VirtualBox

Ticket #17657: VBoxHardening.log

File VBoxHardening.log, 238.4 KB (added by aanbar, 6 years ago)

Log File

Line 
14e4.2630: Log file opened: 5.2.8r121009 g_hStartupLog=0000000000000014 g_uNtVerCombined=0x611db110
24e4.2630: \SystemRoot\System32\ntdll.dll:
34e4.2630: CreationTime: 2017-08-14T17:14:44.340157000Z
44e4.2630: LastWriteTime: 2016-01-22T06:24:12.217581500Z
54e4.2630: ChangeTime: 2017-08-15T14:19:38.552447400Z
64e4.2630: FileAttributes: 0x20
74e4.2630: Size: 0x1a73d8
84e4.2630: NT Headers: 0xe0
94e4.2630: Timestamp: 0x56a1c9c5
104e4.2630: Machine: 0x8664 - amd64
114e4.2630: Timestamp: 0x56a1c9c5
124e4.2630: Image Version: 6.1
134e4.2630: SizeOfImage: 0x1aa000 (1744896)
144e4.2630: Resource Dir: 0x14e000 LB 0x5a028
154e4.2630: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
164e4.2630: [Raw version resource data: 0x14e0f0 LB 0x380, codepage 0x0 (reserved 0x0)]
174e4.2630: ProductName: Microsoft® Windows® Operating System
184e4.2630: ProductVersion: 6.1.7601.19135
194e4.2630: FileVersion: 6.1.7601.19135 (win7sp1_gdr.160121-1718)
204e4.2630: FileDescription: NT Layer DLL
214e4.2630: \SystemRoot\System32\kernel32.dll:
224e4.2630: CreationTime: 2017-08-14T17:14:42.421353600Z
234e4.2630: LastWriteTime: 2016-01-22T06:15:31.619000000Z
244e4.2630: ChangeTime: 2017-08-15T14:19:39.675649400Z
254e4.2630: FileAttributes: 0x20
264e4.2630: Size: 0x11c000
274e4.2630: NT Headers: 0xe8
284e4.2630: Timestamp: 0x56a1c9ab
294e4.2630: Machine: 0x8664 - amd64
304e4.2630: Timestamp: 0x56a1c9ab
314e4.2630: Image Version: 6.1
324e4.2630: SizeOfImage: 0x11f000 (1175552)
334e4.2630: Resource Dir: 0x116000 LB 0x528
344e4.2630: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
354e4.2630: [Raw version resource data: 0x1160b0 LB 0x3a4, codepage 0x0 (reserved 0x0)]
364e4.2630: ProductName: Microsoft® Windows® Operating System
374e4.2630: ProductVersion: 6.1.7601.19135
384e4.2630: FileVersion: 6.1.7601.19135 (win7sp1_gdr.160121-1718)
394e4.2630: FileDescription: Windows NT BASE API Client DLL
404e4.2630: \SystemRoot\System32\KernelBase.dll:
414e4.2630: CreationTime: 2017-08-14T17:14:42.296553400Z
424e4.2630: LastWriteTime: 2016-01-22T06:15:31.822000000Z
434e4.2630: ChangeTime: 2017-08-15T14:19:39.691249400Z
444e4.2630: FileAttributes: 0x20
454e4.2630: Size: 0x67200
464e4.2630: NT Headers: 0xe8
474e4.2630: Timestamp: 0x56a1c9ac
484e4.2630: Machine: 0x8664 - amd64
494e4.2630: Timestamp: 0x56a1c9ac
504e4.2630: Image Version: 6.1
514e4.2630: SizeOfImage: 0x6b000 (438272)
524e4.2630: Resource Dir: 0x69000 LB 0x530
534e4.2630: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
544e4.2630: [Raw version resource data: 0x690b0 LB 0x3ac, codepage 0x0 (reserved 0x0)]
554e4.2630: ProductName: Microsoft® Windows® Operating System
564e4.2630: ProductVersion: 6.1.7601.19135
574e4.2630: FileVersion: 6.1.7601.19135 (win7sp1_gdr.160121-1718)
584e4.2630: FileDescription: Windows NT BASE API Client DLL
594e4.2630: \SystemRoot\System32\apisetschema.dll:
604e4.2630: CreationTime: 2017-08-14T17:14:40.192149700Z
614e4.2630: LastWriteTime: 2016-01-22T06:12:25.181000000Z
624e4.2630: ChangeTime: 2017-08-15T14:19:38.474447300Z
634e4.2630: FileAttributes: 0x20
644e4.2630: Size: 0x1a00
654e4.2630: NT Headers: 0xc0
664e4.2630: Timestamp: 0x56a1c890
674e4.2630: Machine: 0x8664 - amd64
684e4.2630: Timestamp: 0x56a1c890
694e4.2630: Image Version: 6.1
704e4.2630: SizeOfImage: 0x50000 (327680)
714e4.2630: Resource Dir: 0x30000 LB 0x3f8
724e4.2630: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
734e4.2630: [Raw version resource data: 0x30060 LB 0x398, codepage 0x0 (reserved 0x0)]
744e4.2630: ProductName: Microsoft® Windows® Operating System
754e4.2630: ProductVersion: 6.1.7601.19135
764e4.2630: FileVersion: 6.1.7601.19135 (win7sp1_gdr.160121-1718)
774e4.2630: FileDescription: ApiSet Schema DLL
784e4.2630: Found driver klkbdflt (0x40)
794e4.2630: Found driver klmouflt (0x40)
804e4.2630: Found driver KLIM6 (0x40)
814e4.2630: Found driver kl1 (0x40)
824e4.2630: Found driver klflt (0x40)
834e4.2630: Found driver kneps (0x40)
844e4.2630: Found driver kltdi (0x40)
854e4.2630: supR3HardenedWinFindAdversaries: 0x40
864e4.2630: \SystemRoot\System32\drivers\kl1.sys:
874e4.2630: CreationTime: 2016-09-30T23:26:00.000000000Z
884e4.2630: LastWriteTime: 2016-09-30T23:26:00.000000000Z
894e4.2630: ChangeTime: 2017-08-14T17:05:02.334784600Z
904e4.2630: FileAttributes: 0x20
914e4.2630: Size: 0x875a8
924e4.2630: NT Headers: 0xe8
934e4.2630: Timestamp: 0x56fe83ac
944e4.2630: Machine: 0x8664 - amd64
954e4.2630: Timestamp: 0x56fe83ac
964e4.2630: Image Version: 0.0
974e4.2630: SizeOfImage: 0x709000 (7376896)
984e4.2630: Resource Dir: 0x707000 LB 0x448
994e4.2630: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x419)]
1004e4.2630: [Raw version resource data: 0x707060 LB 0x3e4, codepage 0x0 (reserved 0x0)]
1014e4.2630: ProductName: Kaspersky Anti-Virus
1024e4.2630: ProductVersion: 6.0.1.990
1034e4.2630: FileVersion: 6.8.0.67
1044e4.2630: FileDescription: Kaspersky Unified Driver
1054e4.2630: \SystemRoot\System32\drivers\klflt.sys:
1064e4.2630: CreationTime: 2017-08-14T17:04:42.007949100Z
1074e4.2630: LastWriteTime: 2017-10-15T12:48:48.677255100Z
1084e4.2630: ChangeTime: 2017-10-15T12:50:31.265122800Z
1094e4.2630: FileAttributes: 0x20
1104e4.2630: Size: 0x324d8
1114e4.2630: NT Headers: 0xf8
1124e4.2630: Timestamp: 0x596f4b46
1134e4.2630: Machine: 0x8664 - amd64
1144e4.2630: Timestamp: 0x596f4b46
1154e4.2630: Image Version: 6.0
1164e4.2630: SizeOfImage: 0x3e000 (253952)
1174e4.2630: Resource Dir: 0x3c000 LB 0x418
1184e4.2630: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
1194e4.2630: [Raw version resource data: 0x3c060 LB 0x3b4, codepage 0x0 (reserved 0x0)]
1204e4.2630: ProductName: System Interceptors PDK
1214e4.2630: ProductVersion: 13.0.56.0
1224e4.2630: FileVersion: 13.0.56.0
1234e4.2630: FileDescription: Filter Core [fre_wlh_x64]
1244e4.2630: \SystemRoot\System32\drivers\klif.sys:
1254e4.2630: CreationTime: 2017-08-14T17:04:42.023549200Z
1264e4.2630: LastWriteTime: 2018-02-21T13:22:36.506612300Z
1274e4.2630: ChangeTime: 2018-02-21T13:22:40.842860400Z
1284e4.2630: FileAttributes: 0x20
1294e4.2630: Size: 0x105ec8
1304e4.2630: NT Headers: 0x118
1314e4.2630: Timestamp: 0x5a6b1fa1
1324e4.2630: Machine: 0x8664 - amd64
1334e4.2630: Timestamp: 0x5a6b1fa1
1344e4.2630: Image Version: 6.0
1354e4.2630: SizeOfImage: 0x10d000 (1101824)
1364e4.2630: Resource Dir: 0x109000 LB 0x2230
1374e4.2630: [Version info resource found at 0x150! (ID/Name: 0x1; SubID/SubName: 0x409)]
1384e4.2630: [Raw version resource data: 0x109618 LB 0x3d8, codepage 0x0 (reserved 0x0)]
1394e4.2630: ProductName: System Interceptors PDK
1404e4.2630: ProductVersion: 13.0.349.0
1414e4.2630: FileVersion: 13.0.349.0
1424e4.2630: FileDescription: Core System Interceptors [fre_wlh_x64]
1434e4.2630: \SystemRoot\System32\drivers\klim6.sys:
1444e4.2630: CreationTime: 2016-10-11T11:14:28.000000000Z
1454e4.2630: LastWriteTime: 2018-02-21T13:22:36.699623400Z
1464e4.2630: ChangeTime: 2018-02-21T13:22:40.852860900Z
1474e4.2630: FileAttributes: 0x20
1484e4.2630: Size: 0xdec0
1494e4.2630: NT Headers: 0x100
1504e4.2630: Timestamp: 0x5a5f21e8
1514e4.2630: Machine: 0x8664 - amd64
1524e4.2630: Timestamp: 0x5a5f21e8
1534e4.2630: Image Version: 6.0
1544e4.2630: SizeOfImage: 0xc000 (49152)
1554e4.2630: Resource Dir: 0xa000 LB 0x428
1564e4.2630: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
1574e4.2630: [Raw version resource data: 0xa060 LB 0x3c8, codepage 0x0 (reserved 0x0)]
1584e4.2630: ProductName: System Interceptors PDK
1594e4.2630: ProductVersion: 14.0.0.16
1604e4.2630: FileVersion: 14.0.0.16
1614e4.2630: FileDescription: Packet Network Filter [fre_wlh_x64]
1624e4.2630: \SystemRoot\System32\drivers\klkbdflt.sys:
1634e4.2630: CreationTime: 2016-12-23T06:19:30.000000000Z
1644e4.2630: LastWriteTime: 2016-12-23T06:19:30.000000000Z
1654e4.2630: ChangeTime: 2017-08-14T17:05:02.693585200Z
1664e4.2630: FileAttributes: 0x20
1674e4.2630: Size: 0xe0e0
1684e4.2630: NT Headers: 0xf8
1694e4.2630: Timestamp: 0x5859ab81
1704e4.2630: Machine: 0x8664 - amd64
1714e4.2630: Timestamp: 0x5859ab81
1724e4.2630: Image Version: 6.0
1734e4.2630: SizeOfImage: 0xe000 (57344)
1744e4.2630: Resource Dir: 0xc000 LB 0x438
1754e4.2630: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
1764e4.2630: [Raw version resource data: 0xc060 LB 0x3d4, codepage 0x0 (reserved 0x0)]
1774e4.2630: ProductName: System Interceptors PDK
1784e4.2630: ProductVersion: 13.0.0.8
1794e4.2630: FileVersion: 13.0.0.8
1804e4.2630: FileDescription: Keyboard Device Filter [fre_wlh_x64]
1814e4.2630: \SystemRoot\System32\drivers\klmouflt.sys:
1824e4.2630: CreationTime: 2016-12-07T06:38:46.000000000Z
1834e4.2630: LastWriteTime: 2016-12-07T06:38:46.000000000Z
1844e4.2630: ChangeTime: 2017-08-14T17:05:02.568785000Z
1854e4.2630: FileAttributes: 0x20
1864e4.2630: Size: 0xe4e0
1874e4.2630: NT Headers: 0xf8
1884e4.2630: Timestamp: 0x583e86c3
1894e4.2630: Machine: 0x8664 - amd64
1904e4.2630: Timestamp: 0x583e86c3
1914e4.2630: Image Version: 6.0
1924e4.2630: SizeOfImage: 0xf000 (61440)
1934e4.2630: Resource Dir: 0xd000 LB 0x430
1944e4.2630: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
1954e4.2630: [Raw version resource data: 0xd060 LB 0x3cc, codepage 0x0 (reserved 0x0)]
1964e4.2630: ProductName: System Interceptors PDK
1974e4.2630: ProductVersion: 13.0.0.5
1984e4.2630: FileVersion: 13.0.0.5
1994e4.2630: FileDescription: Mouse Device Filter [fre_wlh_x64]
2004e4.2630: \SystemRoot\System32\drivers\kltdi.sys:
2014e4.2630: CreationTime: 2017-06-20T11:32:46.000000000Z
2024e4.2630: LastWriteTime: 2017-06-20T11:32:46.000000000Z
2034e4.2630: ChangeTime: 2017-08-14T17:05:03.083585900Z
2044e4.2630: FileAttributes: 0x20
2054e4.2630: Size: 0x13ff0
2064e4.2630: NT Headers: 0xf0
2074e4.2630: Timestamp: 0x58bd327c
2084e4.2630: Machine: 0x8664 - amd64
2094e4.2630: Timestamp: 0x58bd327c
2104e4.2630: Image Version: 5.2
2114e4.2630: SizeOfImage: 0x12000 (73728)
2124e4.2630: Resource Dir: 0x10000 LB 0x430
2134e4.2630: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
2144e4.2630: [Raw version resource data: 0x10060 LB 0x3cc, codepage 0x0 (reserved 0x0)]
2154e4.2630: ProductName: System Interceptors PDK
2164e4.2630: ProductVersion: 13.0.0.12
2174e4.2630: FileVersion: 13.0.0.12
2184e4.2630: FileDescription: Legacy Network Filter [fre_wnet_x64]
2194e4.2630: \SystemRoot\System32\drivers\kneps.sys:
2204e4.2630: CreationTime: 2017-06-20T11:32:46.000000000Z
2214e4.2630: LastWriteTime: 2017-12-14T16:33:26.144749900Z
2224e4.2630: ChangeTime: 2017-12-14T16:33:29.624949000Z
2234e4.2630: FileAttributes: 0x20
2244e4.2630: Size: 0x30ae0
2254e4.2630: NT Headers: 0x110
2264e4.2630: Timestamp: 0x5a0e923b
2274e4.2630: Machine: 0x8664 - amd64
2284e4.2630: Timestamp: 0x5a0e923b
2294e4.2630: Image Version: 5.2
2304e4.2630: SizeOfImage: 0x2d000 (184320)
2314e4.2630: Resource Dir: 0x2b000 LB 0x428
2324e4.2630: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
2334e4.2630: [Raw version resource data: 0x2b060 LB 0x3c4, codepage 0x0 (reserved 0x0)]
2344e4.2630: ProductName: System Interceptors PDK
2354e4.2630: ProductVersion: 13.0.0.40
2364e4.2630: FileVersion: 13.0.0.40
2374e4.2630: FileDescription: Network Processor [fre_wnet_x64]
2384e4.2630: \SystemRoot\System32\klfphc.dll:
2394e4.2630: CreationTime: 2017-08-14T17:05:02.287984500Z
2404e4.2630: LastWriteTime: 2013-05-06T05:13:26.000000000Z
2414e4.2630: ChangeTime: 2017-08-14T17:04:53.863969800Z
2424e4.2630: FileAttributes: 0x20
2434e4.2630: Size: 0x1ae60
2444e4.2630: NT Headers: 0xe8
2454e4.2630: Timestamp: 0x51873bf2
2464e4.2630: Machine: 0x8664 - amd64
2474e4.2630: Timestamp: 0x51873bf2
2484e4.2630: Image Version: 0.0
2494e4.2630: SizeOfImage: 0x1d000 (118784)
2504e4.2630: Resource Dir: 0x18000 LB 0x3c80
2514e4.2630: [Version info resource found at 0x188! (ID/Name: 0x1; SubID/SubName: 0x409)]
2524e4.2630: [Raw version resource data: 0x1b800 LB 0x324, codepage 0x4e4 (reserved 0x0)]
2534e4.2630: ProductName: Kaspersky™ Anti-Virus ®
2544e4.2630: ProductVersion: 1.0.0.12
2554e4.2630: FileVersion: 1.0.0.12
2564e4.2630: FileDescription: Filtering Platform Helper Class
2574e4.2630: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
2584e4.2630: Calling main()
2594e4.2630: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
2604e4.2630: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
2614e4.2630: SUPR3HardenedMain: Respawn #1
2624e4.2630: System32: \Device\HarddiskVolume2\Windows\System32
2634e4.2630: WinSxS: \Device\HarddiskVolume2\Windows\winsxs
2644e4.2630: KnownDllPath: C:\Windows\system32
2654e4.2630: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
2664e4.2630: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe)
2674e4.2630: supR3HardNtEnableThreadCreation:
2684e4.2630: supR3HardNtDisableThreadCreation: pvLdrInitThunk=000000007760b170 pvNtTerminateThread=000000007762d8e0
2694e4.2630: supR3HardenedWinDoReSpawn(1): New child 1c4c.1fcc [kernel32].
