128f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\profapi.dll (Input=profapi.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000023c3c1:<flags> [calling]
204228f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd780000 'C:\WINDOWS\system32\profapi.dll'
204328f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
204428f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'ole32.dll'.
204528f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
204628f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'imm32.dll'.
204728f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'winmm.dll'.
204828f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'oleaut32.dll'.
204928f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'shell32.dll'.
205028f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'advapi32.dll'.
205128f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'qt5guivbox.dll'.
205228f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'qt5corevbox.dll'.
205328f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'msvcr100.dll'.
205428f8.2aa4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\local\apps\Virtualbox\platforms\qwindows.dll) WinVerifyTrust
205528f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\local\apps\Virtualbox\platforms\qwindows.dll
205628f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
205728f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
205828f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
205928f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
206028f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\Qt5CoreVBox.dll
206128f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
206228f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
206328f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\Qt5GuiVBox.dll
206428f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
206528f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
206628f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
206728f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
206828f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
206928f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
207028f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
207128f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
207228f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
207328f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
207428f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
207528f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
207628f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume2\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
207728f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\imm32.dll
207828f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
207928f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
208028f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
208128f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
208228f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
208328f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
208428f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
208528f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\local\apps\Virtualbox\platforms\qwindows.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000023e6b1:<flags> [calling]
208628f8.2aa4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\platforms\qwindows.dll
208728f8.2aa4: supR3HardenedDllNotificationCallback: load 000007fee86f0000 LB 0x0012e000 C:\local\apps\Virtualbox\platforms\qwindows.dll [fFlags=0x0]
208828f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\platforms\qwindows.dll
208928f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee86f0000 'C:\local\apps\Virtualbox\platforms\qwindows.dll'
209028f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cryptbase.dll
209128f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\CRYPTBASE.dll (Input=CRYPTBASE.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000023e5e1:<flags> [calling]
209228f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd5c0000 'C:\WINDOWS\system32\CRYPTBASE.dll'
209328f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000005e4 pwszName=\Device\HarddiskVolume2\Windows\System32\uxtheme.dll
209428f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
209528f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
209628f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=936D45CC7026757A151F62882B557DD75D5FCB21
209728f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\uxtheme.dll'
209828f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
209928f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
210028f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
210128f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'gdi32.dll'.
210228f8.2aa4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\uxtheme.dll) WinVerifyTrust
210328f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
210428f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
210528f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
210628f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
210728f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
210828f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
210928f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
211028f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000023e0b1:<flags> [calling]
211128f8.2aa4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
211228f8.2aa4: supR3HardenedDllNotificationCallback: load 000007fefbeb0000 LB 0x00056000 C:\WINDOWS\system32\uxtheme.dll [fFlags=0x0]
211328f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
211428f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbeb0000 'C:\WINDOWS\system32\uxtheme.dll'
211528f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
211628f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000023daf1:<flags> [calling]
211728f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbeb0000 'C:\WINDOWS\system32\uxtheme.dll'
211828f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
211928f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000023d861:<flags> [calling]
212028f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbeb0000 'C:\WINDOWS\system32\uxtheme.dll'
212128f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
212228f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000023d861:<flags> [calling]
212328f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbeb0000 'C:\WINDOWS\system32\uxtheme.dll'
212428f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077830000 'C:\WINDOWS\system32\user32.dll'
212528f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
212628f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000023e8f1:<flags> [calling]
212728f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefed00000 'C:\WINDOWS\system32\shell32.dll'
212828f8.2aa4: supR3HardenedMonitor_LdrLoadDll: error opening 'C:\WINDOWS\system32\wintab32.dll': 0 (NtPath=\??\C:\WINDOWS\system32\wintab32.dll; Input=C:\WINDOWS\system32\wintab32.dll; rcNtGetDll=0x0
212928f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\wintab32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000023e7d1:<flags> [calling]
213028f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000135 'C:\WINDOWS\system32\wintab32.dll'
213128f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
213228f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\winmm.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000023ed11:<flags> [calling]
213328f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefae90000 'C:\WINDOWS\system32\winmm.dll'
213428f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
213528f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\winmm.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000023ed11:<flags> [calling]
213628f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefae90000 'C:\WINDOWS\system32\winmm.dll'
213728f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
213828f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000023eff1:<flags> [calling]
213928f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefed00000 'C:\WINDOWS\system32\shell32.dll'
214028f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
214128f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000023efc1:<flags> [calling]
214228f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbeb0000 'C:\WINDOWS\system32\uxtheme.dll'
214328f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe940000 'C:\WINDOWS\system32\advapi32.dll'
214428f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\userenv.dll
214528f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\userenv.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000023ef21:<flags> [calling]
214628f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd7b0000 'C:\WINDOWS\system32\userenv.dll'
214728f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll
214828f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\kernel32.dll (Input=kernel32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000023f001:<flags> [calling]
214928f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077930000 'C:\WINDOWS\system32\kernel32.dll'
215028f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000005ec pwszName=\Device\HarddiskVolume2\Windows\System32\clbcatq.dll
215128f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
215228f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
215328f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B01469787CE9D8C6FEE98FB207652B88B8494526
215428f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\clbcatq.dll'
215528f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
215628f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
215728f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'ole32.dll'.
215828f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
215928f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
216028f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'oleaut32.dll'.
216128f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'rpcrt4.dll'.
216228f8.2aa4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\clbcatq.dll) WinVerifyTrust
216328f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\clbcatq.dll
216428f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
216528f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
216628f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
216728f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
216828f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
216928f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
217028f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
217128f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
217228f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
217328f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
217428f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
217528f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
217628f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
217728f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
217828f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
217928f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
218028f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\CLBCatQ.DLL (Input=CLBCatQ.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000023bd81:<flags> [calling]
218128f8.2aa4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\clbcatq.dll
218228f8.2aa4: supR3HardenedDllNotificationCallback: load 000007fefe8a0000 LB 0x00099000 C:\WINDOWS\system32\CLBCatQ.DLL [fFlags=0x0]
218328f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\clbcatq.dll
218428f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe8a0000 'C:\WINDOWS\system32\CLBCatQ.DLL'
218528f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe940000 'C:\WINDOWS\system32\ADVAPI32.dll'
218628f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cryptsp.dll
218728f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\CRYPTSP.dll (Input=CRYPTSP.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000023ab71:<flags> [calling]
218828f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcf60000 'C:\WINDOWS\system32\CRYPTSP.dll'
218928f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000062c pwszName=\Device\HarddiskVolume2\Windows\System32\RpcRtRemote.dll
219028f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
219128f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
219228f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=DFC4A7C7E103D324218E6EF5D219B953746D6EC1
219328f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\RpcRtRemote.dll'
219428f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
219528f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'rpcrt4.dll'.
219628f8.2aa4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\RpcRtRemote.dll) WinVerifyTrust
219728f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\RpcRtRemote.dll
219828f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
219928f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
220028f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\RpcRtRemote.dll (Input=RpcRtRemote.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000023a741:<flags> [calling]
220128f8.2aa4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\RpcRtRemote.dll
220228f8.2aa4: supR3HardenedDllNotificationCallback: load 000007fefd5d0000 LB 0x00014000 C:\WINDOWS\system32\RpcRtRemote.dll [fFlags=0x0]
220328f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\RpcRtRemote.dll
220428f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd5d0000 'C:\WINDOWS\system32\RpcRtRemote.dll'
220528f8.26bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
220628f8.26bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
220728f8.26bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
220828f8.26bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
220928f8.26bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ole32.dll'.
221028f8.26bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'oleaut32.dll'.
221128f8.26bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\local\apps\Virtualbox\VBoxC.dll) WinVerifyTrust
221228f8.26bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxC.dll
221328f8.26bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
221428f8.26bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
221528f8.26bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
221628f8.26bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
221728f8.26bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
221828f8.26bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
221928f8.26bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
222028f8.26bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
222128f8.26bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
222228f8.26bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\vboxrt.dll' [rcNtRedir=0xc0150008]
222328f8.26bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
222428f8.26bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\msvcp100.dll' [rcNtRedir=0xc0150008]
222528f8.26bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\msvcp100.dll
222628f8.26bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
222728f8.26bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
222828f8.26bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\local\apps\Virtualbox\VBoxC.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000004abeb01:<flags> [calling]
222928f8.26bc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxC.dll
223028f8.26bc: supR3HardenedDllNotificationCallback: load 000007fed6c80000 LB 0x004f5000 C:\local\apps\Virtualbox\VBoxC.dll [fFlags=0x0]
223128f8.26bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxC.dll
223228f8.26bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fed6c80000 'C:\local\apps\Virtualbox\VBoxC.dll'
223328f8.26bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
223428f8.26bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
223528f8.26bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
223628f8.26bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'shlwapi.dll'.
223728f8.26bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ole32.dll'.
223828f8.26bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'oleaut32.dll'.
