VirtualBox

Ticket #17300: VBoxHardening - Copy.log

File VBoxHardening - Copy.log, 360.7 KB (added by ArtZ, 7 years ago)
Line 
12350.87c: Log file opened: 5.2.0r118431 g_hStartupLog=000000000000006c g_uNtVerCombined=0xa03fab00
22350.87c: \SystemRoot\System32\ntdll.dll:
32350.87c: CreationTime: 2017-11-16T13:33:16.236116900Z
42350.87c: LastWriteTime: 2017-10-25T04:37:21.227931100Z
52350.87c: ChangeTime: 2017-11-16T13:45:56.274982100Z
62350.87c: FileAttributes: 0x20
72350.87c: Size: 0x1dd100
82350.87c: NT Headers: 0xe0
92350.87c: Timestamp: 0x493793ea
102350.87c: Machine: 0x8664 - amd64
112350.87c: Timestamp: 0x493793ea
122350.87c: Image Version: 10.0
132350.87c: SizeOfImage: 0x1e0000 (1966080)
142350.87c: Resource Dir: 0x174000 LB 0x6a1d8
152350.87c: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
162350.87c: [Raw version resource data: 0x1740f0 LB 0x380, codepage 0x0 (reserved 0x0)]
172350.87c: ProductName: Microsoft® Windows® Operating System
182350.87c: ProductVersion: 10.0.16299.64
192350.87c: FileVersion: 10.0.16299.64 (WinBuild.160101.0800)
202350.87c: FileDescription: NT Layer DLL
212350.87c: \SystemRoot\System32\kernel32.dll:
222350.87c: CreationTime: 2017-09-29T13:42:04.954227600Z
232350.87c: LastWriteTime: 2017-09-29T13:42:04.954227600Z
242350.87c: ChangeTime: 2017-10-21T05:32:20.052658800Z
252350.87c: FileAttributes: 0x20
262350.87c: Size: 0xab868
272350.87c: NT Headers: 0xe8
282350.87c: Timestamp: 0xc2cf900
292350.87c: Machine: 0x8664 - amd64
302350.87c: Timestamp: 0xc2cf900
312350.87c: Image Version: 10.0
322350.87c: SizeOfImage: 0xae000 (712704)
332350.87c: Resource Dir: 0xac000 LB 0x520
342350.87c: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
352350.87c: [Raw version resource data: 0xac0b0 LB 0x3a4, codepage 0x0 (reserved 0x0)]
362350.87c: ProductName: Microsoft® Windows® Operating System
372350.87c: ProductVersion: 10.0.16299.15
382350.87c: FileVersion: 10.0.16299.15 (WinBuild.160101.0800)
392350.87c: FileDescription: Windows NT BASE API Client DLL
402350.87c: \SystemRoot\System32\KernelBase.dll:
412350.87c: CreationTime: 2017-09-29T13:41:43.124345500Z
422350.87c: LastWriteTime: 2017-09-29T13:41:43.124345500Z
432350.87c: ChangeTime: 2017-10-21T05:32:20.302684800Z
442350.87c: FileAttributes: 0x20
452350.87c: Size: 0x266000
462350.87c: NT Headers: 0xf0
472350.87c: Timestamp: 0x4736733c
482350.87c: Machine: 0x8664 - amd64
492350.87c: Timestamp: 0x4736733c
502350.87c: Image Version: 10.0
512350.87c: SizeOfImage: 0x266000 (2514944)
522350.87c: Resource Dir: 0x245000 LB 0x548
532350.87c: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
542350.87c: [Raw version resource data: 0x2450b0 LB 0x3bc, codepage 0x0 (reserved 0x0)]
552350.87c: ProductName: Microsoft® Windows® Operating System
562350.87c: ProductVersion: 10.0.16299.15
572350.87c: FileVersion: 10.0.16299.15 (WinBuild.160101.0800)
582350.87c: FileDescription: Windows NT BASE API Client DLL
592350.87c: \SystemRoot\System32\apisetschema.dll:
602350.87c: CreationTime: 2017-09-29T13:42:07.095026600Z
612350.87c: LastWriteTime: 2017-09-29T13:42:07.095026600Z
622350.87c: ChangeTime: 2017-10-21T02:24:31.486231200Z
632350.87c: FileAttributes: 0x20
642350.87c: Size: 0x1b398
652350.87c: NT Headers: 0xc8
662350.87c: Timestamp: 0xf30abf31
672350.87c: Machine: 0x8664 - amd64
682350.87c: Timestamp: 0xf30abf31
692350.87c: Image Version: 10.0
702350.87c: SizeOfImage: 0x1c000 (114688)
712350.87c: Resource Dir: 0x1b000 LB 0x408
722350.87c: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
732350.87c: [Raw version resource data: 0x1b060 LB 0x3a8, codepage 0x0 (reserved 0x0)]
742350.87c: ProductName: Microsoft® Windows® Operating System
752350.87c: ProductVersion: 10.0.16299.15
762350.87c: FileVersion: 10.0.16299.15 (WinBuild.160101.0800)
772350.87c: FileDescription: ApiSet Schema DLL
782350.87c: NtOpenDirectoryObject failed on \Driver: 0xc0000022
792350.87c: supR3HardenedWinFindAdversaries: 0x0
802350.87c: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox'
812350.87c: Calling main()
822350.87c: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
832350.87c: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox'
842350.87c: SUPR3HardenedMain: Respawn #1
852350.87c: System32: \Device\HarddiskVolume2\Windows\System32
862350.87c: WinSxS: \Device\HarddiskVolume2\Windows\WinSxS
872350.87c: KnownDllPath: C:\WINDOWS\System32
882350.87c: '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
892350.87c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VirtualBox.exe)
902350.87c: supR3HardNtEnableThreadCreation:
912350.87c: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffb01ec91b0 pvNtTerminateThread=00007ffb01ef0890
922350.87c: supR3HardenedWinDoReSpawn(1): New child fb4.1394 [kernel32].
932350.87c: supR3HardNtChildGatherData: PebBaseAddress=0000000000395000 cbPeb=0x388
942350.87c: supR3HardNtPuChFindNtdll: uNtDllParentAddr=00007ffb01e50000 uNtDllChildAddr=00007ffb01e50000
952350.87c: supR3HardenedWinSetupChildInit: uLdrInitThunk=00007ffb01ec91b0
962350.87c: supR3HardenedWinSetupChildInit: Start child.
972350.87c: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
982350.87c: supR3HardNtChildPurify: Startup delay kludge #1/0: 258 ms, 30 sleeps
992350.87c: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
1002350.87c: *0000000000000000-00000000000effff 0x0001/0x0000 0x0000000
1012350.87c: *00000000000f0000-000000000010ffff 0x0004/0x0004 0x0020000
1022350.87c: *0000000000110000-0000000000128fff 0x0002/0x0002 0x0040000
1032350.87c: 0000000000129000-000000000012ffff 0x0001/0x0000 0x0000000
1042350.87c: *0000000000130000-0000000000133fff 0x0002/0x0002 0x0040000
1052350.87c: 0000000000134000-000000000013ffff 0x0001/0x0000 0x0000000
1062350.87c: *0000000000140000-0000000000140fff 0x0004/0x0004 0x0020000
1072350.87c: 0000000000141000-00000000001fffff 0x0001/0x0000 0x0000000
1082350.87c: *0000000000200000-0000000000394fff 0x0000/0x0004 0x0020000
1092350.87c: 0000000000395000-0000000000397fff 0x0004/0x0004 0x0020000
1102350.87c: 0000000000398000-00000000003fffff 0x0000/0x0004 0x0020000
1112350.87c: *0000000000400000-00000000004fafff 0x0000/0x0004 0x0020000
1122350.87c: 00000000004fb000-00000000004fdfff 0x0104/0x0004 0x0020000
1132350.87c: 00000000004fe000-00000000004fffff 0x0004/0x0004 0x0020000
1142350.87c: 0000000000500000-000000007ffdffff 0x0001/0x0000 0x0000000
1152350.87c: *000000007ffe0000-000000007ffe0fff 0x0002/0x0002 0x0020000
1162350.87c: *000000007ffe1000-000000007ffeffff 0x0000/0x0002 0x0020000
1172350.87c: 000000007fff0000-00007ff783e6ffff 0x0001/0x0000 0x0000000
1182350.87c: *00007ff783e70000-00007ff783e92fff 0x0002/0x0002 0x0040000
1192350.87c: 00007ff783e93000-00007ff78456ffff 0x0001/0x0000 0x0000000
1202350.87c: *00007ff784570000-00007ff784570fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VirtualBox.exe
1212350.87c: 00007ff784571000-00007ff7845e1fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VirtualBox.exe
1222350.87c: 00007ff7845e2000-00007ff7845e2fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VirtualBox.exe
1232350.87c: 00007ff7845e3000-00007ff784628fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VirtualBox.exe
1242350.87c: 00007ff784629000-00007ff784629fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VirtualBox.exe
1252350.87c: 00007ff78462a000-00007ff78462afff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VirtualBox.exe
1262350.87c: 00007ff78462b000-00007ff78462ffff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VirtualBox.exe
1272350.87c: 00007ff784630000-00007ff784630fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VirtualBox.exe
1282350.87c: 00007ff784631000-00007ff784631fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VirtualBox.exe
1292350.87c: 00007ff784632000-00007ff784635fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VirtualBox.exe
1302350.87c: 00007ff784636000-00007ff78467dfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VirtualBox.exe
1312350.87c: 00007ff78467e000-00007ffb01e4ffff 0x0001/0x0000 0x0000000
1322350.87c: *00007ffb01e50000-00007ffb01e50fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
1332350.87c: 00007ffb01e51000-00007ffb01f62fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
1342350.87c: 00007ffb01f63000-00007ffb01fa8fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
1352350.87c: 00007ffb01fa9000-00007ffb01fb0fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
1362350.87c: 00007ffb01fb1000-00007ffb01fbefff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
1372350.87c: 00007ffb01fbf000-00007ffb01fbffff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
1382350.87c: 00007ffb01fc0000-00007ffb01fc2fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
1392350.87c: 00007ffb01fc3000-00007ffb0202ffff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
1402350.87c: 00007ffb02030000-00007ffffffdffff 0x0001/0x0000 0x0000000
1412350.87c: *00007ffffffe0000-00007ffffffeffff 0x0001/0x0002 0x0020000
1422350.87c: VirtualBox.exe: timestamp 0x59e6e5d5 (rc=VINF_SUCCESS)
1432350.87c: '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
1442350.87c: '\Device\HarddiskVolume2\Windows\System32\ntdll.dll' has no imports
1452350.87c: supR3HardNtChildPurify: Done after 279 ms and 0 fixes (loop #0).
146fb4.1394: Log file opened: 5.2.0r118431 g_hStartupLog=0000000000000004 g_uNtVerCombined=0xa03fab00
147fb4.1394: supR3HardenedVmProcessInit: uNtDllAddr=00007ffb01e50000 g_uNtVerCombined=0xa03fab00
148fb4.1394: ntdll.dll: timestamp 0x493793ea (rc=VINF_SUCCESS)
149fb4.1394: New simple heap: #1 0000000000600000 LB 0x400000 (for 1966080 allocation)
1502350.87c: supR3HardNtEnableThreadCreation:
151fb4.1394: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox'
152fb4.1394: System32: \Device\HarddiskVolume2\Windows\System32
153fb4.1394: WinSxS: \Device\HarddiskVolume2\Windows\WinSxS
154fb4.1394: KnownDllPath: C:\WINDOWS\System32
155fb4.1394: supR3HardenedVmProcessInit: Opening vboxdrv stub...
156fb4.1394: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
157fb4.1394: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
158fb4.1394: Registered Dll notification callback with NTDLL.
159fb4.1394: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\kernel32.dll)
160fb4.1394: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\kernel32.dll
161fb4.1394: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\KERNEL32.DLL (Input=KERNEL32.DLL, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000004001:<flags> [calling]
162fb4.1394: supR3HardenedDllNotificationCallback: load 00007ffafeca0000 LB 0x00266000 C:\WINDOWS\System32\KERNELBASE.dll [fFlags=0x0]
163fb4.1394: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\KernelBase.dll)
164fb4.1394: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\KernelBase.dll
165fb4.1394: supR3HardenedDllNotificationCallback: load 00007ffb01c60000 LB 0x000ae000 C:\WINDOWS\System32\KERNEL32.DLL [fFlags=0x0]
166fb4.1394: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
167fb4.1394: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb01c60000 'C:\WINDOWS\System32\KERNEL32.DLL'
168fb4.1394: supR3HardenedDllNotificationCallback: load 00007ff784570000 LB 0x0010e000 Z:\Program Files\Oracle\VirtualBox\VirtualBox.exe [fFlags=0x0]
169fb4.1394: '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
170fb4.1394: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VirtualBox.exe)
171fb4.1394: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VirtualBox.exe
172fb4.1394: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffb01ec91b0 pvNtTerminateThread=00007ffb01ef0890
1732350.87c: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 54 ms.
174fb4.1394: \SystemRoot\System32\ntdll.dll:
175fb4.1394: CreationTime: 2017-11-16T13:33:16.236116900Z
176fb4.1394: LastWriteTime: 2017-10-25T04:37:21.227931100Z
177fb4.1394: ChangeTime: 2017-11-16T13:45:56.274982100Z
178fb4.1394: FileAttributes: 0x20
179fb4.1394: Size: 0x1dd100
180fb4.1394: NT Headers: 0xe0
181fb4.1394: Timestamp: 0x493793ea
182fb4.1394: Machine: 0x8664 - amd64
183fb4.1394: Timestamp: 0x493793ea
184fb4.1394: Image Version: 10.0
185fb4.1394: SizeOfImage: 0x1e0000 (1966080)
186fb4.1394: Resource Dir: 0x174000 LB 0x6a1d8
187fb4.1394: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
188fb4.1394: [Raw version resource data: 0x1740f0 LB 0x380, codepage 0x0 (reserved 0x0)]
189fb4.1394: ProductName: Microsoft® Windows® Operating System
190fb4.1394: ProductVersion: 10.0.16299.64
191fb4.1394: FileVersion: 10.0.16299.64 (WinBuild.160101.0800)
192fb4.1394: FileDescription: NT Layer DLL
193fb4.1394: \SystemRoot\System32\kernel32.dll:
194fb4.1394: CreationTime: 2017-09-29T13:42:04.954227600Z
195fb4.1394: LastWriteTime: 2017-09-29T13:42:04.954227600Z
196fb4.1394: ChangeTime: 2017-10-21T05:32:20.052658800Z
197fb4.1394: FileAttributes: 0x20
198fb4.1394: Size: 0xab868
199fb4.1394: NT Headers: 0xe8
200fb4.1394: Timestamp: 0xc2cf900
201fb4.1394: Machine: 0x8664 - amd64
202fb4.1394: Timestamp: 0xc2cf900
203fb4.1394: Image Version: 10.0
204fb4.1394: SizeOfImage: 0xae000 (712704)
205fb4.1394: Resource Dir: 0xac000 LB 0x520
206fb4.1394: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
207fb4.1394: [Raw version resource data: 0xac0b0 LB 0x3a4, codepage 0x0 (reserved 0x0)]
208fb4.1394: ProductName: Microsoft® Windows® Operating System
209fb4.1394: ProductVersion: 10.0.16299.15
210fb4.1394: FileVersion: 10.0.16299.15 (WinBuild.160101.0800)
211fb4.1394: FileDescription: Windows NT BASE API Client DLL
212fb4.1394: \SystemRoot\System32\KernelBase.dll:
213fb4.1394: CreationTime: 2017-09-29T13:41:43.124345500Z
214fb4.1394: LastWriteTime: 2017-09-29T13:41:43.124345500Z
215fb4.1394: ChangeTime: 2017-10-21T05:32:20.302684800Z
216fb4.1394: FileAttributes: 0x20
217fb4.1394: Size: 0x266000
218fb4.1394: NT Headers: 0xf0
219fb4.1394: Timestamp: 0x4736733c
220fb4.1394: Machine: 0x8664 - amd64
221fb4.1394: Timestamp: 0x4736733c
222fb4.1394: Image Version: 10.0
223fb4.1394: SizeOfImage: 0x266000 (2514944)
224fb4.1394: Resource Dir: 0x245000 LB 0x548
225fb4.1394: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
226fb4.1394: [Raw version resource data: 0x2450b0 LB 0x3bc, codepage 0x0 (reserved 0x0)]
227fb4.1394: ProductName: Microsoft® Windows® Operating System
228fb4.1394: ProductVersion: 10.0.16299.15
229fb4.1394: FileVersion: 10.0.16299.15 (WinBuild.160101.0800)
230fb4.1394: FileDescription: Windows NT BASE API Client DLL
231fb4.1394: \SystemRoot\System32\apisetschema.dll:
232fb4.1394: CreationTime: 2017-09-29T13:42:07.095026600Z
233fb4.1394: LastWriteTime: 2017-09-29T13:42:07.095026600Z
234fb4.1394: ChangeTime: 2017-10-21T02:24:31.486231200Z
235fb4.1394: FileAttributes: 0x20
236fb4.1394: Size: 0x1b398
237fb4.1394: NT Headers: 0xc8
238fb4.1394: Timestamp: 0xf30abf31
239fb4.1394: Machine: 0x8664 - amd64
240fb4.1394: Timestamp: 0xf30abf31
241fb4.1394: Image Version: 10.0
242fb4.1394: SizeOfImage: 0x1c000 (114688)
243fb4.1394: Resource Dir: 0x1b000 LB 0x408
244fb4.1394: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
245fb4.1394: [Raw version resource data: 0x1b060 LB 0x3a8, codepage 0x0 (reserved 0x0)]
246fb4.1394: ProductName: Microsoft® Windows® Operating System
247fb4.1394: ProductVersion: 10.0.16299.15
248fb4.1394: FileVersion: 10.0.16299.15 (WinBuild.160101.0800)
249fb4.1394: FileDescription: ApiSet Schema DLL
250fb4.1394: NtOpenDirectoryObject failed on \Driver: 0xc0000022
251fb4.1394: supR3HardenedWinFindAdversaries: 0x0
252fb4.1394: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox'
253fb4.1394: Calling main()
254fb4.1394: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
255fb4.1394: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox'
256fb4.1394: '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
257fb4.1394: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VirtualBox.exe)
258fb4.1394: SUPR3HardenedMain: Respawn #2
259fb4.1394: supR3HardNtEnableThreadCreation:
260fb4.1394: '\Device\HarddiskVolume2\Windows\System32\ntdll.dll' has no imports
261fb4.1394: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ntdll.dll)
262fb4.1394: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ntdll.dll
263fb4.1394: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\ntdll.dll (Input=ntdll.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
264fb4.1394: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb01e50000 'C:\WINDOWS\System32\ntdll.dll'
265fb4.1394: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffb01ec91b0 pvNtTerminateThread=00007ffb01ef0890
266fb4.1394: supR3HardenedWinDoReSpawn(2): New child 1568.584 [kernel32].
267fb4.1394: supR3HardenedWinReSpawn: NtSetInformationThread/ThreadHideFromDebugger failed: 0xc0000022 (harmless)
268fb4.1394: supR3HardNtChildGatherData: PebBaseAddress=00000000006eb000 cbPeb=0x388
269fb4.1394: supR3HardNtPuChFindNtdll: uNtDllParentAddr=00007ffb01e50000 uNtDllChildAddr=00007ffb01e50000
270fb4.1394: supR3HardenedWinSetupChildInit: uLdrInitThunk=00007ffb01ec91b0
271fb4.1394: supR3HardenedWinSetupChildInit: Start child.