2704e4.2630: supR3HardNtChildGatherData: PebBaseAddress=000007fffffda000 cbPeb=0x380
2714e4.2630: supR3HardNtPuChFindNtdll: uNtDllParentAddr=00000000775e0000 uNtDllChildAddr=00000000775e0000
2724e4.2630: supR3HardenedWinSetupChildInit: uLdrInitThunk=000000007760b170
2734e4.2630: supR3HardenedWinSetupChildInit: Start child.
2744e4.2630: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
2754e4.2630: supR3HardNtChildPurify: Startup delay kludge #1/0: 520 ms, 65 sleeps
2764e4.2630: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
2774e4.2630: *0000000000000000-000000000000ffff 0x0001/0x0000 0x0000000
2784e4.2630: *0000000000010000-000000000002ffff 0x0004/0x0004 0x0020000
2794e4.2630: *0000000000030000-0000000000033fff 0x0002/0x0002 0x0040000
2804e4.2630: 0000000000034000-000000000003ffff 0x0001/0x0000 0x0000000
2814e4.2630: *0000000000040000-0000000000040fff 0x0004/0x0004 0x0020000
2824e4.2630: 0000000000041000-000000000012ffff 0x0001/0x0000 0x0000000
2834e4.2630: *0000000000130000-000000000022bfff 0x0000/0x0004 0x0020000
2844e4.2630: 000000000022c000-000000000022dfff 0x0104/0x0004 0x0020000
2854e4.2630: 000000000022e000-000000000022ffff 0x0004/0x0004 0x0020000
2864e4.2630: 0000000000230000-00000000775dffff 0x0001/0x0000 0x0000000
2874e4.2630: *00000000775e0000-00000000775e0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
2884e4.2630: 00000000775e1000-00000000776dffff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
2894e4.2630: 00000000776e0000-000000007770efff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
2904e4.2630: 000000007770f000-0000000077716fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
2914e4.2630: 0000000077717000-0000000077717fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
2924e4.2630: 0000000077718000-000000007771afff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
2934e4.2630: 000000007771b000-0000000077789fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
2944e4.2630: 000000007778a000-000000007efdffff 0x0001/0x0000 0x0000000
2954e4.2630: *000000007efe0000-000000007ffdffff 0x0000/0x0002 0x0020000
2964e4.2630: *000000007ffe0000-000000007ffe0fff 0x0002/0x0002 0x0020000
2974e4.2630: 000000007ffe1000-000000007ffeffff 0x0000/0x0002 0x0020000
2984e4.2630: 000000007fff0000-000000013f2dffff 0x0001/0x0000 0x0000000
2994e4.2630: *000000013f2e0000-000000013f2e0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
3004e4.2630: 000000013f2e1000-000000013f351fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
3014e4.2630: 000000013f352000-000000013f352fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
3024e4.2630: 000000013f353000-000000013f398fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
3034e4.2630: 000000013f399000-000000013f399fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
3044e4.2630: 000000013f39a000-000000013f39afff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
3054e4.2630: 000000013f39b000-000000013f39ffff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
3064e4.2630: 000000013f3a0000-000000013f3a0fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
3074e4.2630: 000000013f3a1000-000000013f3a1fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
3084e4.2630: 000000013f3a2000-000000013f3a5fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
3094e4.2630: 000000013f3a6000-000000013f3edfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
3104e4.2630: 000000013f3ee000-000007feff8cffff 0x0001/0x0000 0x0000000
3114e4.2630: *000007feff8d0000-000007feff8d0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\apisetschema.dll
3124e4.2630: 000007feff8d1000-000007fffffaffff 0x0001/0x0000 0x0000000
3134e4.2630: *000007fffffb0000-000007fffffd2fff 0x0002/0x0002 0x0040000
3144e4.2630: 000007fffffd3000-000007fffffd9fff 0x0001/0x0000 0x0000000
3154e4.2630: *000007fffffda000-000007fffffdafff 0x0004/0x0004 0x0020000
3164e4.2630: 000007fffffdb000-000007fffffddfff 0x0001/0x0000 0x0000000
3174e4.2630: *000007fffffde000-000007fffffdffff 0x0004/0x0004 0x0020000
3184e4.2630: *000007fffffe0000-000007fffffeffff 0x0001/0x0002 0x0020000
3194e4.2630: apisetschema.dll: timestamp 0x56a1c890 (rc=VINF_SUCCESS)
3204e4.2630: VirtualBox.exe: timestamp 0x5a942b95 (rc=VINF_SUCCESS)
3214e4.2630: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
3224e4.2630: '\Device\HarddiskVolume2\Windows\System32\apisetschema.dll' has no imports
3234e4.2630: '\Device\HarddiskVolume2\Windows\System32\ntdll.dll' has no imports
3244e4.2630: supR3HardNtChildPurify: Done after 574 ms and 0 fixes (loop #0).
3251c4c.1fcc: Log file opened: 5.2.8r121009 g_hStartupLog=0000000000000004 g_uNtVerCombined=0x611db100
3261c4c.1fcc: supR3HardenedVmProcessInit: uNtDllAddr=00000000775e0000 g_uNtVerCombined=0x611db100
3271c4c.1fcc: ntdll.dll: timestamp 0x56a1c9c5 (rc=VINF_SUCCESS)
3281c4c.1fcc: New simple heap: #1 0000000000330000 LB 0x400000 (for 1744896 allocation)
3294e4.2630: supR3HardNtEnableThreadCreation:
3301c4c.1fcc: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
3311c4c.1fcc: System32: \Device\HarddiskVolume2\Windows\System32
3321c4c.1fcc: WinSxS: \Device\HarddiskVolume2\Windows\winsxs
3331c4c.1fcc: KnownDllPath: C:\Windows\system32
3341c4c.1fcc: supR3HardenedVmProcessInit: Opening vboxdrv stub...
3351c4c.1fcc: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
3361c4c.1fcc: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
3371c4c.1fcc: Registered Dll notification callback with NTDLL.
3381c4c.1fcc: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\kernel32.dll)
3391c4c.1fcc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\kernel32.dll
3401c4c.1fcc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
3411c4c.1fcc: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
3421c4c.1fcc: supR3HardenedDllNotificationCallback: load 00000000773c0000 LB 0x0011f000 C:\Windows\system32\kernel32.dll [fFlags=0x0]
3431c4c.1fcc: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
3441c4c.1fcc: supR3HardenedDllNotificationCallback: load 000007fefd5f0000 LB 0x0006b000 C:\Windows\system32\KERNELBASE.dll [fFlags=0x0]
3451c4c.1fcc: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\KernelBase.dll)
3461c4c.1fcc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\KernelBase.dll
3471c4c.1fcc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00000000773c0000 'C:\Windows\system32\kernel32.dll'
3481c4c.1fcc: supR3HardNtDisableThreadCreation: pvLdrInitThunk=000000007760b170 pvNtTerminateThread=000000007762d8e0
3494e4.2630: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 33 ms.
3501c4c.1fcc: \SystemRoot\System32\ntdll.dll:
3511c4c.1fcc: CreationTime: 2017-08-14T17:14:44.340157000Z
3521c4c.1fcc: LastWriteTime: 2016-01-22T06:24:12.217581500Z
3531c4c.1fcc: ChangeTime: 2017-08-15T14:19:38.552447400Z
3541c4c.1fcc: FileAttributes: 0x20
3551c4c.1fcc: Size: 0x1a73d8
3561c4c.1fcc: NT Headers: 0xe0
3571c4c.1fcc: Timestamp: 0x56a1c9c5
3581c4c.1fcc: Machine: 0x8664 - amd64
3591c4c.1fcc: Timestamp: 0x56a1c9c5
3601c4c.1fcc: Image Version: 6.1
3611c4c.1fcc: SizeOfImage: 0x1aa000 (1744896)
3621c4c.1fcc: Resource Dir: 0x14e000 LB 0x5a028
3631c4c.1fcc: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
3641c4c.1fcc: [Raw version resource data: 0x14e0f0 LB 0x380, codepage 0x0 (reserved 0x0)]
3651c4c.1fcc: ProductName: Microsoft® Windows® Operating System
3661c4c.1fcc: ProductVersion: 6.1.7601.19135
3671c4c.1fcc: FileVersion: 6.1.7601.19135 (win7sp1_gdr.160121-1718)
3681c4c.1fcc: FileDescription: NT Layer DLL
3691c4c.1fcc: \SystemRoot\System32\kernel32.dll:
3701c4c.1fcc: CreationTime: 2017-08-14T17:14:42.421353600Z
3711c4c.1fcc: LastWriteTime: 2016-01-22T06:15:31.619000000Z
3721c4c.1fcc: ChangeTime: 2017-08-15T14:19:39.675649400Z
3731c4c.1fcc: FileAttributes: 0x20
3741c4c.1fcc: Size: 0x11c000
3751c4c.1fcc: NT Headers: 0xe8
3761c4c.1fcc: Timestamp: 0x56a1c9ab
3771c4c.1fcc: Machine: 0x8664 - amd64
3781c4c.1fcc: Timestamp: 0x56a1c9ab
3791c4c.1fcc: Image Version: 6.1
3801c4c.1fcc: SizeOfImage: 0x11f000 (1175552)
3811c4c.1fcc: Resource Dir: 0x116000 LB 0x528
3821c4c.1fcc: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
3831c4c.1fcc: [Raw version resource data: 0x1160b0 LB 0x3a4, codepage 0x0 (reserved 0x0)]
3841c4c.1fcc: ProductName: Microsoft® Windows® Operating System
3851c4c.1fcc: ProductVersion: 6.1.7601.19135
3861c4c.1fcc: FileVersion: 6.1.7601.19135 (win7sp1_gdr.160121-1718)
3871c4c.1fcc: FileDescription: Windows NT BASE API Client DLL
3881c4c.1fcc: \SystemRoot\System32\KernelBase.dll:
3891c4c.1fcc: CreationTime: 2017-08-14T17:14:42.296553400Z
3901c4c.1fcc: LastWriteTime: 2016-01-22T06:15:31.822000000Z
3911c4c.1fcc: ChangeTime: 2017-08-15T14:19:39.691249400Z
3921c4c.1fcc: FileAttributes: 0x20
3931c4c.1fcc: Size: 0x67200
3941c4c.1fcc: NT Headers: 0xe8
3951c4c.1fcc: Timestamp: 0x56a1c9ac
3961c4c.1fcc: Machine: 0x8664 - amd64
3971c4c.1fcc: Timestamp: 0x56a1c9ac
3981c4c.1fcc: Image Version: 6.1
3991c4c.1fcc: SizeOfImage: 0x6b000 (438272)
4001c4c.1fcc: Resource Dir: 0x69000 LB 0x530
4011c4c.1fcc: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
4021c4c.1fcc: [Raw version resource data: 0x690b0 LB 0x3ac, codepage 0x0 (reserved 0x0)]
4031c4c.1fcc: ProductName: Microsoft® Windows® Operating System
4041c4c.1fcc: ProductVersion: 6.1.7601.19135
4051c4c.1fcc: FileVersion: 6.1.7601.19135 (win7sp1_gdr.160121-1718)
4061c4c.1fcc: FileDescription: Windows NT BASE API Client DLL
4071c4c.1fcc: \SystemRoot\System32\apisetschema.dll:
4081c4c.1fcc: CreationTime: 2017-08-14T17:14:40.192149700Z
4091c4c.1fcc: LastWriteTime: 2016-01-22T06:12:25.181000000Z
4101c4c.1fcc: ChangeTime: 2017-08-15T14:19:38.474447300Z
4111c4c.1fcc: FileAttributes: 0x20
4121c4c.1fcc: Size: 0x1a00
4131c4c.1fcc: NT Headers: 0xc0
4141c4c.1fcc: Timestamp: 0x56a1c890
4151c4c.1fcc: Machine: 0x8664 - amd64
4161c4c.1fcc: Timestamp: 0x56a1c890
4171c4c.1fcc: Image Version: 6.1
4181c4c.1fcc: SizeOfImage: 0x50000 (327680)
4191c4c.1fcc: Resource Dir: 0x30000 LB 0x3f8
4201c4c.1fcc: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
4211c4c.1fcc: [Raw version resource data: 0x30060 LB 0x398, codepage 0x0 (reserved 0x0)]
4221c4c.1fcc: ProductName: Microsoft® Windows® Operating System
4231c4c.1fcc: ProductVersion: 6.1.7601.19135
4241c4c.1fcc: FileVersion: 6.1.7601.19135 (win7sp1_gdr.160121-1718)
4251c4c.1fcc: FileDescription: ApiSet Schema DLL
4261c4c.1fcc: Found driver klkbdflt (0x40)
4271c4c.1fcc: Found driver klmouflt (0x40)
4281c4c.1fcc: Found driver KLIM6 (0x40)
4291c4c.1fcc: Found driver kl1 (0x40)
4301c4c.1fcc: Found driver klflt (0x40)
4311c4c.1fcc: Found driver kneps (0x40)
4321c4c.1fcc: Found driver kltdi (0x40)
4331c4c.1fcc: supR3HardenedWinFindAdversaries: 0x40
4341c4c.1fcc: \SystemRoot\System32\drivers\kl1.sys:
4351c4c.1fcc: CreationTime: 2016-09-30T23:26:00.000000000Z
4361c4c.1fcc: LastWriteTime: 2016-09-30T23:26:00.000000000Z
4371c4c.1fcc: ChangeTime: 2017-08-14T17:05:02.334784600Z
4381c4c.1fcc: FileAttributes: 0x20
4391c4c.1fcc: Size: 0x875a8
4401c4c.1fcc: NT Headers: 0xe8
4411c4c.1fcc: Timestamp: 0x56fe83ac
4421c4c.1fcc: Machine: 0x8664 - amd64
4431c4c.1fcc: Timestamp: 0x56fe83ac
4441c4c.1fcc: Image Version: 0.0
4451c4c.1fcc: SizeOfImage: 0x709000 (7376896)
4461c4c.1fcc: Resource Dir: 0x707000 LB 0x448
4471c4c.1fcc: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x419)]
4481c4c.1fcc: [Raw version resource data: 0x707060 LB 0x3e4, codepage 0x0 (reserved 0x0)]
4491c4c.1fcc: ProductName: Kaspersky Anti-Virus
4501c4c.1fcc: ProductVersion: 6.0.1.990
4511c4c.1fcc: FileVersion: 6.8.0.67
4521c4c.1fcc: FileDescription: Kaspersky Unified Driver
4531c4c.1fcc: \SystemRoot\System32\drivers\klflt.sys:
4541c4c.1fcc: CreationTime: 2017-08-14T17:04:42.007949100Z
4551c4c.1fcc: LastWriteTime: 2017-10-15T12:48:48.677255100Z
4561c4c.1fcc: ChangeTime: 2017-10-15T12:50:31.265122800Z
4571c4c.1fcc: FileAttributes: 0x20
4581c4c.1fcc: Size: 0x324d8
4591c4c.1fcc: NT Headers: 0xf8
4601c4c.1fcc: Timestamp: 0x596f4b46
4611c4c.1fcc: Machine: 0x8664 - amd64
4621c4c.1fcc: Timestamp: 0x596f4b46
4631c4c.1fcc: Image Version: 6.0
4641c4c.1fcc: SizeOfImage: 0x3e000 (253952)
4651c4c.1fcc: Resource Dir: 0x3c000 LB 0x418
4661c4c.1fcc: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
4671c4c.1fcc: [Raw version resource data: 0x3c060 LB 0x3b4, codepage 0x0 (reserved 0x0)]
4681c4c.1fcc: ProductName: System Interceptors PDK
4691c4c.1fcc: ProductVersion: 13.0.56.0
4701c4c.1fcc: FileVersion: 13.0.56.0
4711c4c.1fcc: FileDescription: Filter Core [fre_wlh_x64]
4721c4c.1fcc: \SystemRoot\System32\drivers\klif.sys:
4731c4c.1fcc: CreationTime: 2017-08-14T17:04:42.023549200Z
4741c4c.1fcc: LastWriteTime: 2018-02-21T13:22:36.506612300Z
4751c4c.1fcc: ChangeTime: 2018-02-21T13:22:40.842860400Z
4761c4c.1fcc: FileAttributes: 0x20
4771c4c.1fcc: Size: 0x105ec8
4781c4c.1fcc: NT Headers: 0x118
4791c4c.1fcc: Timestamp: 0x5a6b1fa1
4801c4c.1fcc: Machine: 0x8664 - amd64
4811c4c.1fcc: Timestamp: 0x5a6b1fa1
4821c4c.1fcc: Image Version: 6.0
4831c4c.1fcc: SizeOfImage: 0x10d000 (1101824)
4841c4c.1fcc: Resource Dir: 0x109000 LB 0x2230
4851c4c.1fcc: [Version info resource found at 0x150! (ID/Name: 0x1; SubID/SubName: 0x409)]
4861c4c.1fcc: [Raw version resource data: 0x109618 LB 0x3d8, codepage 0x0 (reserved 0x0)]
4871c4c.1fcc: ProductName: System Interceptors PDK
4881c4c.1fcc: ProductVersion: 13.0.349.0
4891c4c.1fcc: FileVersion: 13.0.349.0
4901c4c.1fcc: FileDescription: Core System Interceptors [fre_wlh_x64]
4911c4c.1fcc: \SystemRoot\System32\drivers\klim6.sys:
4921c4c.1fcc: CreationTime: 2016-10-11T11:14:28.000000000Z
4931c4c.1fcc: LastWriteTime: 2018-02-21T13:22:36.699623400Z
4941c4c.1fcc: ChangeTime: 2018-02-21T13:22:40.852860900Z
4951c4c.1fcc: FileAttributes: 0x20
4961c4c.1fcc: Size: 0xdec0
4971c4c.1fcc: NT Headers: 0x100
4981c4c.1fcc: Timestamp: 0x5a5f21e8
4991c4c.1fcc: Machine: 0x8664 - amd64
5001c4c.1fcc: Timestamp: 0x5a5f21e8
5011c4c.1fcc: Image Version: 6.0
5021c4c.1fcc: SizeOfImage: 0xc000 (49152)
5031c4c.1fcc: Resource Dir: 0xa000 LB 0x428
5041c4c.1fcc: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
5051c4c.1fcc: [Raw version resource data: 0xa060 LB 0x3c8, codepage 0x0 (reserved 0x0)]
5061c4c.1fcc: ProductName: System Interceptors PDK
5071c4c.1fcc: ProductVersion: 14.0.0.16
5081c4c.1fcc: FileVersion: 14.0.0.16
5091c4c.1fcc: FileDescription: Packet Network Filter [fre_wlh_x64]
5101c4c.1fcc: \SystemRoot\System32\drivers\klkbdflt.sys:
5111c4c.1fcc: CreationTime: 2016-12-23T06:19:30.000000000Z
5121c4c.1fcc: LastWriteTime: 2016-12-23T06:19:30.000000000Z
5131c4c.1fcc: ChangeTime: 2017-08-14T17:05:02.693585200Z
5141c4c.1fcc: FileAttributes: 0x20
5151c4c.1fcc: Size: 0xe0e0
5161c4c.1fcc: NT Headers: 0xf8
5171c4c.1fcc: Timestamp: 0x5859ab81
5181c4c.1fcc: Machine: 0x8664 - amd64
5191c4c.1fcc: Timestamp: 0x5859ab81
5201c4c.1fcc: Image Version: 6.0
5211c4c.1fcc: SizeOfImage: 0xe000 (57344)
5221c4c.1fcc: Resource Dir: 0xc000 LB 0x438
5231c4c.1fcc: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
5241c4c.1fcc: [Raw version resource data: 0xc060 LB 0x3d4, codepage 0x0 (reserved 0x0)]
5251c4c.1fcc: ProductName: System Interceptors PDK
5261c4c.1fcc: ProductVersion: 13.0.0.8
5271c4c.1fcc: FileVersion: 13.0.0.8
5281c4c.1fcc: FileDescription: Keyboard Device Filter [fre_wlh_x64]
5291c4c.1fcc: \SystemRoot\System32\drivers\klmouflt.sys:
5301c4c.1fcc: CreationTime: 2016-12-07T06:38:46.000000000Z
5311c4c.1fcc: LastWriteTime: 2016-12-07T06:38:46.000000000Z
5321c4c.1fcc: ChangeTime: 2017-08-14T17:05:02.568785000Z
5331c4c.1fcc: FileAttributes: 0x20
5341c4c.1fcc: Size: 0xe4e0
5351c4c.1fcc: NT Headers: 0xf8
5361c4c.1fcc: Timestamp: 0x583e86c3
5371c4c.1fcc: Machine: 0x8664 - amd64
5381c4c.1fcc: Timestamp: 0x583e86c3
5391c4c.1fcc: Image Version: 6.0
5401c4c.1fcc: SizeOfImage: 0xf000 (61440)
5411c4c.1fcc: Resource Dir: 0xd000 LB 0x430
5421c4c.1fcc: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
5431c4c.1fcc: [Raw version resource data: 0xd060 LB 0x3cc, codepage 0x0 (reserved 0x0)]
5441c4c.1fcc: ProductName: System Interceptors PDK
5451c4c.1fcc: ProductVersion: 13.0.0.5
5461c4c.1fcc: FileVersion: 13.0.0.5
5471c4c.1fcc: FileDescription: Mouse Device Filter [fre_wlh_x64]
5481c4c.1fcc: \SystemRoot\System32\drivers\kltdi.sys:
5491c4c.1fcc: CreationTime: 2017-06-20T11:32:46.000000000Z
5501c4c.1fcc: LastWriteTime: 2017-06-20T11:32:46.000000000Z
5511c4c.1fcc: ChangeTime: 2017-08-14T17:05:03.083585900Z
5521c4c.1fcc: FileAttributes: 0x20
5531c4c.1fcc: Size: 0x13ff0
5541c4c.1fcc: NT Headers: 0xf0
5551c4c.1fcc: Timestamp: 0x58bd327c
5561c4c.1fcc: Machine: 0x8664 - amd64
5571c4c.1fcc: Timestamp: 0x58bd327c
5581c4c.1fcc: Image Version: 5.2
5591c4c.1fcc: SizeOfImage: 0x12000 (73728)
5601c4c.1fcc: Resource Dir: 0x10000 LB 0x430
5611c4c.1fcc: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
5621c4c.1fcc: [Raw version resource data: 0x10060 LB 0x3cc, codepage 0x0 (reserved 0x0)]
5631c4c.1fcc: ProductName: System Interceptors PDK
5641c4c.1fcc: ProductVersion: 13.0.0.12
5651c4c.1fcc: FileVersion: 13.0.0.12
5661c4c.1fcc: FileDescription: Legacy Network Filter [fre_wnet_x64]
5671c4c.1fcc: \SystemRoot\System32\drivers\kneps.sys:
5681c4c.1fcc: CreationTime: 2017-06-20T11:32:46.000000000Z
5691c4c.1fcc: LastWriteTime: 2017-12-14T16:33:26.144749900Z
5701c4c.1fcc: ChangeTime: 2017-12-14T16:33:29.624949000Z
5711c4c.1fcc: FileAttributes: 0x20
5721c4c.1fcc: Size: 0x30ae0
5731c4c.1fcc: NT Headers: 0x110
5741c4c.1fcc: Timestamp: 0x5a0e923b
5751c4c.1fcc: Machine: 0x8664 - amd64
5761c4c.1fcc: Timestamp: 0x5a0e923b
5771c4c.1fcc: Image Version: 5.2
5781c4c.1fcc: SizeOfImage: 0x2d000 (184320)
5791c4c.1fcc: Resource Dir: 0x2b000 LB 0x428
5801c4c.1fcc: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
5811c4c.1fcc: [Raw version resource data: 0x2b060 LB 0x3c4, codepage 0x0 (reserved 0x0)]
5821c4c.1fcc: ProductName: System Interceptors PDK
5831c4c.1fcc: ProductVersion: 13.0.0.40
5841c4c.1fcc: FileVersion: 13.0.0.40
5851c4c.1fcc: FileDescription: Network Processor [fre_wnet_x64]
5861c4c.1fcc: \SystemRoot\System32\klfphc.dll:
5871c4c.1fcc: CreationTime: 2017-08-14T17:05:02.287984500Z
5881c4c.1fcc: LastWriteTime: 2013-05-06T05:13:26.000000000Z
5891c4c.1fcc: ChangeTime: 2017-08-14T17:04:53.863969800Z
5901c4c.1fcc: FileAttributes: 0x20
5911c4c.1fcc: Size: 0x1ae60
5921c4c.1fcc: NT Headers: 0xe8
5931c4c.1fcc: Timestamp: 0x51873bf2
5941c4c.1fcc: Machine: 0x8664 - amd64
5951c4c.1fcc: Timestamp: 0x51873bf2
5961c4c.1fcc: Image Version: 0.0
5971c4c.1fcc: SizeOfImage: 0x1d000 (118784)
5981c4c.1fcc: Resource Dir: 0x18000 LB 0x3c80
5991c4c.1fcc: [Version info resource found at 0x188! (ID/Name: 0x1; SubID/SubName: 0x409)]
6001c4c.1fcc: [Raw version resource data: 0x1b800 LB 0x324, codepage 0x4e4 (reserved 0x0)]
6011c4c.1fcc: ProductName: Kaspersky™ Anti-Virus ®
6021c4c.1fcc: ProductVersion: 1.0.0.12
6031c4c.1fcc: FileVersion: 1.0.0.12
6041c4c.1fcc: FileDescription: Filtering Platform Helper Class
6051c4c.1fcc: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
6061c4c.1fcc: Calling main()
6071c4c.1fcc: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
6081c4c.1fcc: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
6091c4c.1fcc: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
6101c4c.1fcc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe)
6111c4c.1fcc: SUPR3HardenedMain: Respawn #2
6121c4c.1fcc: supR3HardNtEnableThreadCreation:
6131c4c.1fcc: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\apphelp.dll)
6141c4c.1fcc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\apphelp.dll
6151c4c.1fcc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\apphelp.dll (rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
6161c4c.1fcc: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\apphelp.dll [lacks WinVerifyTrust]
6171c4c.1fcc: supR3HardenedDllNotificationCallback: load 000007fefd3d0000 LB 0x00057000 C:\Windows\system32\apphelp.dll [fFlags=0x0]
6181c4c.1fcc: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\apphelp.dll [lacks WinVerifyTrust]
6191c4c.1fcc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd3d0000 'C:\Windows\system32\apphelp.dll'
6201c4c.1fcc: supR3HardNtDisableThreadCreation: pvLdrInitThunk=000000007760b170 pvNtTerminateThread=000000007762d8e0
6211c4c.1fcc: supR3HardenedWinDoReSpawn(2): New child 13a8.fe0 [kernel32].
6221c4c.1fcc: supR3HardNtChildGatherData: PebBaseAddress=000007fffffd5000 cbPeb=0x380
6231c4c.1fcc: supR3HardNtPuChFindNtdll: uNtDllParentAddr=00000000775e0000 uNtDllChildAddr=00000000775e0000
6241c4c.1fcc: supR3HardenedWinSetupChildInit: uLdrInitThunk=000000007760b170
6251c4c.1fcc: supR3HardenedWinSetupChildInit: Start child.
6261c4c.1fcc: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
6271c4c.1fcc: supR3HardNtChildPurify: Startup delay kludge #1/0: 520 ms, 65 sleeps
6281c4c.1fcc: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
6291c4c.1fcc: *0000000000000000-000000000000ffff 0x0001/0x0000 0x0000000
6301c4c.1fcc: *0000000000010000-000000000002ffff 0x0004/0x0004 0x0020000
6311c4c.1fcc: *0000000000030000-0000000000033fff 0x0002/0x0002 0x0040000
6321c4c.1fcc: 0000000000034000-000000000003ffff 0x0001/0x0000 0x0000000
6331c4c.1fcc: *0000000000040000-0000000000040fff 0x0004/0x0004 0x0020000
6341c4c.1fcc: 0000000000041000-000000000008ffff 0x0001/0x0000 0x0000000
6351c4c.1fcc: *0000000000090000-000000000018bfff 0x0000/0x0004 0x0020000
6361c4c.1fcc: 000000000018c000-000000000018dfff 0x0104/0x0004 0x0020000
6371c4c.1fcc: 000000000018e000-000000000018ffff 0x0004/0x0004 0x0020000
6381c4c.1fcc: 0000000000190000-00000000775dffff 0x0001/0x0000 0x0000000
6391c4c.1fcc: *00000000775e0000-00000000775e0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
6401c4c.1fcc: 00000000775e1000-00000000776dffff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
6411c4c.1fcc: 00000000776e0000-000000007770efff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
6421c4c.1fcc: 000000007770f000-0000000077716fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
6431c4c.1fcc: 0000000077717000-0000000077717fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
6441c4c.1fcc: 0000000077718000-000000007771afff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
6451c4c.1fcc: 000000007771b000-0000000077789fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
6461c4c.1fcc: 000000007778a000-000000007efdffff 0x0001/0x0000 0x0000000
6471c4c.1fcc: *000000007efe0000-000000007ffdffff 0x0000/0x0002 0x0020000
6481c4c.1fcc: *000000007ffe0000-000000007ffe0fff 0x0002/0x0002 0x0020000
6491c4c.1fcc: 000000007ffe1000-000000007ffeffff 0x0000/0x0002 0x0020000
6501c4c.1fcc: 000000007fff0000-000000013f2dffff 0x0001/0x0000 0x0000000
6511c4c.1fcc: *000000013f2e0000-000000013f2e0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
6521c4c.1fcc: 000000013f2e1000-000000013f351fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
6531c4c.1fcc: 000000013f352000-000000013f352fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
6541c4c.1fcc: 000000013f353000-000000013f398fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
6551c4c.1fcc: 000000013f399000-000000013f399fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
6561c4c.1fcc: 000000013f39a000-000000013f39afff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
6571c4c.1fcc: 000000013f39b000-000000013f39ffff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
6581c4c.1fcc: 000000013f3a0000-000000013f3a0fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
6591c4c.1fcc: 000000013f3a1000-000000013f3a1fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
6601c4c.1fcc: 000000013f3a2000-000000013f3a5fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
6611c4c.1fcc: 000000013f3a6000-000000013f3edfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
6621c4c.1fcc: 000000013f3ee000-000007feff8cffff 0x0001/0x0000 0x0000000
6631c4c.1fcc: *000007feff8d0000-000007feff8d0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\apisetschema.dll
6641c4c.1fcc: 000007feff8d1000-000007fffffaffff 0x0001/0x0000 0x0000000
6651c4c.1fcc: *000007fffffb0000-000007fffffd2fff 0x0002/0x0002 0x0040000
6661c4c.1fcc: 000007fffffd3000-000007fffffd4fff 0x0001/0x0000 0x0000000
6671c4c.1fcc: *000007fffffd5000-000007fffffd5fff 0x0004/0x0004 0x0020000
6681c4c.1fcc: 000007fffffd6000-000007fffffddfff 0x0001/0x0000 0x0000000
6691c4c.1fcc: *000007fffffde000-000007fffffdffff 0x0004/0x0004 0x0020000
6701c4c.1fcc: *000007fffffe0000-000007fffffeffff 0x0001/0x0002 0x0020000
6711c4c.1fcc: apisetschema.dll: timestamp 0x56a1c890 (rc=VINF_SUCCESS)
6721c4c.1fcc: VirtualBox.exe: timestamp 0x5a942b95 (rc=VINF_SUCCESS)
6731c4c.1fcc: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
6741c4c.1fcc: '\Device\HarddiskVolume2\Windows\System32\apisetschema.dll' has no imports
6751c4c.1fcc: '\Device\HarddiskVolume2\Windows\System32\ntdll.dll' has no imports
6761c4c.1fcc: supR3HardNtChildPurify: Done after 561 ms and 0 fixes (loop #0).
67713a8.fe0: Log file opened: 5.2.8r121009 g_hStartupLog=0000000000000004 g_uNtVerCombined=0x611db100
67813a8.fe0: supR3HardenedVmProcessInit: uNtDllAddr=00000000775e0000 g_uNtVerCombined=0x611db100
67913a8.fe0: ntdll.dll: timestamp 0x56a1c9c5 (rc=VINF_SUCCESS)
68013a8.fe0: New simple heap: #1 0000000000290000 LB 0x400000 (for 1744896 allocation)
6811c4c.1fcc: supR3HardenedEarlyCompact: Removed heap 1 (0x00000000330000 LB 0x400000)
6821c4c.1fcc: supR3HardNtEnableThreadCreation:
68313a8.fe0: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
68413a8.fe0: System32: \Device\HarddiskVolume2\Windows\System32
68513a8.fe0: WinSxS: \Device\HarddiskVolume2\Windows\winsxs
68613a8.fe0: KnownDllPath: C:\Windows\system32
68713a8.fe0: supR3HardenedVmProcessInit: Opening vboxdrv...
68813a8.fe0: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
68913a8.fe0: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
69013a8.fe0: Registered Dll notification callback with NTDLL.
69113a8.fe0: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\kernel32.dll)
69213a8.fe0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\kernel32.dll
69313a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
69413a8.fe0: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
69513a8.fe0: supR3HardenedDllNotificationCallback: load 00000000773c0000 LB 0x0011f000 C:\Windows\system32\kernel32.dll [fFlags=0x0]
69613a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
69713a8.fe0: supR3HardenedDllNotificationCallback: load 000007fefd5f0000 LB 0x0006b000 C:\Windows\system32\KERNELBASE.dll [fFlags=0x0]
69813a8.fe0: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\KernelBase.dll)
69913a8.fe0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\KernelBase.dll
70013a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00000000773c0000 'C:\Windows\system32\kernel32.dll'
70113a8.fe0: supR3HardNtDisableThreadCreation: pvLdrInitThunk=000000007760b170 pvNtTerminateThread=000000007762d8e0
7021c4c.1fcc: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 30 ms.