223928f8.26bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
224028f8.26bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\local\apps\Virtualbox\VBoxProxyStub.dll) WinVerifyTrust
224128f8.26bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxProxyStub.dll
224228f8.26bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
224328f8.26bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
224428f8.26bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
224528f8.26bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
224628f8.26bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
224728f8.26bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
224828f8.26bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
224928f8.26bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
225028f8.26bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
225128f8.26bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll
225228f8.26bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
225328f8.26bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
225428f8.26bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
225528f8.26bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\vboxrt.dll' [rcNtRedir=0xc0150008]
225628f8.26bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
225728f8.26bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
225828f8.26bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\local\apps\Virtualbox\VBoxProxyStub.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000004abd621:<flags> [calling]
225928f8.26bc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxProxyStub.dll
226028f8.26bc: supR3HardenedDllNotificationCallback: load 000007fee8630000 LB 0x000b5000 C:\local\apps\Virtualbox\VBoxProxyStub.dll [fFlags=0x0]
226128f8.26bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxProxyStub.dll
226228f8.26bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee8630000 'C:\local\apps\Virtualbox\VBoxProxyStub.dll'
226328f8.26bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
226428f8.26bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\oleaut32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000004abd4a1:<flags> [calling]
226528f8.26bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe170000 'C:\Windows\system32\oleaut32.dll'
226628f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe940000 'C:\WINDOWS\system32\ADVAPI32.dll'
226728f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefea60000 'C:\WINDOWS\system32\gdi32.dll'
226828f8.1448: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
226928f8.1448: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
227028f8.1448: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\local\apps\Virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMain.dll) WinVerifyTrust
227128f8.1448: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\local\apps\Virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMain.dll
227228f8.1448: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
227328f8.1448: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\vboxrt.dll' [rcNtRedir=0xc0150008]
227428f8.1448: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
227528f8.1448: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
227628f8.1448: supR3HardenedMonitor_LdrLoadDll: pName=C:\local\apps\Virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMain.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000452a191:<flags> [calling]
227728f8.1448: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMain.dll
227828f8.1448: supR3HardenedDllNotificationCallback: load 000007fefa300000 LB 0x0000d000 C:\local\apps\Virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMain.DLL [fFlags=0x0]
227928f8.1448: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMain.dll
228028f8.1448: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa300000 'C:\local\apps\Virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMain.DLL'
228128f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'vboxoglhostcrutil.dll'.
228228f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
228328f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msvcr100.dll'.
228428f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qt5corevbox.dll'.
228528f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qt5openglvbox.dll'.
228628f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'qt5widgetsvbox.dll'.
228728f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'opengl32.dll'.
228828f8.2aa4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\local\apps\Virtualbox\VBoxTestOGL.exe)
228928f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxTestOGL.exe
229028f8.2aa4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\local\apps\Virtualbox\VBoxTestOGL.exe'
229128f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000009d4 pwszName=\Device\HarddiskVolume2\Windows\System32\apphelp.dll
229228f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
229328f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
229428f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=279DFE2A04C40CE4B22260C26A5BB57DF440B52E
229528f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3107998~31bf3856ad364e35~amd64~~6.1.1.2.cat'; file='\Device\HarddiskVolume2\Windows\System32\apphelp.dll'
229628f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
229728f8.2aa4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\apphelp.dll) WinVerifyTrust
229828f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\apphelp.dll
229928f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
230028f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
230128f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
230228f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
230328f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
230428f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\Qt5WidgetsVBox.dll
230528f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5openglvbox.dll'...
230628f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5openglvbox.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\qt5openglvbox.dll' [rcNtRedir=0xc0150008]
230728f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\Qt5OpenGLVBox.dll
230828f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
230928f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
231028f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\Qt5CoreVBox.dll
231128f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
231228f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
231328f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
231428f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\vboxrt.dll' [rcNtRedir=0xc0150008]
231528f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxoglhostcrutil.dll'...
231628f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxoglhostcrutil.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\vboxoglhostcrutil.dll' [rcNtRedir=0xc0150008]
231728f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
231828f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
231928f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'shlwapi.dll'.
232028f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ws2_32.dll'.
232128f8.2aa4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\local\apps\Virtualbox\VBoxOGLhostcrutil.dll) WinVerifyTrust
232228f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxOGLhostcrutil.dll
232328f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
232428f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
232528f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
232628f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
232728f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
232828f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll
232928f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
233028f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\vboxrt.dll' [rcNtRedir=0xc0150008]
233128f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
233228f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
233328f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\apphelp.dll (rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
233428f8.2aa4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\apphelp.dll
233528f8.2aa4: supR3HardenedDllNotificationCallback: load 000007fefd560000 LB 0x00057000 C:\WINDOWS\system32\apphelp.dll [fFlags=0x0]
233628f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\apphelp.dll
233728f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd560000 'C:\WINDOWS\system32\apphelp.dll'
233828f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdf60000 'C:\WINDOWS\system32\ole32.dll'
233928f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msctf.dll
234028f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\MSCTF.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000023a251:<flags> [calling]
234128f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe250000 'C:\WINDOWS\system32\MSCTF.dll'
234228f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdf60000 'C:\WINDOWS\system32\ole32.dll'
234328f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
234428f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\OLEAUT32.dll (Input=OLEAUT32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000237ef1:<flags> [calling]
234528f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe170000 'C:\WINDOWS\system32\OLEAUT32.dll'
234628f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000009e4 pwszName=\Device\HarddiskVolume2\Windows\System32\wbem\wbemprox.dll
234728f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
234828f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
234928f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=9D23EA973FAFAFAD87237AB3723340580276449F
235028f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\WIN8IP-Microsoft-Windows-WMI-Package~31bf3856ad364e35~amd64~~7.1.7601.16398.cat'; file='\Device\HarddiskVolume2\Windows\System32\wbem\wbemprox.dll'
235128f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
235228f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
235328f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'ole32.dll'.
235428f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'oleaut32.dll'.
235528f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ws2_32.dll'.
235628f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'wbemcomn2.dll'.
235728f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'advapi32.dll'.
235828f8.2aa4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\wbem\wbemprox.dll) WinVerifyTrust
235928f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wbem\wbemprox.dll
236028f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
236128f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
236228f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wbemcomn2.dll'...
236328f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'wbemcomn2.dll' -> '\Device\HarddiskVolume2\Windows\System32\wbemcomn2.dll' [rcNtRedir=0xc0150008]
236428f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000009d0 pwszName=\Device\HarddiskVolume2\Windows\System32\wbemcomn2.dll
236528f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
236628f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
236728f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=4FBA45F4BB79A35153BA469FD01507C644BE39AB
236828f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\WIN8IP-Microsoft-Windows-WMI-Package~31bf3856ad364e35~amd64~~7.1.7601.16398.cat'; file='\Device\HarddiskVolume2\Windows\System32\wbemcomn2.dll'
236928f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
237028f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
237128f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'ole32.dll'.
237228f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'oleaut32.dll'.
237328f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ws2_32.dll'.
237428f8.2aa4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\wbemcomn2.dll) WinVerifyTrust
237528f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wbemcomn2.dll
237628f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
237728f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
237828f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
237928f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
238028f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
238128f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
238228f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
238328f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
238428f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
238528f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
238628f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
238728f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
238828f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
238928f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
239028f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
239128f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
239228f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
239328f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
239428f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\wbem\wbemprox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000236811:<flags> [calling]
239528f8.2aa4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbem\wbemprox.dll
239628f8.2aa4: supR3HardenedDllNotificationCallback: load 000007fefa010000 LB 0x0000e000 C:\WINDOWS\system32\wbem\wbemprox.dll [fFlags=0x0]
239728f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbem\wbemprox.dll
239828f8.2aa4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbemcomn2.dll
239928f8.2aa4: supR3HardenedDllNotificationCallback: load 000007fef9f90000 LB 0x0007d000 C:\WINDOWS\system32\wbemcomn2.dll [fFlags=0x0]
240028f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbemcomn2.dll
240128f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa010000 'C:\WINDOWS\system32\wbem\wbemprox.dll'
240228f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000a18 pwszName=\Device\HarddiskVolume2\Windows\System32\wbem\wbemsvc.dll
240328f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
240428f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
240528f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=77AE9E0AB565BD4B55146072708C69CC76B02AEC
240628f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\WIN8IP-Microsoft-Windows-WMI-Package~31bf3856ad364e35~amd64~~7.1.7601.16398.cat'; file='\Device\HarddiskVolume2\Windows\System32\wbem\wbemsvc.dll'
240728f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
240828f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
240928f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'advapi32.dll'.
241028f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rpcrt4.dll'.
241128f8.2aa4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\wbem\wbemsvc.dll) WinVerifyTrust
241228f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wbem\wbemsvc.dll
241328f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
241428f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
241528f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
241628f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
241728f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
241828f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
241928f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
242028f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\wbem\wbemsvc.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000236421:<flags> [calling]
242128f8.2aa4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbem\wbemsvc.dll
242228f8.2aa4: supR3HardenedDllNotificationCallback: load 000007fef3a20000 LB 0x00014000 C:\WINDOWS\system32\wbem\wbemsvc.dll [fFlags=0x0]
242328f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbem\wbemsvc.dll
242428f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef3a20000 'C:\WINDOWS\system32\wbem\wbemsvc.dll'
242528f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000a1c pwszName=\Device\HarddiskVolume2\Windows\System32\wbem\fastprox.dll
242628f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
242728f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
242828f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=F312241187BEEDD628B7F991D95066A380534AC2
242928f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\WIN8IP-Microsoft-Windows-WMI-Package~31bf3856ad364e35~amd64~~7.1.7601.16398.cat'; file='\Device\HarddiskVolume2\Windows\System32\wbem\fastprox.dll'
243028f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
243128f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
243228f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'oleaut32.dll'.
243328f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'ole32.dll'.
243428f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'wbemcomn2.dll'.
243528f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'advapi32.dll'.
243628f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'ntdsapi.dll'.
243728f8.2aa4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\wbem\fastprox.dll) WinVerifyTrust
243828f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wbem\fastprox.dll
243928f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntdsapi.dll'...
244028f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntdsapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\ntdsapi.dll' [rcNtRedir=0xc0150008]
244128f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000009e8 pwszName=\Device\HarddiskVolume2\Windows\System32\ntdsapi.dll
244228f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
244328f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
244428f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=67C74E045820FCAB3FC8AD5C180928A20C1F11CE
244528f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\ntdsapi.dll'
244628f8.2aa4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
244728f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
244828f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'rpcrt4.dll'.
244928f8.2aa4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'ws2_32.dll'.
245028f8.2aa4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ntdsapi.dll) WinVerifyTrust
245128f8.2aa4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ntdsapi.dll
245228f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
245328f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
245428f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wbemcomn2.dll'...