272fb4.1394: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
273fb4.1394: supR3HardNtChildPurify: Startup delay kludge #1/0: 257 ms, 30 sleeps
274fb4.1394: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
275fb4.1394: *0000000000000000-00000000005effff 0x0001/0x0000 0x0000000
276fb4.1394: *00000000005f0000-00000000005f3fff 0x0002/0x0002 0x0040000
277fb4.1394: 00000000005f4000-00000000005fffff 0x0001/0x0000 0x0000000
278fb4.1394: *0000000000600000-00000000006eafff 0x0000/0x0004 0x0020000
279fb4.1394: 00000000006eb000-00000000006edfff 0x0004/0x0004 0x0020000
280fb4.1394: 00000000006ee000-00000000007fffff 0x0000/0x0004 0x0020000
281fb4.1394: *0000000000800000-000000000081ffff 0x0004/0x0004 0x0020000
282fb4.1394: *0000000000820000-0000000000838fff 0x0002/0x0002 0x0040000
283fb4.1394: 0000000000839000-000000000083ffff 0x0001/0x0000 0x0000000
284fb4.1394: *0000000000840000-000000000093afff 0x0000/0x0004 0x0020000
285fb4.1394: 000000000093b000-000000000093dfff 0x0104/0x0004 0x0020000
286fb4.1394: 000000000093e000-000000000093ffff 0x0004/0x0004 0x0020000
287fb4.1394: *0000000000940000-0000000000940fff 0x0004/0x0004 0x0020000
288fb4.1394: 0000000000941000-000000007ffdffff 0x0001/0x0000 0x0000000
289fb4.1394: *000000007ffe0000-000000007ffe0fff 0x0002/0x0002 0x0020000
290fb4.1394: *000000007ffe1000-000000007ffeffff 0x0000/0x0002 0x0020000
291fb4.1394: 000000007fff0000-00007ff783d0ffff 0x0001/0x0000 0x0000000
292fb4.1394: *00007ff783d10000-00007ff783d32fff 0x0002/0x0002 0x0040000
293fb4.1394: 00007ff783d33000-00007ff78456ffff 0x0001/0x0000 0x0000000
294fb4.1394: *00007ff784570000-00007ff784570fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VirtualBox.exe
295fb4.1394: 00007ff784571000-00007ff7845e1fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VirtualBox.exe
296fb4.1394: 00007ff7845e2000-00007ff7845e2fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VirtualBox.exe
297fb4.1394: 00007ff7845e3000-00007ff784628fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VirtualBox.exe
298fb4.1394: 00007ff784629000-00007ff784629fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VirtualBox.exe
299fb4.1394: 00007ff78462a000-00007ff78462afff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VirtualBox.exe
300fb4.1394: 00007ff78462b000-00007ff78462ffff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VirtualBox.exe
301fb4.1394: 00007ff784630000-00007ff784630fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VirtualBox.exe
302fb4.1394: 00007ff784631000-00007ff784631fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VirtualBox.exe
303fb4.1394: 00007ff784632000-00007ff784635fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VirtualBox.exe
304fb4.1394: 00007ff784636000-00007ff78467dfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VirtualBox.exe
305fb4.1394: 00007ff78467e000-00007ffb01e4ffff 0x0001/0x0000 0x0000000
306fb4.1394: *00007ffb01e50000-00007ffb01e50fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
307fb4.1394: 00007ffb01e51000-00007ffb01f62fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
308fb4.1394: 00007ffb01f63000-00007ffb01fa8fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
309fb4.1394: 00007ffb01fa9000-00007ffb01fb0fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
310fb4.1394: 00007ffb01fb1000-00007ffb01fbefff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
311fb4.1394: 00007ffb01fbf000-00007ffb01fbffff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
312fb4.1394: 00007ffb01fc0000-00007ffb01fc2fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
313fb4.1394: 00007ffb01fc3000-00007ffb0202ffff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
314fb4.1394: 00007ffb02030000-00007ffffffdffff 0x0001/0x0000 0x0000000
315fb4.1394: *00007ffffffe0000-00007ffffffeffff 0x0001/0x0002 0x0020000
316fb4.1394: VirtualBox.exe: timestamp 0x59e6e5d5 (rc=VINF_SUCCESS)
317fb4.1394: '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
318fb4.1394: '\Device\HarddiskVolume2\Windows\System32\ntdll.dll' has no imports
319fb4.1394: supR3HardNtChildPurify: Done after 279 ms and 0 fixes (loop #0).
3201568.584: Log file opened: 5.2.0r118431 g_hStartupLog=0000000000000004 g_uNtVerCombined=0xa03fab00
3211568.584: supR3HardenedVmProcessInit: uNtDllAddr=00007ffb01e50000 g_uNtVerCombined=0xa03fab00
322fb4.1394: supR3HardenedEarlyCompact: Removed heap 1 (0x00000000600000 LB 0x400000)
3231568.584: ntdll.dll: timestamp 0x493793ea (rc=VINF_SUCCESS)
3241568.584: New simple heap: #1 0000000000a50000 LB 0x400000 (for 1966080 allocation)
325fb4.1394: supR3HardNtEnableThreadCreation:
3261568.584: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox'
3271568.584: System32: \Device\HarddiskVolume2\Windows\System32
3281568.584: WinSxS: \Device\HarddiskVolume2\Windows\WinSxS
3291568.584: KnownDllPath: C:\WINDOWS\System32
3301568.584: supR3HardenedVmProcessInit: Opening vboxdrv...
3311568.584: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
3321568.584: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
3331568.584: Registered Dll notification callback with NTDLL.
3341568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\kernel32.dll)
3351568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\kernel32.dll
3361568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\KERNEL32.DLL (Input=KERNEL32.DLL, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000004001:<flags> [calling]
3371568.584: supR3HardenedDllNotificationCallback: load 00007ffafeca0000 LB 0x00266000 C:\WINDOWS\System32\KERNELBASE.dll [fFlags=0x0]
3381568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\KernelBase.dll)
3391568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\KernelBase.dll
3401568.584: supR3HardenedDllNotificationCallback: load 00007ffb01c60000 LB 0x000ae000 C:\WINDOWS\System32\KERNEL32.DLL [fFlags=0x0]
3411568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
3421568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb01c60000 'C:\WINDOWS\System32\KERNEL32.DLL'
3431568.584: supR3HardenedDllNotificationCallback: load 00007ff784570000 LB 0x0010e000 Z:\Program Files\Oracle\VirtualBox\VirtualBox.exe [fFlags=0x0]
3441568.584: '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
3451568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VirtualBox.exe)
3461568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VirtualBox.exe
3471568.584: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffb01ec91b0 pvNtTerminateThread=00007ffb01ef0890
348fb4.1394: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 60 ms.
3491568.584: \SystemRoot\System32\ntdll.dll:
3501568.584: CreationTime: 2017-11-16T13:33:16.236116900Z
3511568.584: LastWriteTime: 2017-10-25T04:37:21.227931100Z
3521568.584: ChangeTime: 2017-11-16T13:45:56.274982100Z
3531568.584: FileAttributes: 0x20
3541568.584: Size: 0x1dd100
3551568.584: NT Headers: 0xe0
3561568.584: Timestamp: 0x493793ea
3571568.584: Machine: 0x8664 - amd64
3581568.584: Timestamp: 0x493793ea
3591568.584: Image Version: 10.0
3601568.584: SizeOfImage: 0x1e0000 (1966080)
3611568.584: Resource Dir: 0x174000 LB 0x6a1d8
3621568.584: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
3631568.584: [Raw version resource data: 0x1740f0 LB 0x380, codepage 0x0 (reserved 0x0)]
3641568.584: ProductName: Microsoft® Windows® Operating System
3651568.584: ProductVersion: 10.0.16299.64
3661568.584: FileVersion: 10.0.16299.64 (WinBuild.160101.0800)
3671568.584: FileDescription: NT Layer DLL
3681568.584: \SystemRoot\System32\kernel32.dll:
3691568.584: CreationTime: 2017-09-29T13:42:04.954227600Z
3701568.584: LastWriteTime: 2017-09-29T13:42:04.954227600Z
3711568.584: ChangeTime: 2017-10-21T05:32:20.052658800Z
3721568.584: FileAttributes: 0x20
3731568.584: Size: 0xab868
3741568.584: NT Headers: 0xe8
3751568.584: Timestamp: 0xc2cf900
3761568.584: Machine: 0x8664 - amd64
3771568.584: Timestamp: 0xc2cf900
3781568.584: Image Version: 10.0
3791568.584: SizeOfImage: 0xae000 (712704)
3801568.584: Resource Dir: 0xac000 LB 0x520
3811568.584: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
3821568.584: [Raw version resource data: 0xac0b0 LB 0x3a4, codepage 0x0 (reserved 0x0)]
3831568.584: ProductName: Microsoft® Windows® Operating System
3841568.584: ProductVersion: 10.0.16299.15
3851568.584: FileVersion: 10.0.16299.15 (WinBuild.160101.0800)
3861568.584: FileDescription: Windows NT BASE API Client DLL
3871568.584: \SystemRoot\System32\KernelBase.dll:
3881568.584: CreationTime: 2017-09-29T13:41:43.124345500Z
3891568.584: LastWriteTime: 2017-09-29T13:41:43.124345500Z
3901568.584: ChangeTime: 2017-10-21T05:32:20.302684800Z
3911568.584: FileAttributes: 0x20
3921568.584: Size: 0x266000
3931568.584: NT Headers: 0xf0
3941568.584: Timestamp: 0x4736733c
3951568.584: Machine: 0x8664 - amd64
3961568.584: Timestamp: 0x4736733c
3971568.584: Image Version: 10.0
3981568.584: SizeOfImage: 0x266000 (2514944)
3991568.584: Resource Dir: 0x245000 LB 0x548
4001568.584: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
4011568.584: [Raw version resource data: 0x2450b0 LB 0x3bc, codepage 0x0 (reserved 0x0)]
4021568.584: ProductName: Microsoft® Windows® Operating System
4031568.584: ProductVersion: 10.0.16299.15
4041568.584: FileVersion: 10.0.16299.15 (WinBuild.160101.0800)
4051568.584: FileDescription: Windows NT BASE API Client DLL
4061568.584: \SystemRoot\System32\apisetschema.dll:
4071568.584: CreationTime: 2017-09-29T13:42:07.095026600Z
4081568.584: LastWriteTime: 2017-09-29T13:42:07.095026600Z
4091568.584: ChangeTime: 2017-10-21T02:24:31.486231200Z
4101568.584: FileAttributes: 0x20
4111568.584: Size: 0x1b398
4121568.584: NT Headers: 0xc8
4131568.584: Timestamp: 0xf30abf31
4141568.584: Machine: 0x8664 - amd64
4151568.584: Timestamp: 0xf30abf31
4161568.584: Image Version: 10.0
4171568.584: SizeOfImage: 0x1c000 (114688)
4181568.584: Resource Dir: 0x1b000 LB 0x408
4191568.584: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
4201568.584: [Raw version resource data: 0x1b060 LB 0x3a8, codepage 0x0 (reserved 0x0)]
4211568.584: ProductName: Microsoft® Windows® Operating System
4221568.584: ProductVersion: 10.0.16299.15
4231568.584: FileVersion: 10.0.16299.15 (WinBuild.160101.0800)
4241568.584: FileDescription: ApiSet Schema DLL
4251568.584: NtOpenDirectoryObject failed on \Driver: 0xc0000022
4261568.584: supR3HardenedWinFindAdversaries: 0x0
4271568.584: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox'
4281568.584: Calling main()
4291568.584: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
4301568.584: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox'
4311568.584: '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
4321568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VirtualBox.exe)
4331568.584: SUPR3HardenedMain: Final process, opening VBoxDrv...
4341568.584: supR3HardenedEarlyCompact: Removed heap 1 (0x00000000a50000 LB 0x400000)
4351568.584: supR3HardNtEnableThreadCreation:
4361568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxSupLib.dll)
4371568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxSupLib.dll
4381568.584: supR3HardenedMonitor_LdrLoadDll: pName=Z:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
4391568.584: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
4401568.584: supR3HardenedDllNotificationCallback: load 00007ffafb310000 LB 0x00005000 Z:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL [fFlags=0x0]
4411568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
4421568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
4431568.584: supR3HardenedMonitor_LdrLoadDll: pName=Z:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
4441568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafb310000 'Z:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
4451568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
4461568.584: supR3HardenedMonitor_LdrLoadDll: pName=Z:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
4471568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafb310000 'Z:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
4481568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafb310000 'Z:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
4491568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
4501568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msasn1.dll'.
4511568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'crypt32.dll'.
4521568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #27 'rpcrt4.dll'.
4531568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\wintrust.dll)
4541568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wintrust.dll
4551568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
4561568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
4571568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll)
4581568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
4591568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
4601568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume2\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
4611568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #33 'msasn1.dll'.
4621568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\crypt32.dll)
4631568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\crypt32.dll
4641568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
4651568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume2\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
4661568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\msasn1.dll)
4671568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msasn1.dll
4681568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
4691568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
4701568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\msvcrt.dll)
4711568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
4721568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
4731568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume2\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
4741568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
4751568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
4761568.584: supR3HardenedDllNotificationCallback: load 00007ffaffb90000 LB 0x0009d000 C:\WINDOWS\System32\msvcrt.dll [fFlags=0x0]
4771568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
4781568.584: supR3HardenedDllNotificationCallback: load 00007ffafe210000 LB 0x00012000 C:\WINDOWS\System32\MSASN1.dll [fFlags=0x0]
4791568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
4801568.584: supR3HardenedDllNotificationCallback: load 00007ffafeb40000 LB 0x000f6000 C:\WINDOWS\System32\ucrtbase.dll [fFlags=0x0]
4811568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ucrtbase.dll)
4821568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ucrtbase.dll
4831568.584: supR3HardenedDllNotificationCallback: load 00007ffafef10000 LB 0x001ce000 C:\WINDOWS\System32\CRYPT32.dll [fFlags=0x0]
4841568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
4851568.584: supR3HardenedDllNotificationCallback: load 00007ffb01490000 LB 0x0011f000 C:\WINDOWS\System32\RPCRT4.dll [fFlags=0x0]
4861568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
4871568.584: supR3HardenedDllNotificationCallback: load 00007ffb01c00000 LB 0x0005b000 C:\WINDOWS\System32\sechost.dll [fFlags=0x0]
4881568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'rpcrt4.dll'.
4891568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\sechost.dll)
4901568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\sechost.dll
4911568.584: supR3HardenedDllNotificationCallback: load 00007ffaff8d0000 LB 0x000a1000 C:\WINDOWS\System32\advapi32.dll [fFlags=0x0]
4921568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
4931568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'sechost.dll'.
4941568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #27 'rpcrt4.dll'.
4951568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\advapi32.dll)
4961568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\advapi32.dll
4971568.584: supR3HardenedDllNotificationCallback: load 00007ffafec40000 LB 0x00058000 C:\WINDOWS\System32\Wintrust.dll [fFlags=0x0]
4981568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
4991568.584: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
5001568.584: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
5011568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafeca0000 'api-ms-win-core-synch-l1-2-0'
5021568.584: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-fibers-l1-1-1) -> 0x0, fPresent=1
5031568.584: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
5041568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafeca0000 'api-ms-win-core-fibers-l1-1-1'
5051568.584: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-fibers-l1-1-1) -> 0x0, fPresent=1
5061568.584: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
5071568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafeca0000 'api-ms-win-core-fibers-l1-1-1'
5081568.584: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
5091568.584: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
5101568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafeca0000 'api-ms-win-core-synch-l1-2-0'
5111568.584: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-l1-2-1) -> 0x0, fPresent=1
5121568.584: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-l1-2-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
5131568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafeca0000 'api-ms-win-core-localization-l1-2-1'
5141568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafec40000 'C:\WINDOWS\system32\Wintrust.dll'
5151568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\bcrypt.dll)
5161568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\bcrypt.dll
5171568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
5181568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
5191568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
5201568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'sechost.dll'...
5211568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'sechost.dll' -> '\Device\HarddiskVolume2\Windows\System32\sechost.dll' [rcNtRedir=0xc0150008]
5221568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\sechost.dll [lacks WinVerifyTrust]
5231568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
5241568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
5251568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
5261568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
5271568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
5281568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
5291568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\bcrypt.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
5301568.584: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
5311568.584: supR3HardenedDllNotificationCallback: load 00007ffafdd00000 LB 0x00025000 C:\WINDOWS\system32\bcrypt.dll [fFlags=0x0]
5321568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
5331568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafdd00000 'C:\WINDOWS\system32\bcrypt.dll'
5341568.584: bcrypt.dll loaded at 00007ffafdd00000, BCryptOpenAlgorithmProvider at 00007ffafdd02590, preloading providers:
5351568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll)
5361568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll
5371568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\bcryptprimitives.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
5381568.584: supR3HardenedDllNotificationCallback: load 00007ffaff190000 LB 0x00072000 C:\WINDOWS\System32\bcryptprimitives.dll [fFlags=0x0]
5391568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
5401568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaff190000 'C:\WINDOWS\system32\bcryptprimitives.dll'
5411568.584: BCryptOpenAlgorithmProvider(,'MD2',0,0) -> 0x0 (hAlgo=0000000002fa4ec0)
5421568.584: BCryptOpenAlgorithmProvider(,'MD4',0,0) -> 0x0 (hAlgo=0000000002faed60)
5431568.584: BCryptOpenAlgorithmProvider(,'MD5',0,0) -> 0x0 (hAlgo=0000000002faf030)
5441568.584: BCryptOpenAlgorithmProvider(,'SHA1',0,0) -> 0x0 (hAlgo=0000000002faf300)
5451568.584: BCryptOpenAlgorithmProvider(,'SHA256',0,0) -> 0x0 (hAlgo=0000000002faf5d0)
5461568.584: BCryptOpenAlgorithmProvider(,'SHA512',0,0) -> 0x0 (hAlgo=0000000002fb00b0)
5471568.584: BCryptOpenAlgorithmProvider(,'RSA',0,0) -> 0x0 (hAlgo=0000000002fb0380)
5481568.584: BCryptOpenAlgorithmProvider(,'DSA',0,0) -> 0x0 (hAlgo=0000000002fb0650)
5491568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
5501568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
5511568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafec40000 'C:\Windows\System32\WINTRUST.DLL'
5521568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
5531568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
5541568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafec40000 'C:\Windows\System32\WINTRUST.DLL'
5551568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
5561568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
5571568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafec40000 'C:\Windows\System32\WINTRUST.DLL'
5581568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
5591568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
5601568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafec40000 'C:\Windows\System32\WINTRUST.DLL'
5611568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
5621568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
5631568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafec40000 'C:\Windows\System32\WINTRUST.DLL'
5641568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
5651568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
5661568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafec40000 'C:\Windows\System32\WINTRUST.DLL'
5671568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
5681568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
5691568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafec40000 'C:\Windows\System32\WINTRUST.DLL'
5701568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\cryptsp.dll)
5711568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cryptsp.dll
5721568.584: supR3HardenedDllNotificationCallback: load 00007ffafdbf0000 LB 0x00017000 C:\WINDOWS\SYSTEM32\CRYPTSP.dll [fFlags=0x0]
5731568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cryptsp.dll [lacks WinVerifyTrust]
5741568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'bcrypt.dll'.
5751568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\rsaenh.dll)
5761568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\rsaenh.dll
5771568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
5781568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume2\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
5791568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
5801568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
5811568.584: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
5821568.584: supR3HardenedDllNotificationCallback: load 00007ffafd5e0000 LB 0x00033000 C:\WINDOWS\system32\rsaenh.dll [fFlags=0x0]
5831568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
5841568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
5851568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'bcryptprimitives.dll'.
5861568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\cryptbase.dll)
5871568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cryptbase.dll
5881568.584: supR3HardenedDllNotificationCallback: load 00007ffafdc10000 LB 0x0000b000 C:\WINDOWS\SYSTEM32\CRYPTBASE.dll [fFlags=0x0]
5891568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cryptbase.dll [lacks WinVerifyTrust]
5901568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
5911568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcryptprimitives.dll'...