70313a8.fe0: \SystemRoot\System32\ntdll.dll:
70413a8.fe0: CreationTime: 2017-08-14T17:14:44.340157000Z
70513a8.fe0: LastWriteTime: 2016-01-22T06:24:12.217581500Z
70613a8.fe0: ChangeTime: 2017-08-15T14:19:38.552447400Z
70713a8.fe0: FileAttributes: 0x20
70813a8.fe0: Size: 0x1a73d8
70913a8.fe0: NT Headers: 0xe0
71013a8.fe0: Timestamp: 0x56a1c9c5
71113a8.fe0: Machine: 0x8664 - amd64
71213a8.fe0: Timestamp: 0x56a1c9c5
71313a8.fe0: Image Version: 6.1
71413a8.fe0: SizeOfImage: 0x1aa000 (1744896)
71513a8.fe0: Resource Dir: 0x14e000 LB 0x5a028
71613a8.fe0: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
71713a8.fe0: [Raw version resource data: 0x14e0f0 LB 0x380, codepage 0x0 (reserved 0x0)]
71813a8.fe0: ProductName: Microsoft® Windows® Operating System
71913a8.fe0: ProductVersion: 6.1.7601.19135
72013a8.fe0: FileVersion: 6.1.7601.19135 (win7sp1_gdr.160121-1718)
72113a8.fe0: FileDescription: NT Layer DLL
72213a8.fe0: \SystemRoot\System32\kernel32.dll:
72313a8.fe0: CreationTime: 2017-08-14T17:14:42.421353600Z
72413a8.fe0: LastWriteTime: 2016-01-22T06:15:31.619000000Z
72513a8.fe0: ChangeTime: 2017-08-15T14:19:39.675649400Z
72613a8.fe0: FileAttributes: 0x20
72713a8.fe0: Size: 0x11c000
72813a8.fe0: NT Headers: 0xe8
72913a8.fe0: Timestamp: 0x56a1c9ab
73013a8.fe0: Machine: 0x8664 - amd64
73113a8.fe0: Timestamp: 0x56a1c9ab
73213a8.fe0: Image Version: 6.1
73313a8.fe0: SizeOfImage: 0x11f000 (1175552)
73413a8.fe0: Resource Dir: 0x116000 LB 0x528
73513a8.fe0: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
73613a8.fe0: [Raw version resource data: 0x1160b0 LB 0x3a4, codepage 0x0 (reserved 0x0)]
73713a8.fe0: ProductName: Microsoft® Windows® Operating System
73813a8.fe0: ProductVersion: 6.1.7601.19135
73913a8.fe0: FileVersion: 6.1.7601.19135 (win7sp1_gdr.160121-1718)
74013a8.fe0: FileDescription: Windows NT BASE API Client DLL
74113a8.fe0: \SystemRoot\System32\KernelBase.dll:
74213a8.fe0: CreationTime: 2017-08-14T17:14:42.296553400Z
74313a8.fe0: LastWriteTime: 2016-01-22T06:15:31.822000000Z
74413a8.fe0: ChangeTime: 2017-08-15T14:19:39.691249400Z
74513a8.fe0: FileAttributes: 0x20
74613a8.fe0: Size: 0x67200
74713a8.fe0: NT Headers: 0xe8
74813a8.fe0: Timestamp: 0x56a1c9ac
74913a8.fe0: Machine: 0x8664 - amd64
75013a8.fe0: Timestamp: 0x56a1c9ac
75113a8.fe0: Image Version: 6.1
75213a8.fe0: SizeOfImage: 0x6b000 (438272)
75313a8.fe0: Resource Dir: 0x69000 LB 0x530
75413a8.fe0: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
75513a8.fe0: [Raw version resource data: 0x690b0 LB 0x3ac, codepage 0x0 (reserved 0x0)]
75613a8.fe0: ProductName: Microsoft® Windows® Operating System
75713a8.fe0: ProductVersion: 6.1.7601.19135
75813a8.fe0: FileVersion: 6.1.7601.19135 (win7sp1_gdr.160121-1718)
75913a8.fe0: FileDescription: Windows NT BASE API Client DLL
76013a8.fe0: \SystemRoot\System32\apisetschema.dll:
76113a8.fe0: CreationTime: 2017-08-14T17:14:40.192149700Z
76213a8.fe0: LastWriteTime: 2016-01-22T06:12:25.181000000Z
76313a8.fe0: ChangeTime: 2017-08-15T14:19:38.474447300Z
76413a8.fe0: FileAttributes: 0x20
76513a8.fe0: Size: 0x1a00
76613a8.fe0: NT Headers: 0xc0
76713a8.fe0: Timestamp: 0x56a1c890
76813a8.fe0: Machine: 0x8664 - amd64
76913a8.fe0: Timestamp: 0x56a1c890
77013a8.fe0: Image Version: 6.1
77113a8.fe0: SizeOfImage: 0x50000 (327680)
77213a8.fe0: Resource Dir: 0x30000 LB 0x3f8
77313a8.fe0: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
77413a8.fe0: [Raw version resource data: 0x30060 LB 0x398, codepage 0x0 (reserved 0x0)]
77513a8.fe0: ProductName: Microsoft® Windows® Operating System
77613a8.fe0: ProductVersion: 6.1.7601.19135
77713a8.fe0: FileVersion: 6.1.7601.19135 (win7sp1_gdr.160121-1718)
77813a8.fe0: FileDescription: ApiSet Schema DLL
77913a8.fe0: Found driver klkbdflt (0x40)
78013a8.fe0: Found driver klmouflt (0x40)
78113a8.fe0: Found driver KLIM6 (0x40)
78213a8.fe0: Found driver kl1 (0x40)
78313a8.fe0: Found driver klflt (0x40)
78413a8.fe0: Found driver kneps (0x40)
78513a8.fe0: Found driver kltdi (0x40)
78613a8.fe0: supR3HardenedWinFindAdversaries: 0x40
78713a8.fe0: \SystemRoot\System32\drivers\kl1.sys:
78813a8.fe0: CreationTime: 2016-09-30T23:26:00.000000000Z
78913a8.fe0: LastWriteTime: 2016-09-30T23:26:00.000000000Z
79013a8.fe0: ChangeTime: 2017-08-14T17:05:02.334784600Z
79113a8.fe0: FileAttributes: 0x20
79213a8.fe0: Size: 0x875a8
79313a8.fe0: NT Headers: 0xe8
79413a8.fe0: Timestamp: 0x56fe83ac
79513a8.fe0: Machine: 0x8664 - amd64
79613a8.fe0: Timestamp: 0x56fe83ac
79713a8.fe0: Image Version: 0.0
79813a8.fe0: SizeOfImage: 0x709000 (7376896)
79913a8.fe0: Resource Dir: 0x707000 LB 0x448
80013a8.fe0: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x419)]
80113a8.fe0: [Raw version resource data: 0x707060 LB 0x3e4, codepage 0x0 (reserved 0x0)]
80213a8.fe0: ProductName: Kaspersky Anti-Virus
80313a8.fe0: ProductVersion: 6.0.1.990
80413a8.fe0: FileVersion: 6.8.0.67
80513a8.fe0: FileDescription: Kaspersky Unified Driver
80613a8.fe0: \SystemRoot\System32\drivers\klflt.sys:
80713a8.fe0: CreationTime: 2017-08-14T17:04:42.007949100Z
80813a8.fe0: LastWriteTime: 2017-10-15T12:48:48.677255100Z
80913a8.fe0: ChangeTime: 2017-10-15T12:50:31.265122800Z
81013a8.fe0: FileAttributes: 0x20
81113a8.fe0: Size: 0x324d8
81213a8.fe0: NT Headers: 0xf8
81313a8.fe0: Timestamp: 0x596f4b46
81413a8.fe0: Machine: 0x8664 - amd64
81513a8.fe0: Timestamp: 0x596f4b46
81613a8.fe0: Image Version: 6.0
81713a8.fe0: SizeOfImage: 0x3e000 (253952)
81813a8.fe0: Resource Dir: 0x3c000 LB 0x418
81913a8.fe0: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
82013a8.fe0: [Raw version resource data: 0x3c060 LB 0x3b4, codepage 0x0 (reserved 0x0)]
82113a8.fe0: ProductName: System Interceptors PDK
82213a8.fe0: ProductVersion: 13.0.56.0
82313a8.fe0: FileVersion: 13.0.56.0
82413a8.fe0: FileDescription: Filter Core [fre_wlh_x64]
82513a8.fe0: \SystemRoot\System32\drivers\klif.sys:
82613a8.fe0: CreationTime: 2017-08-14T17:04:42.023549200Z
82713a8.fe0: LastWriteTime: 2018-02-21T13:22:36.506612300Z
82813a8.fe0: ChangeTime: 2018-02-21T13:22:40.842860400Z
82913a8.fe0: FileAttributes: 0x20
83013a8.fe0: Size: 0x105ec8
83113a8.fe0: NT Headers: 0x118
83213a8.fe0: Timestamp: 0x5a6b1fa1
83313a8.fe0: Machine: 0x8664 - amd64
83413a8.fe0: Timestamp: 0x5a6b1fa1
83513a8.fe0: Image Version: 6.0
83613a8.fe0: SizeOfImage: 0x10d000 (1101824)
83713a8.fe0: Resource Dir: 0x109000 LB 0x2230
83813a8.fe0: [Version info resource found at 0x150! (ID/Name: 0x1; SubID/SubName: 0x409)]
83913a8.fe0: [Raw version resource data: 0x109618 LB 0x3d8, codepage 0x0 (reserved 0x0)]
84013a8.fe0: ProductName: System Interceptors PDK
84113a8.fe0: ProductVersion: 13.0.349.0
84213a8.fe0: FileVersion: 13.0.349.0
84313a8.fe0: FileDescription: Core System Interceptors [fre_wlh_x64]
84413a8.fe0: \SystemRoot\System32\drivers\klim6.sys:
84513a8.fe0: CreationTime: 2016-10-11T11:14:28.000000000Z
84613a8.fe0: LastWriteTime: 2018-02-21T13:22:36.699623400Z
84713a8.fe0: ChangeTime: 2018-02-21T13:22:40.852860900Z
84813a8.fe0: FileAttributes: 0x20
84913a8.fe0: Size: 0xdec0
85013a8.fe0: NT Headers: 0x100
85113a8.fe0: Timestamp: 0x5a5f21e8
85213a8.fe0: Machine: 0x8664 - amd64
85313a8.fe0: Timestamp: 0x5a5f21e8
85413a8.fe0: Image Version: 6.0
85513a8.fe0: SizeOfImage: 0xc000 (49152)
85613a8.fe0: Resource Dir: 0xa000 LB 0x428
85713a8.fe0: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
85813a8.fe0: [Raw version resource data: 0xa060 LB 0x3c8, codepage 0x0 (reserved 0x0)]
85913a8.fe0: ProductName: System Interceptors PDK
86013a8.fe0: ProductVersion: 14.0.0.16
86113a8.fe0: FileVersion: 14.0.0.16
86213a8.fe0: FileDescription: Packet Network Filter [fre_wlh_x64]
86313a8.fe0: \SystemRoot\System32\drivers\klkbdflt.sys:
86413a8.fe0: CreationTime: 2016-12-23T06:19:30.000000000Z
86513a8.fe0: LastWriteTime: 2016-12-23T06:19:30.000000000Z
86613a8.fe0: ChangeTime: 2017-08-14T17:05:02.693585200Z
86713a8.fe0: FileAttributes: 0x20
86813a8.fe0: Size: 0xe0e0
86913a8.fe0: NT Headers: 0xf8
87013a8.fe0: Timestamp: 0x5859ab81
87113a8.fe0: Machine: 0x8664 - amd64
87213a8.fe0: Timestamp: 0x5859ab81
87313a8.fe0: Image Version: 6.0
87413a8.fe0: SizeOfImage: 0xe000 (57344)
87513a8.fe0: Resource Dir: 0xc000 LB 0x438
87613a8.fe0: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
87713a8.fe0: [Raw version resource data: 0xc060 LB 0x3d4, codepage 0x0 (reserved 0x0)]
87813a8.fe0: ProductName: System Interceptors PDK
87913a8.fe0: ProductVersion: 13.0.0.8
88013a8.fe0: FileVersion: 13.0.0.8
88113a8.fe0: FileDescription: Keyboard Device Filter [fre_wlh_x64]
88213a8.fe0: \SystemRoot\System32\drivers\klmouflt.sys:
88313a8.fe0: CreationTime: 2016-12-07T06:38:46.000000000Z
88413a8.fe0: LastWriteTime: 2016-12-07T06:38:46.000000000Z
88513a8.fe0: ChangeTime: 2017-08-14T17:05:02.568785000Z
88613a8.fe0: FileAttributes: 0x20
88713a8.fe0: Size: 0xe4e0
88813a8.fe0: NT Headers: 0xf8
88913a8.fe0: Timestamp: 0x583e86c3
89013a8.fe0: Machine: 0x8664 - amd64
89113a8.fe0: Timestamp: 0x583e86c3
89213a8.fe0: Image Version: 6.0
89313a8.fe0: SizeOfImage: 0xf000 (61440)
89413a8.fe0: Resource Dir: 0xd000 LB 0x430
89513a8.fe0: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
89613a8.fe0: [Raw version resource data: 0xd060 LB 0x3cc, codepage 0x0 (reserved 0x0)]
89713a8.fe0: ProductName: System Interceptors PDK
89813a8.fe0: ProductVersion: 13.0.0.5
89913a8.fe0: FileVersion: 13.0.0.5
90013a8.fe0: FileDescription: Mouse Device Filter [fre_wlh_x64]
90113a8.fe0: \SystemRoot\System32\drivers\kltdi.sys:
90213a8.fe0: CreationTime: 2017-06-20T11:32:46.000000000Z
90313a8.fe0: LastWriteTime: 2017-06-20T11:32:46.000000000Z
90413a8.fe0: ChangeTime: 2017-08-14T17:05:03.083585900Z
90513a8.fe0: FileAttributes: 0x20
90613a8.fe0: Size: 0x13ff0
90713a8.fe0: NT Headers: 0xf0
90813a8.fe0: Timestamp: 0x58bd327c
90913a8.fe0: Machine: 0x8664 - amd64
91013a8.fe0: Timestamp: 0x58bd327c
91113a8.fe0: Image Version: 5.2
91213a8.fe0: SizeOfImage: 0x12000 (73728)
91313a8.fe0: Resource Dir: 0x10000 LB 0x430
91413a8.fe0: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
91513a8.fe0: [Raw version resource data: 0x10060 LB 0x3cc, codepage 0x0 (reserved 0x0)]
91613a8.fe0: ProductName: System Interceptors PDK
91713a8.fe0: ProductVersion: 13.0.0.12
91813a8.fe0: FileVersion: 13.0.0.12
91913a8.fe0: FileDescription: Legacy Network Filter [fre_wnet_x64]
92013a8.fe0: \SystemRoot\System32\drivers\kneps.sys:
92113a8.fe0: CreationTime: 2017-06-20T11:32:46.000000000Z
92213a8.fe0: LastWriteTime: 2017-12-14T16:33:26.144749900Z
92313a8.fe0: ChangeTime: 2017-12-14T16:33:29.624949000Z
92413a8.fe0: FileAttributes: 0x20
92513a8.fe0: Size: 0x30ae0
92613a8.fe0: NT Headers: 0x110
92713a8.fe0: Timestamp: 0x5a0e923b
92813a8.fe0: Machine: 0x8664 - amd64
92913a8.fe0: Timestamp: 0x5a0e923b
93013a8.fe0: Image Version: 5.2
93113a8.fe0: SizeOfImage: 0x2d000 (184320)
93213a8.fe0: Resource Dir: 0x2b000 LB 0x428
93313a8.fe0: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
93413a8.fe0: [Raw version resource data: 0x2b060 LB 0x3c4, codepage 0x0 (reserved 0x0)]
93513a8.fe0: ProductName: System Interceptors PDK
93613a8.fe0: ProductVersion: 13.0.0.40
93713a8.fe0: FileVersion: 13.0.0.40
93813a8.fe0: FileDescription: Network Processor [fre_wnet_x64]
93913a8.fe0: \SystemRoot\System32\klfphc.dll:
94013a8.fe0: CreationTime: 2017-08-14T17:05:02.287984500Z
94113a8.fe0: LastWriteTime: 2013-05-06T05:13:26.000000000Z
94213a8.fe0: ChangeTime: 2017-08-14T17:04:53.863969800Z
94313a8.fe0: FileAttributes: 0x20
94413a8.fe0: Size: 0x1ae60
94513a8.fe0: NT Headers: 0xe8
94613a8.fe0: Timestamp: 0x51873bf2
94713a8.fe0: Machine: 0x8664 - amd64
94813a8.fe0: Timestamp: 0x51873bf2
94913a8.fe0: Image Version: 0.0
95013a8.fe0: SizeOfImage: 0x1d000 (118784)
95113a8.fe0: Resource Dir: 0x18000 LB 0x3c80
95213a8.fe0: [Version info resource found at 0x188! (ID/Name: 0x1; SubID/SubName: 0x409)]
95313a8.fe0: [Raw version resource data: 0x1b800 LB 0x324, codepage 0x4e4 (reserved 0x0)]
95413a8.fe0: ProductName: Kaspersky™ Anti-Virus ®
95513a8.fe0: ProductVersion: 1.0.0.12
95613a8.fe0: FileVersion: 1.0.0.12
95713a8.fe0: FileDescription: Filtering Platform Helper Class
95813a8.fe0: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
95913a8.fe0: Calling main()
96013a8.fe0: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
96113a8.fe0: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
96213a8.fe0: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
96313a8.fe0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe)
96413a8.fe0: SUPR3HardenedMain: Final process, opening VBoxDrv...