245528f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'wbemcomn2.dll' -> '\Device\HarddiskVolume2\Windows\System32\wbemcomn2.dll' [rcNtRedir=0xc0150008]
245628f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbemcomn2.dll
245728f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
245828f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
245928f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
246028f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
246128f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
246228f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
246328f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
246428f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
246528f8.2aa4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
246628f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
246728f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
246828f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
246928f8.2aa4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
247028f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\wbem\fastprox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000236421:<flags> [calling]
247128f8.2aa4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbem\fastprox.dll
247228f8.2aa4: supR3HardenedDllNotificationCallback: load 000007fef98e0000 LB 0x000d4000 C:\WINDOWS\system32\wbem\fastprox.dll [fFlags=0x0]
247328f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbem\fastprox.dll
247428f8.2aa4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ntdsapi.dll
247528f8.2aa4: supR3HardenedDllNotificationCallback: load 000007fef98b0000 LB 0x00027000 C:\WINDOWS\system32\NTDSAPI.dll [fFlags=0x0]
247628f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ntdsapi.dll
247728f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef98e0000 'C:\WINDOWS\system32\wbem\fastprox.dll'
247828f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe170000 'C:\WINDOWS\system32\OLEAUT32.dll'
247928f8.2bd4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
248028f8.2bd4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrem.dll'.
248128f8.2bd4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
248228f8.2bd4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\local\apps\Virtualbox\VBoxVMM.dll) WinVerifyTrust
248328f8.2bd4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxVMM.dll
248428f8.2bd4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
248528f8.2bd4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\vboxrt.dll' [rcNtRedir=0xc0150008]
248628f8.2bd4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrem.dll'...
248728f8.2bd4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrem.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\vboxrem.dll' [rcNtRedir=0xc0150008]
248828f8.2bd4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'vboxrt.dll'.
248928f8.2bd4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
249028f8.2bd4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcrt.dll'.
249128f8.2bd4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\local\apps\Virtualbox\VBoxREM.dll) WinVerifyTrust
249228f8.2bd4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxREM.dll
249328f8.2bd4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
249428f8.2bd4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
249528f8.2bd4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\msvcr100.dll
249628f8.2bd4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
249728f8.2bd4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
249828f8.2bd4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
249928f8.2bd4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\vboxvmm.dll' [rcNtRedir=0xc0150008]
250028f8.2bd4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxVMM.dll
250128f8.2bd4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
250228f8.2bd4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\vboxrt.dll' [rcNtRedir=0xc0150008]
250328f8.2bd4: supR3HardenedMonitor_LdrLoadDll: pName=C:\local\apps\Virtualbox\VBoxVMM.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000006aae701:<flags> [calling]
250428f8.2bd4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxVMM.dll
250528f8.2bd4: supR3HardenedDllNotificationCallback: load 000007fed3bb0000 LB 0x0029d000 C:\local\apps\Virtualbox\VBoxVMM.DLL [fFlags=0x0]
250628f8.2bd4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxVMM.dll
250728f8.2bd4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxREM.dll
250828f8.2bd4: supR3HardenedDllNotificationCallback: load 000000006f500000 LB 0x0010b000 C:\local\apps\Virtualbox\VBoxREM.dll [fFlags=0x0]
250928f8.2bd4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxREM.dll
251028f8.2bd4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fed3bb0000 'C:\local\apps\Virtualbox\VBoxVMM.DLL'
251128f8.2aa4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
251228f8.2aa4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\WINMM.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000002360b1:<flags> [calling]
251328f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefae90000 'C:\WINDOWS\system32\WINMM.dll'
251428f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe170000 'C:\WINDOWS\system32\OLEAUT32.DLL'
251528f8.2804: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
251628f8.2804: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
251728f8.2804: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
251828f8.2804: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
251928f8.2804: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\local\apps\Virtualbox\VBoxSharedClipboard.dll) WinVerifyTrust
252028f8.2804: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxSharedClipboard.dll
252128f8.2804: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
252228f8.2804: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
252328f8.2804: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll
252428f8.2804: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
252528f8.2804: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\vboxrt.dll' [rcNtRedir=0xc0150008]
252628f8.2804: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
252728f8.2804: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\vboxvmm.dll' [rcNtRedir=0xc0150008]
252828f8.2804: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxVMM.dll
252928f8.2804: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
253028f8.2804: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
253128f8.2804: supR3HardenedMonitor_LdrLoadDll: pName=C:\local\apps\Virtualbox\VBoxSharedClipboard.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000007c3d721:<flags> [calling]
253228f8.2804: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxSharedClipboard.dll
253328f8.2804: supR3HardenedDllNotificationCallback: load 000007fee4360000 LB 0x0000b000 C:\local\apps\Virtualbox\VBoxSharedClipboard.DLL [fFlags=0x0]
253428f8.2804: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxSharedClipboard.dll
253528f8.2804: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4360000 'C:\local\apps\Virtualbox\VBoxSharedClipboard.DLL'
253628f8.2804: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077830000 'C:\WINDOWS\system32\User32.dll'
253728f8.17d0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
253828f8.17d0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
253928f8.17d0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
254028f8.17d0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\local\apps\Virtualbox\VBoxDragAndDropSvc.dll) WinVerifyTrust
254128f8.17d0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxDragAndDropSvc.dll
254228f8.17d0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
254328f8.17d0: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\vboxrt.dll' [rcNtRedir=0xc0150008]
254428f8.17d0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
254528f8.17d0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\msvcp100.dll' [rcNtRedir=0xc0150008]
254628f8.17d0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\msvcp100.dll
254728f8.17d0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
254828f8.17d0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
254928f8.17d0: supR3HardenedMonitor_LdrLoadDll: pName=C:\local\apps\Virtualbox\VBoxDragAndDropSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000007f7da21:<flags> [calling]
255028f8.17d0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxDragAndDropSvc.dll
255128f8.17d0: supR3HardenedDllNotificationCallback: load 000007fee4350000 LB 0x0000d000 C:\local\apps\Virtualbox\VBoxDragAndDropSvc.DLL [fFlags=0x0]
255228f8.17d0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxDragAndDropSvc.dll
255328f8.17d0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee4350000 'C:\local\apps\Virtualbox\VBoxDragAndDropSvc.DLL'
255428f8.2ba8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxTestOGL.exe
255528f8.818: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
255628f8.818: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxoglhostcrutil.dll'.
255728f8.818: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
255828f8.818: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vboxvmm.dll'.
255928f8.818: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'vboxoglrenderspu.dll'.
256028f8.818: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'advapi32.dll'.
256128f8.818: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'ole32.dll'.
256228f8.818: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'oleaut32.dll'.
256328f8.818: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\local\apps\Virtualbox\VBoxSharedCrOpenGL.dll) WinVerifyTrust
256428f8.818: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxSharedCrOpenGL.dll
256528f8.818: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
256628f8.818: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
256728f8.818: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
256828f8.818: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
256928f8.818: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
257028f8.818: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
257128f8.818: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxoglrenderspu.dll'...
257228f8.818: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxoglrenderspu.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\vboxoglrenderspu.dll' [rcNtRedir=0xc0150008]
257328f8.818: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
257428f8.818: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxoglhostcrutil.dll'.
257528f8.818: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
257628f8.818: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
257728f8.818: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
257828f8.818: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'advapi32.dll'.
257928f8.818: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\local\apps\Virtualbox\VBoxOGLrenderspu.dll) WinVerifyTrust
258028f8.818: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxOGLrenderspu.dll
258128f8.818: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
258228f8.818: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\vboxvmm.dll' [rcNtRedir=0xc0150008]
258328f8.818: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxVMM.dll
258428f8.818: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
258528f8.818: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\vboxrt.dll' [rcNtRedir=0xc0150008]
258628f8.818: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxoglhostcrutil.dll'...
258728f8.818: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxoglhostcrutil.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\vboxoglhostcrutil.dll' [rcNtRedir=0xc0150008]
258828f8.818: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxOGLhostcrutil.dll
258928f8.818: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
259028f8.818: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
259128f8.818: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
259228f8.818: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
259328f8.818: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
259428f8.818: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
259528f8.818: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
259628f8.818: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
259728f8.818: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
259828f8.818: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\vboxrt.dll' [rcNtRedir=0xc0150008]
259928f8.818: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxoglhostcrutil.dll'...
260028f8.818: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxoglhostcrutil.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\vboxoglhostcrutil.dll' [rcNtRedir=0xc0150008]
260128f8.818: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxOGLhostcrutil.dll
260228f8.818: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
260328f8.818: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
260428f8.818: supR3HardenedMonitor_LdrLoadDll: pName=C:\local\apps\Virtualbox\VBoxSharedCrOpenGL.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000829d861:<flags> [calling]
260528f8.818: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxSharedCrOpenGL.dll
260628f8.818: supR3HardenedDllNotificationCallback: load 000007fed4d50000 LB 0x0010e000 C:\local\apps\Virtualbox\VBoxSharedCrOpenGL.DLL [fFlags=0x0]
260728f8.818: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxSharedCrOpenGL.dll
260828f8.818: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxOGLhostcrutil.dll
260928f8.818: supR3HardenedDllNotificationCallback: load 000007fed7970000 LB 0x0002f000 C:\local\apps\Virtualbox\VBoxOGLhostcrutil.dll [fFlags=0x0]
261028f8.818: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxOGLhostcrutil.dll
261128f8.818: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxOGLrenderspu.dll
261228f8.818: supR3HardenedDllNotificationCallback: load 000007fed48d0000 LB 0x00026000 C:\local\apps\Virtualbox\VBoxOGLrenderspu.dll [fFlags=0x0]
261328f8.818: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxOGLrenderspu.dll
261428f8.818: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fed4d50000 'C:\local\apps\Virtualbox\VBoxSharedCrOpenGL.DLL'
261528f8.818: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxOGLrenderspu.dll
261628f8.818: supR3HardenedMonitor_LdrLoadDll: pName=C:\local\apps\Virtualbox\VBoxOGLrenderspu.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000829e6a1:<flags> [calling]
261728f8.818: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fed48d0000 'C:\local\apps\Virtualbox\VBoxOGLrenderspu.dll'
261828f8.818: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
261928f8.818: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxoglhostcrutil.dll'.