5921568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcryptprimitives.dll' -> '\Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll' [rcNtRedir=0xc0150008]
5931568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
5941568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
5951568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb01c60000 'C:\WINDOWS\System32\kernel32.dll'
5961568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
5971568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafec40000 'C:\Windows\System32\WINTRUST.DLL'
5981568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
5991568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\CRYPT32.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
6001568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\CRYPT32.dll'
6011568.584: supR3HardenedDllNotificationCallback: load 00007ffb01170000 LB 0x0001d000 C:\WINDOWS\System32\imagehlp.dll [fFlags=0x0]
6021568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\imagehlp.dll)
6031568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\imagehlp.dll
6041568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
6051568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
6061568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
6071568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
6081568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'rpcrt4.dll'.
6091568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\gpapi.dll)
6101568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\gpapi.dll
6111568.584: supR3HardenedDllNotificationCallback: load 00007ffafcf90000 LB 0x00022000 C:\WINDOWS\SYSTEM32\gpapi.dll [fFlags=0x0]
6121568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gpapi.dll [lacks WinVerifyTrust]
6131568.584: supR3HardenedDllNotificationCallback: load 00007ffafe230000 LB 0x0001b000 C:\WINDOWS\System32\profapi.dll [fFlags=0x0]
6141568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\profapi.dll)
6151568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\profapi.dll
6161568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
6171568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'crypt32.dll'.
6181568.584: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\cryptnet.dll)
6191568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cryptnet.dll
6201568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
6211568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume2\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
6221568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
6231568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
6241568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
6251568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
6261568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
6271568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
6281568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
6291568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
6301568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
6311568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
6321568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (Input=cryptnet.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
6331568.584: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6341568.584: supR3HardenedDllNotificationCallback: load 00007ffadfae0000 LB 0x0002f000 C:\WINDOWS\System32\cryptnet.dll [fFlags=0x0]
6351568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6361568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6371568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
6381568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffadfae0000 'C:\WINDOWS\System32\cryptnet.dll'
6391568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6401568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
6411568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffadfae0000 'C:\WINDOWS\System32\cryptnet.dll'
6421568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6431568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
6441568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffadfae0000 'C:\WINDOWS\System32\cryptnet.dll'
6451568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6461568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
6471568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffadfae0000 'C:\WINDOWS\System32\cryptnet.dll'
6481568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6491568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
6501568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffadfae0000 'C:\WINDOWS\System32\cryptnet.dll'
6511568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6521568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
6531568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffadfae0000 'C:\WINDOWS\System32\cryptnet.dll'
6541568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6551568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffadfae0000 'C:\WINDOWS\System32\cryptnet.dll'
6561568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6571568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffadfae0000 'C:\WINDOWS\System32\cryptnet.dll'
6581568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6591568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffadfae0000 'C:\WINDOWS\System32\cryptnet.dll'
6601568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6611568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffadfae0000 'C:\WINDOWS\System32\cryptnet.dll'
6621568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6631568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffadfae0000 'C:\WINDOWS\System32\cryptnet.dll'
6641568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffadfae0000 'C:\WINDOWS\System32\cryptnet.dll'
6651568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6661568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffadfae0000 'C:\Windows\System32\cryptnet.dll'
6671568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
6681568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
6691568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
6701568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
6711568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
6721568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
6731568.584: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000000 pwszName=\SystemRoot\System32\ntdll.dll
6741568.584: supR3HardNtViCallWinVerifyTrustCatFile: New context 000000000302c490
6751568.584: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000302c490
6761568.584: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=53496CD1E8E6D63F8EA58DDB173BEA60E4848C3E
6771568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
6781568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\rpcrt4.dll (Input=rpcrt4.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
6791568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb01490000 'C:\WINDOWS\System32\rpcrt4.dll'
6801568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
6811568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafec40000 'C:\Windows\System32\WINTRUST.DLL'
6821568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
6831568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafec40000 'C:\Windows\System32\WINTRUST.DLL'
6841568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
6851568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafec40000 'C:\Windows\System32\WINTRUST.DLL'
6861568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
6871568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafec40000 'C:\Windows\System32\WINTRUST.DLL'
6881568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
6891568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafec40000 'C:\Windows\System32\WINTRUST.DLL'
6901568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
6911568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafec40000 'C:\Windows\System32\WINTRUST.DLL'
6921568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
6931568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
6941568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafec40000 'C:\Windows\System32\WINTRUST.DLL'
6951568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
6961568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
6971568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
6981568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
6991568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
7001568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
7011568.584: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_564_for_KB4048955~31bf3856ad364e35~amd64~~10.0.1.8.cat'; file='\SystemRoot\System32\ntdll.dll'
7021568.584: g_pfnWinVerifyTrust=00007ffafec46bc0
7031568.584: supR3HardenedScreenImage/preload: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [redoing WinVerifyTrust]
7041568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
7051568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
7061568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
7071568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
7081568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
7091568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
7101568.584: supR3HardenedScreenImage/preload: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\crypt32.dll'
7111568.584: supR3HardenedScreenImage/preload: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [redoing WinVerifyTrust]
7121568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
7131568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
7141568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
7151568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll
7161568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
7171568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
7181568.584: supR3HardenedScreenImage/preload: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\wintrust.dll'
7191568.584: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000388 pwszName=\Device\HarddiskVolume2\Windows\System32\cryptnet.dll
7201568.584: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000302c490
7211568.584: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000302c490
7221568.584: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=5A0BC1B38B9F5EE15493A1BB6ABB29D2FFBB4119
7231568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
7241568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
7251568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
7261568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
7271568.584: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0015~31bf3856ad364e35~amd64~~10.0.16299.15.cat'; file='\Device\HarddiskVolume2\Windows\System32\cryptnet.dll'
7281568.584: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
7291568.584: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\cryptnet.dll'
7301568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
7311568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
7321568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
7331568.584: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\profapi.dll'
7341568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
7351568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
7361568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
7371568.584: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\gpapi.dll'
7381568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
7391568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
7401568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
7411568.584: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\imagehlp.dll'
7421568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
7431568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
7441568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
7451568.584: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\cryptbase.dll'
7461568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
7471568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
7481568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
7491568.584: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\rsaenh.dll'
7501568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
7511568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
7521568.584: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\cryptsp.dll'
7531568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
7541568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll
7551568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
7561568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
7571568.584: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll'
7581568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll
7591568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
7601568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
7611568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
7621568.584: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\bcrypt.dll'
7631568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
7641568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
7651568.584: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\advapi32.dll'
7661568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
7671568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
7681568.584: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\sechost.dll'
7691568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
7701568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
7711568.584: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\ucrtbase.dll'
7721568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
7731568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
7741568.584: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll'
7751568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
7761568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
7771568.584: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\msasn1.dll'
7781568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
7791568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
7801568.584: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll'
7811568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
7821568.584: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxSupLib.dll'
7831568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
7841568.584: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VirtualBox.exe'
7851568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
7861568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
7871568.584: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\KernelBase.dll'
7881568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
7891568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
7901568.584: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\kernel32.dll'
7911568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\system32\crypt32.dll'
7921568.584: supR3HardenedWinIsDesiredRootCA: Adding 0x5ad46780fa5df300 DC=com, DC=microsoft, CN=Microsoft Root Certificate Authority
7931568.584: supR3HardenedWinIsDesiredRootCA: Adding 0xea5386456178582b C=ZA, ST=Western Cape, L=Durbanville, O=Thawte, OU=Thawte Certification, CN=Thawte Timestamping CA
7941568.584: supR3HardenedWinIsDesiredRootCA: Adding 0x3be670c1bd02a900 OU=Copyright (c) 1997 Microsoft Corp., OU=Microsoft Corporation, CN=Microsoft Root Authority
7951568.584: supR3HardenedWinIsDesiredRootCA: Adding 0xe991ee72b03db500 C=US, O=Symantec Corporation, CN=Symantec Enterprise Mobile Root for Microsoft
7961568.584: supR3HardenedWinIsDesiredRootCA: Adding 0x4d3835aa4180b200 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2011
7971568.584: supR3HardenedWinIsDesiredRootCA: Adding 0x646e3fe3ba08df00 C=US, O=MSFT, CN=Microsoft Authenticode(tm) Root Authority
7981568.584: supR3HardenedWinIsDesiredRootCA: Adding 0xece4e4289e08b900 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010
7991568.584: supR3HardenedWinIsDesiredRootCA: Adding 0x43a9cc371ff5385a O=Microsoft Trust Network, OU=Microsoft Corporation, OU=Microsoft Time Stamping Service Root, OU=Copyright (c) 1997 Microsoft Corp.
8001568.584: supR3HardenedWinIsDesiredRootCA: Adding 0x2e2d2c7c68f0202e O=VeriSign Trust Network, OU=VeriSign, Inc., OU=VeriSign Time Stamping Service Root, OU=NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.
8011568.584: supR3HardenedWinIsDesiredRootCA: Adding 0xd8dbfb2c27bfb200 C=US, O=thawte, Inc., OU=Certification Services Division, OU=(c) 2008 thawte, Inc. - For authorized use only, CN=thawte Primary Root CA - G3
8021568.584: supR3HardenedWinIsDesiredRootCA: Adding 0x61a3a33f81aace00 C=US, ST=UT, L=Salt Lake City, O=The USERTRUST Network, OU=http://www.usertrust.com, CN=UTN-USERFirst-Object
8031568.584: supR3HardenedWinIsDesiredRootCA: Adding 0x50bb81640c01cb00 C=TW, O=TAIWAN-CA, OU=Root CA, CN=TWCA Root Certification Authority
8041568.584: supR3HardenedWinIsDesiredRootCA: Adding 0x57ba5395b561bf00 C=BM, O=QuoVadis Limited, OU=Root Certification Authority, CN=QuoVadis Root Certification Authority
8051568.584: supR3HardenedWinIsDesiredRootCA: Adding 0xf4fd306318ccda00 C=US, O=GeoTrust Inc., CN=GeoTrust Global CA
8061568.584: supR3HardenedWinIsDesiredRootCA: Adding 0x83085097e9afdf00 O=Digital Signature Trust Co., CN=DST Root CA X3
8071568.584: supR3HardenedWinIsDesiredRootCA: Adding 0x780679907625cc00 OU=GlobalSign Root CA - R3, O=GlobalSign, CN=GlobalSign
8081568.584: supR3HardenedWinIsDesiredRootCA: Adding 0x3d98ab22bb04a300 C=IE, O=Baltimore, OU=CyberTrust, CN=Baltimore CyberTrust Root
8091568.584: supR3HardenedWinIsDesiredRootCA: Adding 0xa0ee62086758b15d C=US, O=Equifax, OU=Equifax Secure Certificate Authority
8101568.584: supR3HardenedWinIsDesiredRootCA: Adding 0x9403a4b8727eb000 C=TW, O=TAIWAN-CA, OU=Root CA, CN=TWCA Root Certification Authority
8111568.584: supR3HardenedWinIsDesiredRootCA: Adding 0xd944bca189a00 C=BM, O=QuoVadis Limited, CN=QuoVadis Root CA 2
8121568.584: supR3HardenedWinIsDesiredRootCA: Adding 0x8ff6fc03c1edbd00 C=US, ST=Arizona, L=Scottsdale, O=Starfield Technologies, Inc., CN=Starfield Root Certificate Authority - G2
8131568.584: supR3HardenedWinIsDesiredRootCA: Adding 0xc6fa4243b695b600 C=US, O=Entrust, Inc., OU=www.entrust.net/CPS is incorporated by reference, OU=(c) 2006 Entrust, Inc., CN=Entrust Root Certification Authority
8141568.584: supR3HardenedWinIsDesiredRootCA: Adding 0xa3ce8d99e60eda00 C=BE, O=GlobalSign nv-sa, OU=Root CA, CN=GlobalSign Root CA
8151568.584: supR3HardenedWinIsDesiredRootCA: Adding 0x560ad29254e89100 C=GB, ST=Greater Manchester, L=Salford, O=COMODO CA Limited, CN=COMODO RSA Certification Authority
8161568.584: supR3HardenedWinIsDesiredRootCA: Adding 0xa671e9fec832b700 C=US, O=Starfield Technologies, Inc., OU=Starfield Class 2 Certification Authority
8171568.584: supR3HardenedWinIsDesiredRootCA: Adding 0xa8de7211e13be200 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root CA
8181568.584: supR3HardenedWinIsDesiredRootCA: Adding 0xd45980fbf0a0ac00 C=US, O=thawte, Inc., OU=Certification Services Division, OU=(c) 2006 thawte, Inc. - For authorized use only, CN=thawte Primary Root CA
8191568.584: supR3HardenedWinIsDesiredRootCA: Adding 0xc9edb72b684ba00 C=US, O=Entrust, Inc., OU=See www.entrust.net/legal-terms, OU=(c) 2009 Entrust, Inc. - for authorized use only, CN=Entrust Root Certification Authority - G2
8201568.584: supR3HardenedWinIsDesiredRootCA: Adding 0xf5cd95e581a4ab00 C=US, O=SecureTrust Corporation, CN=SecureTrust CA
8211568.584: supR3HardenedWinIsDesiredRootCA: Adding 0x6f2ebe0e24cfa600 OU=GlobalSign Root CA - R2, O=GlobalSign, CN=GlobalSign
8221568.584: supR3HardenedWinIsDesiredRootCA: Adding 0x14018a1bf29e595c C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority
8231568.584: supR3HardenedWinIsDesiredRootCA: Adding 0x9e5bc2d78b6a3636 C=ZA, ST=Western Cape, L=Cape Town, O=Thawte Consulting cc, OU=Certification Services Division, CN=Thawte Premium Server CA, Email=premium-server@thawte.com
8241568.584: supR3HardenedWinIsDesiredRootCA: Adding 0x7c4fd32ec1b1ce00 C=PL, O=Unizeto Sp. z o.o., CN=Certum CA
8251568.584: supR3HardenedWinIsDesiredRootCA: Adding 0xd4fbe673e5ccc600 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA
8261568.584: supR3HardenedWinIsDesiredRootCA: Adding 0x16e64d2a56ccf200 C=US, ST=Arizona, L=Scottsdale, O=Starfield Technologies, Inc., OU=http://certificates.starfieldtech.com/repository/, CN=Starfield Services Root Certificate Authority
8271568.584: supR3HardenedWinIsDesiredRootCA: Adding 0x1b8578514b74ac00 C=US, O=WFA Hotspot 2.0, CN=Hotspot 2.0 Trust Root CA - 03
8281568.584: supR3HardenedWinIsDesiredRootCA: Adding 0xb28612a94b4dad00 O=Entrust.net, OU=www.entrust.net/CPS_2048 incorp. by ref. (limits liab.), OU=(c) 1999 Entrust.net Limited, CN=Entrust.net Certification Authority (2048)
8291568.584: supR3HardenedWinIsDesiredRootCA: Adding 0x357a29080824af00 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2006 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G5
8301568.584: supR3HardenedWinIsDesiredRootCA: Adding 0x59faf1086271bf00 C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com, Inc., CN=Go Daddy Root Certificate Authority - G2
8311568.584: supR3HardenedWinIsDesiredRootCA: Adding 0xb16dd37ffeb3b300 C=JP, O=SECOM Trust.net, OU=Security Communication RootCA1
8321568.584: supR3HardenedWinIsDesiredRootCA: Adding 0x3401b15e3761c700 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2008 VeriSign, Inc. - For authorized use only, CN=VeriSign Universal Root Certification Authority
8331568.584: supR3HardenedWinIsDesiredRootCA: Adding 0x7cd4ff7b15b8be00 C=US, O=GeoTrust Inc., CN=GeoTrust Primary Certification Authority
8341568.584: supR3HardenedWinIsDesiredRootCA: Adding 0x491857ead79dde00 C=US, O=The Go Daddy Group, Inc., OU=Go Daddy Class 2 Certification Authority
8351568.584: supR3HardenedWinIsDesiredRootCA: Adding 0x1f78fc529cbacb00 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 1999 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G3
8361568.584: supR3HardenedWinIsDesiredRootCA: Adding 0xdc1801b225aea100 C=BM, O=QuoVadis Limited, CN=QuoVadis Root CA 2 G3
8371568.584: supR3HardenedWinIsDesiredRootCA: Adding 0xc2ba72a37dfbe300 C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Trusted Network CA
8381568.584: supR3HardenedWinIsDesiredRootCA: Adding 0x8043e4ce150ead00 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID Root CA
8391568.584: supR3HardenedWinIsDesiredRootCA: Adding 0x331d58625ee2dc00 C=US, O=GeoTrust Inc., OU=(c) 2008 GeoTrust Inc. - For authorized use only, CN=GeoTrust Primary Certification Authority - G3
8401568.584: supR3HardenedWinIsDesiredRootCA: Adding 0xf2e6331af7b700 C=SE, O=AddTrust AB, OU=AddTrust External TTP Network, CN=AddTrust External CA Root
8411568.584: supR3HardenedWinRetrieveTrustedRootCAs: cAdded=49
8421568.584: SUPR3HardenedMain: Load Runtime...
8431568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
8441568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
8451568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
8461568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ws2_32.dll'.
8471568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'rpcrt4.dll'.
8481568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxRT.dll) WinVerifyTrust
8491568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxRT.dll
8501568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
8511568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
8521568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
8531568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
8541568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
8551568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
8561568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
8571568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'rpcrt4.dll'.
8581568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ws2_32.dll) WinVerifyTrust
8591568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
8601568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
8611568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
8621568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
8631568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
8641568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
8651568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
8661568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
8671568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcp100.dll) WinVerifyTrust
8681568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcp100.dll
8691568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
8701568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
8711568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
8721568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
8731568.584: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcr100.dll'.
8741568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcr100.dll)
8751568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcr100.dll
8761568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
8771568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcr100.dll) WinVerifyTrust
8781568.584: supR3HardenedMonitor_LdrLoadDll: pName=Z:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000a01:<flags> [calling]
8791568.584: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxRT.dll
8801568.584: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcr100.dll [avoiding WinVerifyTrust]
8811568.584: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcp100.dll
8821568.584: supR3HardenedDllNotificationCallback: load 0000000061010000 LB 0x000d2000 Z:\Program Files\Oracle\VirtualBox\MSVCR100.dll [fFlags=0x0]
8831568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcr100.dll [avoiding WinVerifyTrust]
8841568.584: supR3HardenedDllNotificationCallback: load 00000000610f0000 LB 0x00098000 Z:\Program Files\Oracle\VirtualBox\MSVCP100.dll [fFlags=0x0]
8851568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcp100.dll
8861568.584: supR3HardenedDllNotificationCallback: load 00007ffaff980000 LB 0x0006c000 C:\WINDOWS\System32\WS2_32.dll [fFlags=0x0]
8871568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
8881568.584: supR3HardenedDllNotificationCallback: load 00007ffac8a30000 LB 0x00595000 Z:\Program Files\Oracle\VirtualBox\VBoxRT.dll [fFlags=0x0]
8891568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxRT.dll
8901568.584: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcr100.dll'.