96513a8.fe0: supR3HardenedEarlyCompact: Removed heap 1 (0x00000000290000 LB 0x400000)
96613a8.fe0: supR3HardNtEnableThreadCreation:
96713a8.fe0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll)
96813a8.fe0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll
96913a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000018b431:<flags> [calling]
97013a8.fe0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
97113a8.fe0: supR3HardenedDllNotificationCallback: load 000007feef420000 LB 0x00005000 C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL [fFlags=0x0]
97213a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
97313a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
97413a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000188bb1:<flags> [calling]
97513a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feef420000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
97613a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
97713a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000188bb1:<flags> [calling]
97813a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feef420000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
97913a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feef420000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
98013a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
98113a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'crypt32.dll'.
98213a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msasn1.dll'.
98313a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
98413a8.fe0: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\wintrust.dll)
98513a8.fe0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wintrust.dll
98613a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
98713a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
98813a8.fe0: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll)
98913a8.fe0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
99013a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
99113a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume2\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
99213a8.fe0: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\msasn1.dll)
99313a8.fe0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msasn1.dll
99413a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
99513a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume2\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
99613a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
99713a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msasn1.dll'.
99813a8.fe0: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\crypt32.dll)
99913a8.fe0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\crypt32.dll
100013a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
100113a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
100213a8.fe0: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\msvcrt.dll)
100313a8.fe0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
100413a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
100513a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume2\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
100613a8.fe0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
100713a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
100813a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
100913a8.fe0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
101013a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000018d241:<flags> [calling]
101113a8.fe0: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
101213a8.fe0: supR3HardenedDllNotificationCallback: load 000007fefd720000 LB 0x0003a000 C:\Windows\system32\Wintrust.dll [fFlags=0x0]
101313a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
101413a8.fe0: supR3HardenedDllNotificationCallback: load 000007fefe0e0000 LB 0x0009f000 C:\Windows\system32\msvcrt.dll [fFlags=0x0]
101513a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
101613a8.fe0: supR3HardenedDllNotificationCallback: load 000007fefd760000 LB 0x0016a000 C:\Windows\system32\CRYPT32.dll [fFlags=0x0]
101713a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
101813a8.fe0: supR3HardenedDllNotificationCallback: load 000007fefd5a0000 LB 0x0000f000 C:\Windows\system32\MSASN1.dll [fFlags=0x0]
101913a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
102013a8.fe0: supR3HardenedDllNotificationCallback: load 000007fefe650000 LB 0x0012d000 C:\Windows\system32\RPCRT4.dll [fFlags=0x0]
102113a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
102213a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd720000 'C:\Windows\system32\Wintrust.dll'
102313a8.fe0: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\bcrypt.dll)
102413a8.fe0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\bcrypt.dll
102513a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\bcrypt.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000018d241:<flags> [calling]
102613a8.fe0: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
102713a8.fe0: supR3HardenedDllNotificationCallback: load 000007fefcf20000 LB 0x00022000 C:\Windows\system32\bcrypt.dll [fFlags=0x0]
102813a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
102913a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcf20000 'C:\Windows\system32\bcrypt.dll'
103013a8.fe0: bcrypt.dll loaded at 000007fefcf20000, BCryptOpenAlgorithmProvider at 000007fefcf22640, preloading providers:
103113a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'advapi32.dll'.
103213a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'bcrypt.dll'.
103313a8.fe0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll)
103413a8.fe0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll
103513a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
103613a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume2\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
103713a8.fe0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
103813a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
103913a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
104013a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
104113a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'rpcrt4.dll'.
104213a8.fe0: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\advapi32.dll)
104313a8.fe0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\advapi32.dll
104413a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
104513a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
104613a8.fe0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
104713a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
104813a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
104913a8.fe0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
105013a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\bcryptprimitives.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000018d231:<flags> [calling]
105113a8.fe0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
105213a8.fe0: supR3HardenedDllNotificationCallback: load 000007fefc9d0000 LB 0x0004c000 C:\Windows\system32\bcryptprimitives.dll [fFlags=0x0]
105313a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
105413a8.fe0: supR3HardenedDllNotificationCallback: load 000007feff760000 LB 0x000db000 C:\Windows\system32\ADVAPI32.dll [fFlags=0x0]
105513a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
105613a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msvcrt.dll'.
105713a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'rpcrt4.dll'.
105813a8.fe0: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\sechost.dll)
105913a8.fe0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\sechost.dll
106013a8.fe0: supR3HardenedDllNotificationCallback: load 000007fefe4c0000 LB 0x0001f000 C:\Windows\SYSTEM32\sechost.dll [fFlags=0x0]
106113a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\sechost.dll [lacks WinVerifyTrust]
106213a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc9d0000 'C:\Windows\system32\bcryptprimitives.dll'
106313a8.fe0: BCryptOpenAlgorithmProvider(,'MD2',0,0) -> 0x0 (hAlgo=0000000000805980)
106413a8.fe0: BCryptOpenAlgorithmProvider(,'MD4',0,0) -> 0x0 (hAlgo=0000000000807840)
106513a8.fe0: BCryptOpenAlgorithmProvider(,'MD5',0,0) -> 0x0 (hAlgo=0000000000807960)
106613a8.fe0: BCryptOpenAlgorithmProvider(,'SHA1',0,0) -> 0x0 (hAlgo=0000000000807b70)
106713a8.fe0: BCryptOpenAlgorithmProvider(,'SHA256',0,0) -> 0x0 (hAlgo=0000000000807c90)
106813a8.fe0: BCryptOpenAlgorithmProvider(,'SHA512',0,0) -> 0x0 (hAlgo=0000000000807db0)
106913a8.fe0: BCryptOpenAlgorithmProvider(,'RSA',0,0) -> 0x0 (hAlgo=0000000000807ff0)
107013a8.fe0: BCryptOpenAlgorithmProvider(,'DSA',0,0) -> 0x0 (hAlgo=0000000000808110)
107113a8.fe0: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\cryptsp.dll)
107213a8.fe0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cryptsp.dll
107313a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
107413a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
107513a8.fe0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
107613a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
107713a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
107813a8.fe0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
107913a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTSP.dll (Input=CRYPTSP.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000018cdb1:<flags> [calling]
108013a8.fe0: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptsp.dll [lacks WinVerifyTrust]
108113a8.fe0: supR3HardenedDllNotificationCallback: load 000007fefcdd0000 LB 0x00017000 C:\Windows\system32\CRYPTSP.dll [fFlags=0x0]
108213a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptsp.dll [lacks WinVerifyTrust]
108313a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcdd0000 'C:\Windows\system32\CRYPTSP.dll'
108413a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
108513a8.fe0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\rsaenh.dll)
108613a8.fe0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\rsaenh.dll
108713a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
108813a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
108913a8.fe0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
109013a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000018cd41:<flags> [calling]
109113a8.fe0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
109213a8.fe0: supR3HardenedDllNotificationCallback: load 000007fefca90000 LB 0x00047000 C:\Windows\system32\rsaenh.dll [fFlags=0x0]
109313a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
109413a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefca90000 'C:\Windows\system32\rsaenh.dll'
109513a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
109613a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ADVAPI32.dll (Input=ADVAPI32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000018c5d1:<flags> [calling]
109713a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff760000 'C:\Windows\system32\ADVAPI32.dll'
109813a8.fe0: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\cryptbase.dll)
109913a8.fe0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cryptbase.dll
110013a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTBASE.dll (Input=CRYPTBASE.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000018c951:<flags> [calling]
110113a8.fe0: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptbase.dll [lacks WinVerifyTrust]
110213a8.fe0: supR3HardenedDllNotificationCallback: load 000007fefd430000 LB 0x0000f000 C:\Windows\system32\CRYPTBASE.dll [fFlags=0x0]
110313a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptbase.dll [lacks WinVerifyTrust]
110413a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd430000 'C:\Windows\system32\CRYPTBASE.dll'
110513a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
110613a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000018c381:<flags> [calling]
110713a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00000000773c0000 'C:\Windows\system32\kernel32.dll'
110813a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
110913a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\WINTRUST.DLL (Input=WINTRUST.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000018cd11:<flags> [calling]
111013a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd720000 'C:\Windows\system32\WINTRUST.DLL'
111113a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
111213a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPT32.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=000000000018cb41:<flags> [calling]
111313a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd760000 'C:\Windows\system32\CRYPT32.dll'
111413a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
111513a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'advapi32.dll'.
111613a8.fe0: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\imagehlp.dll)
111713a8.fe0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\imagehlp.dll
111813a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
111913a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
112013a8.fe0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
112113a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
112213a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
112313a8.fe0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
112413a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\imagehlp.dll (Input=imagehlp.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000018cb91:<flags> [calling]
112513a8.fe0: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\imagehlp.dll [lacks WinVerifyTrust]
112613a8.fe0: supR3HardenedDllNotificationCallback: load 000007fefdb30000 LB 0x00019000 C:\Windows\system32\imagehlp.dll [fFlags=0x0]
112713a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\imagehlp.dll [lacks WinVerifyTrust]
112813a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdb30000 'C:\Windows\system32\imagehlp.dll'
112913a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptsp.dll [lacks WinVerifyTrust]
113013a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTSP.dll (Input=CRYPTSP.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000018cce1:<flags> [calling]
113113a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcdd0000 'C:\Windows\system32\CRYPTSP.dll'
113213a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
113313a8.fe0: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\user32.dll)
113413a8.fe0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\user32.dll
113513a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
113613a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
113713a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
113813a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'lpk.dll'.
113913a8.fe0: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\gdi32.dll)
114013a8.fe0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\gdi32.dll
114113a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'lpk.dll'...
114213a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'lpk.dll' -> '\Device\HarddiskVolume2\Windows\System32\lpk.dll' [rcNtRedir=0xc0150008]
114313a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'gdi32.dll'.
114413a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'user32.dll'.
114513a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'usp10.dll'.
114613a8.fe0: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\lpk.dll)
114713a8.fe0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\lpk.dll
114813a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
114913a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
115013a8.fe0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
115113a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'usp10.dll'...
115213a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'usp10.dll' -> '\Device\HarddiskVolume2\Windows\System32\usp10.dll' [rcNtRedir=0xc0150008]
115313a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
115413a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
115513a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'gdi32.dll'.
115613a8.fe0: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\usp10.dll)
115713a8.fe0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\usp10.dll
115813a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
115913a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
116013a8.fe0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
116113a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
116213a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
116313a8.fe0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
116413a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
116513a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
116613a8.fe0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
116713a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
116813a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
116913a8.fe0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
117013a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
117113a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
117213a8.fe0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
117313a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\USER32.dll (Input=USER32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000018c811:<flags> [calling]
117413a8.fe0: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
117513a8.fe0: supR3HardenedDllNotificationCallback: load 00000000774e0000 LB 0x000fa000 C:\Windows\system32\USER32.dll [fFlags=0x0]
117613a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
117713a8.fe0: supR3HardenedDllNotificationCallback: load 000007feff850000 LB 0x00067000 C:\Windows\system32\GDI32.dll [fFlags=0x0]
117813a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
117913a8.fe0: supR3HardenedDllNotificationCallback: load 000007feff840000 LB 0x0000e000 C:\Windows\system32\LPK.dll [fFlags=0x0]
118013a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\lpk.dll [lacks WinVerifyTrust]
118113a8.fe0: supR3HardenedDllNotificationCallback: load 000007fefe010000 LB 0x000c9000 C:\Windows\system32\USP10.dll [fFlags=0x0]
118213a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\usp10.dll [lacks WinVerifyTrust]
118313a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
118413a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\gdi32.dll (Input=gdi32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000018bd11:<flags> [calling]
118513a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff850000 'C:\Windows\system32\gdi32.dll'
118613a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'user32.dll'.
118713a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
118813a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msctf.dll'.
118913a8.fe0: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\imm32.dll)
119013a8.fe0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\imm32.dll
119113a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msctf.dll'...
119213a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msctf.dll' -> '\Device\HarddiskVolume2\Windows\System32\msctf.dll' [rcNtRedir=0xc0150008]
119313a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
119413a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
119513a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'gdi32.dll'.
119613a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'imm32.dll'.
119713a8.fe0: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\msctf.dll)
119813a8.fe0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msctf.dll
119913a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
120013a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
120113a8.fe0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
120213a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
120313a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
120413a8.fe0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
120513a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
120613a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume2\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
120713a8.fe0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\imm32.dll [lacks WinVerifyTrust]
120813a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
120913a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
121013a8.fe0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
121113a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
121213a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
121313a8.fe0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
121413a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
121513a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
121613a8.fe0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
121713a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\IMM32.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000018b651:<flags> [calling]
121813a8.fe0: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\imm32.dll [lacks WinVerifyTrust]
121913a8.fe0: supR3HardenedDllNotificationCallback: load 000007fefe300000 LB 0x0002e000 C:\Windows\system32\IMM32.DLL [fFlags=0x0]
122013a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\imm32.dll [lacks WinVerifyTrust]
122113a8.fe0: supR3HardenedDllNotificationCallback: load 000007fefe4e0000 LB 0x00109000 C:\Windows\system32\MSCTF.dll [fFlags=0x0]
122213a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msctf.dll [lacks WinVerifyTrust]
122313a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe300000 'C:\Windows\system32\IMM32.DLL'
122413a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00000000774e0000 'C:\Windows\system32\USER32.dll'
122513a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'bcrypt.dll'.
122613a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
122713a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msasn1.dll'.
122813a8.fe0: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\ncrypt.dll)
122913a8.fe0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ncrypt.dll
123013a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
123113a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume2\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
123213a8.fe0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
123313a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
123413a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
123513a8.fe0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
123613a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
123713a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume2\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
123813a8.fe0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
123913a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ncrypt.dll (Input=ncrypt.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000018cb11:<flags> [calling]
124013a8.fe0: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\ncrypt.dll [lacks WinVerifyTrust]
124113a8.fe0: supR3HardenedDllNotificationCallback: load 000007fefcf50000 LB 0x00050000 C:\Windows\system32\ncrypt.dll [fFlags=0x0]
124213a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\ncrypt.dll [lacks WinVerifyTrust]
124313a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcf50000 'C:\Windows\system32\ncrypt.dll'
124413a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
124513a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\bcrypt.dll (Input=bcrypt.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000018c901:<flags> [calling]
124613a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcf20000 'C:\Windows\system32\bcrypt.dll'
124713a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
124813a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'rpcrt4.dll'.
124913a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'profapi.dll'.
125013a8.fe0: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\userenv.dll)
125113a8.fe0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\userenv.dll
125213a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'profapi.dll'...
125313a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'profapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\profapi.dll' [rcNtRedir=0xc0150008]
125413a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
125513a8.fe0: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\profapi.dll)
125613a8.fe0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\profapi.dll
125713a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
125813a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
125913a8.fe0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
126013a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
126113a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
126213a8.fe0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
126313a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
126413a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
126513a8.fe0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
126613a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\USERENV.dll (Input=USERENV.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000018c301:<flags> [calling]
126713a8.fe0: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\userenv.dll [lacks WinVerifyTrust]
126813a8.fe0: supR3HardenedDllNotificationCallback: load 000007fefc840000 LB 0x0001e000 C:\Windows\system32\USERENV.dll [fFlags=0x0]
126913a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\userenv.dll [lacks WinVerifyTrust]
127013a8.fe0: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\profapi.dll [lacks WinVerifyTrust]
127113a8.fe0: supR3HardenedDllNotificationCallback: load 000007fefd500000 LB 0x0000f000 C:\Windows\system32\profapi.dll [fFlags=0x0]
127213a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\profapi.dll [lacks WinVerifyTrust]
127313a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc840000 'C:\Windows\system32\USERENV.dll'
127413a8.fe0: supR3HardenedIsApiSetDll: '<NULL>' -> true
127513a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=000000000018c061:<flags> [calling]
127613a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe4c0000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
127713a8.fe0: supR3HardenedIsApiSetDll: '<NULL>' -> true
127813a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=000000000018c3f1:<flags> [calling]
127913a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe4c0000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
128013a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
128113a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'rpcrt4.dll'.