262028f8.818: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\local\apps\Virtualbox\VBoxOGLhosterrorspu.dll) WinVerifyTrust
262128f8.818: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxOGLhosterrorspu.dll
262228f8.818: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxoglhostcrutil.dll'...
262328f8.818: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxoglhostcrutil.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\vboxoglhostcrutil.dll' [rcNtRedir=0xc0150008]
262428f8.818: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxOGLhostcrutil.dll
262528f8.818: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
262628f8.818: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
262728f8.818: supR3HardenedMonitor_LdrLoadDll: pName=C:\local\apps\Virtualbox\VBoxOGLhosterrorspu.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000829e641:<flags> [calling]
262828f8.818: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxOGLhosterrorspu.dll
262928f8.818: supR3HardenedDllNotificationCallback: load 000007fed49e0000 LB 0x0001a000 C:\local\apps\Virtualbox\VBoxOGLhosterrorspu.dll [fFlags=0x0]
263028f8.818: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxOGLhosterrorspu.dll
263128f8.818: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fed49e0000 'C:\local\apps\Virtualbox\VBoxOGLhosterrorspu.dll'
263228f8.818: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
263328f8.818: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32/opengl32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000829c641:<flags> [calling]
263428f8.818: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
263528f8.818: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee5d90000 'C:\WINDOWS\system32/opengl32.dll'
263628f8.2bcc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dwmapi.dll
263728f8.2bcc: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\dwmapi.dll (Input=dwmapi.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000008baf031:<flags> [calling]
263828f8.2bcc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefb420000 'C:\WINDOWS\system32\dwmapi.dll'
263928f8.818: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
264028f8.818: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\OPENGL32.dll (Input=OPENGL32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000829e191:<flags> [calling]
264128f8.818: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee5d90000 'C:\WINDOWS\system32\OPENGL32.dll'
264228f8.818: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefea60000 'C:\WINDOWS\system32\gdi32.dll'
264328f8.818: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefea60000 'C:\WINDOWS\system32\gdi32.dll'
264428f8.818: \Device\HarddiskVolume2\Windows\System32\ig9icd64.dll: Owner is administrators group.
264528f8.818: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll
264628f8.818: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000829bbc1:<flags> [calling]
264728f8.818: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd9b0000 'C:\WINDOWS\system32\crypt32.dll'
264828f8.818: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'shell32.dll'.
264928f8.818: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'opengl32.dll'.
265028f8.818: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
265128f8.818: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'gdi32.dll'.
265228f8.818: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'advapi32.dll'.
265328f8.818: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'igc64.dll'.
265428f8.818: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'wtsapi32.dll'.
265528f8.818: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'dwmapi.dll'.
265628f8.818: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ig9icd64.dll) WinVerifyTrust
265728f8.818: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ig9icd64.dll
265828f8.818: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dwmapi.dll'...
265928f8.818: supR3HardenedWinVerifyCacheProcessImportTodos: 'dwmapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\dwmapi.dll' [rcNtRedir=0xc0150008]
266028f8.818: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dwmapi.dll
266128f8.818: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wtsapi32.dll'...
266228f8.818: supR3HardenedWinVerifyCacheProcessImportTodos: 'wtsapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\wtsapi32.dll' [rcNtRedir=0xc0150008]
266328f8.818: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000bd8 pwszName=\Device\HarddiskVolume2\Windows\System32\wtsapi32.dll
266428f8.818: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
266528f8.818: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
266628f8.818: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=E653B4F2F82EC27E9205DC90EBEB7A5AAB37A8B0
266728f8.818: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\wtsapi32.dll'
266828f8.818: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
266928f8.818: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
267028f8.818: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\wtsapi32.dll) WinVerifyTrust
267128f8.818: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wtsapi32.dll
267228f8.818: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'igc64.dll'...
267328f8.818: supR3HardenedWinVerifyCacheProcessImportTodos: 'igc64.dll' -> '\Device\HarddiskVolume2\Windows\System32\igc64.dll' [rcNtRedir=0xc0150008]
267428f8.818: \Device\HarddiskVolume2\Windows\System32\igc64.dll: Owner is administrators group.
267528f8.818: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll
267628f8.818: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
267728f8.818: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
267828f8.818: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000829b5e1:<flags> [calling]
267928f8.818: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd9b0000 'C:\WINDOWS\system32\crypt32.dll'
268028f8.818: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\igc64.dll) WinVerifyTrust
268128f8.818: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\igc64.dll
268228f8.818: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
268328f8.818: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
268428f8.818: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
268528f8.818: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
268628f8.818: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
268728f8.818: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
268828f8.818: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
268928f8.818: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
269028f8.818: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
269128f8.818: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
269228f8.818: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
269328f8.818: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\ig9icd64.dll (Input=ig9icd64.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000829d9c1:<flags> [calling]
269428f8.818: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ig9icd64.dll
269528f8.818: supR3HardenedDllNotificationCallback: load 000007fed1730000 LB 0x00d0b000 C:\WINDOWS\system32\ig9icd64.dll [fFlags=0x0]
269628f8.818: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ig9icd64.dll
269728f8.818: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\igc64.dll
269828f8.818: supR3HardenedDllNotificationCallback: load 000007fedcb30000 LB 0x00e70000 C:\WINDOWS\system32\igc64.dll [fFlags=0x0]
269928f8.818: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\igc64.dll
270028f8.818: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wtsapi32.dll
270128f8.818: supR3HardenedDllNotificationCallback: load 000007fefc840000 LB 0x00011000 C:\WINDOWS\system32\WTSAPI32.dll [fFlags=0x0]
270228f8.818: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wtsapi32.dll
270328f8.818: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fed1730000 'C:\WINDOWS\system32\ig9icd64.dll'
270428f8.818: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefea60000 'C:\WINDOWS\system32\gdi32.dll'
270528f8.818: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefea60000 'C:\WINDOWS\system32\gdi32.dll'
270628f8.818: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee5d90000 'C:\WINDOWS\system32\OPENGL32.dll'
270728f8.818: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee5d90000 'C:\WINDOWS\system32\OPENGL32.dll'
270828f8.818: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee5d90000 'C:\WINDOWS\system32\OPENGL32.dll'
270928f8.818: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee5d90000 'C:\WINDOWS\system32\OPENGL32.dll'
271028f8.818: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee5d90000 'C:\WINDOWS\system32\OPENGL32.dll'
271128f8.818: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee5d90000 'C:\WINDOWS\system32\OPENGL32.dll'
271228f8.818: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
271328f8.818: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\OPENGL32.dll (Input=OPENGL32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000829e561:<flags> [calling]
271428f8.818: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee5d90000 'C:\WINDOWS\system32\OPENGL32.dll'
271528f8.818: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000c0c pwszName=\Device\HarddiskVolume2\Windows\System32\version.dll
271628f8.818: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
271728f8.818: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
271828f8.818: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=A3AB94A028D0330A3DBCAE54C04C648532198DB9
271928f8.818: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\version.dll'
272028f8.818: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
272128f8.818: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
272228f8.818: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\version.dll) WinVerifyTrust
272328f8.818: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\version.dll
272428f8.818: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
272528f8.818: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
272628f8.818: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\version.dll (Input=version.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000829e3c1:<flags> [calling]
272728f8.818: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\version.dll
272828f8.818: supR3HardenedDllNotificationCallback: load 000007fefd6b0000 LB 0x0000c000 C:\WINDOWS\system32\version.dll [fFlags=0x0]
272928f8.818: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\version.dll
273028f8.818: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd6b0000 'C:\WINDOWS\system32\version.dll'
273128f8.818: supR3HardenedDllNotificationCallback: Unload 000007fefd6b0000 LB 0x0000c000 C:\WINDOWS\system32\version.dll [flags=0x0]
273228f8.818: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee5d90000 'C:\WINDOWS\system32\OPENGL32.dll'
273328f8.818: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077830000 'C:\WINDOWS\system32\USER32.dll'
273428f8.818: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000c10 pwszName=\Device\HarddiskVolume2\Windows\System32\winsta.dll
273528f8.818: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
273628f8.818: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
273728f8.818: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=1784FF9CB91ACF5CDF00DE84F778DD4A67C759FA
273828f8.818: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_51_for_KB2984972~31bf3856ad364e35~amd64~~6.1.1.4.cat'; file='\Device\HarddiskVolume2\Windows\System32\winsta.dll'
273928f8.818: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
274028f8.818: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
274128f8.818: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\winsta.dll) WinVerifyTrust
274228f8.818: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\winsta.dll
274328f8.818: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
274428f8.818: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
274528f8.818: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\WINSTA.dll (Input=WINSTA.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000829e4f1:<flags> [calling]
274628f8.818: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winsta.dll
274728f8.818: supR3HardenedDllNotificationCallback: load 000007fefcb30000 LB 0x0003d000 C:\WINDOWS\system32\WINSTA.dll [fFlags=0x0]
274828f8.818: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winsta.dll
274928f8.818: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcb30000 'C:\WINDOWS\system32\WINSTA.dll'
275028f8.818: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe940000 'C:\WINDOWS\system32\ADVAPI32.dll'
275128f8.818: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feffbb0000 'C:\WINDOWS\system32\RPCRT4.dll'
275228f8.ee4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
275328f8.ee4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
275428f8.ee4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
275528f8.ee4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\local\apps\Virtualbox\VBoxGuestPropSvc.dll) WinVerifyTrust
275628f8.ee4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxGuestPropSvc.dll
275728f8.ee4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
275828f8.ee4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\vboxrt.dll' [rcNtRedir=0xc0150008]
275928f8.ee4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
276028f8.ee4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\msvcp100.dll' [rcNtRedir=0xc0150008]
276128f8.ee4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
276228f8.ee4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
276328f8.ee4: supR3HardenedMonitor_LdrLoadDll: pName=C:\local\apps\Virtualbox\VBoxGuestPropSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000004aecd931:<flags> [calling]
276428f8.ee4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxGuestPropSvc.dll
276528f8.ee4: supR3HardenedDllNotificationCallback: load 000007feda290000 LB 0x0000c000 C:\local\apps\Virtualbox\VBoxGuestPropSvc.DLL [fFlags=0x0]
276628f8.ee4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxGuestPropSvc.dll
276728f8.ee4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feda290000 'C:\local\apps\Virtualbox\VBoxGuestPropSvc.DLL'
276828f8.9b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
276928f8.9b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
277028f8.9b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
277128f8.9b0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\local\apps\Virtualbox\VBoxGuestControlSvc.dll) WinVerifyTrust
277228f8.9b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxGuestControlSvc.dll
277328f8.9b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
277428f8.9b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\vboxrt.dll' [rcNtRedir=0xc0150008]
277528f8.9b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
277628f8.9b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\msvcp100.dll' [rcNtRedir=0xc0150008]
277728f8.9b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
277828f8.9b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
277928f8.9b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\local\apps\Virtualbox\VBoxGuestControlSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000004b18d951:<flags> [calling]
278028f8.9b0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxGuestControlSvc.dll
278128f8.9b0: supR3HardenedDllNotificationCallback: load 000007fed89e0000 LB 0x0000b000 C:\local\apps\Virtualbox\VBoxGuestControlSvc.DLL [fFlags=0x0]
278228f8.9b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxGuestControlSvc.dll
278328f8.9b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fed89e0000 'C:\local\apps\Virtualbox\VBoxGuestControlSvc.DLL'
278428f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefed00000 'C:\WINDOWS\system32\Shell32.dll'
278528f8.2ba8: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000068897f1:<flags> [calling]
278628f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdf40000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
278728f8.2ba8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxVMM.dll
278828f8.2ba8: supR3HardenedMonitor_LdrLoadDll: pName=C:\local\apps\Virtualbox\VBoxVMM.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000688bb21:<flags> [calling]
278928f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fed3bb0000 'C:\local\apps\Virtualbox\VBoxVMM.DLL'
279028f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
279128f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
279228f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
279328f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ole32.dll'.