8911568.584: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
8921568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxRT.dll
8931568.584: supR3HardenedMonitor_LdrLoadDll: pName=Z:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
8941568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac8a30000 'Z:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
8951568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxRT.dll
8961568.584: supR3HardenedMonitor_LdrLoadDll: pName=Z:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
8971568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac8a30000 'Z:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
8981568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxRT.dll
8991568.584: supR3HardenedMonitor_LdrLoadDll: pName=Z:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
9001568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac8a30000 'Z:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9011568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxRT.dll
9021568.584: supR3HardenedMonitor_LdrLoadDll: pName=Z:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
9031568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac8a30000 'Z:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9041568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxRT.dll
9051568.584: supR3HardenedMonitor_LdrLoadDll: pName=Z:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
9061568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac8a30000 'Z:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9071568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxRT.dll
9081568.584: supR3HardenedMonitor_LdrLoadDll: pName=Z:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
9091568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac8a30000 'Z:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9101568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac8a30000 'Z:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9111568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac8a30000 'Z:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9121568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac8a30000 'Z:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9131568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac8a30000 'Z:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9141568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac8a30000 'Z:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9151568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac8a30000 'Z:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9161568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac8a30000 'Z:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9171568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxRT.dll
9181568.584: supR3HardenedMonitor_LdrLoadDll: pName=Z:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
9191568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac8a30000 'Z:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9201568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac8a30000 'Z:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9211568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac8a30000 'Z:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9221568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac8a30000 'Z:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9231568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac8a30000 'Z:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9241568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac8a30000 'Z:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9251568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac8a30000 'Z:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9261568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac8a30000 'Z:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9271568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac8a30000 'Z:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9281568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac8a30000 'Z:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9291568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac8a30000 'Z:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9301568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac8a30000 'Z:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9311568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac8a30000 'Z:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9321568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac8a30000 'Z:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9331568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac8a30000 'Z:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9341568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac8a30000 'Z:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9351568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxRT.dll
9361568.584: supR3HardenedMonitor_LdrLoadDll: pName=Z:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
9371568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac8a30000 'Z:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9381568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac8a30000 'Z:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9391568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac8a30000 'Z:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9401568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac8a30000 'Z:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9411568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafec40000 'C:\WINDOWS\system32\Wintrust.dll'
9421568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
9431568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
9441568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll
9451568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
9461568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
9471568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
9481568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\system32\crypt32.dll'
9491568.584: SUPR3HardenedMain: Load TrustedMain...
9501568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
9511568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'opengl32.dll'.
9521568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
9531568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msvcp100.dll'.
9541568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcr100.dll'.
9551568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qt5corevbox.dll'.
9561568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'qt5guivbox.dll'.
9571568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'qt5widgetsvbox.dll'.
9581568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'qt5printsupportvbox.dll'.
9591568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'qt5openglvbox.dll'.
9601568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'user32.dll'.
9611568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'advapi32.dll'.
9621568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'shell32.dll'.
9631568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'ole32.dll'.
9641568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'oleaut32.dll'.
9651568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #15 'winmm.dll'.
9661568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VirtualBox.dll) WinVerifyTrust
9671568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VirtualBox.dll
9681568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
9691568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
9701568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
9711568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
9721568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'winmmbase.dll'.
9731568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msvcrt.dll'.
9741568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\winmm.dll) WinVerifyTrust
9751568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\winmm.dll
9761568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
9771568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
9781568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
9791568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
9801568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
9811568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmmbase.dll'...
9821568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmmbase.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmmbase.dll' [rcNtRedir=0xc0150008]
9831568.584: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\winmmbase.dll'.
9841568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
9851568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\winmmbase.dll)
9861568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\winmmbase.dll
9871568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
9881568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
9891568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
9901568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
9911568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll
9921568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
9931568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
9941568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
9951568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'combase.dll'.
9961568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'rpcrt4.dll'.
9971568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\oleaut32.dll) WinVerifyTrust
9981568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
9991568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
10001568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
10011568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
10021568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
10031568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
10041568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
10051568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume2\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
10061568.584: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\combase.dll'.
10071568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rpcrt4.dll'.
10081568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #45 'bcryptprimitives.dll'.
10091568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\combase.dll)
10101568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\combase.dll
10111568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
10121568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
10131568.584: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\msvcp_win.dll'.
10141568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\msvcp_win.dll)
10151568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msvcp_win.dll
10161568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcryptprimitives.dll'...
10171568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcryptprimitives.dll' -> '\Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll' [rcNtRedir=0xc0150008]
10181568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll
10191568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
10201568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
10211568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
10221568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
10231568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #22 'rpcrt4.dll'.
10241568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #46 'gdi32.dll'.
10251568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #47 'user32.dll'.
10261568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #48 'combase.dll'.
10271568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ole32.dll) WinVerifyTrust
10281568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ole32.dll
10291568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
10301568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
10311568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
10321568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume2\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
10331568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\combase.dll [lacks WinVerifyTrust]
10341568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
10351568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
10361568.584: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\user32.dll'.
10371568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'win32u.dll'.
10381568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #34 'gdi32.dll'.
10391568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\user32.dll)
10401568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\user32.dll
10411568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
10421568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
10431568.584: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\gdi32.dll'.
10441568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\gdi32.dll)
10451568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\gdi32.dll
10461568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
10471568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
10481568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
10491568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
10501568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
10511568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
10521568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume2\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
10531568.584: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\win32u.dll'.
10541568.584: '\Device\HarddiskVolume2\Windows\System32\win32u.dll' has no imports
10551568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\win32u.dll)
10561568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\win32u.dll
10571568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
10581568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
10591568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
10601568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #73 'user32.dll'.
10611568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #75 'gdi32.dll'.
10621568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\shell32.dll) WinVerifyTrust
10631568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\shell32.dll
10641568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
10651568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
10661568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
10671568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
10681568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
10691568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll [redoing WinVerifyTrust]
10701568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
10711568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
10721568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
10731568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
10741568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
10751568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
10761568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
10771568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
10781568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
10791568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
10801568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
10811568.584: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\user32.dll'
10821568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5openglvbox.dll'...
10831568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5openglvbox.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\qt5openglvbox.dll' [rcNtRedir=0xc0150008]
10841568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
10851568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'qt5widgetsvbox.dll'.
10861568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'qt5guivbox.dll'.
10871568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5corevbox.dll'.
10881568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcr100.dll'.
10891568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll) WinVerifyTrust
10901568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll
10911568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5printsupportvbox.dll'...
10921568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5printsupportvbox.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\qt5printsupportvbox.dll' [rcNtRedir=0xc0150008]
10931568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
10941568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
10951568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
10961568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
10971568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
10981568.584: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll'.
10991568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
11001568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'shell32.dll'.
11011568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ole32.dll'.
11021568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
11031568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ws2_32.dll'.
11041568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'mpr.dll'.
11051568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'msvcp100.dll'.
11061568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'msvcr100.dll'.
11071568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll)
11081568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
11091568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
11101568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
11111568.584: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll'.
11121568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ole32.dll'.
11131568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'opengl32.dll'.
11141568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
11151568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
11161568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qt5corevbox.dll'.
11171568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcp100.dll'.
11181568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msvcr100.dll'.
11191568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll)
11201568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
11211568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
11221568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
11231568.584: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll'.
11241568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
11251568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
11261568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5guivbox.dll'.
11271568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qt5corevbox.dll'.
11281568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'shell32.dll'.
11291568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcp100.dll'.
11301568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msvcr100.dll'.
11311568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll)
11321568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll
11331568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
11341568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
11351568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
11361568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
11371568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
11381568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcp100.dll
11391568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
11401568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
11411568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
11421568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
11431568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
11441568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [lacks WinVerifyTrust]
11451568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
11461568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
11471568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll [lacks WinVerifyTrust]
11481568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
11491568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
11501568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll
11511568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
11521568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
11531568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
11541568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
11551568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
11561568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
11571568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
11581568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
11591568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcp100.dll
11601568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
11611568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
11621568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [lacks WinVerifyTrust]
11631568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
11641568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
11651568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll
11661568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
11671568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
11681568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
11691568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
11701568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
11711568.584: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume2\Windows\System32\opengl32.dll'.
11721568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
11731568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'advapi32.dll'.
11741568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
11751568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
11761568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'glu32.dll'.
11771568.584: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\opengl32.dll)
11781568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\opengl32.dll
11791568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
11801568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
11811568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
11821568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
11831568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
11841568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
11851568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
11861568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
11871568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcp100.dll
11881568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mpr.dll'...
11891568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'mpr.dll' -> '\Device\HarddiskVolume2\Windows\System32\mpr.dll' [rcNtRedir=0xc0150008]
11901568.584: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\mpr.dll'.
11911568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\mpr.dll)
11921568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\mpr.dll
11931568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
11941568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
11951568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
11961568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
11971568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
11981568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
11991568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
12001568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
12011568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
12021568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
12031568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
12041568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
12051568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
12061568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
12071568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll
12081568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'glu32.dll'...
12091568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'glu32.dll' -> '\Device\HarddiskVolume2\Windows\System32\glu32.dll' [rcNtRedir=0xc0150008]
12101568.584: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume2\Windows\System32\glu32.dll'.
12111568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
12121568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
12131568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'opengl32.dll'.
12141568.584: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\glu32.dll)
12151568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\glu32.dll
12161568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
12171568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
12181568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
12191568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
12201568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
12211568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll
12221568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
12231568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
12241568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
12251568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
12261568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
12271568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
12281568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
12291568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
12301568.584: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll [lacks WinVerifyTrust]
12311568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
12321568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
12331568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll
12341568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
12351568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
12361568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
12371568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
12381568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
12391568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5widgetsvbox.dll'.
12401568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qt5guivbox.dll'.
12411568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qt5corevbox.dll'.
12421568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'winspool.drv'.
12431568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'comdlg32.dll'.
12441568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'msvcr100.dll'.
12451568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\Qt5PrintSupportVBox.dll) WinVerifyTrust
12461568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\Qt5PrintSupportVBox.dll
12471568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
12481568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
12491568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll [redoing WinVerifyTrust]
12501568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
12511568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
12521568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
12531568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comdlg32.dll'...
12541568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'comdlg32.dll' -> '\Device\HarddiskVolume2\Windows\System32\comdlg32.dll' [rcNtRedir=0xc0150008]
12551568.584: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume2\Windows\System32\comdlg32.dll'.
12561568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
12571568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #36 'user32.dll'.
12581568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #37 'shlwapi.dll'.
12591568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #38 'gdi32.dll'.
12601568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #39 'comctl32.dll'.
12611568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #40 'shell32.dll'.
12621568.584: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\comdlg32.dll)
12631568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\comdlg32.dll
12641568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winspool.drv'...
12651568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'winspool.drv' -> '\Device\HarddiskVolume2\Windows\System32\winspool.drv' [rcNtRedir=0xc0150008]
12661568.584: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume2\Windows\System32\winspool.drv'.
12671568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
12681568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'iphlpapi.dll'.
12691568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #34 'bcrypt.dll'.
12701568.584: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\winspool.drv)
12711568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\winspool.drv
12721568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
12731568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
12741568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [lacks WinVerifyTrust]
12751568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
12761568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
12771568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll [lacks WinVerifyTrust]
12781568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
12791568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
12801568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll [lacks WinVerifyTrust]
12811568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
12821568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
12831568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll
12841568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
12851568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
12861568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
12871568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
12881568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume2\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
12891568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll
12901568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'iphlpapi.dll'...
12911568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'iphlpapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\iphlpapi.dll' [rcNtRedir=0xc0150008]
12921568.584: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL'.
12931568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL)
12941568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL
12951568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
12961568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
12971568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
12981568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
12991568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
13001568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comctl32.dll'...
13011568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'comctl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\comctl32.dll' [rcNtRedir=0x0]
13021568.584: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\comctl32.dll'.
13031568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'advapi32.dll'.
13041568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
13051568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
13061568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\comctl32.dll)
13071568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\comctl32.dll
13081568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
13091568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
13101568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
13111568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
13121568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
13131568.584: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll'.
13141568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
13151568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #45 'gdi32.dll'.
13161568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #46 'user32.dll'.
13171568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\shlwapi.dll)
13181568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\shlwapi.dll
13191568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
13201568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
13211568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
13221568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
13231568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
13241568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
13251568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
13261568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
13271568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
13281568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
13291568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
13301568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
13311568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
13321568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
13331568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
13341568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
13351568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
13361568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
13371568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
13381568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
13391568.584: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll'
13401568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
13411568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
13421568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll [redoing WinVerifyTrust]
13431568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
13441568.584: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll'
13451568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
13461568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
13471568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [redoing WinVerifyTrust]
13481568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
13491568.584: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll'
13501568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
13511568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
13521568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcr100.dll [redoing WinVerifyTrust]
13531568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
13541568.584: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcr100.dll'
13551568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
13561568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
13571568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcp100.dll
13581568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
13591568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
13601568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
13611568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
13621568.584: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll [redoing WinVerifyTrust]
13631568.584: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000460 pwszName=\Device\HarddiskVolume2\Windows\System32\opengl32.dll
13641568.584: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000302c490
13651568.584: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000302c490
13661568.584: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=F39C902102F30859FF82648A950427FCB81FB124
13671568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
13681568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
13691568.584: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package00111~31bf3856ad364e35~amd64~~10.0.16299.15.cat'; file='\Device\HarddiskVolume2\Windows\System32\opengl32.dll'
13701568.584: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
13711568.584: supR3HardenedScreenImage/Imports: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\opengl32.dll'
13721568.584: supR3HardenedMonitor_LdrLoadDll: pName=Z:\Program Files\Oracle\VirtualBox\VirtualBox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000a01:<flags> [calling]
13731568.584: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VirtualBox.dll
13741568.584: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
13751568.584: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
13761568.584: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
13771568.584: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll
13781568.584: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\Qt5PrintSupportVBox.dll
13791568.584: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll
13801568.584: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
13811568.584: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\glu32.dll [avoiding WinVerifyTrust]
13821568.584: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\mpr.dll [avoiding WinVerifyTrust]
13831568.584: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\winspool.drv [avoiding WinVerifyTrust]
13841568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'advapi32.dll'.
13851568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
13861568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
13871568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.16299.64_none_e47b13aa03396f3a\comctl32.dll)
13881568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.16299.64_none_e47b13aa03396f3a\comctl32.dll
13891568.584: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmmbase.dll [avoiding WinVerifyTrust]
13901568.584: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL [avoiding WinVerifyTrust]
13911568.584: supR3HardenedDllNotificationCallback: load 00007ffaff2b0000 LB 0x00020000 C:\WINDOWS\System32\win32u.dll [fFlags=0x0]
13921568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\win32u.dll [avoiding WinVerifyTrust]
13931568.584: supR3HardenedDllNotificationCallback: load 00007ffaff210000 LB 0x0009b000 C:\WINDOWS\System32\msvcp_win.dll [fFlags=0x0]
13941568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcp_win.dll [avoiding WinVerifyTrust]
13951568.584: supR3HardenedDllNotificationCallback: load 00007ffafe250000 LB 0x00194000 C:\WINDOWS\System32\gdi32full.dll [fFlags=0x0]
13961568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
13971568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #33 'gdi32.dll'.
13981568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #35 'user32.dll'.
13991568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #36 'win32u.dll'.
14001568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\gdi32full.dll)
14011568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\gdi32full.dll
14021568.584: supR3HardenedDllNotificationCallback: load 00007ffb01460000 LB 0x00028000 C:\WINDOWS\System32\GDI32.dll [fFlags=0x0]
14031568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [avoiding WinVerifyTrust]
14041568.584: supR3HardenedDllNotificationCallback: load 00007ffb01260000 LB 0x0018f000 C:\WINDOWS\System32\USER32.dll [fFlags=0x0]
14051568.584: supR3HardenedDllNotificationCallback: load 00007ffafb250000 LB 0x0002c000 C:\WINDOWS\SYSTEM32\GLU32.dll [fFlags=0x0]
14061568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\glu32.dll [avoiding WinVerifyTrust]
14071568.584: supR3HardenedDllNotificationCallback: load 00007ffae15b0000 LB 0x0011e000 C:\WINDOWS\SYSTEM32\OPENGL32.dll [fFlags=0x0]
14081568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
14091568.584: supR3HardenedDllNotificationCallback: load 00007ffaff2d0000 LB 0x0004a000 C:\WINDOWS\System32\cfgmgr32.dll [fFlags=0x0]
14101568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll)
14111568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll
14121568.584: supR3HardenedDllNotificationCallback: load 00007ffaff5c0000 LB 0x00308000 C:\WINDOWS\System32\combase.dll [fFlags=0x0]
14131568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\combase.dll [avoiding WinVerifyTrust]
14141568.584: supR3HardenedDllNotificationCallback: load 00007ffaff320000 LB 0x000a6000 C:\WINDOWS\System32\shcore.dll [fFlags=0x0]
14151568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
14161568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #37 'rpcrt4.dll'.
14171568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #44 'combase.dll'.
14181568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\SHCore.dll)
14191568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\SHCore.dll
14201568.584: supR3HardenedDllNotificationCallback: load 00007ffaffc60000 LB 0x00051000 C:\WINDOWS\System32\shlwapi.dll [fFlags=0x0]
14211568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll [avoiding WinVerifyTrust]
14221568.584: supR3HardenedDllNotificationCallback: load 00007ffafe1a0000 LB 0x00011000 C:\WINDOWS\System32\kernel.appcore.dll [fFlags=0x0]
14231568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'msvcrt.dll'.
14241568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'rpcrt4.dll'.
14251568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\kernel.appcore.dll)
14261568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\kernel.appcore.dll
14271568.584: supR3HardenedDllNotificationCallback: load 00007ffafe1c0000 LB 0x0004c000 C:\WINDOWS\System32\powrprof.dll [fFlags=0x0]
14281568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'rpcrt4.dll'.
14291568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\powrprof.dll)
14301568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\powrprof.dll
14311568.584: supR3HardenedDllNotificationCallback: load 00007ffafe3f0000 LB 0x00747000 C:\WINDOWS\System32\windows.storage.dll [fFlags=0x0]
14321568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
14331568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'rpcrt4.dll'.
14341568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #55 'combase.dll'.
14351568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #75 'profapi.dll'.
14361568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\windows.storage.dll)
14371568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\windows.storage.dll
14381568.584: supR3HardenedDllNotificationCallback: load 00007ffaffd20000 LB 0x01437000 C:\WINDOWS\System32\SHELL32.dll [fFlags=0x0]
14391568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
14401568.584: supR3HardenedDllNotificationCallback: load 00007ffaff3d0000 LB 0x00149000 C:\WINDOWS\System32\ole32.dll [fFlags=0x0]
14411568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
14421568.584: supR3HardenedDllNotificationCallback: load 00007ffae53e0000 LB 0x0001b000 C:\WINDOWS\SYSTEM32\MPR.dll [fFlags=0x0]
14431568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\mpr.dll [avoiding WinVerifyTrust]
14441568.584: supR3HardenedDllNotificationCallback: load 0000000060a40000 LB 0x00565000 Z:\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [fFlags=0x0]
14451568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
14461568.584: supR3HardenedDllNotificationCallback: load 00007ffac6c50000 LB 0x005f7000 Z:\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll [fFlags=0x0]
14471568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
14481568.584: supR3HardenedDllNotificationCallback: load 00000000604d0000 LB 0x00561000 Z:\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll [fFlags=0x0]
14491568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll
14501568.584: supR3HardenedDllNotificationCallback: load 00007ffafd7c0000 LB 0x00039000 C:\WINDOWS\SYSTEM32\IPHLPAPI.DLL [fFlags=0x0]
14511568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL [avoiding WinVerifyTrust]
14521568.584: supR3HardenedDllNotificationCallback: load 00007ffaf9210000 LB 0x00086000 C:\WINDOWS\SYSTEM32\WINSPOOL.DRV [fFlags=0x0]
14531568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\winspool.drv [avoiding WinVerifyTrust]
14541568.584: supR3HardenedDllNotificationCallback: load 00007ffaf7a00000 LB 0x000a6000 C:\WINDOWS\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.16299.64_none_e47b13aa03396f3a\COMCTL32.dll [fFlags=0x0]
14551568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.16299.64_none_e47b13aa03396f3a\comctl32.dll [avoiding WinVerifyTrust]
14561568.584: supR3HardenedDllNotificationCallback: load 00007ffb01d10000 LB 0x0010a000 C:\WINDOWS\System32\COMDLG32.dll [fFlags=0x0]
14571568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\comdlg32.dll [avoiding WinVerifyTrust]
14581568.584: supR3HardenedDllNotificationCallback: load 00007ffafb280000 LB 0x00051000 Z:\Program Files\Oracle\VirtualBox\Qt5PrintSupportVBox.dll [fFlags=0x0]
14591568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\Qt5PrintSupportVBox.dll
14601568.584: supR3HardenedDllNotificationCallback: load 0000000060fb0000 LB 0x00054000 Z:\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll [fFlags=0x0]
14611568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll
14621568.584: supR3HardenedDllNotificationCallback: load 00007ffb01190000 LB 0x000c5000 C:\WINDOWS\System32\OLEAUT32.dll [fFlags=0x0]
14631568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
14641568.584: supR3HardenedDllNotificationCallback: load 00007ffaf9f40000 LB 0x0002a000 C:\WINDOWS\SYSTEM32\WINMMBASE.dll [fFlags=0x0]
14651568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmmbase.dll [avoiding WinVerifyTrust]
14661568.584: supR3HardenedDllNotificationCallback: load 00007ffaf9f70000 LB 0x00023000 C:\WINDOWS\SYSTEM32\WINMM.dll [fFlags=0x0]
14671568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
14681568.584: supR3HardenedDllNotificationCallback: load 00007ffac7250000 LB 0x009cf000 Z:\Program Files\Oracle\VirtualBox\VirtualBox.dll [fFlags=0x0]
14691568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VirtualBox.dll
14701568.584: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\windows.storage.dll'.