128213a8.fe0: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\gpapi.dll)
128313a8.fe0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\gpapi.dll
128413a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
128513a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
128613a8.fe0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
128713a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
128813a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
128913a8.fe0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
129013a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\GPAPI.dll (Input=GPAPI.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000018c621:<flags> [calling]
129113a8.fe0: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gpapi.dll [lacks WinVerifyTrust]
129213a8.fe0: supR3HardenedDllNotificationCallback: load 000007fefc820000 LB 0x0001b000 C:\Windows\system32\GPAPI.dll [fFlags=0x0]
129313a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gpapi.dll [lacks WinVerifyTrust]
129413a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc820000 'C:\Windows\system32\GPAPI.dll'
129513a8.fe0: supR3HardenedIsApiSetDll: '<NULL>' -> true
129613a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-Management-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=000000000018c571:<flags> [calling]
129713a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe4c0000 'API-MS-WIN-Service-Management-L1-1-0.dll'
129813a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
129913a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rpcrt4.dll (Input=rpcrt4.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000018bc71:<flags> [calling]
130013a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe650000 'C:\Windows\system32\rpcrt4.dll'
130113a8.fe0: supR3HardenedIsApiSetDll: '<NULL>' -> true
130213a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-Management-L2-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=000000000018c551:<flags> [calling]
130313a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe4c0000 'API-MS-WIN-Service-Management-L2-1-0.dll'
130413a8.fe0: supR3HardenedIsApiSetDll: '<NULL>' -> true
130513a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=000000000018c561:<flags> [calling]
130613a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe4c0000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
130713a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
130813a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'advapi32.dll'.
130913a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'crypt32.dll'.
131013a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'wldap32.dll'.
131113a8.fe0: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\cryptnet.dll)
131213a8.fe0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cryptnet.dll
131313a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wldap32.dll'...
131413a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'wldap32.dll' -> '\Device\HarddiskVolume2\Windows\System32\wldap32.dll' [rcNtRedir=0xc0150008]
131513a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
131613a8.fe0: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\Wldap32.dll)
131713a8.fe0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\Wldap32.dll
131813a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
131913a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume2\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
132013a8.fe0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
132113a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
132213a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
132313a8.fe0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
132413a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
132513a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
132613a8.fe0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
132713a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
132813a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
132913a8.fe0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
133013a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (Input=cryptnet.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000018c041:<flags> [calling]
133113a8.fe0: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
133213a8.fe0: supR3HardenedDllNotificationCallback: load 000007fef7820000 LB 0x00027000 C:\Windows\system32\cryptnet.dll [fFlags=0x0]
133313a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
133413a8.fe0: supR3HardenedDllNotificationCallback: load 000007fefe5f0000 LB 0x00052000 C:\Windows\system32\WLDAP32.dll [fFlags=0x0]
133513a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\Wldap32.dll [lacks WinVerifyTrust]
133613a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
133713a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=000000000018b271:<flags> [calling]
133813a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef7820000 'C:\Windows\system32\cryptnet.dll'
133913a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
134013a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=000000000018b271:<flags> [calling]
134113a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef7820000 'C:\Windows\system32\cryptnet.dll'
134213a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
134313a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=000000000018b271:<flags> [calling]
134413a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef7820000 'C:\Windows\system32\cryptnet.dll'
134513a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
134613a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=000000000018b271:<flags> [calling]
134713a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef7820000 'C:\Windows\system32\cryptnet.dll'
134813a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
134913a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=000000000018b271:<flags> [calling]
135013a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef7820000 'C:\Windows\system32\cryptnet.dll'
135113a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
135213a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=000000000018b271:<flags> [calling]
135313a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef7820000 'C:\Windows\system32\cryptnet.dll'
135413a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
135513a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef7820000 'C:\Windows\system32\cryptnet.dll'
135613a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
135713a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef7820000 'C:\Windows\system32\cryptnet.dll'
135813a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
135913a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef7820000 'C:\Windows\system32\cryptnet.dll'
136013a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
136113a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef7820000 'C:\Windows\system32\cryptnet.dll'
136213a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
136313a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef7820000 'C:\Windows\system32\cryptnet.dll'
136413a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef7820000 'C:\Windows\system32\cryptnet.dll'
136513a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
136613a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef7820000 'C:\Windows\system32\cryptnet.dll'
136713a8.fe0: supR3HardenedIsApiSetDll: '<NULL>' -> true
136813a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=000000000018b9d1:<flags> [calling]
136913a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe4c0000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
137013a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\profapi.dll [lacks WinVerifyTrust]
137113a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\profapi.dll (Input=profapi.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000018b9d1:<flags> [calling]
137213a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd500000 'C:\Windows\system32\profapi.dll'
137313a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
137413a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
137513a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msvcrt.dll'.
137613a8.fe0: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\shlwapi.dll)
137713a8.fe0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\shlwapi.dll
137813a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
137913a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
138013a8.fe0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
138113a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
138213a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
138313a8.fe0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
138413a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
138513a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
138613a8.fe0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
138713a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\SHLWAPI.dll (Input=SHLWAPI.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000018b471:<flags> [calling]
138813a8.fe0: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll [lacks WinVerifyTrust]
138913a8.fe0: supR3HardenedDllNotificationCallback: load 000007fefe780000 LB 0x00071000 C:\Windows\system32\SHLWAPI.dll [fFlags=0x0]
139013a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll [lacks WinVerifyTrust]
139113a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe780000 'C:\Windows\system32\SHLWAPI.dll'
139213a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000000 pwszName=\SystemRoot\System32\ntdll.dll
139313a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: New context 00000000007ff4b0
139413a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ff4b0
139513a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=881FA305C5390C7D979151AFB211130389B9E066
139613a8.fe0: supR3HardenedIsApiSetDll: '<NULL>' -> true
139713a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=000000000018c2c1:<flags> [calling]
139813a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe4c0000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
139913a8.fe0: supR3HardenedIsApiSetDll: '<NULL>' -> true
140013a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-Management-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=000000000018be21:<flags> [calling]
140113a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe4c0000 'API-MS-WIN-Service-Management-L1-1-0.dll'
140213a8.fe0: supR3HardenedIsApiSetDll: '<NULL>' -> true
140313a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-winsvc-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=000000000018be21:<flags> [calling]
140413a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe4c0000 'API-MS-WIN-Service-winsvc-L1-1-0.dll'
140513a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
140613a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ADVAPI32.dll (Input=ADVAPI32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000018c2c1:<flags> [calling]
140713a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff760000 'C:\Windows\system32\ADVAPI32.dll'
140813a8.fe0: supR3HardenedIsApiSetDll: '<NULL>' -> true
140913a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-LSALookup-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=000000000018c271:<flags> [calling]
141013a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe4c0000 'API-MS-Win-Security-LSALookup-L1-1-0.dll'
141113a8.fe0: supR3HardenedIsApiSetDll: '<NULL>' -> true
141213a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-LSALookup-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=000000000018bf61:<flags> [calling]
141313a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe4c0000 'API-MS-Win-Security-LSALookup-L1-1-0.dll'
141413a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_88_for_KB3126587~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\SystemRoot\System32\ntdll.dll'
141513a8.fe0: g_pfnWinVerifyTrust=000007fefd721010
141613a8.fe0: supR3HardenedScreenImage/preload: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [redoing WinVerifyTrust]
141713a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000e0 pwszName=\Device\HarddiskVolume2\Windows\System32\crypt32.dll
141813a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ff4b0
141913a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ff4b0
142013a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=F4982E5F19EEC9EA72436D469FB5B41639FB6890
142113a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_115_for_KB2813430~31bf3856ad364e35~amd64~~6.1.1.4.cat'; file='\Device\HarddiskVolume2\Windows\System32\crypt32.dll'
142213a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
142313a8.fe0: supR3HardenedScreenImage/preload: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\crypt32.dll'
142413a8.fe0: supR3HardenedScreenImage/preload: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [redoing WinVerifyTrust]
142513a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000d4 pwszName=\Device\HarddiskVolume2\Windows\System32\wintrust.dll
142613a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ff4b0
142713a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ff4b0
142813a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=DBD5D88D100825A4A22743B0FD6EF53BF9B657CA
142913a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB2653956~31bf3856ad364e35~amd64~~6.1.1.5.cat'; file='\Device\HarddiskVolume2\Windows\System32\wintrust.dll'
143013a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
143113a8.fe0: supR3HardenedScreenImage/preload: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\wintrust.dll'
143213a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000003a0 pwszName=\Device\HarddiskVolume2\Windows\System32\shlwapi.dll
143313a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ff4b0
143413a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ff4b0
143513a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=0AB8D9C9D3E1FC95D01F9A984B16ED031BB40CD8
143613a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\shlwapi.dll'
143713a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
143813a8.fe0: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll'
143913a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000398 pwszName=\Device\HarddiskVolume2\Windows\System32\Wldap32.dll
144013a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ff4b0
144113a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ff4b0
144213a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=87E73086F2528CF31D3AD5F0D71E04F8B942D5D8
144313a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\Wldap32.dll'
144413a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
144513a8.fe0: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\Wldap32.dll'
144613a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000394 pwszName=\Device\HarddiskVolume2\Windows\System32\cryptnet.dll
144713a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ff4b0
144813a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ff4b0
144913a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=E0763F1478C58F0F99A6A6E775E5D3BF96015915
145013a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_75_for_KB2813430~31bf3856ad364e35~amd64~~6.1.1.4.cat'; file='\Device\HarddiskVolume2\Windows\System32\cryptnet.dll'
145113a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
145213a8.fe0: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\cryptnet.dll'
145313a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000260 pwszName=\Device\HarddiskVolume2\Windows\System32\gpapi.dll
145413a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ff4b0
145513a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ff4b0
145613a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=EBDAA16C3FD93DFF9C20BA3B2689DFF4C8D31061
145713a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_115_for_KB3159398~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\gpapi.dll'
145813a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
145913a8.fe0: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\gpapi.dll'
146013a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000001cc pwszName=\Device\HarddiskVolume2\Windows\System32\profapi.dll
146113a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ff4b0
146213a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ff4b0
146313a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2449672745D9BA339420451D13FA0380AA768231
146413a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\profapi.dll'
146513a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
146613a8.fe0: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\profapi.dll'
146713a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000001c8 pwszName=\Device\HarddiskVolume2\Windows\System32\userenv.dll
146813a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ff4b0
146913a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ff4b0
147013a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=D3E1A2CC7367F751C19EBF4E6EDF5E9A10E47313
147113a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\userenv.dll'
147213a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
147313a8.fe0: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\userenv.dll'
147413a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000001b4 pwszName=\Device\HarddiskVolume2\Windows\System32\ncrypt.dll
147513a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ff4b0
147613a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ff4b0
147713a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=5D1D092E2A4891EA2A659F7204097B2FDEA00B39
147813a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_88_for_KB3126587~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\ncrypt.dll'
147913a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
148013a8.fe0: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\ncrypt.dll'
148113a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000019c pwszName=\Device\HarddiskVolume2\Windows\System32\msctf.dll
148213a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ff4b0
148313a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ff4b0
148413a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=803AF52F95A9EFDFDA06C595023831EE36ACD3A8
148513a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\msctf.dll'
148613a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
148713a8.fe0: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\msctf.dll'
148813a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000198 pwszName=\Device\HarddiskVolume2\Windows\System32\imm32.dll
148913a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ff4b0
149013a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ff4b0
149113a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=6EEE1AB3B6D79AFF857940FF5F51ED27698153EC
149213a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\imm32.dll'
149313a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
149413a8.fe0: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\imm32.dll'
149513a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000194 pwszName=\Device\HarddiskVolume2\Windows\System32\usp10.dll
149613a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ff4b0
149713a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ff4b0
149813a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=97AE9B5B40144F2794F30A891013393C80D631A1
149913a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\usp10.dll'
150013a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
150113a8.fe0: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\usp10.dll'
150213a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000190 pwszName=\Device\HarddiskVolume2\Windows\System32\lpk.dll
150313a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ff4b0
150413a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ff4b0
150513a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=A42DFBB8A3A26D2178D79D34DA1CE275E2A0BE37
150613a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\lpk.dll'
150713a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
150813a8.fe0: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\lpk.dll'
150913a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000018c pwszName=\Device\HarddiskVolume2\Windows\System32\gdi32.dll
151013a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ff4b0
151113a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ff4b0
151213a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=C8F7179D2AEB0FEB168A01D182223AC2D7B8F331
151313a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\gdi32.dll'
151413a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
151513a8.fe0: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\gdi32.dll'
151613a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000188 pwszName=\Device\HarddiskVolume2\Windows\System32\user32.dll
151713a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ff4b0
151813a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ff4b0
151913a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=FB05A6DD4AF9AC247D37C4B7BAFCCBD178A41E64
152013a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: Retrying with fresh context (CryptCATAdminEnumCatalogFromHash -> 1168; iCat=0x0)
152113a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: New context 00000000007ff4b0
152213a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ff4b0
152313a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=FB05A6DD4AF9AC247D37C4B7BAFCCBD178A41E64
152413a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: CryptCATAdminEnumCatalogFromHash failed ERRROR_NOT_FOUND (1168)
152513a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile -> -22900 (org 22900)
152613a8.fe0: supR3HardenedWinVerifyCacheProcessWvtTodos: -22900 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\user32.dll'
152713a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000184 pwszName=\Device\HarddiskVolume2\Windows\System32\imagehlp.dll
152813a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ff4b0
152913a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ff4b0
153013a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2F0A0F84DD55507C56A273E145872B7ECBEDE3F5
153113a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB2653956~31bf3856ad364e35~amd64~~6.1.1.5.cat'; file='\Device\HarddiskVolume2\Windows\System32\imagehlp.dll'
153213a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
153313a8.fe0: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\imagehlp.dll'
153413a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000130 pwszName=\Device\HarddiskVolume2\Windows\System32\cryptbase.dll
153513a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ff4b0
153613a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ff4b0
153713a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=1B332BBD335EB2D5000C2255987CB8F1140EB342
153813a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_88_for_KB3126587~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\cryptbase.dll'
153913a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
154013a8.fe0: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\cryptbase.dll'
154113a8.fe0: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\rsaenh.dll'
154213a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000012c pwszName=\Device\HarddiskVolume2\Windows\System32\cryptsp.dll
154313a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ff4b0
154413a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ff4b0
154513a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=40667EDBA9045D4A4BE1D4844665D3B88F8CD0E0
154613a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\cryptsp.dll'
154713a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
154813a8.fe0: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\cryptsp.dll'
154913a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000120 pwszName=\Device\HarddiskVolume2\Windows\System32\sechost.dll
155013a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ff4b0
155113a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ff4b0
155213a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=3FA2A014BF360CDC0E203A174FFC9DC5343C5323
155313a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\sechost.dll'
155413a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
155513a8.fe0: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\sechost.dll'
155613a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000011c pwszName=\Device\HarddiskVolume2\Windows\System32\advapi32.dll
155713a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ff4b0
155813a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ff4b0
155913a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=1D906429F9D53CF720E851B490EC83BEAAF9B21A
156013a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_151_for_KB3126587~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\advapi32.dll'
156113a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
156213a8.fe0: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\advapi32.dll'
156313a8.fe0: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll'
156413a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000104 pwszName=\Device\HarddiskVolume2\Windows\System32\bcrypt.dll
156513a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ff4b0
156613a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ff4b0
156713a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=62E377A1F0AD0C2EDC0A73CB3EFF841FF18D00D2
156813a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\bcrypt.dll'
156913a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
157013a8.fe0: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\bcrypt.dll'
157113a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000e4 pwszName=\Device\HarddiskVolume2\Windows\System32\msvcrt.dll
157213a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ff4b0
157313a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ff4b0
157413a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2CA2FD632B264C063162F71474266E3615B6420C
157513a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB2654428~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\Windows\System32\msvcrt.dll'
157613a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
157713a8.fe0: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll'
157813a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000dc pwszName=\Device\HarddiskVolume2\Windows\System32\msasn1.dll
157913a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ff4b0
158013a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ff4b0
158113a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=F2FF57DC30D774F93061607060DAA0DD15E39CCE
158213a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\msasn1.dll'
158313a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
158413a8.fe0: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\msasn1.dll'
158513a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000d8 pwszName=\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
158613a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ff4b0
158713a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ff4b0
158813a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B7ADE500A5ED2DBC433C8ECAF28966675E5CFE36
158913a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_88_for_KB3126587~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll'
159013a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
159113a8.fe0: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll'
159213a8.fe0: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll'
159313a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000028 pwszName=\Device\HarddiskVolume2\Windows\System32\KernelBase.dll
159413a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ff4b0
159513a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ff4b0
159613a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=051C28F4FFE71436B92254D1A7955B1849CE5AA5
159713a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_88_for_KB3126587~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\KernelBase.dll'
159813a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
159913a8.fe0: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\KernelBase.dll'
160013a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000020 pwszName=\Device\HarddiskVolume2\Windows\System32\kernel32.dll
160113a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ff4b0
160213a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ff4b0
160313a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=AD27BC39174E86B1E177AF200D6BC895B032AB0E
160413a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_88_for_KB3126587~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\kernel32.dll'
160513a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
160613a8.fe0: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\kernel32.dll'
160713a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll
160813a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\crypt32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000018bd51:<flags> [calling]
160913a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd760000 'C:\Windows\system32\crypt32.dll'
161013a8.fe0: supR3HardenedWinIsDesiredRootCA: Adding 0x5ad46780fa5df300 DC=com, DC=microsoft, CN=Microsoft Root Certificate Authority
161113a8.fe0: supR3HardenedWinIsDesiredRootCA: Adding 0xea5386456178582b C=ZA, ST=Western Cape, L=Durbanville, O=Thawte, OU=Thawte Certification, CN=Thawte Timestamping CA
161213a8.fe0: supR3HardenedWinIsDesiredRootCA: Adding 0x3be670c1bd02a900 OU=Copyright (c) 1997 Microsoft Corp., OU=Microsoft Corporation, CN=Microsoft Root Authority
161313a8.fe0: supR3HardenedWinIsDesiredRootCA: Adding 0x4d3835aa4180b200 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2011
161413a8.fe0: supR3HardenedWinIsDesiredRootCA: Adding 0x646e3fe3ba08df00 C=US, O=MSFT, CN=Microsoft Authenticode(tm) Root Authority
161513a8.fe0: supR3HardenedWinIsDesiredRootCA: Adding 0xece4e4289e08b900 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010
161613a8.fe0: supR3HardenedWinIsDesiredRootCA: Adding 0x97edbd2d1165c200 O=AO Kaspersky Lab, CN=Kaspersky Anti-Virus Personal Root Certificate
161713a8.fe0: supR3HardenedWinIsDesiredRootCA: Adding 0x43a9cc371ff5385a O=Microsoft Trust Network, OU=Microsoft Corporation, OU=Microsoft Time Stamping Service Root, OU=Copyright (c) 1997 Microsoft Corp.