279428f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'oleaut32.dll'.
279528f8.2ba8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\local\apps\Virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll) WinVerifyTrust
279628f8.2ba8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\local\apps\Virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
279728f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
279828f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
279928f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
280028f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
280128f8.2ba8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
280228f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
280328f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
280428f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
280528f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\vboxrt.dll' [rcNtRedir=0xc0150008]
280628f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
280728f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
280828f8.2ba8: supR3HardenedMonitor_LdrLoadDll: pName=C:\local\apps\Virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000688ccd1:<flags> [calling]
280928f8.2ba8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
281028f8.2ba8: supR3HardenedDllNotificationCallback: load 000007fed48a0000 LB 0x0002d000 C:\local\apps\Virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL [fFlags=0x0]
281128f8.2ba8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
281228f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fed48a0000 'C:\local\apps\Virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL'
281328f8.2ba8: supR3HardenedDllNotificationCallback: Unload 000007fed48a0000 LB 0x0002d000 C:\local\apps\Virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL [flags=0x0]
281428f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
281528f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
281628f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
281728f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vboxddu.dll'.
281828f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'vboxdd2.dll'.
281928f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
282028f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'setupapi.dll'.
282128f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'ws2_32.dll'.
282228f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'ole32.dll'.
282328f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'iphlpapi.dll'.
282428f8.2ba8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\local\apps\Virtualbox\VBoxDD.dll) WinVerifyTrust
282528f8.2ba8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxDD.dll
282628f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'iphlpapi.dll'...
282728f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'iphlpapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\iphlpapi.dll' [rcNtRedir=0xc0150008]
282828f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000d6c pwszName=\Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL
282928f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
283028f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
283128f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=3BDC72529DA09BA841BE702C4C902C8AA1242642
283228f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL'
283328f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
283428f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
283528f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'nsi.dll'.
283628f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'winnsi.dll'.
283728f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'rpcrt4.dll'.
283828f8.2ba8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL) WinVerifyTrust
283928f8.2ba8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL
284028f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
284128f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
284228f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
284328f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
284428f8.2ba8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
284528f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
284628f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
284728f8.2ba8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\setupapi.dll
284828f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
284928f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
285028f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxdd2.dll'...
285128f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxdd2.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\vboxdd2.dll' [rcNtRedir=0xc0150008]
285228f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
285328f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
285428f8.2ba8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\local\apps\Virtualbox\VBoxDD2.dll) WinVerifyTrust
285528f8.2ba8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxDD2.dll
285628f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxddu.dll'...
285728f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxddu.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\vboxddu.dll' [rcNtRedir=0xc0150008]
285828f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
285928f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
286028f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
286128f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'setupapi.dll'.
286228f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'advapi32.dll'.
286328f8.2ba8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\local\apps\Virtualbox\VBoxDDU.dll) WinVerifyTrust
286428f8.2ba8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxDDU.dll
286528f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
286628f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\vboxrt.dll' [rcNtRedir=0xc0150008]
286728f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
286828f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\vboxvmm.dll' [rcNtRedir=0xc0150008]
286928f8.2ba8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxVMM.dll
287028f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
287128f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
287228f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
287328f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
287428f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
287528f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
287628f8.2ba8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\setupapi.dll
287728f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
287828f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
287928f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
288028f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\vboxrt.dll' [rcNtRedir=0xc0150008]
288128f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
288228f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
288328f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
288428f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\vboxrt.dll' [rcNtRedir=0xc0150008]
288528f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
288628f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
288728f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
288828f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
288928f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winnsi.dll'...
289028f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'winnsi.dll' -> '\Device\HarddiskVolume2\Windows\System32\winnsi.dll' [rcNtRedir=0xc0150008]
289128f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000d58 pwszName=\Device\HarddiskVolume2\Windows\System32\winnsi.dll
289228f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
289328f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
289428f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B28F3E0DF5586B9FB3AEAC48E4ECCA0AFB6ABD91
289528f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\winnsi.dll'
289628f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
289728f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
289828f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'rpcrt4.dll'.
289928f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'nsi.dll'.
290028f8.2ba8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\winnsi.dll) WinVerifyTrust
290128f8.2ba8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\winnsi.dll
290228f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
290328f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume2\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
290428f8.2ba8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\nsi.dll
290528f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
290628f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
290728f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
290828f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume2\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
290928f8.2ba8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\nsi.dll
291028f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
291128f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
291228f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
291328f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
291428f8.2ba8: supR3HardenedMonitor_LdrLoadDll: pName=C:\local\apps\Virtualbox\VBoxDD.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000688dcc1:<flags> [calling]
291528f8.2ba8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxDD.dll
291628f8.2ba8: supR3HardenedDllNotificationCallback: load 000007fed32e0000 LB 0x008c5000 C:\local\apps\Virtualbox\VBoxDD.DLL [fFlags=0x0]
291728f8.2ba8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxDD.dll
291828f8.2ba8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxDDU.dll
291928f8.2ba8: supR3HardenedDllNotificationCallback: load 000007fee88e0000 LB 0x00057000 C:\local\apps\Virtualbox\VBoxDDU.dll [fFlags=0x0]
292028f8.2ba8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxDDU.dll
292128f8.2ba8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxDD2.dll
292228f8.2ba8: supR3HardenedDllNotificationCallback: load 000007fed3280000 LB 0x0005d000 C:\local\apps\Virtualbox\VBoxDD2.dll [fFlags=0x0]
292328f8.2ba8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxDD2.dll
292428f8.2ba8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL
292528f8.2ba8: supR3HardenedDllNotificationCallback: load 000007fef9a00000 LB 0x00027000 C:\WINDOWS\system32\IPHLPAPI.DLL [fFlags=0x0]
292628f8.2ba8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL
292728f8.2ba8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winnsi.dll
292828f8.2ba8: supR3HardenedDllNotificationCallback: load 000007fef99f0000 LB 0x0000b000 C:\WINDOWS\system32\WINNSI.DLL [fFlags=0x0]
292928f8.2ba8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winnsi.dll
293028f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fed32e0000 'C:\local\apps\Virtualbox\VBoxDD.DLL'
293128f8.2ba8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
293228f8.2ba8: supR3HardenedMonitor_LdrLoadDll: pName=C:\local\apps\Virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000688dcc1:<flags> [calling]
293328f8.2ba8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
293428f8.2ba8: supR3HardenedDllNotificationCallback: load 000007fed3250000 LB 0x0002d000 C:\local\apps\Virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL [fFlags=0x0]
293528f8.2ba8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
293628f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fed3250000 'C:\local\apps\Virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL'
293728f8.2ba8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxC.dll
293828f8.2ba8: supR3HardenedMonitor_LdrLoadDll: pName=C:\local\apps\Virtualbox\VBoxC.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000688dcc1:<flags> [calling]
293928f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fed6c80000 'C:\local\apps\Virtualbox\VBoxC.DLL'
294028f8.2ba8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxDD2.dll
294128f8.2ba8: supR3HardenedMonitor_LdrLoadDll: pName=C:\local\apps\Virtualbox\VBoxDD2.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000688dbd1:<flags> [calling]
294228f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fed3280000 'C:\local\apps\Virtualbox\VBoxDD2.DLL'
294328f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
294428f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
294528f8.2ba8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\local\apps\Virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.dll) WinVerifyTrust
294628f8.2ba8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\local\apps\Virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.dll
294728f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
294828f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\vboxrt.dll' [rcNtRedir=0xc0150008]
294928f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
295028f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
295128f8.2ba8: supR3HardenedMonitor_LdrLoadDll: pName=C:\local\apps\Virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000688dbd1:<flags> [calling]
295228f8.2ba8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.dll
295328f8.2ba8: supR3HardenedDllNotificationCallback: load 000007fed48b0000 LB 0x0001e000 C:\local\apps\Virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.DLL [fFlags=0x0]
295428f8.2ba8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.dll
295528f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fed48b0000 'C:\local\apps\Virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.DLL'
295628f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
295728f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
295828f8.2ba8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\local\apps\Virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.dll) WinVerifyTrust
295928f8.2ba8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\local\apps\Virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.dll
296028f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
296128f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\vboxrt.dll' [rcNtRedir=0xc0150008]
296228f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
296328f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
296428f8.2ba8: supR3HardenedMonitor_LdrLoadDll: pName=C:\local\apps\Virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000688dbd1:<flags> [calling]
296528f8.2ba8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.dll
296628f8.2ba8: supR3HardenedDllNotificationCallback: load 000007fed4890000 LB 0x00017000 C:\local\apps\Virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.DLL [fFlags=0x0]
296728f8.2ba8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.dll
296828f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fed4890000 'C:\local\apps\Virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.DLL'
296928f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
297028f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
297128f8.2ba8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\local\apps\Virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.dll) WinVerifyTrust
297228f8.2ba8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\local\apps\Virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.dll
297328f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
297428f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\vboxrt.dll' [rcNtRedir=0xc0150008]
297528f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
297628f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
297728f8.2ba8: supR3HardenedMonitor_LdrLoadDll: pName=C:\local\apps\Virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000688dbd1:<flags> [calling]