14711568.584: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\windows.storage.dll' [rescheduled]
14721568.584: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\powrprof.dll'.
14731568.584: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\powrprof.dll' [rescheduled]
14741568.584: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\kernel.appcore.dll'.
14751568.584: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\kernel.appcore.dll' [rescheduled]
14761568.584: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\SHCore.dll'.
14771568.584: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\SHCore.dll' [rescheduled]
14781568.584: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll'.
14791568.584: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll' [rescheduled]
14801568.584: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\gdi32full.dll'.
14811568.584: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\gdi32full.dll' [rescheduled]
14821568.584: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.16299.64_none_e47b13aa03396f3a\comctl32.dll'.
14831568.584: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.16299.64_none_e47b13aa03396f3a\comctl32.dll' [rescheduled]
14841568.584: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll'.
14851568.584: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll' [rescheduled]
14861568.584: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\comctl32.dll'.
14871568.584: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\comctl32.dll' [rescheduled]
14881568.584: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL'.
14891568.584: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL' [rescheduled]
14901568.584: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume2\Windows\System32\winspool.drv'.
14911568.584: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\winspool.drv' [rescheduled]
14921568.584: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume2\Windows\System32\comdlg32.dll'.
14931568.584: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\comdlg32.dll' [rescheduled]
14941568.584: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume2\Windows\System32\glu32.dll'.
14951568.584: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\glu32.dll' [rescheduled]
14961568.584: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\mpr.dll'.
14971568.584: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\mpr.dll' [rescheduled]
14981568.584: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\win32u.dll'.
14991568.584: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\win32u.dll' [rescheduled]
15001568.584: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\gdi32.dll'.
15011568.584: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rescheduled]
15021568.584: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\msvcp_win.dll'.
15031568.584: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\msvcp_win.dll' [rescheduled]
15041568.584: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\combase.dll'.
15051568.584: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\combase.dll' [rescheduled]
15061568.584: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\winmmbase.dll'.
15071568.584: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\winmmbase.dll' [rescheduled]
15081568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll
15091568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'profapi.dll'...
15101568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'profapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\profapi.dll' [rcNtRedir=0xc0150008]
15111568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\profapi.dll
15121568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
15131568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume2\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
15141568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\combase.dll [redoing WinVerifyTrust]
15151568.584: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\combase.dll'.
15161568.584: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume2\Windows\System32\combase.dll
15171568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
15181568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
15191568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
15201568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
15211568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
15221568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
15231568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
15241568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
15251568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
15261568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
15271568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
15281568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume2\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
15291568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\combase.dll [redoing WinVerifyTrust]
15301568.584: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\combase.dll'.
15311568.584: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume2\Windows\System32\combase.dll
15321568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
15331568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
15341568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
15351568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
15361568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
15371568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume2\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
15381568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\win32u.dll [redoing WinVerifyTrust]
15391568.584: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\win32u.dll'.
15401568.584: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume2\Windows\System32\win32u.dll
15411568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
15421568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
15431568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
15441568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
15451568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [redoing WinVerifyTrust]
15461568.584: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\gdi32.dll'.
15471568.584: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume2\Windows\System32\gdi32.dll
15481568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
15491568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
15501568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcp_win.dll [redoing WinVerifyTrust]
15511568.584: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\msvcp_win.dll'.
15521568.584: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume2\Windows\System32\msvcp_win.dll
15531568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
15541568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
15551568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
15561568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
15571568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [redoing WinVerifyTrust]
15581568.584: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\gdi32.dll'.
15591568.584: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume2\Windows\System32\gdi32.dll
15601568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
15611568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
15621568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
15631568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\kernel32.dll (Input=kernel32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
15641568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb01c60000 'C:\WINDOWS\System32\kernel32.dll'
15651568.584: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-string-l1-1-0) -> 0x0, fPresent=1
15661568.584: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-string-l1-1-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
15671568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafeca0000 'api-ms-win-core-string-l1-1-0'
15681568.584: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-datetime-l1-1-1) -> 0x0, fPresent=1
15691568.584: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-datetime-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
15701568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafeca0000 'api-ms-win-core-datetime-l1-1-1'
15711568.584: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-obsolete-l1-2-0) -> 0x0, fPresent=1
15721568.584: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-obsolete-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
15731568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafeca0000 'api-ms-win-core-localization-obsolete-l1-2-0'
15741568.584: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\imm32.dll'.
15751568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'user32.dll'.
15761568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'win32u.dll'.
15771568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\imm32.dll)
15781568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\imm32.dll
15791568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
15801568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume2\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
15811568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\win32u.dll [redoing WinVerifyTrust]
15821568.584: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\win32u.dll'.
15831568.584: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume2\Windows\System32\win32u.dll
15841568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
15851568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
15861568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\IMM32.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
15871568.584: supR3HardenedDllNotificationCallback: load 00007ffaffc30000 LB 0x0002d000 C:\WINDOWS\System32\IMM32.DLL [fFlags=0x0]
15881568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\imm32.dll [avoiding WinVerifyTrust]
15891568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaffc30000 'C:\WINDOWS\system32\IMM32.DLL'
15901568.584: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\imm32.dll'.
15911568.584: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\imm32.dll' [rescheduled]
15921568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\imm32.dll [redoing WinVerifyTrust]
15931568.584: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\imm32.dll'.
15941568.584: supR3HardenedScreenImage/LdrLoadDll: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume2\Windows\System32\imm32.dll
15951568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\imm32.dll (Input=imm32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
15961568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaffc30000 'C:\WINDOWS\System32\imm32.dll'
15971568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
15981568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\ADVAPI32.DLL (Input=ADVAPI32.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
15991568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaff8d0000 'C:\WINDOWS\System32\ADVAPI32.DLL'
16001568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac7250000 'Z:\Program Files\Oracle\VirtualBox\VirtualBox.dll'
16011568.584: SUPR3HardenedMain: Calling TrustedMain (00007ffac72514f0)...
16021568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
16031568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
16041568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'ole32.dll'.
16051568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
16061568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'imm32.dll'.
16071568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'winmm.dll'.
16081568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'oleaut32.dll'.
16091568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'shell32.dll'.
16101568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'advapi32.dll'.
16111568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'qt5guivbox.dll'.
16121568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'qt5corevbox.dll'.
16131568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'msvcr100.dll'.
16141568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\platforms\qwindows.dll) WinVerifyTrust
16151568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\platforms\qwindows.dll
16161568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
16171568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
16181568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
16191568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
16201568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
16211568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
16221568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
16231568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
16241568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
16251568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
16261568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
16271568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
16281568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
16291568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
16301568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
16311568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
16321568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
16331568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
16341568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
16351568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
16361568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
16371568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume2\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
16381568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\imm32.dll [redoing WinVerifyTrust]
16391568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
16401568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
16411568.584: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\imm32.dll'
16421568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
16431568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
16441568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll
16451568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
16461568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
16471568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
16481568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
16491568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
16501568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [redoing WinVerifyTrust]
16511568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
16521568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
16531568.584: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\gdi32.dll'
16541568.584: supR3HardenedMonitor_LdrLoadDll: pName=Z:\Program Files\Oracle\VirtualBox\platforms\qwindows.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
16551568.584: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\platforms\qwindows.dll
16561568.584: supR3HardenedDllNotificationCallback: load 00007ffad4640000 LB 0x0012e000 Z:\Program Files\Oracle\VirtualBox\platforms\qwindows.dll [fFlags=0x0]
16571568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\platforms\qwindows.dll
16581568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad4640000 'Z:\Program Files\Oracle\VirtualBox\platforms\qwindows.dll'
16591568.584: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000644 pwszName=\Device\HarddiskVolume2\Windows\System32\uxtheme.dll
16601568.584: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000302c490
16611568.584: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000302c490
16621568.584: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=0AB199956403E78CE61C981F6BA97CA632BE55AC
16631568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
16641568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
16651568.584: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package00114~31bf3856ad364e35~amd64~~10.0.16299.15.cat'; file='\Device\HarddiskVolume2\Windows\System32\uxtheme.dll'
16661568.584: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
16671568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
16681568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #33 'gdi32.dll'.
16691568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #34 'user32.dll'.
16701568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\uxtheme.dll) WinVerifyTrust
16711568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
16721568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
16731568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
16741568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
16751568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
16761568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
16771568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
16781568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
16791568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
16801568.584: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
16811568.584: supR3HardenedDllNotificationCallback: load 00007ffafc980000 LB 0x00095000 C:\WINDOWS\system32\uxtheme.dll [fFlags=0x0]
16821568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
16831568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafc980000 'C:\WINDOWS\system32\uxtheme.dll'
16841568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb01260000 'C:\WINDOWS\system32\user32.dll'
16851568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
16861568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
16871568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaffd20000 'C:\WINDOWS\system32\shell32.dll'
16881568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\SHCore.dll [redoing WinVerifyTrust]
16891568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
16901568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
16911568.584: supR3HardenedScreenImage/LdrLoadDll: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\SHCore.dll'
16921568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\SHCore.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
16931568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaff320000 'C:\WINDOWS\system32\SHCore.dll'
16941568.584: supR3HardenedMonitor_LdrLoadDll: error opening 'C:\WINDOWS\system32\wintab32.dll': 0 (NtPath=\??\C:\WINDOWS\system32\wintab32.dll; Input=C:\WINDOWS\system32\wintab32.dll; rcNtGetDll=0x0
16951568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000034 'C:\WINDOWS\system32\wintab32.dll'
16961568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
16971568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #22 'win32u.dll'.
16981568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'user32.dll'.
16991568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #24 'gdi32.dll'.
17001568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\dwmapi.dll)
17011568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\dwmapi.dll
17021568.584: supR3HardenedDllNotificationCallback: load 00007ffafca50000 LB 0x0002a000 C:\WINDOWS\system32\dwmapi.dll [fFlags=0x0]
17031568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dwmapi.dll [avoiding WinVerifyTrust]
17041568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
17051568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
17061568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
17071568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
17081568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
17091568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume2\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
17101568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\win32u.dll [lacks WinVerifyTrust]
17111568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
17121568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
17131568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
17141568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
17151568.584: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\dwmapi.dll'
17161568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
17171568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\winmm.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
17181568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaf9f70000 'C:\WINDOWS\system32\winmm.dll'
17191568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
17201568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\winmm.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
17211568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaf9f70000 'C:\WINDOWS\system32\winmm.dll'
17221568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
17231568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
17241568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaffd20000 'C:\WINDOWS\system32\shell32.dll'
17251568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
17261568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
17271568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafc980000 'C:\WINDOWS\system32\uxtheme.dll'
17281568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
17291568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\advapi32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
17301568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaff8d0000 'C:\WINDOWS\system32\advapi32.dll'
17311568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
17321568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
17331568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'rpcrt4.dll'.
17341568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #27 'profapi.dll'.
17351568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\userenv.dll) WinVerifyTrust
17361568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\userenv.dll
17371568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'profapi.dll'...
17381568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'profapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\profapi.dll' [rcNtRedir=0xc0150008]
17391568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\profapi.dll
17401568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
17411568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
17421568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\userenv.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
17431568.584: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\userenv.dll
17441568.584: supR3HardenedDllNotificationCallback: load 00007ffafe0d0000 LB 0x00029000 C:\WINDOWS\system32\userenv.dll [fFlags=0x0]
17451568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\userenv.dll
17461568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafe0d0000 'C:\WINDOWS\system32\userenv.dll'
17471568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll
17481568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\kernel32.dll (Input=kernel32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
17491568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb01c60000 'C:\WINDOWS\System32\kernel32.dll'
17501568.584: supR3HardenedDllNotificationCallback: load 00007ffaff520000 LB 0x0009e000 C:\WINDOWS\System32\clbcatq.dll [fFlags=0x0]
17511568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
17521568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #28 'rpcrt4.dll'.
17531568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\clbcatq.dll)
17541568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\clbcatq.dll
17551568.243c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
17561568.243c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
17571568.243c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
17581568.243c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
17591568.243c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
17601568.243c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
17611568.243c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
17621568.243c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\clbcatq.dll'
17631568.243c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
17641568.243c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
17651568.243c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
17661568.243c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
17671568.243c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
17681568.243c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ole32.dll'.
17691568.243c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'oleaut32.dll'.
17701568.243c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxC.dll) WinVerifyTrust
17711568.243c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxC.dll
17721568.243c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
17731568.243c: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
17741568.243c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
17751568.243c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
17761568.243c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
17771568.243c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
17781568.243c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
17791568.243c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
17801568.243c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
17811568.243c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
17821568.243c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
17831568.243c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
17841568.243c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcp100.dll
17851568.243c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
17861568.243c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
17871568.243c: supR3HardenedMonitor_LdrLoadDll: pName=Z:\Program Files\Oracle\VirtualBox\VBoxC.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
17881568.243c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxC.dll
17891568.243c: supR3HardenedDllNotificationCallback: load 00007ffac6750000 LB 0x004ff000 Z:\Program Files\Oracle\VirtualBox\VBoxC.dll [fFlags=0x0]
17901568.243c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxC.dll
17911568.243c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac6750000 'Z:\Program Files\Oracle\VirtualBox\VBoxC.dll'
17921568.243c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
17931568.243c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
17941568.243c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
17951568.243c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
17961568.243c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'shlwapi.dll'.
17971568.243c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ole32.dll'.
17981568.243c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'oleaut32.dll'.
17991568.243c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
18001568.243c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll) WinVerifyTrust
18011568.243c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll
18021568.243c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
18031568.243c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
18041568.243c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
18051568.243c: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
18061568.243c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
18071568.243c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
18081568.243c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
18091568.243c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
18101568.243c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
18111568.243c: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
18121568.243c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll [redoing WinVerifyTrust]
18131568.243c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
18141568.243c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
18151568.243c: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll'
18161568.243c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
18171568.243c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
18181568.243c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
18191568.243c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
18201568.243c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
18211568.243c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
18221568.243c: supR3HardenedMonitor_LdrLoadDll: pName=Z:\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
18231568.243c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll
18241568.243c: supR3HardenedDllNotificationCallback: load 00007ffad6d90000 LB 0x000ba000 Z:\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll [fFlags=0x0]
18251568.243c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll
18261568.243c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad6d90000 'Z:\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll'
18271568.243c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
18281568.243c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\oleaut32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
18291568.243c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb01190000 'C:\Windows\System32\oleaut32.dll'
18301568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll
18311568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\gdi32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
18321568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb01460000 'C:\WINDOWS\system32\gdi32.dll'
18331568.154c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
18341568.154c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
18351568.154c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
18361568.154c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
18371568.154c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
18381568.154c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMainVM.dll) WinVerifyTrust
18391568.154c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMainVM.dll
18401568.154c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
18411568.154c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
18421568.154c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
18431568.154c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
18441568.154c: supR3HardenedMonitor_LdrLoadDll: pName=Z:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMainVM.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
18451568.154c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMainVM.dll
18461568.154c: supR3HardenedDllNotificationCallback: load 00007ffaf8650000 LB 0x0000e000 Z:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMainVM.DLL [fFlags=0x0]
18471568.154c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMainVM.dll
18481568.154c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaf8650000 'Z:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMainVM.DLL'
18491568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
18501568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
18511568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaffd20000 'C:\WINDOWS\system32\shell32.dll'
18521568.584: supR3HardenedDllNotificationCallback: load 00007ffb015b0000 LB 0x00167000 C:\WINDOWS\System32\MSCTF.dll [fFlags=0x0]
18531568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
18541568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #19 'oleaut32.dll'.
18551568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #36 'user32.dll'.
18561568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #37 'gdi32.dll'.
18571568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #38 'imm32.dll'.
18581568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\msctf.dll)
18591568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msctf.dll
18601568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
18611568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume2\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
18621568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\imm32.dll
18631568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
18641568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
18651568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
18661568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
18671568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
18681568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
18691568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
18701568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
18711568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
18721568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
18731568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
18741568.584: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\msctf.dll'
18751568.584: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000a18 pwszName=\Device\HarddiskVolume2\Windows\System32\DataExchange.dll
18761568.584: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000302c490
18771568.584: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000302c490
18781568.584: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=87FA668FC207CB724FFDD342C6B5B8D273E3498D
18791568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
18801568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
18811568.584: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0010~31bf3856ad364e35~amd64~~10.0.16299.15.cat'; file='\Device\HarddiskVolume2\Windows\System32\DataExchange.dll'
18821568.584: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
18831568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
18841568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'shcore.dll'.
18851568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #28 'combase.dll'.
18861568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #31 'd3d11.dll'.
18871568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #32 'dcomp.dll'.
18881568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\DataExchange.dll) WinVerifyTrust
18891568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\DataExchange.dll
18901568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dcomp.dll'...
18911568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'dcomp.dll' -> '\Device\HarddiskVolume2\Windows\System32\dcomp.dll' [rcNtRedir=0xc0150008]
18921568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
18931568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
18941568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'win32u.dll'.
18951568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
18961568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\dcomp.dll) WinVerifyTrust
18971568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\dcomp.dll
18981568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'd3d11.dll'...
18991568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'd3d11.dll' -> '\Device\HarddiskVolume2\Windows\System32\d3d11.dll' [rcNtRedir=0xc0150008]
19001568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
19011568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
19021568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
19031568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume2\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
19041568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\win32u.dll [lacks WinVerifyTrust]
19051568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
19061568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
19071568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
19081568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'dxgi.dll'.
19091568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #35 'win32u.dll'.
19101568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\d3d11.dll) WinVerifyTrust
19111568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\d3d11.dll
19121568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
19131568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume2\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
19141568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\combase.dll [redoing WinVerifyTrust]
19151568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll
19161568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
19171568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume2\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
19181568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\win32u.dll [lacks WinVerifyTrust]
19191568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dxgi.dll'...
19201568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'dxgi.dll' -> '\Device\HarddiskVolume2\Windows\System32\dxgi.dll' [rcNtRedir=0xc0150008]
19211568.584: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\dxgi.dll'.
19221568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
19231568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'win32u.dll'.