161813a8.fe0: supR3HardenedWinIsDesiredRootCA: Adding 0x2e2d2c7c68f0202e O=VeriSign Trust Network, OU=VeriSign, Inc., OU=VeriSign Time Stamping Service Root, OU=NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.
161913a8.fe0: supR3HardenedWinIsDesiredRootCA: Adding 0xd8dbfb2c27bfb200 C=US, O=thawte, Inc., OU=Certification Services Division, OU=(c) 2008 thawte, Inc. - For authorized use only, CN=thawte Primary Root CA - G3
162013a8.fe0: supR3HardenedWinIsDesiredRootCA: Adding 0x61a3a33f81aace00 C=US, ST=UT, L=Salt Lake City, O=The USERTRUST Network, OU=http://www.usertrust.com, CN=UTN-USERFirst-Object
162113a8.fe0: supR3HardenedWinIsDesiredRootCA: Adding 0x6b7bdc34cd37bb00 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root G2
162213a8.fe0: supR3HardenedWinIsDesiredRootCA: Adding 0xf4fd306318ccda00 C=US, O=GeoTrust Inc., CN=GeoTrust Global CA
162313a8.fe0: supR3HardenedWinIsDesiredRootCA: Adding 0x83085097e9afdf00 O=Digital Signature Trust Co., CN=DST Root CA X3
162413a8.fe0: supR3HardenedWinIsDesiredRootCA: Adding 0x780679907625cc00 OU=GlobalSign Root CA - R3, O=GlobalSign, CN=GlobalSign
162513a8.fe0: supR3HardenedWinIsDesiredRootCA: Adding 0x3d98ab22bb04a300 C=IE, O=Baltimore, OU=CyberTrust, CN=Baltimore CyberTrust Root
162613a8.fe0: supR3HardenedWinIsDesiredRootCA: Adding 0xa0ee62086758b15d C=US, O=Equifax, OU=Equifax Secure Certificate Authority
162713a8.fe0: supR3HardenedWinIsDesiredRootCA: Adding 0xd944bca189a00 C=BM, O=QuoVadis Limited, CN=QuoVadis Root CA 2
162813a8.fe0: supR3HardenedWinIsDesiredRootCA: Adding 0x8ff6fc03c1edbd00 C=US, ST=Arizona, L=Scottsdale, O=Starfield Technologies, Inc., CN=Starfield Root Certificate Authority - G2
162913a8.fe0: supR3HardenedWinIsDesiredRootCA: Adding 0xc6fa4243b695b600 C=US, O=Entrust, Inc., OU=www.entrust.net/CPS is incorporated by reference, OU=(c) 2006 Entrust, Inc., CN=Entrust Root Certification Authority
163013a8.fe0: supR3HardenedWinIsDesiredRootCA: Adding 0xa3ce8d99e60eda00 C=BE, O=GlobalSign nv-sa, OU=Root CA, CN=GlobalSign Root CA
163113a8.fe0: supR3HardenedWinIsDesiredRootCA: Adding 0x560ad29254e89100 C=GB, ST=Greater Manchester, L=Salford, O=COMODO CA Limited, CN=COMODO RSA Certification Authority
163213a8.fe0: supR3HardenedWinIsDesiredRootCA: Adding 0xa671e9fec832b700 C=US, O=Starfield Technologies, Inc., OU=Starfield Class 2 Certification Authority
163313a8.fe0: supR3HardenedWinIsDesiredRootCA: Adding 0xa8de7211e13be200 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root CA
163413a8.fe0: supR3HardenedWinIsDesiredRootCA: Adding 0x7ae89c50f0b6a00f C=US, O=GTE Corporation, OU=GTE CyberTrust Solutions, Inc., CN=GTE CyberTrust Global Root
163513a8.fe0: supR3HardenedWinIsDesiredRootCA: Adding 0x2fba703484f19900 C=DE, O=D-Trust GmbH, CN=D-TRUST Root Class 3 CA 2 EV 2009
163613a8.fe0: supR3HardenedWinIsDesiredRootCA: Adding 0xd45980fbf0a0ac00 C=US, O=thawte, Inc., OU=Certification Services Division, OU=(c) 2006 thawte, Inc. - For authorized use only, CN=thawte Primary Root CA
163713a8.fe0: supR3HardenedWinIsDesiredRootCA: Adding 0xc9edb72b684ba00 C=US, O=Entrust, Inc., OU=See www.entrust.net/legal-terms, OU=(c) 2009 Entrust, Inc. - for authorized use only, CN=Entrust Root Certification Authority - G2
163813a8.fe0: supR3HardenedWinIsDesiredRootCA: Adding 0xf5cd95e581a4ab00 C=US, O=SecureTrust Corporation, CN=SecureTrust CA
163913a8.fe0: supR3HardenedWinIsDesiredRootCA: Adding 0x298be035a30bab00 C=DE, O=Deutsche Telekom AG, OU=T-TeleSec Trust Center, CN=Deutsche Telekom Root CA 2
164013a8.fe0: supR3HardenedWinIsDesiredRootCA: Adding 0x6f2ebe0e24cfa600 OU=GlobalSign Root CA - R2, O=GlobalSign, CN=GlobalSign
164113a8.fe0: supR3HardenedWinIsDesiredRootCA: Adding 0x14018a1bf29e595c C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority
164213a8.fe0: supR3HardenedWinIsDesiredRootCA: Adding 0x9e5bc2d78b6a3636 C=ZA, ST=Western Cape, L=Cape Town, O=Thawte Consulting cc, OU=Certification Services Division, CN=Thawte Premium Server CA, Email=premium-server@thawte.com
164313a8.fe0: supR3HardenedWinIsDesiredRootCA: Adding 0x7c4fd32ec1b1ce00 C=PL, O=Unizeto Sp. z o.o., CN=Certum CA
164413a8.fe0: supR3HardenedWinIsDesiredRootCA: Adding 0xd4fbe673e5ccc600 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA
164513a8.fe0: supR3HardenedWinIsDesiredRootCA: Adding 0xef477acf4ab2d300 C=DE, O=D-Trust GmbH, CN=D-TRUST Root Class 3 CA 2 2009
164613a8.fe0: supR3HardenedWinIsDesiredRootCA: Adding 0xb28612a94b4dad00 O=Entrust.net, OU=www.entrust.net/CPS_2048 incorp. by ref. (limits liab.), OU=(c) 1999 Entrust.net Limited, CN=Entrust.net Certification Authority (2048)
164713a8.fe0: supR3HardenedWinIsDesiredRootCA: Adding 0x357a29080824af00 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2006 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G5
164813a8.fe0: supR3HardenedWinIsDesiredRootCA: Adding 0x59faf1086271bf00 C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com, Inc., CN=Go Daddy Root Certificate Authority - G2
164913a8.fe0: supR3HardenedWinIsDesiredRootCA: Adding 0x466cbc09db88c100 C=IL, O=StartCom Ltd., OU=Secure Digital Certificate Signing, CN=StartCom Certification Authority
165013a8.fe0: supR3HardenedWinIsDesiredRootCA: Adding 0xb16dd37ffeb3b300 C=JP, O=SECOM Trust.net, OU=Security Communication RootCA1
165113a8.fe0: supR3HardenedWinIsDesiredRootCA: Adding 0x3401b15e3761c700 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2008 VeriSign, Inc. - For authorized use only, CN=VeriSign Universal Root Certification Authority
165213a8.fe0: supR3HardenedWinIsDesiredRootCA: Adding 0x7cd4ff7b15b8be00 C=US, O=GeoTrust Inc., CN=GeoTrust Primary Certification Authority
165313a8.fe0: supR3HardenedWinIsDesiredRootCA: Adding 0x491857ead79dde00 C=US, O=The Go Daddy Group, Inc., OU=Go Daddy Class 2 Certification Authority
165413a8.fe0: supR3HardenedWinIsDesiredRootCA: Adding 0x1f78fc529cbacb00 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 1999 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G3
165513a8.fe0: supR3HardenedWinIsDesiredRootCA: Adding 0xdc1801b225aea100 C=BM, O=QuoVadis Limited, CN=QuoVadis Root CA 2 G3
165613a8.fe0: supR3HardenedWinIsDesiredRootCA: Adding 0xc2ba72a37dfbe300 C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Trusted Network CA
165713a8.fe0: supR3HardenedWinIsDesiredRootCA: Adding 0x8043e4ce150ead00 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID Root CA
165813a8.fe0: supR3HardenedWinIsDesiredRootCA: Adding 0x331d58625ee2dc00 C=US, O=GeoTrust Inc., OU=(c) 2008 GeoTrust Inc. - For authorized use only, CN=GeoTrust Primary Certification Authority - G3
165913a8.fe0: supR3HardenedWinIsDesiredRootCA: Adding 0xf2e6331af7b700 C=SE, O=AddTrust AB, OU=AddTrust External TTP Network, CN=AddTrust External CA Root
166013a8.fe0: supR3HardenedWinRetrieveTrustedRootCAs: cAdded=50
166113a8.fe0: SUPR3HardenedMain: Load Runtime...
166213a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
166313a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
166413a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ws2_32.dll'.
166513a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'rpcrt4.dll'.
166613a8.fe0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll) WinVerifyTrust
166713a8.fe0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
166813a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
166913a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
167013a8.fe0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
167113a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
167213a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
167313a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000003c0 pwszName=\Device\HarddiskVolume2\Windows\System32\ws2_32.dll
167413a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ff4b0
167513a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ff4b0
167613a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=901DCB8172024F14E25295BF5692180F12FC8C18
167713a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3161949~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\Windows\System32\ws2_32.dll'
167813a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
167913a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
168013a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'rpcrt4.dll'.
168113a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'nsi.dll'.
168213a8.fe0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ws2_32.dll) WinVerifyTrust
168313a8.fe0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
168413a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
168513a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
168613a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
168713a8.fe0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll) WinVerifyTrust
168813a8.fe0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
168913a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
169013a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
169113a8.fe0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll) WinVerifyTrust
169213a8.fe0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
169313a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
169413a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
169513a8.fe0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
169613a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
169713a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume2\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
169813a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000418 pwszName=\Device\HarddiskVolume2\Windows\System32\nsi.dll
169913a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ff4b0
170013a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ff4b0
170113a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=7AFD8538945F2D05BC1AF949B9B19B7D2D9FBBF8
170213a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\nsi.dll'
170313a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
170413a8.fe0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\nsi.dll) WinVerifyTrust
170513a8.fe0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\nsi.dll
170613a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
170713a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
170813a8.fe0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
170913a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
171013a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
171113a8.fe0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
171213a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000018c081:<flags> [calling]
171313a8.fe0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
171413a8.fe0: supR3HardenedDllNotificationCallback: load 000007fedeae0000 LB 0x00590000 C:\Program Files\Oracle\VirtualBox\VBoxRT.dll [fFlags=0x0]
171513a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
171613a8.fe0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
171713a8.fe0: supR3HardenedDllNotificationCallback: load 000000006d630000 LB 0x000d2000 C:\Program Files\Oracle\VirtualBox\MSVCR100.dll [fFlags=0x0]
171813a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
171913a8.fe0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
172013a8.fe0: supR3HardenedDllNotificationCallback: load 0000000066960000 LB 0x00098000 C:\Program Files\Oracle\VirtualBox\MSVCP100.dll [fFlags=0x0]
172113a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
172213a8.fe0: supR3HardenedDllNotificationCallback: load 000007fefdde0000 LB 0x0004d000 C:\Windows\system32\WS2_32.dll [fFlags=0x0]
172313a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
172413a8.fe0: supR3HardenedDllNotificationCallback: load 000007fefe330000 LB 0x00008000 C:\Windows\system32\NSI.dll [fFlags=0x0]
172513a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\nsi.dll
172613a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
172713a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001897c1:<flags> [calling]
172813a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fedeae0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
172913a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
173013a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001897c1:<flags> [calling]
173113a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fedeae0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
173213a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
173313a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001897c1:<flags> [calling]
173413a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fedeae0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
173513a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
173613a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001897c1:<flags> [calling]
173713a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fedeae0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
173813a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
173913a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001897c1:<flags> [calling]
174013a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fedeae0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
174113a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
174213a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001897c1:<flags> [calling]
174313a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fedeae0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
174413a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fedeae0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
174513a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fedeae0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
174613a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fedeae0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
174713a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fedeae0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
174813a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fedeae0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
174913a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fedeae0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
175013a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fedeae0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
175113a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
175213a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001897c1:<flags> [calling]
175313a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fedeae0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
175413a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fedeae0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
175513a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fedeae0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
175613a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fedeae0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
175713a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fedeae0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
175813a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fedeae0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
175913a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fedeae0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
176013a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fedeae0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
176113a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fedeae0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
176213a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fedeae0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
176313a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fedeae0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
176413a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fedeae0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
176513a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fedeae0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
176613a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fedeae0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
176713a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fedeae0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
176813a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fedeae0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
176913a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
177013a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000001897c1:<flags> [calling]
177113a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fedeae0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
177213a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fedeae0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
177313a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fedeae0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
177413a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fedeae0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
177513a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll
177613a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000018dbe1:<flags> [calling]
177713a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd720000 'C:\Windows\system32\Wintrust.dll'
177813a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll
177913a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\crypt32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000018c731:<flags> [calling]
178013a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd760000 'C:\Windows\system32\crypt32.dll'
178113a8.fe0: SUPR3HardenedMain: Load TrustedMain...
178213a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'opengl32.dll'.
178313a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
178413a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msvcp100.dll'.
178513a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcr100.dll'.
178613a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qt5corevbox.dll'.
178713a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'qt5guivbox.dll'.
178813a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'qt5widgetsvbox.dll'.
178913a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'qt5printsupportvbox.dll'.
179013a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'qt5openglvbox.dll'.
179113a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'user32.dll'.
179213a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'advapi32.dll'.
179313a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'shell32.dll'.
179413a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'ole32.dll'.
179513a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'oleaut32.dll'.
179613a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #15 'winmm.dll'.
179713a8.fe0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.dll) WinVerifyTrust
179813a8.fe0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.dll
179913a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
180013a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
180113a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000468 pwszName=\Device\HarddiskVolume2\Windows\System32\winmm.dll
180213a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ff4b0
180313a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ff4b0
180413a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=82E2B2A7826F88BEB98FFF0540C9BDB0A12F001A
180513a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\winmm.dll'
180613a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
180713a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
180813a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
180913a8.fe0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\winmm.dll) WinVerifyTrust
181013a8.fe0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\winmm.dll
181113a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
181213a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
181313a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000448 pwszName=\Device\HarddiskVolume2\Windows\System32\oleaut32.dll
181413a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ff4b0
181513a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ff4b0
181613a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=C1D7CC9111C6B5A59641FA11BE0A6A1841FEBBCD
181713a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB2564958~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\oleaut32.dll'
181813a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
181913a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ole32.dll'.
182013a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
182113a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
182213a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'user32.dll'.
182313a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'gdi32.dll'.
182413a8.fe0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\oleaut32.dll) WinVerifyTrust
182513a8.fe0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
182613a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
182713a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
182813a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000474 pwszName=\Device\HarddiskVolume2\Windows\System32\ole32.dll
182913a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ff4b0
183013a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ff4b0
183113a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2E64AE329BD5124592BC8CB0B327AA3B95DC65B7
183213a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\ole32.dll'
183313a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
183413a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
183513a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
183613a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'user32.dll'.
183713a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'rpcrt4.dll'.