297828f8.2ba8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.dll
297928f8.2ba8: supR3HardenedDllNotificationCallback: load 000007fed3230000 LB 0x00017000 C:\local\apps\Virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.DLL [fFlags=0x0]
298028f8.2ba8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.dll
298128f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fed3230000 'C:\local\apps\Virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.DLL'
298228f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
298328f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
298428f8.2ba8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\local\apps\Virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.dll) WinVerifyTrust
298528f8.2ba8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\local\apps\Virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.dll
298628f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
298728f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\vboxrt.dll' [rcNtRedir=0xc0150008]
298828f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
298928f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
299028f8.2ba8: supR3HardenedMonitor_LdrLoadDll: pName=C:\local\apps\Virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000688dbd1:<flags> [calling]
299128f8.2ba8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.dll
299228f8.2ba8: supR3HardenedDllNotificationCallback: load 000007fed3210000 LB 0x00019000 C:\local\apps\Virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.DLL [fFlags=0x0]
299328f8.2ba8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.dll
299428f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fed3210000 'C:\local\apps\Virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.DLL'
299528f8.2afc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
299628f8.2afc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
299728f8.2afc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
299828f8.2afc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\local\apps\Virtualbox\VBoxSharedFolders.dll) WinVerifyTrust
299928f8.2afc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxSharedFolders.dll
300028f8.2afc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
300128f8.2afc: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\vboxrt.dll' [rcNtRedir=0xc0150008]
300228f8.2afc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
300328f8.2afc: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\vboxvmm.dll' [rcNtRedir=0xc0150008]
300428f8.2afc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxVMM.dll
300528f8.2afc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
300628f8.2afc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
300728f8.2afc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\msvcr100.dll
300828f8.2afc: supR3HardenedMonitor_LdrLoadDll: pName=C:\local\apps\Virtualbox\VBoxSharedFolders.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000524ddb51:<flags> [calling]
300928f8.2afc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxSharedFolders.dll
301028f8.2afc: supR3HardenedDllNotificationCallback: load 000007fed89d0000 LB 0x0000d000 C:\local\apps\Virtualbox\VBoxSharedFolders.DLL [fFlags=0x0]
301128f8.2afc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\VBoxSharedFolders.dll
301228f8.2afc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fed89d0000 'C:\local\apps\Virtualbox\VBoxSharedFolders.DLL'
301328f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
301428f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
301528f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
301628f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
301728f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ws2_32.dll'.
301828f8.2ba8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\local\apps\Virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.dll) WinVerifyTrust
301928f8.2ba8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\local\apps\Virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.dll
302028f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
302128f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
302228f8.2ba8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
302328f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
302428f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
302528f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
302628f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
302728f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
302828f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\vboxrt.dll' [rcNtRedir=0xc0150008]
302928f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
303028f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\local\apps\Virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
303128f8.2ba8: supR3HardenedMonitor_LdrLoadDll: pName=C:\local\apps\Virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000688f2b1:<flags> [calling]
303228f8.2ba8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.dll
303328f8.2ba8: supR3HardenedDllNotificationCallback: load 000007feda510000 LB 0x000e5000 C:\local\apps\Virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.DLL [fFlags=0x0]
303428f8.2ba8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\local\apps\Virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.dll
303528f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feda510000 'C:\local\apps\Virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.DLL'
303628f8.2ba8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL
303728f8.2ba8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\Iphlpapi.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000688db01:<flags> [calling]
303828f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef9a00000 'C:\WINDOWS\system32\Iphlpapi.dll'
303928f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000ec0 pwszName=\Device\HarddiskVolume2\Windows\System32\dhcpcsvc.dll
304028f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
304128f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
304228f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=D89E2D6AED9A19082ECA108BEEF81A904C7A9756
304328f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\dhcpcsvc.dll'
304428f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
304528f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
304628f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'rpcrt4.dll'.
304728f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ws2_32.dll'.
304828f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'nsi.dll'.
304928f8.2ba8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\dhcpcsvc.dll) WinVerifyTrust
305028f8.2ba8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\dhcpcsvc.dll
305128f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
305228f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume2\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
305328f8.2ba8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\nsi.dll
305428f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
305528f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
305628f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
305728f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
305828f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
305928f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
306028f8.2ba8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\dhcpcsvc.DLL (Input=dhcpcsvc.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000688eca1:<flags> [calling]
306128f8.2ba8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dhcpcsvc.dll
306228f8.2ba8: supR3HardenedDllNotificationCallback: load 000007fef89f0000 LB 0x00018000 C:\WINDOWS\system32\dhcpcsvc.DLL [fFlags=0x0]
306328f8.2ba8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dhcpcsvc.dll
306428f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef89f0000 'C:\WINDOWS\system32\dhcpcsvc.DLL'
306528f8.2ba8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL
306628f8.2ba8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\IPHLPAPI.DLL (Input=IPHLPAPI.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000688e901:<flags> [calling]
306728f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef9a00000 'C:\WINDOWS\system32\IPHLPAPI.DLL'
306828f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000ec8 pwszName=\Device\HarddiskVolume2\Windows\System32\dhcpcsvc6.dll
306928f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
307028f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
307128f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=A719769A21133C3F89F7BEA09AB706365F35DF8F
307228f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_26_for_KB2763523~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\dhcpcsvc6.dll'
307328f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
307428f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
307528f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'rpcrt4.dll'.
307628f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ws2_32.dll'.
307728f8.2ba8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\dhcpcsvc6.dll) WinVerifyTrust
307828f8.2ba8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\dhcpcsvc6.dll
307928f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
308028f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
308128f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
308228f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
308328f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
308428f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
308528f8.2ba8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\dhcpcsvc6.DLL (Input=dhcpcsvc6.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000688ec51:<flags> [calling]
308628f8.2ba8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dhcpcsvc6.dll
308728f8.2ba8: supR3HardenedDllNotificationCallback: load 000007fef89d0000 LB 0x00011000 C:\WINDOWS\system32\dhcpcsvc6.DLL [fFlags=0x0]
308828f8.2ba8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dhcpcsvc6.dll
308928f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef89d0000 'C:\WINDOWS\system32\dhcpcsvc6.DLL'
309028f8.2ba8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL
309128f8.2ba8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\IPHLPAPI.DLL (Input=IPHLPAPI.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000688e971:<flags> [calling]
309228f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef9a00000 'C:\WINDOWS\system32\IPHLPAPI.DLL'
309328f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000f5c pwszName=\Device\HarddiskVolume2\Windows\System32\dsound.dll
309428f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
309528f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
309628f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=F6C3E3D9F8B48D816E52C31576FFFD4AF86AB813
309728f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\dsound.dll'
309828f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
309928f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
310028f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
310128f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
310228f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ole32.dll'.
310328f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'winmm.dll'.
310428f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'powrprof.dll'.
310528f8.2ba8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\dsound.dll) WinVerifyTrust
310628f8.2ba8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\dsound.dll
310728f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'powrprof.dll'...
310828f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'powrprof.dll' -> '\Device\HarddiskVolume2\Windows\System32\powrprof.dll' [rcNtRedir=0xc0150008]
310928f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000f60 pwszName=\Device\HarddiskVolume2\Windows\System32\powrprof.dll
311028f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
311128f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
311228f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=E0B7DE18787DB24DAD3580634869A9A8FF4AB48F
311328f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\powrprof.dll'
311428f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
311528f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
311628f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'rpcrt4.dll'.
311728f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'setupapi.dll'.
311828f8.2ba8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\powrprof.dll) WinVerifyTrust
311928f8.2ba8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\powrprof.dll
312028f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
312128f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
312228f8.2ba8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
312328f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
312428f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
312528f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
312628f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
312728f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
312828f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
312928f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
313028f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
313128f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
313228f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
313328f8.2ba8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\setupapi.dll
313428f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
313528f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
313628f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
313728f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
313828f8.2ba8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000688dae1:<flags> [calling]
313928f8.2ba8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dsound.dll
314028f8.2ba8: supR3HardenedDllNotificationCallback: load 000007fedfe30000 LB 0x00088000 C:\WINDOWS\System32\dsound.dll [fFlags=0x0]
314128f8.2ba8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dsound.dll
314228f8.2ba8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\powrprof.dll
314328f8.2ba8: supR3HardenedDllNotificationCallback: load 000007fefb980000 LB 0x0002c000 C:\WINDOWS\System32\POWRPROF.dll [fFlags=0x0]
314428f8.2ba8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\powrprof.dll
314528f8.2ba8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dsound.dll
314628f8.2ba8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000688ce51:<flags> [calling]
314728f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fedfe30000 'C:\WINDOWS\System32\dsound.dll'
314828f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fedfe30000 'C:\WINDOWS\System32\dsound.dll'
314928f8.2ba8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dsound.dll
315028f8.2ba8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000688db31:<flags> [calling]
315128f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fedfe30000 'C:\WINDOWS\system32\dsound.dll'
315228f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000f70 pwszName=\Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
315328f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
315428f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
315528f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=704F97298D44B8146C54067788F597E0BF365197
315628f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll'
315728f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
315828f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
315928f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'user32.dll'.