19241568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\dxgi.dll)
19251568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\dxgi.dll
19261568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
19271568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
19281568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
19291568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume2\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
19301568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\win32u.dll [lacks WinVerifyTrust]
19311568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
19321568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
19331568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
19341568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
19351568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
19361568.584: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\combase.dll'
19371568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shcore.dll'...
19381568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'shcore.dll' -> '\Device\HarddiskVolume2\Windows\System32\shcore.dll' [rcNtRedir=0xc0150008]
19391568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\SHCore.dll
19401568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
19411568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
19421568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\dataexchange.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
19431568.584: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\DataExchange.dll
19441568.584: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\d3d11.dll
19451568.584: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dcomp.dll
19461568.584: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dxgi.dll [avoiding WinVerifyTrust]
19471568.584: supR3HardenedDllNotificationCallback: load 00007ffafd010000 LB 0x000af000 C:\WINDOWS\system32\dxgi.dll [fFlags=0x0]
19481568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dxgi.dll [avoiding WinVerifyTrust]
19491568.584: supR3HardenedDllNotificationCallback: load 00007ffafb7a0000 LB 0x002e2000 C:\WINDOWS\system32\d3d11.dll [fFlags=0x0]
19501568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\d3d11.dll
19511568.584: supR3HardenedDllNotificationCallback: load 00007ffafc130000 LB 0x00142000 C:\WINDOWS\system32\dcomp.dll [fFlags=0x0]
19521568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dcomp.dll
19531568.584: supR3HardenedDllNotificationCallback: load 00007ffae0400000 LB 0x0004f000 C:\WINDOWS\system32\dataexchange.dll [fFlags=0x0]
19541568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\DataExchange.dll
19551568.584: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\dxgi.dll'.
19561568.584: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\dxgi.dll' [rescheduled]
19571568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb01460000 'C:\WINDOWS\System32\gdi32.dll'
19581568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffae0400000 'C:\WINDOWS\system32\dataexchange.dll'
19591568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
19601568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'rmclient.dll'.
19611568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #30 'rpcrt4.dll'.
19621568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #32 'bcrypt.dll'.
19631568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #45 'combase.dll'.
19641568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\twinapi.appcore.dll)
19651568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\twinapi.appcore.dll
19661568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
19671568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'rpcrt4.dll'.
19681568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\rmclient.dll)
19691568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\rmclient.dll
19701568.584: supR3HardenedDllNotificationCallback: load 00007ffafcc70000 LB 0x00020000 C:\WINDOWS\system32\RMCLIENT.dll [fFlags=0x0]
19711568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rmclient.dll [avoiding WinVerifyTrust]
19721568.584: supR3HardenedDllNotificationCallback: load 00007ffafca80000 LB 0x0017b000 C:\WINDOWS\system32\twinapi.appcore.dll [fFlags=0x0]
19731568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\twinapi.appcore.dll [avoiding WinVerifyTrust]
19741568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
19751568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'coreuicomponents.dll'.
19761568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'coremessaging.dll'.
19771568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\TextInputFramework.dll)
19781568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\TextInputFramework.dll
19791568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
19801568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #35 'coremessaging.dll'.
19811568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #48 'shcore.dll'.
19821568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\CoreUIComponents.dll)
19831568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\CoreUIComponents.dll
19841568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
19851568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #24 'rpcrt4.dll'.
19861568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\CoreMessaging.dll)
19871568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\CoreMessaging.dll
19881568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ntmarta.dll)
19891568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ntmarta.dll
19901568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'combase.dll'.
19911568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #21 'rpcrt4.dll'.
19921568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #28 'bcryptprimitives.dll'.
19931568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\WinTypes.dll)
19941568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\WinTypes.dll
19951568.584: supR3HardenedDllNotificationCallback: load 00007ffafd2e0000 LB 0x00031000 C:\WINDOWS\SYSTEM32\ntmarta.dll [fFlags=0x0]
19961568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ntmarta.dll [avoiding WinVerifyTrust]
19971568.584: supR3HardenedDllNotificationCallback: load 00007ffafc050000 LB 0x000dd000 C:\WINDOWS\System32\CoreMessaging.dll [fFlags=0x0]
19981568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\CoreMessaging.dll [avoiding WinVerifyTrust]
19991568.584: supR3HardenedDllNotificationCallback: load 00007ffaf99f0000 LB 0x00136000 C:\WINDOWS\SYSTEM32\wintypes.dll [fFlags=0x0]
20001568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\WinTypes.dll [avoiding WinVerifyTrust]
20011568.584: supR3HardenedDllNotificationCallback: load 00007ffaf7540000 LB 0x002ee000 C:\WINDOWS\System32\CoreUIComponents.dll [fFlags=0x0]
20021568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\CoreUIComponents.dll [avoiding WinVerifyTrust]
20031568.584: supR3HardenedDllNotificationCallback: load 00007ffaf3da0000 LB 0x00098000 C:\WINDOWS\System32\TextInputFramework.dll [fFlags=0x0]
20041568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\TextInputFramework.dll [avoiding WinVerifyTrust]
20051568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcryptprimitives.dll'...
20061568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcryptprimitives.dll' -> '\Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll' [rcNtRedir=0xc0150008]
20071568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll
20081568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
20091568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
20101568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
20111568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume2\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
20121568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\combase.dll
20131568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
20141568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
20151568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
20161568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
20171568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shcore.dll'...
20181568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'shcore.dll' -> '\Device\HarddiskVolume2\Windows\System32\shcore.dll' [rcNtRedir=0xc0150008]
20191568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\SHCore.dll
20201568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'coremessaging.dll'...
20211568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'coremessaging.dll' -> '\Device\HarddiskVolume2\Windows\System32\coremessaging.dll' [rcNtRedir=0xc0150008]
20221568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\CoreMessaging.dll [lacks WinVerifyTrust]
20231568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
20241568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
20251568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'coremessaging.dll'...
20261568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'coremessaging.dll' -> '\Device\HarddiskVolume2\Windows\System32\coremessaging.dll' [rcNtRedir=0xc0150008]
20271568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\CoreMessaging.dll [lacks WinVerifyTrust]
20281568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'coreuicomponents.dll'...
20291568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'coreuicomponents.dll' -> '\Device\HarddiskVolume2\Windows\System32\coreuicomponents.dll' [rcNtRedir=0xc0150008]
20301568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\CoreUIComponents.dll [lacks WinVerifyTrust]
20311568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
20321568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
20331568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
20341568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
20351568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
20361568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
20371568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
20381568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume2\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
20391568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\combase.dll
20401568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
20411568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume2\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
20421568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll
20431568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
20441568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
20451568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rmclient.dll'...
20461568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'rmclient.dll' -> '\Device\HarddiskVolume2\Windows\System32\rmclient.dll' [rcNtRedir=0xc0150008]
20471568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rmclient.dll [lacks WinVerifyTrust]
20481568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
20491568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
20501568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
20511568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
20521568.584: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\WinTypes.dll'
20531568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
20541568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
20551568.584: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\ntmarta.dll'
20561568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
20571568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
20581568.584: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\CoreMessaging.dll'
20591568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
20601568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
20611568.584: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\CoreUIComponents.dll'
20621568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
20631568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
20641568.584: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\TextInputFramework.dll'
20651568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
20661568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
20671568.584: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\rmclient.dll'
20681568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
20691568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
20701568.584: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\twinapi.appcore.dll'
20711568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
20721568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\OLEAUT32.DLL (Input=OLEAUT32.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
20731568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb01190000 'C:\WINDOWS\System32\OLEAUT32.DLL'
20741568.584: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(ext-ms-win-rtcore-ntuser-window-ext-l1-1-0.dll) -> 0x0, fPresent=1
20751568.584: supR3HardenedMonitor_LdrLoadDll: pName=ext-ms-win-rtcore-ntuser-window-ext-l1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
20761568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb01260000 'ext-ms-win-rtcore-ntuser-window-ext-l1-1-0.dll'
20771568.584: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(ext-ms-win-rtcore-ntuser-integration-l1-1-0.dll) -> 0x0, fPresent=1
20781568.584: supR3HardenedMonitor_LdrLoadDll: pName=ext-ms-win-rtcore-ntuser-integration-l1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
20791568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb01260000 'ext-ms-win-rtcore-ntuser-integration-l1-1-0.dll'
20801568.584: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-com-l1-1-0.dll) -> 0x0, fPresent=1
20811568.584: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-com-l1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
20821568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaff5c0000 'api-ms-win-core-com-l1-1-0.dll'
20831568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msctf.dll
20841568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\MSCTF.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
20851568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb015b0000 'C:\WINDOWS\System32\MSCTF.dll'
20861568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
20871568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\ole32.dll (Input=ole32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
20881568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaff3d0000 'C:\WINDOWS\System32\ole32.dll'
20891568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
20901568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\OLEAUT32.dll (Input=OLEAUT32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
20911568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb01190000 'C:\WINDOWS\System32\OLEAUT32.dll'
20921568.584: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000b24 pwszName=\Device\HarddiskVolume2\Windows\System32\wbem\wbemprox.dll
20931568.584: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000302c490
20941568.584: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000302c490
20951568.584: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=AE2733DC030E44DCE443886E467FF179D2D68A91
20961568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
20971568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
20981568.584: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package01~31bf3856ad364e35~amd64~~10.0.16299.15.cat'; file='\Device\HarddiskVolume2\Windows\System32\wbem\wbemprox.dll'
20991568.584: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
21001568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
21011568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ws2_32.dll'.
21021568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'wbemcomn.dll'.
21031568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\wbem\wbemprox.dll) WinVerifyTrust
21041568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wbem\wbemprox.dll
21051568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wbemcomn.dll'...
21061568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'wbemcomn.dll' -> '\Device\HarddiskVolume2\Windows\System32\wbemcomn.dll' [rcNtRedir=0xc0150008]
21071568.584: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000b30 pwszName=\Device\HarddiskVolume2\Windows\System32\wbemcomn.dll
21081568.584: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000302c490
21091568.584: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000302c490
21101568.584: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=CA3F9D85214DB0270185C719B931C69440BA9C18
21111568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
21121568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
21131568.584: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package01~31bf3856ad364e35~amd64~~10.0.16299.15.cat'; file='\Device\HarddiskVolume2\Windows\System32\wbemcomn.dll'
21141568.584: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
21151568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
21161568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'bcrypt.dll'.
21171568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'ws2_32.dll'.
21181568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\wbemcomn.dll) WinVerifyTrust
21191568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wbemcomn.dll
21201568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
21211568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
21221568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
21231568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
21241568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
21251568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
21261568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
21271568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
21281568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
21291568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume2\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
21301568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll
21311568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
21321568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
21331568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\wbem\wbemprox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
21341568.584: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbem\wbemprox.dll
21351568.584: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbemcomn.dll
21361568.584: supR3HardenedDllNotificationCallback: load 00007ffaf0db0000 LB 0x00081000 C:\WINDOWS\SYSTEM32\wbemcomn.dll [fFlags=0x0]
21371568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbemcomn.dll
21381568.584: supR3HardenedDllNotificationCallback: load 00007ffaf0c60000 LB 0x0000f000 C:\WINDOWS\system32\wbem\wbemprox.dll [fFlags=0x0]
21391568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbem\wbemprox.dll
21401568.584: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(API-MS-Win-Core-LocalRegistry-L1-1-0.dll) -> 0x0, fPresent=1
21411568.584: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Core-LocalRegistry-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
21421568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafeca0000 'API-MS-Win-Core-LocalRegistry-L1-1-0.dll'
21431568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaf0c60000 'C:\WINDOWS\system32\wbem\wbemprox.dll'
21441568.584: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000b80 pwszName=\Device\HarddiskVolume2\Windows\System32\wbem\wbemsvc.dll
21451568.584: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000302c490
21461568.584: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000302c490
21471568.584: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=4C70145BD7347C12AB1BF3946D40606389C4D331
21481568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
21491568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
21501568.584: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package01~31bf3856ad364e35~amd64~~10.0.16299.15.cat'; file='\Device\HarddiskVolume2\Windows\System32\wbem\wbemsvc.dll'
21511568.584: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
21521568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
21531568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'rpcrt4.dll'.
21541568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\wbem\wbemsvc.dll) WinVerifyTrust
21551568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wbem\wbemsvc.dll
21561568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
21571568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
21581568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
21591568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
21601568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\wbem\wbemsvc.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
21611568.584: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbem\wbemsvc.dll
21621568.584: supR3HardenedDllNotificationCallback: load 00007ffae9b70000 LB 0x00014000 C:\WINDOWS\system32\wbem\wbemsvc.dll [fFlags=0x0]
21631568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbem\wbemsvc.dll
21641568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffae9b70000 'C:\WINDOWS\system32\wbem\wbemsvc.dll'
21651568.584: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-l1-2-0.dll) -> 0x0, fPresent=1
21661568.584: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-l1-2-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
21671568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafeca0000 'api-ms-win-core-localization-l1-2-0.dll'
21681568.584: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-obsolete-l1-1-0.dll) -> 0x0, fPresent=1
21691568.584: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-obsolete-l1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
21701568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafeca0000 'api-ms-win-core-localization-obsolete-l1-1-0.dll'
21711568.584: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000b5c pwszName=\Device\HarddiskVolume2\Windows\System32\wbem\fastprox.dll
21721568.584: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000302c490
21731568.584: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000302c490
21741568.584: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=336CDD3C969CEFC6CE8D502298ED123FE8D2F483
21751568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
21761568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
21771568.584: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package01~31bf3856ad364e35~amd64~~10.0.16299.15.cat'; file='\Device\HarddiskVolume2\Windows\System32\wbem\fastprox.dll'
21781568.584: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
21791568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
21801568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #19 'wbemcomn.dll'.
21811568.584: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\wbem\fastprox.dll) WinVerifyTrust
21821568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wbem\fastprox.dll
21831568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wbemcomn.dll'...
21841568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'wbemcomn.dll' -> '\Device\HarddiskVolume2\Windows\System32\wbemcomn.dll' [rcNtRedir=0xc0150008]
21851568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbemcomn.dll
21861568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
21871568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
21881568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
21891568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\wbem\fastprox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
21901568.584: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbem\fastprox.dll
21911568.584: supR3HardenedDllNotificationCallback: load 00007ffae9d30000 LB 0x000f0000 C:\WINDOWS\system32\wbem\fastprox.dll [fFlags=0x0]
21921568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbem\fastprox.dll
21931568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffae9d30000 'C:\WINDOWS\system32\wbem\fastprox.dll'
21941568.7ec: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
21951568.7ec: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
21961568.7ec: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
21971568.7ec: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
21981568.7ec: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
21991568.7ec: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
22001568.7ec: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ws2_32.dll'.
22011568.7ec: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxVRDP.dll) WinVerifyTrust
22021568.7ec: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxVRDP.dll
22031568.7ec: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
22041568.7ec: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
22051568.7ec: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
22061568.7ec: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
22071568.7ec: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
22081568.7ec: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
22091568.7ec: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
22101568.7ec: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
22111568.7ec: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
22121568.7ec: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
22131568.7ec: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
22141568.7ec: supR3HardenedMonitor_LdrLoadDll: pName=Z:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxVRDP.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
22151568.7ec: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxVRDP.dll
22161568.7ec: supR3HardenedDllNotificationCallback: load 00007ffad43a0000 LB 0x001a5000 Z:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxVRDP.DLL [fFlags=0x0]
22171568.7ec: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxVRDP.dll
22181568.7ec: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad43a0000 'Z:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxVRDP.DLL'
22191568.1930: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
22201568.1930: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
22211568.1930: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'ws2_32.dll'.
22221568.1930: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #22 'rpcrt4.dll'.
22231568.1930: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\mswsock.dll) WinVerifyTrust
22241568.1930: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\mswsock.dll
22251568.1930: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
22261568.1930: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
22271568.1930: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
22281568.1930: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
22291568.1930: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
22301568.1930: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\mswsock.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
22311568.1930: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\mswsock.dll
22321568.1930: supR3HardenedDllNotificationCallback: load 00007ffafda30000 LB 0x00066000 C:\WINDOWS\system32\mswsock.dll [fFlags=0x0]
22331568.1930: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\mswsock.dll
22341568.1930: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafda30000 'C:\WINDOWS\system32\mswsock.dll'
22351568.1930: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\mswsock.dll
22361568.1930: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\mswsock.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
22371568.1930: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafda30000 'C:\WINDOWS\system32\mswsock.dll'
22381568.7ec: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
22391568.7ec: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
22401568.7ec: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrem.dll'.
22411568.7ec: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
22421568.7ec: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxVMM.dll) WinVerifyTrust
22431568.7ec: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxVMM.dll
22441568.7ec: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
22451568.7ec: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
22461568.7ec: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrem.dll'...
22471568.7ec: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrem.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\vboxrem.dll' [rcNtRedir=0xc0150008]
22481568.7ec: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
22491568.7ec: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'vboxrt.dll'.
22501568.7ec: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
22511568.7ec: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcrt.dll'.
22521568.7ec: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxREM.dll) WinVerifyTrust
22531568.7ec: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxREM.dll
22541568.7ec: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
22551568.7ec: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
22561568.7ec: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
22571568.7ec: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
22581568.7ec: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
22591568.7ec: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
22601568.7ec: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxVMM.dll
22611568.7ec: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
22621568.7ec: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
22631568.7ec: supR3HardenedMonitor_LdrLoadDll: pName=Z:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
22641568.7ec: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxVMM.dll
22651568.7ec: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxREM.dll
22661568.7ec: supR3HardenedDllNotificationCallback: load 00000000603c0000 LB 0x0010b000 Z:\Program Files\Oracle\VirtualBox\VBoxREM.dll [fFlags=0x0]
22671568.7ec: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxREM.dll
22681568.7ec: supR3HardenedDllNotificationCallback: load 00007ffacfe00000 LB 0x002c7000 Z:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL [fFlags=0x0]
22691568.7ec: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxVMM.dll
22701568.7ec: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffacfe00000 'Z:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL'
22711568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
22721568.2428: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000cbc pwszName=\Device\HarddiskVolume2\Windows\System32\NetSetupShim.dll
22731568.2428: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000302c490
22741568.2428: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000302c490
22751568.2428: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=F30E80B88384D221750DC79ADCE84BDFB8A5A73A
22761568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
22771568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
22781568.2428: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package00111~31bf3856ad364e35~amd64~~10.0.16299.15.cat'; file='\Device\HarddiskVolume2\Windows\System32\NetSetupShim.dll'
22791568.2428: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
22801568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
22811568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #30 'rpcrt4.dll'.
22821568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #31 'oleaut32.dll'.
22831568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #33 'ws2_32.dll'.
22841568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #34 'netsetupapi.dll'.
22851568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #35 'setupapi.dll'.
22861568.2428: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\NetSetupShim.dll) WinVerifyTrust
22871568.2428: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\NetSetupShim.dll
22881568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
22891568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
22901568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
22911568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
22921568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
22931568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #29 'rpcrt4.dll'.
22941568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #37 'cfgmgr32.dll'.
22951568.2428: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\setupapi.dll) WinVerifyTrust
22961568.2428: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\setupapi.dll
22971568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'netsetupapi.dll'...
22981568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'netsetupapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\netsetupapi.dll' [rcNtRedir=0xc0150008]
22991568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
23001568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
23011568.2428: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll [lacks WinVerifyTrust]
23021568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
23031568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
23041568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
23051568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
23061568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
23071568.2428: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll
23081568.2428: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
23091568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
23101568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
23111568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'rpcrt4.dll'.
23121568.2428: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\NetSetupApi.dll) WinVerifyTrust
23131568.2428: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\NetSetupApi.dll
23141568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
23151568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
23161568.2428: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
23171568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
23181568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
23191568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
23201568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
23211568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
23221568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
23231568.2428: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcp_win.dll [redoing WinVerifyTrust]
23241568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
23251568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
23261568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
23271568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
23281568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
23291568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
23301568.2428: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\msvcp_win.dll'
23311568.2428: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\NetSetupShim.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
23321568.2428: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\NetSetupShim.dll
23331568.2428: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\NetSetupApi.dll
23341568.2428: supR3HardenedDllNotificationCallback: load 00007ffaf1bc0000 LB 0x00026000 C:\Windows\System32\NetSetupApi.dll [fFlags=0x0]
23351568.2428: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\NetSetupApi.dll
23361568.2428: supR3HardenedDllNotificationCallback: load 00007ffb01720000 LB 0x0044e000 C:\WINDOWS\System32\setupapi.dll [fFlags=0x0]
23371568.2428: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\setupapi.dll
23381568.2428: supR3HardenedDllNotificationCallback: load 00007ffaee060000 LB 0x0007d000 C:\Windows\System32\NetSetupShim.dll [fFlags=0x0]
23391568.2428: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\NetSetupShim.dll
23401568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaee060000 'C:\Windows\System32\NetSetupShim.dll'
23411568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
23421568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
23431568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
23441568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #24 'rpcrt4.dll'.
23451568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'nsi.dll'.
23461568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'winnsi.dll'.
23471568.2428: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\NetSetupEngine.dll) WinVerifyTrust
23481568.2428: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\NetSetupEngine.dll
23491568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winnsi.dll'...
23501568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'winnsi.dll' -> '\Device\HarddiskVolume2\Windows\System32\winnsi.dll' [rcNtRedir=0xc0150008]
23511568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
23521568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
23531568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rpcrt4.dll'.
23541568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'nsi.dll'.
23551568.2428: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\winnsi.dll) WinVerifyTrust
23561568.2428: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\winnsi.dll
23571568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
23581568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume2\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
23591568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
23601568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume2\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
23611568.2428: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\nsi.dll'.
23621568.2428: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\nsi.dll)
23631568.2428: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\nsi.dll
23641568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
23651568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
23661568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
23671568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
23681568.2428: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\nsi.dll) WinVerifyTrust
23691568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
23701568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
23711568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
23721568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
23731568.2428: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\NetSetupEngine.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
23741568.2428: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\NetSetupEngine.dll
23751568.2428: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winnsi.dll
23761568.2428: supR3HardenedDllNotificationCallback: load 00007ffb01160000 LB 0x00008000 C:\WINDOWS\System32\NSI.dll [fFlags=0x0]
23771568.2428: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\nsi.dll [avoiding WinVerifyTrust]
23781568.2428: supR3HardenedDllNotificationCallback: load 00007ffaf9800000 LB 0x0000b000 C:\WINDOWS\SYSTEM32\WINNSI.DLL [fFlags=0x0]
23791568.2428: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winnsi.dll
23801568.2428: supR3HardenedDllNotificationCallback: load 00007ffad42d0000 LB 0x000c1000 C:\Windows\System32\NetSetupEngine.dll [fFlags=0x0]
23811568.2428: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\NetSetupEngine.dll
23821568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad42d0000 'C:\Windows\System32\NetSetupEngine.dll'
23831568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
23841568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
23851568.2428: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\nsi.dll'
23861568.2100: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
23871568.2100: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
23881568.2100: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
23891568.2100: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
23901568.2100: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
23911568.2100: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll) WinVerifyTrust
23921568.2100: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll
23931568.2100: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
23941568.2100: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
23951568.2100: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
23961568.2100: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
23971568.2100: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
23981568.2100: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
23991568.2100: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxVMM.dll
24001568.2100: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
24011568.2100: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
24021568.2100: supR3HardenedMonitor_LdrLoadDll: pName=Z:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
24031568.2100: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll
24041568.2100: supR3HardenedDllNotificationCallback: load 00007ffaf8610000 LB 0x0000b000 Z:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL [fFlags=0x0]
24051568.2100: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll
24061568.2100: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaf8610000 'Z:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL'
24071568.2100: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb01260000 'C:\WINDOWS\system32\User32.dll'
24081568.2290: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
24091568.2290: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
24101568.2290: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
24111568.2290: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
24121568.2290: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll) WinVerifyTrust
24131568.2290: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll
24141568.2290: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
24151568.2290: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
24161568.2290: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
24171568.2290: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
24181568.2290: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcp100.dll
24191568.2290: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
24201568.2290: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
24211568.2290: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcr100.dll
24221568.2290: supR3HardenedMonitor_LdrLoadDll: pName=Z:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
24231568.2290: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll
24241568.2290: supR3HardenedDllNotificationCallback: load 00007ffaf8540000 LB 0x0000d000 Z:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL [fFlags=0x0]
24251568.2290: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll
24261568.2290: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaf8540000 'Z:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL'
24271568.1058: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
24281568.1058: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
24291568.1058: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
24301568.1058: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
24311568.1058: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll) WinVerifyTrust
24321568.1058: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll
24331568.1058: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
24341568.1058: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
24351568.1058: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
24361568.1058: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
24371568.1058: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
24381568.1058: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
24391568.1058: supR3HardenedMonitor_LdrLoadDll: pName=Z:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
24401568.1058: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll
24411568.1058: supR3HardenedDllNotificationCallback: load 00007ffaf79f0000 LB 0x0000c000 Z:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL [fFlags=0x0]
24421568.1058: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll
24431568.1058: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaf79f0000 'Z:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL'
24441568.9f4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
24451568.9f4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
24461568.9f4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
24471568.9f4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
24481568.9f4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll) WinVerifyTrust
24491568.9f4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll
24501568.9f4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
24511568.9f4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
24521568.9f4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
24531568.9f4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
24541568.9f4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
24551568.9f4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
24561568.9f4: supR3HardenedMonitor_LdrLoadDll: pName=Z:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
24571568.9f4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll
24581568.9f4: supR3HardenedDllNotificationCallback: load 00007ffaf79e0000 LB 0x0000b000 Z:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL [fFlags=0x0]
24591568.9f4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll
24601568.9f4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaf79e0000 'Z:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL'
24611568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaffd20000 'C:\WINDOWS\system32\Shell32.dll'
24621568.2428: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxVMM.dll
24631568.2428: supR3HardenedMonitor_LdrLoadDll: pName=Z:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
24641568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffacfe00000 'Z:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL'
24651568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
24661568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
24671568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
24681568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
24691568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ole32.dll'.
24701568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'oleaut32.dll'.
24711568.2428: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll) WinVerifyTrust
24721568.2428: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
24731568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
24741568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
24751568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
24761568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
24771568.2428: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
24781568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
24791568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
24801568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
24811568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
24821568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
24831568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
24841568.2428: supR3HardenedMonitor_LdrLoadDll: pName=Z:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
24851568.2428: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
24861568.2428: supR3HardenedDllNotificationCallback: load 00007ffae61e0000 LB 0x00041000 Z:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL [fFlags=0x0]
24871568.2428: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
24881568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffae61e0000 'Z:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL'
24891568.2428: supR3HardenedDllNotificationCallback: Unload 00007ffae61e0000 LB 0x00041000 Z:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL [flags=0x0]
24901568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
24911568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
24921568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
24931568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
24941568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
24951568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vboxddu.dll'.
24961568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'vboxdd2.dll'.
24971568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
24981568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'setupapi.dll'.
24991568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'ws2_32.dll'.
25001568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'ole32.dll'.
25011568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'iphlpapi.dll'.
25021568.2428: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxDD.dll) WinVerifyTrust
25031568.2428: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxDD.dll
25041568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'iphlpapi.dll'...
25051568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'iphlpapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\iphlpapi.dll' [rcNtRedir=0xc0150008]
25061568.2428: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL [redoing WinVerifyTrust]
25071568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
25081568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
25091568.2428: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL'
25101568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
25111568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
25121568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
25131568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
25141568.2428: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
25151568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
25161568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
25171568.2428: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\setupapi.dll
25181568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
25191568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
25201568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxdd2.dll'...
25211568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxdd2.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\vboxdd2.dll' [rcNtRedir=0xc0150008]
25221568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
25231568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
25241568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
25251568.2428: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxDD2.dll) WinVerifyTrust
25261568.2428: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxDD2.dll
25271568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxddu.dll'...
25281568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxddu.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\vboxddu.dll' [rcNtRedir=0xc0150008]
25291568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
25301568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
25311568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
25321568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
25331568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
25341568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
25351568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
25361568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
25371568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'setupapi.dll'.
25381568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'advapi32.dll'.
25391568.2428: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxDDU.dll) WinVerifyTrust
25401568.2428: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxDDU.dll
25411568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
25421568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
25431568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
25441568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
25451568.2428: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxVMM.dll
25461568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
25471568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
25481568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
25491568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
25501568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
25511568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
25521568.2428: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\setupapi.dll
25531568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
25541568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
25551568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
25561568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
25571568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
25581568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
25591568.2428: supR3HardenedMonitor_LdrLoadDll: pName=Z:\Program Files\Oracle\VirtualBox\VBoxDD.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
25601568.2428: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxDD.dll
25611568.2428: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxDDU.dll
25621568.2428: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxDD2.dll
25631568.2428: supR3HardenedDllNotificationCallback: load 00007ffaee770000 LB 0x00063000 Z:\Program Files\Oracle\VirtualBox\VBoxDDU.dll [fFlags=0x0]
25641568.2428: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxDDU.dll
25651568.2428: supR3HardenedDllNotificationCallback: load 00007ffaf3a20000 LB 0x0005d000 Z:\Program Files\Oracle\VirtualBox\VBoxDD2.dll [fFlags=0x0]
25661568.2428: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxDD2.dll
25671568.2428: supR3HardenedDllNotificationCallback: load 00007ffac5d90000 LB 0x009bf000 Z:\Program Files\Oracle\VirtualBox\VBoxDD.DLL [fFlags=0x0]
25681568.2428: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxDD.dll
25691568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac5d90000 'Z:\Program Files\Oracle\VirtualBox\VBoxDD.DLL'
25701568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
25711568.2428: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
25721568.2428: supR3HardenedMonitor_LdrLoadDll: pName=Z:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
25731568.2428: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
25741568.2428: supR3HardenedDllNotificationCallback: load 00007ffae61e0000 LB 0x00041000 Z:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL [fFlags=0x0]
25751568.2428: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
25761568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffae61e0000 'Z:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL'
25771568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
25781568.2428: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxC.dll
25791568.2428: supR3HardenedMonitor_LdrLoadDll: pName=Z:\Program Files\Oracle\VirtualBox\VBoxC.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
25801568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffac6750000 'Z:\Program Files\Oracle\VirtualBox\VBoxC.DLL'
25811568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
25821568.2428: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxDD2.dll
25831568.2428: supR3HardenedMonitor_LdrLoadDll: pName=Z:\Program Files\Oracle\VirtualBox\VBoxDD2.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
25841568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaf3a20000 'Z:\Program Files\Oracle\VirtualBox\VBoxDD2.DLL'
25851568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
25861568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
25871568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
25881568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
25891568.2428: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.dll) WinVerifyTrust
25901568.2428: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.dll
25911568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
25921568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
25931568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
25941568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
25951568.2428: supR3HardenedMonitor_LdrLoadDll: pName=Z:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
25961568.2428: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.dll
25971568.2428: supR3HardenedDllNotificationCallback: load 00007ffaee750000 LB 0x0001f000 Z:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.DLL [fFlags=0x0]
25981568.2428: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.dll
25991568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaee750000 'Z:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.DLL'
26001568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
26011568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
26021568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
26031568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
26041568.2428: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.dll) WinVerifyTrust
26051568.2428: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.dll
26061568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
26071568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
26081568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
26091568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
26101568.2428: supR3HardenedMonitor_LdrLoadDll: pName=Z:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
26111568.2428: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.dll
26121568.2428: supR3HardenedDllNotificationCallback: load 00007ffaee0f0000 LB 0x00018000 Z:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.DLL [fFlags=0x0]
26131568.2428: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.dll
26141568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaee0f0000 'Z:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.DLL'
26151568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
26161568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
26171568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
26181568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
26191568.2428: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.dll) WinVerifyTrust
26201568.2428: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.dll
26211568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
26221568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
26231568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
26241568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
26251568.2428: supR3HardenedMonitor_LdrLoadDll: pName=Z:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
26261568.2428: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.dll
26271568.2428: supR3HardenedDllNotificationCallback: load 00007ffaead30000 LB 0x00018000 Z:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.DLL [fFlags=0x0]
26281568.2428: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.dll
26291568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaead30000 'Z:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.DLL'
26301568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
26311568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
26321568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
26331568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
26341568.2428: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.dll) WinVerifyTrust
26351568.2428: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.dll
26361568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
26371568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
26381568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
26391568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
26401568.2428: supR3HardenedMonitor_LdrLoadDll: pName=Z:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
26411568.2428: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.dll
26421568.2428: supR3HardenedDllNotificationCallback: load 00007ffae80f0000 LB 0x00019000 Z:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.DLL [fFlags=0x0]
26431568.2428: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.dll
26441568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffae80f0000 'Z:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.DLL'
26451568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
26461568.1c6c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
26471568.1c6c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
26481568.1c6c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
26491568.1c6c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
26501568.1c6c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll) WinVerifyTrust
26511568.1c6c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll
26521568.1c6c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
26531568.1c6c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
26541568.1c6c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
26551568.1c6c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
26561568.1c6c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxVMM.dll
26571568.1c6c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
26581568.1c6c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
26591568.1c6c: supR3HardenedMonitor_LdrLoadDll: pName=Z:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
26601568.1c6c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll
26611568.1c6c: supR3HardenedDllNotificationCallback: load 00007ffaf7890000 LB 0x0000d000 Z:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL [fFlags=0x0]
26621568.1c6c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll
26631568.1c6c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaf7890000 'Z:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL'
26641568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
26651568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
26661568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
26671568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
26681568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
26691568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
26701568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ws2_32.dll'.
26711568.2428: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.dll) WinVerifyTrust
26721568.2428: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.dll
26731568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
26741568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
26751568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
26761568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
26771568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
26781568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
26791568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
26801568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
26811568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
26821568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
26831568.2428: supR3HardenedMonitor_LdrLoadDll: pName=Z:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
26841568.2428: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.dll
26851568.2428: supR3HardenedDllNotificationCallback: load 00007ffad4550000 LB 0x000e5000 Z:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.DLL [fFlags=0x0]
26861568.2428: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.dll
26871568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad4550000 'Z:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.DLL'
26881568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
26891568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
26901568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
26911568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'rpcrt4.dll'.
26921568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #32 'devobj.dll'.
26931568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #33 'propsys.dll'.
26941568.2428: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll) WinVerifyTrust
26951568.2428: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
26961568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'propsys.dll'...
26971568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'propsys.dll' -> '\Device\HarddiskVolume2\Windows\System32\propsys.dll' [rcNtRedir=0xc0150008]
26981568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
26991568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
27001568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
27011568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #15 'oleaut32.dll'.
27021568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #31 'rpcrt4.dll'.
27031568.2428: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\propsys.dll) WinVerifyTrust
27041568.2428: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\propsys.dll
27051568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'devobj.dll'...
27061568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'devobj.dll' -> '\Device\HarddiskVolume2\Windows\System32\devobj.dll' [rcNtRedir=0xc0150008]
27071568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
27081568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
27091568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
27101568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
27111568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
27121568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
27131568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
27141568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
27151568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'cfgmgr32.dll'.
27161568.2428: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\devobj.dll) WinVerifyTrust
27171568.2428: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\devobj.dll
27181568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
27191568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
27201568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
27211568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
27221568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
27231568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
27241568.2428: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll [redoing WinVerifyTrust]
27251568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
27261568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
27271568.2428: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll'
27281568.2428: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\MMDevApi.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
27291568.2428: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
27301568.2428: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\devobj.dll
27311568.2428: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\propsys.dll
27321568.2428: supR3HardenedDllNotificationCallback: load 00007ffafdfb0000 LB 0x00027000 C:\WINDOWS\System32\DEVOBJ.dll [fFlags=0x0]
27331568.2428: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\devobj.dll
27341568.2428: supR3HardenedDllNotificationCallback: load 00007ffafa190000 LB 0x001b1000 C:\WINDOWS\System32\PROPSYS.dll [fFlags=0x0]
27351568.2428: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\propsys.dll
27361568.2428: supR3HardenedDllNotificationCallback: load 00007ffaf6320000 LB 0x0006f000 C:\WINDOWS\System32\MMDevApi.dll [fFlags=0x0]
27371568.2428: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
27381568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaf6320000 'C:\WINDOWS\System32\MMDevApi.dll'
27391568.2428: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000001004 pwszName=\Device\HarddiskVolume2\Windows\System32\dsound.dll
27401568.2428: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000302c490
27411568.2428: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000302c490
27421568.2428: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=149E0A5A40CD1471B9EF3D3043A8C754805FEC76
27431568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
27441568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
27451568.2428: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package~31bf3856ad364e35~amd64~~10.0.16299.15.cat'; file='\Device\HarddiskVolume2\Windows\System32\dsound.dll'
27461568.2428: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
27471568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
27481568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #32 'winmm.dll'.
27491568.2428: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\dsound.dll) WinVerifyTrust
27501568.2428: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\dsound.dll
27511568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
27521568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
27531568.2428: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
27541568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
27551568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
27561568.2428: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
27571568.2428: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dsound.dll
27581568.2428: supR3HardenedDllNotificationCallback: load 00007ffad4240000 LB 0x0008f000 C:\WINDOWS\System32\dsound.dll [fFlags=0x0]
27591568.2428: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dsound.dll
27601568.2428: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dsound.dll
27611568.2428: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
27621568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad4240000 'C:\WINDOWS\System32\dsound.dll'
27631568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad4240000 'C:\WINDOWS\System32\dsound.dll'
27641568.2428: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dsound.dll
27651568.2428: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
27661568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad4240000 'C:\WINDOWS\system32\dsound.dll'
27671568.2428: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
27681568.2428: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\MMDEVAPI.DLL (Input=MMDEVAPI.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
27691568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaf6320000 'C:\WINDOWS\System32\MMDEVAPI.DLL'
27701568.2428: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
27711568.2428: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\winmm.dll (Input=winmm.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
27721568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaf9f70000 'C:\WINDOWS\System32\winmm.dll'
27731568.2428: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000001048 pwszName=\Device\HarddiskVolume2\Windows\System32\wdmaud.drv
27741568.2428: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000302c490
27751568.2428: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000302c490
27761568.2428: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=47392EB8EC6AC07C788B971D8BB592B6FD619920
27771568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
27781568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
27791568.2428: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package~31bf3856ad364e35~amd64~~10.0.16299.15.cat'; file='\Device\HarddiskVolume2\Windows\System32\wdmaud.drv'
27801568.2428: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
27811568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
27821568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'mmdevapi.dll'.
27831568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #27 'ksuser.dll'.
27841568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #28 'avrt.dll'.
27851568.2428: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\wdmaud.drv) WinVerifyTrust
27861568.2428: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
27871568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'avrt.dll'...
27881568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'avrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\avrt.dll' [rcNtRedir=0xc0150008]
27891568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
27901568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
27911568.2428: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\avrt.dll) WinVerifyTrust
27921568.2428: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\avrt.dll
27931568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ksuser.dll'...
27941568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'ksuser.dll' -> '\Device\HarddiskVolume2\Windows\System32\ksuser.dll' [rcNtRedir=0xc0150008]
27951568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
27961568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
27971568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
27981568.2428: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ksuser.dll) WinVerifyTrust
27991568.2428: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ksuser.dll
28001568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mmdevapi.dll'...