316028f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'rpcrt4.dll'.
316128f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'propsys.dll'.
316228f8.2ba8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll) WinVerifyTrust
316328f8.2ba8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
316428f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'propsys.dll'...
316528f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'propsys.dll' -> '\Device\HarddiskVolume2\Windows\System32\propsys.dll' [rcNtRedir=0xc0150008]
316628f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000f88 pwszName=\Device\HarddiskVolume2\Windows\System32\propsys.dll
316728f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
316828f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
316928f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=6A1594E841359779EF7EA7EBCF775D89F55388D3
317028f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\propsys.dll'
317128f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
317228f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
317328f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ole32.dll'.
317428f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'oleaut32.dll'.
317528f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'user32.dll'.
317628f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'rpcrt4.dll'.
317728f8.2ba8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\propsys.dll) WinVerifyTrust
317828f8.2ba8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\propsys.dll
317928f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
318028f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
318128f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
318228f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
318328f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
318428f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
318528f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
318628f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
318728f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
318828f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
318928f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
319028f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
319128f8.2ba8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
319228f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
319328f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
319428f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
319528f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
319628f8.2ba8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\MMDevApi.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000688d5b1:<flags> [calling]
319728f8.2ba8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
319828f8.2ba8: supR3HardenedDllNotificationCallback: load 000007fefb9b0000 LB 0x0004b000 C:\WINDOWS\System32\MMDevApi.dll [fFlags=0x0]
319928f8.2ba8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
320028f8.2ba8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\propsys.dll
320128f8.2ba8: supR3HardenedDllNotificationCallback: load 000007fefb490000 LB 0x0012c000 C:\WINDOWS\System32\PROPSYS.dll [fFlags=0x0]
320228f8.2ba8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\propsys.dll
320328f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe940000 'C:\WINDOWS\system32\ADVAPI32.dll'
320428f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefb9b0000 'C:\WINDOWS\System32\MMDevApi.dll'
320528f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdf60000 'C:\WINDOWS\system32\ole32.dll'
320628f8.2ba8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\setupapi.dll
320728f8.2ba8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\SETUPAPI.dll (Input=SETUPAPI.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000688d8c1:<flags> [calling]
320828f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefeb20000 'C:\WINDOWS\system32\SETUPAPI.dll'
320928f8.2ba8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll
321028f8.2ba8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\SHLWAPI.dll (Input=SHLWAPI.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000688e731:<flags> [calling]
321128f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feffce0000 'C:\WINDOWS\system32\SHLWAPI.dll'
321228f8.2ba8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
321328f8.2ba8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\MMDEVAPI.DLL (Input=MMDEVAPI.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000688e951:<flags> [calling]
321428f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefb9b0000 'C:\WINDOWS\system32\MMDEVAPI.DLL'
321528f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdf60000 'C:\WINDOWS\system32\ole32.dll'
321628f8.1ab0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll
321728f8.1ab0: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\CFGMGR32.dll (Input=CFGMGR32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000005cdcf821:<flags> [calling]
321828f8.1ab0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd8d0000 'C:\WINDOWS\system32\CFGMGR32.dll'
321928f8.2ba8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
322028f8.2ba8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\winmm.dll (Input=winmm.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000688e581:<flags> [calling]
322128f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefae90000 'C:\WINDOWS\system32\winmm.dll'
322228f8.2ba8: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-Management-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=000000000688e3e1:<flags> [calling]
322328f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdf40000 'API-MS-WIN-Service-Management-L1-1-0.dll'
322428f8.2ba8: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-winsvc-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=000000000688e3e1:<flags> [calling]
322528f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdf40000 'API-MS-WIN-Service-winsvc-L1-1-0.dll'
322628f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feffbb0000 'C:\WINDOWS\system32\RPCRT4.dll'
322728f8.2ba8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
322828f8.2ba8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\MMDevAPI.DLL (Input=MMDevAPI.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000688e441:<flags> [calling]
322928f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefb9b0000 'C:\WINDOWS\system32\MMDevAPI.DLL'
323028f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000fc0 pwszName=\Device\HarddiskVolume2\Windows\System32\wdmaud.drv
323128f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
323228f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
323328f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=4B64306F5558D2DEC53CF11AAF17F02438929FDD
323428f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\wdmaud.drv'
323528f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
323628f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
323728f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
323828f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ole32.dll'.
323928f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'user32.dll'.
324028f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'winmm.dll'.
324128f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'ksuser.dll'.
324228f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'mmdevapi.dll'.
324328f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'avrt.dll'.
324428f8.2ba8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\wdmaud.drv) WinVerifyTrust
324528f8.2ba8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
324628f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'avrt.dll'...
324728f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'avrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\avrt.dll' [rcNtRedir=0xc0150008]
324828f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000fc4 pwszName=\Device\HarddiskVolume2\Windows\System32\avrt.dll
324928f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
325028f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
325128f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=1362C343929DD08AB918B38DE195D1A11B1D1365
325228f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\avrt.dll'
325328f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
325428f8.2ba8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\avrt.dll) WinVerifyTrust
325528f8.2ba8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\avrt.dll
325628f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mmdevapi.dll'...
325728f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'mmdevapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\mmdevapi.dll' [rcNtRedir=0xc0150008]
325828f8.2ba8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
325928f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ksuser.dll'...
326028f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ksuser.dll' -> '\Device\HarddiskVolume2\Windows\System32\ksuser.dll' [rcNtRedir=0xc0150008]
326128f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000fb0 pwszName=\Device\HarddiskVolume2\Windows\System32\ksuser.dll
326228f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
326328f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
326428f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2D99CFB3BFCA1F454FC7109DB98D18923ABBA361
326528f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_5_for_KB3110329~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\ksuser.dll'
326628f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
326728f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
326828f8.2ba8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ksuser.dll) WinVerifyTrust
326928f8.2ba8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ksuser.dll
327028f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
327128f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
327228f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
327328f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
327428f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
327528f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
327628f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
327728f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
327828f8.2ba8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
327928f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
328028f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
328128f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
328228f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
328328f8.2ba8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000688dfb1:<flags> [calling]
328428f8.2ba8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
328528f8.2ba8: supR3HardenedDllNotificationCallback: load 000007fefa1d0000 LB 0x0003b000 C:\WINDOWS\system32\wdmaud.drv [fFlags=0x0]
328628f8.2ba8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
328728f8.2ba8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ksuser.dll
328828f8.2ba8: supR3HardenedDllNotificationCallback: load 0000000074620000 LB 0x00006000 C:\WINDOWS\system32\ksuser.dll [fFlags=0x0]
328928f8.2ba8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ksuser.dll
329028f8.2ba8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\avrt.dll
329128f8.2ba8: supR3HardenedDllNotificationCallback: load 000007fefbc00000 LB 0x00009000 C:\WINDOWS\system32\AVRT.dll [fFlags=0x0]
329228f8.2ba8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\avrt.dll
329328f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa1d0000 'C:\WINDOWS\system32\wdmaud.drv'
329428f8.2ba8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
329528f8.2ba8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000688dfb1:<flags> [calling]
329628f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa1d0000 'C:\WINDOWS\system32\wdmaud.drv'
329728f8.2ba8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
329828f8.2ba8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000688e161:<flags> [calling]
329928f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa1d0000 'C:\WINDOWS\system32\wdmaud.drv'
330028f8.2ba8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
330128f8.2ba8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000688e161:<flags> [calling]
330228f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa1d0000 'C:\WINDOWS\system32\wdmaud.drv'
330328f8.2ba8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
330428f8.2ba8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000688e161:<flags> [calling]
330528f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa1d0000 'C:\WINDOWS\system32\wdmaud.drv'
330628f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000ffc pwszName=\Device\HarddiskVolume2\Windows\System32\AudioSes.dll
330728f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
330828f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
330928f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=6A3BDEC1E955295C342E14C90909598248B24E5B
331028f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_134_for_KB3192403~31bf3856ad364e35~amd64~~6.1.1.2.cat'; file='\Device\HarddiskVolume2\Windows\System32\AudioSes.dll'
331128f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
331228f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
331328f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
331428f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ole32.dll'.
331528f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'oleaut32.dll'.
331628f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
331728f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
331828f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'mmdevapi.dll'.
331928f8.2ba8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\AudioSes.dll) WinVerifyTrust
332028f8.2ba8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\AudioSes.dll
332128f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mmdevapi.dll'...
332228f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'mmdevapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\mmdevapi.dll' [rcNtRedir=0xc0150008]
332328f8.2ba8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
332428f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
332528f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
332628f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
332728f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
332828f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
332928f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
333028f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
333128f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
333228f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
333328f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
333428f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
333528f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
333628f8.2ba8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\AUDIOSES.DLL (Input=AUDIOSES.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000688e171:<flags> [calling]
333728f8.2ba8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\AudioSes.dll
333828f8.2ba8: supR3HardenedDllNotificationCallback: load 000007fefa160000 LB 0x0004f000 C:\WINDOWS\system32\AUDIOSES.DLL [fFlags=0x0]
333928f8.2ba8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\AudioSes.dll
334028f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa160000 'C:\WINDOWS\system32\AUDIOSES.DLL'
334128f8.2ba8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
334228f8.2ba8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000688e161:<flags> [calling]
334328f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa1d0000 'C:\WINDOWS\system32\wdmaud.drv'
334428f8.2ba8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
334528f8.2ba8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000688e161:<flags> [calling]
334628f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa1d0000 'C:\WINDOWS\system32\wdmaud.drv'
334728f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa1d0000 'C:\WINDOWS\system32\wdmaud.drv'
334828f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa1d0000 'C:\WINDOWS\system32\wdmaud.drv'
334928f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa1d0000 'C:\WINDOWS\system32\wdmaud.drv'
335028f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa1d0000 'C:\WINDOWS\system32\wdmaud.drv'
335128f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000fd8 pwszName=\Device\HarddiskVolume2\Windows\System32\msacm32.drv
335228f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
335328f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
335428f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=522563F5384AD4C93CF5CF4EEA899D3267552328
335528f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\msacm32.drv'
335628f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
335728f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
335828f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
335928f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'winmm.dll'.