28011568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'mmdevapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\mmdevapi.dll' [rcNtRedir=0xc0150008]
28021568.2428: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
28031568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
28041568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
28051568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
28061568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
28071568.2428: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
28081568.2428: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
28091568.2428: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ksuser.dll
28101568.2428: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\avrt.dll
28111568.2428: supR3HardenedDllNotificationCallback: load 00007ffae6010000 LB 0x00009000 C:\WINDOWS\SYSTEM32\ksuser.dll [fFlags=0x0]
28121568.2428: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ksuser.dll
28131568.2428: supR3HardenedDllNotificationCallback: load 00007ffaf8890000 LB 0x0000a000 C:\WINDOWS\SYSTEM32\AVRT.dll [fFlags=0x0]
28141568.2428: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\avrt.dll
28151568.2428: supR3HardenedDllNotificationCallback: load 00007ffae1560000 LB 0x00042000 C:\WINDOWS\System32\wdmaud.drv [fFlags=0x0]
28161568.2428: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
28171568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffae1560000 'C:\WINDOWS\System32\wdmaud.drv'
28181568.2428: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
28191568.2428: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
28201568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffae1560000 'C:\WINDOWS\System32\wdmaud.drv'
28211568.2428: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
28221568.2428: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
28231568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffae1560000 'C:\WINDOWS\System32\wdmaud.drv'
28241568.2428: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
28251568.2428: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
28261568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffae1560000 'C:\WINDOWS\System32\wdmaud.drv'
28271568.2428: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
28281568.2428: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
28291568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffae1560000 'C:\WINDOWS\System32\wdmaud.drv'
28301568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
28311568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
28321568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
28331568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'rpcrt4.dll'.
28341568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'oleaut32.dll'.
28351568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #55 'mmdevapi.dll'.
28361568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #56 'avrt.dll'.
28371568.2428: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\AudioSes.dll) WinVerifyTrust
28381568.2428: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\AudioSes.dll
28391568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'avrt.dll'...
28401568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'avrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\avrt.dll' [rcNtRedir=0xc0150008]
28411568.2428: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\avrt.dll
28421568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mmdevapi.dll'...
28431568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'mmdevapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\mmdevapi.dll' [rcNtRedir=0xc0150008]
28441568.2428: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
28451568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
28461568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
28471568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
28481568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
28491568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
28501568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
28511568.2428: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcp_win.dll
28521568.2428: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\AUDIOSES.DLL (Input=AUDIOSES.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
28531568.2428: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\AudioSes.dll
28541568.2428: supR3HardenedDllNotificationCallback: load 00007ffad8d40000 LB 0x00122000 C:\WINDOWS\System32\AUDIOSES.DLL [fFlags=0x0]
28551568.2428: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\AudioSes.dll
28561568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad8d40000 'C:\WINDOWS\System32\AUDIOSES.DLL'
28571568.2428: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
28581568.2428: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
28591568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffae1560000 'C:\WINDOWS\System32\wdmaud.drv'
28601568.2428: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
28611568.2428: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
28621568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffae1560000 'C:\WINDOWS\System32\wdmaud.drv'
28631568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffae1560000 'C:\WINDOWS\System32\wdmaud.drv'
28641568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffae1560000 'C:\WINDOWS\System32\wdmaud.drv'
28651568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffae1560000 'C:\WINDOWS\System32\wdmaud.drv'
28661568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffae1560000 'C:\WINDOWS\System32\wdmaud.drv'
28671568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffae1560000 'C:\WINDOWS\System32\wdmaud.drv'
28681568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffae1560000 'C:\WINDOWS\System32\wdmaud.drv'
28691568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffae1560000 'C:\WINDOWS\System32\wdmaud.drv'
28701568.2428: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
28711568.2428: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
28721568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffae1560000 'C:\WINDOWS\System32\wdmaud.drv'
28731568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffae1560000 'C:\WINDOWS\System32\wdmaud.drv'
28741568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffae1560000 'C:\WINDOWS\System32\wdmaud.drv'
28751568.2428: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000010cc pwszName=\Device\HarddiskVolume2\Windows\System32\msacm32.drv
28761568.2428: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000302c490
28771568.2428: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000302c490
28781568.2428: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=8069FA07F8A743E03BD7E2DA392DE4429701D8E6
28791568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
28801568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
28811568.2428: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package~31bf3856ad364e35~amd64~~10.0.16299.15.cat'; file='\Device\HarddiskVolume2\Windows\System32\msacm32.drv'
28821568.2428: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
28831568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
28841568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'mmdevapi.dll'.
28851568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'msacm32.dll'.
28861568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'winmmbase.dll'.
28871568.2428: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\msacm32.drv) WinVerifyTrust
28881568.2428: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msacm32.drv
28891568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmmbase.dll'...
28901568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmmbase.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmmbase.dll' [rcNtRedir=0xc0150008]
28911568.2428: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmmbase.dll [redoing WinVerifyTrust]
28921568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
28931568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
28941568.2428: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\winmmbase.dll'
28951568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msacm32.dll'...
28961568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'msacm32.dll' -> '\Device\HarddiskVolume2\Windows\System32\msacm32.dll' [rcNtRedir=0xc0150008]
28971568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
28981568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
28991568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
29001568.2428: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\msacm32.dll) WinVerifyTrust
29011568.2428: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msacm32.dll
29021568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mmdevapi.dll'...
29031568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'mmdevapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\mmdevapi.dll' [rcNtRedir=0xc0150008]
29041568.2428: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
29051568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
29061568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
29071568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
29081568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
29091568.2428: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
29101568.2428: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
29111568.2428: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.dll
29121568.2428: supR3HardenedDllNotificationCallback: load 00007ffae80d0000 LB 0x0001c000 C:\WINDOWS\SYSTEM32\MSACM32.dll [fFlags=0x0]
29131568.2428: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.dll
29141568.2428: supR3HardenedDllNotificationCallback: load 00007ffaf3a90000 LB 0x0000c000 C:\WINDOWS\System32\msacm32.drv [fFlags=0x0]
29151568.2428: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
29161568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaf3a90000 'C:\WINDOWS\System32\msacm32.drv'
29171568.2428: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
29181568.2428: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
29191568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaf3a90000 'C:\WINDOWS\System32\msacm32.drv'
29201568.2428: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
29211568.2428: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
29221568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaf3a90000 'C:\WINDOWS\System32\msacm32.drv'
29231568.2428: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
29241568.2428: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
29251568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaf3a90000 'C:\WINDOWS\System32\msacm32.drv'
29261568.2428: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
29271568.2428: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
29281568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaf3a90000 'C:\WINDOWS\System32\msacm32.drv'
29291568.2428: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
29301568.2428: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
29311568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaf3a90000 'C:\WINDOWS\System32\msacm32.drv'
29321568.2428: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
29331568.2428: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
29341568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaf3a90000 'C:\WINDOWS\System32\msacm32.drv'
29351568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaf3a90000 'C:\WINDOWS\System32\msacm32.drv'
29361568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaf3a90000 'C:\WINDOWS\System32\msacm32.drv'
29371568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaf3a90000 'C:\WINDOWS\System32\msacm32.drv'
29381568.2428: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000010d4 pwszName=\Device\HarddiskVolume2\Windows\System32\midimap.dll
29391568.2428: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000302c490
29401568.2428: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000302c490
29411568.2428: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=725292B88FCE45C617EE0258A333B14CA2D7EF04
29421568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
29431568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
29441568.2428: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package~31bf3856ad364e35~amd64~~10.0.16299.15.cat'; file='\Device\HarddiskVolume2\Windows\System32\midimap.dll'
29451568.2428: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
29461568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
29471568.2428: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'winmm.dll'.
29481568.2428: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\midimap.dll) WinVerifyTrust
29491568.2428: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\midimap.dll
29501568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
29511568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
29521568.2428: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
29531568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
29541568.2428: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
29551568.2428: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
29561568.2428: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\midimap.dll
29571568.2428: supR3HardenedDllNotificationCallback: load 00007ffaee0e0000 LB 0x0000a000 C:\WINDOWS\System32\midimap.dll [fFlags=0x0]
29581568.2428: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\midimap.dll
29591568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaee0e0000 'C:\WINDOWS\System32\midimap.dll'
29601568.2428: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\midimap.dll
29611568.2428: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
29621568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaee0e0000 'C:\WINDOWS\System32\midimap.dll'
29631568.2428: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\midimap.dll
29641568.2428: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
29651568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaee0e0000 'C:\WINDOWS\System32\midimap.dll'
29661568.2428: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\midimap.dll
29671568.2428: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
29681568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaee0e0000 'C:\WINDOWS\System32\midimap.dll'
29691568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaf9f70000 'C:\WINDOWS\System32\winmm.dll'
29701568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaf9f70000 'C:\WINDOWS\System32\winmm.dll'
29711568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaf9f70000 'C:\WINDOWS\System32\winmm.dll'
29721568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaf9f70000 'C:\WINDOWS\System32\winmm.dll'
29731568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaf9f70000 'C:\WINDOWS\System32\winmm.dll'
29741568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaf9f70000 'C:\WINDOWS\System32\winmm.dll'
29751568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaf9f70000 'C:\WINDOWS\System32\winmm.dll'
29761568.2428: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
29771568.2428: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\winmm.dll (Input=winmm.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
29781568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaf9f70000 'C:\WINDOWS\System32\winmm.dll'
29791568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaf9f70000 'C:\WINDOWS\System32\winmm.dll'
29801568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaf9f70000 'C:\WINDOWS\System32\winmm.dll'
29811568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaf9f70000 'C:\WINDOWS\System32\winmm.dll'
29821568.2428: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dsound.dll
29831568.2428: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
29841568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad4240000 'C:\WINDOWS\system32\dsound.dll'
29851568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaf9f70000 'C:\WINDOWS\System32\winmm.dll'
29861568.2428: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dsound.dll
29871568.2428: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
29881568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad4240000 'C:\WINDOWS\system32\dsound.dll'
29891568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaf9f70000 'C:\WINDOWS\System32\winmm.dll'
29901568.2428: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dsound.dll
29911568.2428: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
29921568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad4240000 'C:\WINDOWS\system32\dsound.dll'
29931568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaf9f70000 'C:\WINDOWS\System32\winmm.dll'
29941568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaf9f70000 'C:\WINDOWS\System32\winmm.dll'
29951568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaf9f70000 'C:\WINDOWS\System32\winmm.dll'
29961568.2428: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume21\Program Files\Oracle\VirtualBox\VBoxVMM.dll
29971568.2428: supR3HardenedMonitor_LdrLoadDll: pName=Z:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
29981568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffacfe00000 'Z:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL'
29991568.2428: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll
30001568.2428: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
30011568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
30021568.1c04: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dsound.dll
30031568.1c04: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
30041568.1c04: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad4240000 'C:\WINDOWS\system32\dsound.dll'
30051568.1c04: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaf9f70000 'C:\WINDOWS\System32\winmm.dll'
30061568.1c04: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad4240000 'C:\WINDOWS\system32\dsound.dll'
30071568.1c04: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaf9f70000 'C:\WINDOWS\System32\winmm.dll'
30081568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad4240000 'C:\WINDOWS\system32\dsound.dll'
30091568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaf9f70000 'C:\WINDOWS\System32\winmm.dll'
30101568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffad4240000 'C:\WINDOWS\system32\dsound.dll'
30111568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaf9f70000 'C:\WINDOWS\System32\winmm.dll'
30121568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaffd20000 'C:\WINDOWS\system32\shell32.dll'
30131568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaffd20000 'C:\WINDOWS\system32\shell32.dll'
30141568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaffd20000 'C:\WINDOWS\system32\shell32.dll'
30151568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaffd20000 'C:\WINDOWS\system32\shell32.dll'
30161568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaffd20000 'C:\WINDOWS\system32\shell32.dll'
30171568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaffd20000 'C:\WINDOWS\system32\shell32.dll'
30181568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
30191568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'rpcrt4.dll'.
30201568.584: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #24 'oleaut32.dll'.
30211568.584: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\edputil.dll)
30221568.584: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\edputil.dll
30231568.584: supR3HardenedDllNotificationCallback: load 00007ffadfe90000 LB 0x00044000 C:\WINDOWS\SYSTEM32\edputil.dll [fFlags=0x0]
30241568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\edputil.dll [avoiding WinVerifyTrust]
30251568.584: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000013f0 pwszName=\Device\HarddiskVolume2\Windows\System32\edputil.dll
30261568.584: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000302c490
30271568.584: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000302c490
30281568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
30291568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
30301568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
30311568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
30321568.584: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
30331568.584: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
30341568.584: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
30351568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafec40000 'C:\Windows\System32\WINTRUST.DLL'
30361568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\CRYPT32.dll'
30371568.584: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=A34C0BC98EA1F260DAC64D9ADCCC23BF6FE80E1B
30381568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafd5e0000 'C:\WINDOWS\system32\rsaenh.dll'
30391568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffafef10000 'C:\WINDOWS\System32\crypt32.dll'
30401568.584: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0017~31bf3856ad364e35~amd64~~10.0.16299.15.cat'; file='\Device\HarddiskVolume2\Windows\System32\edputil.dll'
30411568.584: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
30421568.584: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\edputil.dll'
30431568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
30441568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
30451568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaffd20000 'C:\WINDOWS\system32\shell32.dll'
30461568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaffd20000 'C:\WINDOWS\system32\shell32.dll'
30471568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaffd20000 'C:\WINDOWS\system32\shell32.dll'
30481568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaffd20000 'C:\WINDOWS\system32\shell32.dll'
30491568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaffd20000 'C:\WINDOWS\system32\shell32.dll'
30501568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaffd20000 'C:\WINDOWS\system32\shell32.dll'
30511568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaffd20000 'C:\WINDOWS\system32\shell32.dll'
30521568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaffd20000 'C:\WINDOWS\system32\shell32.dll'
30531568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaffd20000 'C:\WINDOWS\system32\shell32.dll'
30541568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaffd20000 'C:\WINDOWS\system32\shell32.dll'
30551568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaffd20000 'C:\WINDOWS\system32\shell32.dll'
30561568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaffd20000 'C:\WINDOWS\system32\shell32.dll'
30571568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaffd20000 'C:\WINDOWS\system32\shell32.dll'
30581568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaffd20000 'C:\WINDOWS\system32\shell32.dll'
30591568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaffd20000 'C:\WINDOWS\system32\shell32.dll'
30601568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaffd20000 'C:\WINDOWS\system32\shell32.dll'
30611568.584: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
30621568.584: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
30631568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaffd20000 'C:\WINDOWS\system32\shell32.dll'
30641568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaffd20000 'C:\WINDOWS\system32\shell32.dll'
30651568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaffd20000 'C:\WINDOWS\system32\shell32.dll'
30661568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaffd20000 'C:\WINDOWS\system32\shell32.dll'
30671568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaffd20000 'C:\WINDOWS\system32\shell32.dll'
30681568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaffd20000 'C:\WINDOWS\system32\shell32.dll'
30691568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaffd20000 'C:\WINDOWS\system32\shell32.dll'
30701568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaffd20000 'C:\WINDOWS\system32\shell32.dll'
30711568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaffd20000 'C:\WINDOWS\system32\shell32.dll'
30721568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaffd20000 'C:\WINDOWS\system32\shell32.dll'
30731568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaffd20000 'C:\WINDOWS\system32\shell32.dll'
30741568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaffd20000 'C:\WINDOWS\system32\shell32.dll'
30751568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaffd20000 'C:\WINDOWS\system32\shell32.dll'
30761568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaffd20000 'C:\WINDOWS\system32\shell32.dll'
30771568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaffd20000 'C:\WINDOWS\system32\shell32.dll'
30781568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaffd20000 'C:\WINDOWS\system32\shell32.dll'
30791568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaffd20000 'C:\WINDOWS\system32\shell32.dll'
30801568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaffd20000 'C:\WINDOWS\system32\shell32.dll'
30811568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaffd20000 'C:\WINDOWS\system32\shell32.dll'
30821568.584: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaffd20000 'C:\WINDOWS\system32\shell32.dll'
30831568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffae1560000 'C:\WINDOWS\System32\wdmaud.drv'
30841568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffae1560000 'C:\WINDOWS\System32\wdmaud.drv'
30851568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffae1560000 'C:\WINDOWS\System32\wdmaud.drv'
30861568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffae1560000 'C:\WINDOWS\System32\wdmaud.drv'
30871568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffae1560000 'C:\WINDOWS\System32\wdmaud.drv'
30881568.2428: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffae1560000 'C:\WINDOWS\System32\wdmaud.drv'
30891568.1c6c: supR3HardenedDllNotificationCallback: Unload 00007ffaf7890000 LB 0x0000d000 Z:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL [flags=0x0]
30901568.9f4: supR3HardenedDllNotificationCallback: Unload 00007ffaf79e0000 LB 0x0000b000 Z:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL [flags=0x0]
30911568.1058: supR3HardenedDllNotificationCallback: Unload 00007ffaf79f0000 LB 0x0000c000 Z:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL [flags=0x0]
30921568.2290: supR3HardenedDllNotificationCallback: Unload 00007ffaf8540000 LB 0x0000d000 Z:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL [flags=0x0]
30931568.2100: supR3HardenedDllNotificationCallback: Unload 00007ffaf8610000 LB 0x0000b000 Z:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL [flags=0x0]
30941568.2428: supR3HardenedDllNotificationCallback: Unload 00007ffae80f0000 LB 0x00019000 Z:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.DLL [flags=0x0]
30951568.2428: supR3HardenedDllNotificationCallback: Unload 00007ffaead30000 LB 0x00018000 Z:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.DLL [flags=0x0]
30961568.2428: supR3HardenedDllNotificationCallback: Unload 00007ffaee0f0000 LB 0x00018000 Z:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.DLL [flags=0x0]
30971568.2428: supR3HardenedDllNotificationCallback: Unload 00007ffaee750000 LB 0x0001f000 Z:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.DLL [flags=0x0]
30981568.2428: supR3HardenedDllNotificationCallback: Unload 00007ffae61e0000 LB 0x00041000 Z:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL [flags=0x0]
30991568.2428: supR3HardenedDllNotificationCallback: Unload 00007ffac5d90000 LB 0x009bf000 Z:\Program Files\Oracle\VirtualBox\VBoxDD.DLL [flags=0x0]
31001568.2428: supR3HardenedDllNotificationCallback: Unload 00007ffaee770000 LB 0x00063000 Z:\Program Files\Oracle\VirtualBox\VBoxDDU.dll [flags=0x0]
31011568.2428: supR3HardenedDllNotificationCallback: Unload 00007ffaf3a20000 LB 0x0005d000 Z:\Program Files\Oracle\VirtualBox\VBoxDD2.dll [flags=0x0]
31021568.584: supR3HardenedDllNotificationCallback: Unload 00007ffaf8650000 LB 0x0000e000 Z:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMainVM.DLL [flags=0x0]
31031568.584: supR3HardenedDllNotificationCallback: Unload 00007ffae9b70000 LB 0x00014000 C:\WINDOWS\system32\wbem\wbemsvc.dll [flags=0x0]
31041568.584: supR3HardenedDllNotificationCallback: Unload 00007ffae9d30000 LB 0x000f0000 C:\WINDOWS\system32\wbem\fastprox.dll [flags=0x0]
31051568.584: supR3HardenedDllNotificationCallback: Unload 00007ffaf0c60000 LB 0x0000f000 C:\WINDOWS\system32\wbem\wbemprox.dll [flags=0x0]
31061568.584: supR3HardenedDllNotificationCallback: Unload 00007ffaf0db0000 LB 0x00081000 C:\WINDOWS\SYSTEM32\wbemcomn.dll [flags=0x0]
31071568.584: Terminating the normal way: rcExit=0
3108fb4.1394: supR3HardNtChildWaitFor[2]: Quitting: ExitCode=0x0 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 303261839 ms, the end);
31092350.87c: supR3HardNtChildWaitFor[1]: Quitting: ExitCode=0x0 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 303262203 ms, the end);

© 2024 Oracle Support Privacy / Do Not Sell My Info Terms of Use Trademark Policy Automated Access Etiquette