336028f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msacm32.dll'.
336128f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'mmdevapi.dll'.
336228f8.2ba8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\msacm32.drv) WinVerifyTrust
336328f8.2ba8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msacm32.drv
336428f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mmdevapi.dll'...
336528f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'mmdevapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\mmdevapi.dll' [rcNtRedir=0xc0150008]
336628f8.2ba8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
336728f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msacm32.dll'...
336828f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msacm32.dll' -> '\Device\HarddiskVolume2\Windows\System32\msacm32.dll' [rcNtRedir=0xc0150008]
336928f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000fec pwszName=\Device\HarddiskVolume2\Windows\System32\msacm32.dll
337028f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
337128f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
337228f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=DCA0A8AEE81B82C402AA72A300B2C8D2DC17C1DA
337328f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\msacm32.dll'
337428f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
337528f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
337628f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
337728f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
337828f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
337928f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'winmm.dll'.
338028f8.2ba8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\msacm32.dll) WinVerifyTrust
338128f8.2ba8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msacm32.dll
338228f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
338328f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
338428f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
338528f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
338628f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
338728f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
338828f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
338928f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
339028f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
339128f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
339228f8.2ba8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll
339328f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
339428f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
339528f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
339628f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
339728f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
339828f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
339928f8.2ba8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000688df61:<flags> [calling]
340028f8.2ba8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
340128f8.2ba8: supR3HardenedDllNotificationCallback: load 000007fefa140000 LB 0x0000a000 C:\WINDOWS\system32\msacm32.drv [fFlags=0x0]
340228f8.2ba8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
340328f8.2ba8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.dll
340428f8.2ba8: supR3HardenedDllNotificationCallback: load 000007fefa110000 LB 0x00018000 C:\WINDOWS\system32\MSACM32.dll [fFlags=0x0]
340528f8.2ba8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.dll
340628f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa140000 'C:\WINDOWS\system32\msacm32.drv'
340728f8.2ba8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
340828f8.2ba8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000688d961:<flags> [calling]
340928f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa140000 'C:\WINDOWS\system32\msacm32.drv'
341028f8.2ba8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
341128f8.2ba8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000688d961:<flags> [calling]
341228f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa140000 'C:\WINDOWS\system32\msacm32.drv'
341328f8.2ba8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
341428f8.2ba8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000688d961:<flags> [calling]
341528f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa140000 'C:\WINDOWS\system32\msacm32.drv'
341628f8.2ba8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
341728f8.2ba8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000688d961:<flags> [calling]
341828f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa140000 'C:\WINDOWS\system32\msacm32.drv'
341928f8.2ba8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
342028f8.2ba8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000688d961:<flags> [calling]
342128f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa140000 'C:\WINDOWS\system32\msacm32.drv'
342228f8.2ba8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
342328f8.2ba8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000688d961:<flags> [calling]
342428f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa140000 'C:\WINDOWS\system32\msacm32.drv'
342528f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa140000 'C:\WINDOWS\system32\msacm32.drv'
342628f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa140000 'C:\WINDOWS\system32\msacm32.drv'
342728f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa140000 'C:\WINDOWS\system32\msacm32.drv'
342828f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000ff8 pwszName=\Device\HarddiskVolume2\Windows\System32\midimap.dll
342928f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
343028f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
343128f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=43116C5C719A4751DA70B12932084D73D7AACEA3
343228f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\midimap.dll'
343328f8.2ba8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
343428f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
343528f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
343628f8.2ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'winmm.dll'.
343728f8.2ba8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\midimap.dll) WinVerifyTrust
343828f8.2ba8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\midimap.dll
343928f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
344028f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
344128f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
344228f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
344328f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
344428f8.2ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
344528f8.2ba8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000688df61:<flags> [calling]
344628f8.2ba8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\midimap.dll
344728f8.2ba8: supR3HardenedDllNotificationCallback: load 000007fefa100000 LB 0x00009000 C:\WINDOWS\system32\midimap.dll [fFlags=0x0]
344828f8.2ba8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\midimap.dll
344928f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa100000 'C:\WINDOWS\system32\midimap.dll'
345028f8.2ba8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\midimap.dll
345128f8.2ba8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000688d931:<flags> [calling]
345228f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa100000 'C:\WINDOWS\system32\midimap.dll'
345328f8.2ba8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\midimap.dll
345428f8.2ba8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000688d931:<flags> [calling]
345528f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa100000 'C:\WINDOWS\system32\midimap.dll'
345628f8.2ba8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\midimap.dll
345728f8.2ba8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000688df61:<flags> [calling]
345828f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa100000 'C:\WINDOWS\system32\midimap.dll'
345928f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefae90000 'C:\WINDOWS\system32\winmm.dll'
346028f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefae90000 'C:\WINDOWS\system32\winmm.dll'
346128f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefae90000 'C:\WINDOWS\system32\winmm.dll'
346228f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdf60000 'C:\WINDOWS\system32\ole32.dll'
346328f8.2ba8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
346428f8.2ba8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\winmm.dll (Input=winmm.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000688e581:<flags> [calling]
346528f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefae90000 'C:\WINDOWS\system32\winmm.dll'
346628f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefae90000 'C:\WINDOWS\system32\winmm.dll'
346728f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefae90000 'C:\WINDOWS\system32\winmm.dll'
346828f8.2ba8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dsound.dll
346928f8.2ba8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000688db21:<flags> [calling]
347028f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fedfe30000 'C:\WINDOWS\system32\dsound.dll'
347128f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefae90000 'C:\WINDOWS\system32\winmm.dll'
347228f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefae90000 'C:\WINDOWS\system32\winmm.dll'
347328f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefae90000 'C:\WINDOWS\system32\winmm.dll'
347428f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefae90000 'C:\WINDOWS\system32\winmm.dll'
347528f8.269c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\AudioSes.dll
347628f8.269c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\audioses.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000005d6adbc1:<flags> [calling]
347728f8.269c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa160000 'C:\WINDOWS\System32\audioses.dll'
347828f8.2ba8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dsound.dll
347928f8.2ba8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000688dcf1:<flags> [calling]
348028f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fedfe30000 'C:\WINDOWS\system32\dsound.dll'
348128f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefae90000 'C:\WINDOWS\system32\winmm.dll'
348228f8.2ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fed3bb0000 'C:\local\apps\Virtualbox\VBoxVMM.DLL'
348328f8.2bd4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe170000 'C:\WINDOWS\system32\OLEAUT32.dll'
348428f8.2aa4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe940000 'C:\WINDOWS\system32\ADVAPI32.dll'
348528f8.498: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000011cc pwszName=\Device\HarddiskVolume2\Windows\System32\mswsock.dll
348628f8.498: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
348728f8.498: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
348828f8.498: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=A0B91C962716871F5DE8282805DA288326E03A9F
348928f8.498: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3161949~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\Windows\System32\mswsock.dll'
349028f8.498: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
349128f8.498: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
349228f8.498: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
349328f8.498: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rpcrt4.dll'.
349428f8.498: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ws2_32.dll'.
349528f8.498: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\mswsock.dll) WinVerifyTrust
349628f8.498: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\mswsock.dll
349728f8.498: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
349828f8.498: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
349928f8.498: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
350028f8.498: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
350128f8.498: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
350228f8.498: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
350328f8.498: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
350428f8.498: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
350528f8.498: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\mswsock.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000005c94f211:<flags> [calling]
350628f8.498: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\mswsock.dll
350728f8.498: supR3HardenedDllNotificationCallback: load 000007fefcf00000 LB 0x00055000 C:\WINDOWS\system32\mswsock.dll [fFlags=0x0]
350828f8.498: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\mswsock.dll
350928f8.498: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcf00000 'C:\WINDOWS\system32\mswsock.dll'
351028f8.498: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000011ec pwszName=\Device\HarddiskVolume2\Windows\System32\WSHTCPIP.DLL
351128f8.498: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000082a990
351228f8.498: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000082a990
351328f8.498: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=1EFFE58BB9FD8A94FD1609B7F82A43C8E09D98AA
351428f8.498: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\WSHTCPIP.DLL'
351528f8.498: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
351628f8.498: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'ws2_32.dll'.
351728f8.498: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\WSHTCPIP.DLL) WinVerifyTrust
351828f8.498: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\WSHTCPIP.DLL
351928f8.498: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
352028f8.498: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
352128f8.498: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\wshtcpip.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000005c94f3b1:<flags> [calling]
352228f8.498: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\WSHTCPIP.DLL
352328f8.498: supR3HardenedDllNotificationCallback: load 000007fefc6f0000 LB 0x00007000 C:\WINDOWS\System32\wshtcpip.dll [fFlags=0x0]
352428f8.498: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\WSHTCPIP.DLL
352528f8.498: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc6f0000 'C:\WINDOWS\System32\wshtcpip.dll'
352628f8.24e0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\avrt.dll
352728f8.24e0: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\avrt.dll (Input=avrt.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000c393f791:<flags> [calling]
352828f8.24e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbc00000 'C:\WINDOWS\system32\avrt.dll'
352928f8.1ab0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077830000 'C:\WINDOWS\system32\USER32.dll'
35302af0.2ae8: supR3HardNtChildWaitFor[2]: Quitting: ExitCode=0xc0000005 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 3675482 ms, the end);
35312ad8.2ae4: supR3HardNtChildWaitFor[1]: Quitting: ExitCode=0xc0000005 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 3676106 ms, the end);

© 2024 Oracle Support Privacy / Do Not Sell My Info Terms of Use Trademark Policy Automated Access Etiquette