183813a8.fe0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ole32.dll) WinVerifyTrust
183913a8.fe0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ole32.dll
184013a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
184113a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
184213a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000480 pwszName=\Device\HarddiskVolume2\Windows\System32\shell32.dll
184313a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ff4b0
184413a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ff4b0
184513a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=F13C2B4E594038A8834146A1D81AAE9B43ED8649
184613a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_41_for_KB3184143~31bf3856ad364e35~amd64~~6.1.1.4.cat'; file='\Device\HarddiskVolume2\Windows\System32\shell32.dll'
184713a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
184813a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
184913a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #21 'shlwapi.dll'.
185013a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'user32.dll'.
185113a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #24 'gdi32.dll'.
185213a8.fe0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\shell32.dll) WinVerifyTrust
185313a8.fe0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\shell32.dll
185413a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
185513a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
185613a8.fe0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
185713a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
185813a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
185913a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5openglvbox.dll'...
186013a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5openglvbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5openglvbox.dll' [rcNtRedir=0xc0150008]
186113a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'qt5widgetsvbox.dll'.
186213a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'qt5guivbox.dll'.
186313a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5corevbox.dll'.
186413a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcr100.dll'.
186513a8.fe0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll) WinVerifyTrust
186613a8.fe0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll
186713a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5printsupportvbox.dll'...
186813a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5printsupportvbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5printsupportvbox.dll' [rcNtRedir=0xc0150008]
186913a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
187013a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
187113a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5widgetsvbox.dll'.
187213a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qt5guivbox.dll'.
187313a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qt5corevbox.dll'.
187413a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'winspool.drv'.
187513a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'comdlg32.dll'.
187613a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'msvcr100.dll'.
187713a8.fe0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5PrintSupportVBox.dll) WinVerifyTrust
187813a8.fe0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5PrintSupportVBox.dll
187913a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
188013a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
188113a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
188213a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
188313a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5guivbox.dll'.
188413a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qt5corevbox.dll'.
188513a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'shell32.dll'.
188613a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcp100.dll'.
188713a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msvcr100.dll'.
188813a8.fe0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll) WinVerifyTrust
188913a8.fe0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll
189013a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
189113a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
189213a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ole32.dll'.
189313a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'opengl32.dll'.
189413a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
189513a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
189613a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qt5corevbox.dll'.
189713a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcp100.dll'.
189813a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msvcr100.dll'.
189913a8.fe0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll) WinVerifyTrust
190013a8.fe0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
190113a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
190213a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
190313a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
190413a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'shell32.dll'.
190513a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ole32.dll'.
190613a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
190713a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ws2_32.dll'.
190813a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'mpr.dll'.
190913a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'msvcp100.dll'.
191013a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'msvcr100.dll'.
191113a8.fe0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll) WinVerifyTrust
191213a8.fe0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
191313a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
191413a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
191513a8.fe0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
191613a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
191713a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
191813a8.fe0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
191913a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
192013a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
192113a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
192213a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
192313a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004a0 pwszName=\Device\HarddiskVolume2\Windows\System32\opengl32.dll
192413a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ff4b0
192513a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ff4b0
192613a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=608AC397FCC42B9FBAE25CB8C25EAF4C19AA384D
192713a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\opengl32.dll'
192813a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
192913a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
193013a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
193113a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'gdi32.dll'.
193213a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'glu32.dll'.
193313a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'ddraw.dll'.
193413a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'user32.dll'.
193513a8.fe0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\opengl32.dll) WinVerifyTrust
193613a8.fe0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\opengl32.dll
193713a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
193813a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
193913a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ddraw.dll'...
194013a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'ddraw.dll' -> '\Device\HarddiskVolume2\Windows\System32\ddraw.dll' [rcNtRedir=0xc0150008]
194113a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000494 pwszName=\Device\HarddiskVolume2\Windows\System32\ddraw.dll
194213a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ff4b0
194313a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ff4b0
194413a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=24C763EA54CD792A0F1618411061DC356EE31FF6
194513a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\ddraw.dll'
194613a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
194713a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
194813a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
194913a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'dciman32.dll'.
195013a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
195113a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'setupapi.dll'.
195213a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'dwmapi.dll'.
195313a8.fe0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ddraw.dll) WinVerifyTrust
195413a8.fe0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ddraw.dll
195513a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'glu32.dll'...
195613a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'glu32.dll' -> '\Device\HarddiskVolume2\Windows\System32\glu32.dll' [rcNtRedir=0xc0150008]
195713a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000049c pwszName=\Device\HarddiskVolume2\Windows\System32\glu32.dll
195813a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ff4b0
195913a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ff4b0
196013a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=60E45AB914E06A11F44EA76C6EF750AF892F9EA2
196113a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\glu32.dll'
196213a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
196313a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
196413a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'opengl32.dll'.
196513a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
196613a8.fe0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\glu32.dll) WinVerifyTrust
196713a8.fe0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\glu32.dll
196813a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
196913a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
197013a8.fe0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll
197113a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
197213a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
197313a8.fe0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
197413a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
197513a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
197613a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
197713a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
197813a8.fe0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
197913a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
198013a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
198113a8.fe0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
198213a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mpr.dll'...
198313a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'mpr.dll' -> '\Device\HarddiskVolume2\Windows\System32\mpr.dll' [rcNtRedir=0xc0150008]
198413a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004b0 pwszName=\Device\HarddiskVolume2\Windows\System32\mpr.dll
198513a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ff4b0
198613a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ff4b0
198713a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=F84FE9BA047B24E7694C9E0C349B48B9FD5F925B
198813a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\mpr.dll'
198913a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
199013a8.fe0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\mpr.dll) WinVerifyTrust
199113a8.fe0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\mpr.dll
199213a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
199313a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
199413a8.fe0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
199513a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
199613a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
199713a8.fe0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
199813a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
199913a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
200013a8.fe0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
200113a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
200213a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
200313a8.fe0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
200413a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
200513a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
200613a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
200713a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
200813a8.fe0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
200913a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
201013a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
201113a8.fe0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
201213a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
201313a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
201413a8.fe0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
201513a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
201613a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
201713a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
201813a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
201913a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
202013a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
202113a8.fe0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
202213a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
202313a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
202413a8.fe0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
202513a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
202613a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
202713a8.fe0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
202813a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
202913a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
203013a8.fe0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
203113a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
203213a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
203313a8.fe0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
203413a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
203513a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
203613a8.fe0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
203713a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
203813a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
203913a8.fe0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
204013a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
204113a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
204213a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
204313a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
204413a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
204513a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
204613a8.fe0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
204713a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comdlg32.dll'...
204813a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'comdlg32.dll' -> '\Device\HarddiskVolume2\Windows\System32\comdlg32.dll' [rcNtRedir=0xc0150008]
204913a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004bc pwszName=\Device\HarddiskVolume2\Windows\System32\comdlg32.dll
205013a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ff4b0
205113a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ff4b0
205213a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=66EE5BDFFA413AEA9E1FE7838A08646E94136DA5
205313a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\comdlg32.dll'
205413a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
205513a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
205613a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'shlwapi.dll'.
205713a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
205813a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'gdi32.dll'.
205913a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'comctl32.dll'.
206013a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'shell32.dll'.
206113a8.fe0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\comdlg32.dll) WinVerifyTrust
206213a8.fe0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\comdlg32.dll
206313a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winspool.drv'...
206413a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'winspool.drv' -> '\Device\HarddiskVolume2\Windows\System32\winspool.drv' [rcNtRedir=0xc0150008]
206513a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004c0 pwszName=\Device\HarddiskVolume2\Windows\System32\winspool.drv
206613a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ff4b0
206713a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ff4b0
206813a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=C89A2ED7B99A056D78CA6BAC9CCAB8B1FF119A14
206913a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\winspool.drv'
207013a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
207113a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
207213a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
207313a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
207413a8.fe0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\winspool.drv) WinVerifyTrust
207513a8.fe0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\winspool.drv
207613a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
207713a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
207813a8.fe0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
207913a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
208013a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
208113a8.fe0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
208213a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
208313a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
208413a8.fe0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll
208513a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
208613a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
208713a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
208813a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
208913a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
209013a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
209113a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
209213a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
209313a8.fe0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
209413a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
209513a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
209613a8.fe0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
209713a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
209813a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
209913a8.fe0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll
210013a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
210113a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
210213a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
210313a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
210413a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
210513a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
210613a8.fe0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll
210713a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
210813a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
210913a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
211013a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
211113a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
211213a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
211313a8.fe0: supR3HardenedScreenImage/Imports: cache hit (Unknown Status -22900 (0xffffa68c)) on \Device\HarddiskVolume2\Windows\System32\user32.dll
211413a8.fe0: Error (rc=0):
211513a8.fe0: supR3HardenedScreenImage/Imports: cached rc=Unknown Status -22900 (0xffffa68c) fImage=1 fProtect=0x0 fAccess=0x0 cHits=16 \Device\HarddiskVolume2\Windows\System32\user32.dll
211613a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
211713a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
211813a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
211913a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
212013a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
212113a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
212213a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
212313a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
212413a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
212513a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
212613a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
212713a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
212813a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
212913a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
213013a8.fe0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
213113a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
213213a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
213313a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
213413a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
213513a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
213613a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
213713a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
213813a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
213913a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
214013a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
214113a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
214213a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
214313a8.fe0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
214413a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comctl32.dll'...
214513a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'comctl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\comctl32.dll' [rcNtRedir=0x0]
214613a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004b8 pwszName=\Device\HarddiskVolume2\Windows\System32\comctl32.dll
214713a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ff4b0
214813a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ff4b0
214913a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=4D3B2DA266DE92D9E1311E30C810160CDC5BD5AA
215013a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\comctl32.dll'
215113a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
215213a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'advapi32.dll'.
215313a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
215413a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
215513a8.fe0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\comctl32.dll) WinVerifyTrust
215613a8.fe0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\comctl32.dll
215713a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
215813a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
215913a8.fe0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll
216013a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
216113a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
216213a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
216313a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
216413a8.fe0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll
216513a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
216613a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
216713a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
216813a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
216913a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
217013a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
217113a8.fe0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
217213a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
217313a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
217413a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dwmapi.dll'...
217513a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'dwmapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\dwmapi.dll' [rcNtRedir=0xc0150008]
217613a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000490 pwszName=\Device\HarddiskVolume2\Windows\System32\dwmapi.dll
217713a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ff4b0
217813a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ff4b0
217913a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B79EE7B5AD74EF51A849809202E043183A2C727E
218013a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\dwmapi.dll'
218113a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
218213a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
218313a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
218413a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
218513a8.fe0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\dwmapi.dll) WinVerifyTrust
218613a8.fe0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\dwmapi.dll
218713a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
218813a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
218913a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004c8 pwszName=\Device\HarddiskVolume2\Windows\System32\setupapi.dll
219013a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ff4b0
219113a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ff4b0
219213a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=1499C4FEA6E143F9BEC35B4FFA098917D3A6EBF2
219313a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\setupapi.dll'
219413a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
219513a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'cfgmgr32.dll'.
219613a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msvcrt.dll'.
219713a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'gdi32.dll'.
219813a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
219913a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'user32.dll'.
220013a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'oleaut32.dll'.
220113a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'devobj.dll'.
220213a8.fe0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\setupapi.dll) WinVerifyTrust
220313a8.fe0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\setupapi.dll
220413a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
220513a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
220613a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dciman32.dll'...
220713a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'dciman32.dll' -> '\Device\HarddiskVolume2\Windows\System32\dciman32.dll' [rcNtRedir=0xc0150008]
220813a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004d4 pwszName=\Device\HarddiskVolume2\Windows\System32\dciman32.dll
220913a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ff4b0
221013a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ff4b0
221113a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=D3FEC714D729F7CAEB9B7A25E2012B6A6E9007F5
221213a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\dciman32.dll'
221313a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
221413a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
221513a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'gdi32.dll'.
221613a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
221713a8.fe0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\dciman32.dll) WinVerifyTrust
221813a8.fe0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\dciman32.dll
221913a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
222013a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
222113a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
222213a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
222313a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
222413a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
222513a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
222613a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
222713a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
222813a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
222913a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'devobj.dll'...
223013a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'devobj.dll' -> '\Device\HarddiskVolume2\Windows\System32\devobj.dll' [rcNtRedir=0xc0150008]
223113a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000498 pwszName=\Device\HarddiskVolume2\Windows\System32\devobj.dll
223213a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ff4b0
223313a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ff4b0
223413a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B410A095222E69F0ECE7D66E4AC27A7125D2EB5A
223513a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\devobj.dll'
223613a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
223713a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
223813a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'cfgmgr32.dll'.
223913a8.fe0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\devobj.dll) WinVerifyTrust
224013a8.fe0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\devobj.dll
224113a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
224213a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
224313a8.fe0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
224413a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
224513a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
224613a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
224713a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
224813a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
224913a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
225013a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
225113a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
225213a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
225313a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
225413a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004e0 pwszName=\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll
225513a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ff4b0
225613a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ff4b0
225713a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=8F731777EFC4BC982C1E1467FBF29A74CC14D93A
225813a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll'
225913a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
226013a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
226113a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'rpcrt4.dll'.
226213a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
226313a8.fe0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll) WinVerifyTrust
226413a8.fe0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll
226513a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
226613a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
226713a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
226813a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
226913a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
227013a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
227113a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
227213a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
227313a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
227413a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
227513a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
227613a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
227713a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
227813a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
227913a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
228013a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
228113a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
228213a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
228313a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
228413a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
228513a8.fe0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll
228613a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
228713a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
228813a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VirtualBox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000018c091:<flags> [calling]
228913a8.fe0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.dll
229013a8.fe0: supR3HardenedDllNotificationCallback: load 000007fede0d0000 LB 0x00a06000 C:\Program Files\Oracle\VirtualBox\VirtualBox.dll [fFlags=0x0]
229113a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.dll
229213a8.fe0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
229313a8.fe0: supR3HardenedDllNotificationCallback: load 000007feddfb0000 LB 0x0011d000 C:\Windows\system32\OPENGL32.dll [fFlags=0x0]
229413a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
229513a8.fe0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\glu32.dll
229613a8.fe0: supR3HardenedDllNotificationCallback: load 000007fee1270000 LB 0x0002d000 C:\Windows\system32\GLU32.dll [fFlags=0x0]
229713a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\glu32.dll
229813a8.fe0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ddraw.dll
229913a8.fe0: supR3HardenedDllNotificationCallback: load 000007feddeb0000 LB 0x000f1000 C:\Windows\system32\DDRAW.dll [fFlags=0x0]
230013a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ddraw.dll
230113a8.fe0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dciman32.dll
230213a8.fe0: supR3HardenedDllNotificationCallback: load 000007fee4690000 LB 0x00008000 C:\Windows\system32\DCIMAN32.dll [fFlags=0x0]
230313a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dciman32.dll
230413a8.fe0: supR3HardenedDllNotificationCallback: load 000007fefde30000 LB 0x001d7000 C:\Windows\system32\SETUPAPI.dll [fFlags=0x0]
230513a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\setupapi.dll
230613a8.fe0: supR3HardenedDllNotificationCallback: load 000007fefd5b0000 LB 0x00036000 C:\Windows\system32\CFGMGR32.dll [fFlags=0x0]
230713a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll
230813a8.fe0: supR3HardenedDllNotificationCallback: load 000007fefe180000 LB 0x000d7000 C:\Windows\system32\OLEAUT32.dll [fFlags=0x0]
230913a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
231013a8.fe0: supR3HardenedDllNotificationCallback: load 000007fefdbd0000 LB 0x00203000 C:\Windows\system32\ole32.dll [fFlags=0x0]
231113a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
231213a8.fe0: supR3HardenedDllNotificationCallback: load 000007fefd700000 LB 0x0001a000 C:\Windows\system32\DEVOBJ.dll [fFlags=0x0]
231313a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\devobj.dll
231413a8.fe0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dwmapi.dll
231513a8.fe0: supR3HardenedDllNotificationCallback: load 000007fefb860000 LB 0x00018000 C:\Windows\system32\dwmapi.dll [fFlags=0x0]
231613a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dwmapi.dll
231713a8.fe0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
231813a8.fe0: supR3HardenedDllNotificationCallback: load 000000005a1f0000 LB 0x00565000 C:\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [fFlags=0x0]
231913a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
232013a8.fe0: supR3HardenedDllNotificationCallback: load 000007fefe8a0000 LB 0x00d8a000 C:\Windows\system32\SHELL32.dll [fFlags=0x0]
232113a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
232213a8.fe0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\mpr.dll
232313a8.fe0: supR3HardenedDllNotificationCallback: load 000007fefa890000 LB 0x00018000 C:\Windows\system32\MPR.dll [fFlags=0x0]
232413a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\mpr.dll
232513a8.fe0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
232613a8.fe0: supR3HardenedDllNotificationCallback: load 000007fedd8b0000 LB 0x005f7000 C:\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll [fFlags=0x0]
232713a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
232813a8.fe0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll
232913a8.fe0: supR3HardenedDllNotificationCallback: load 0000000057d50000 LB 0x00561000 C:\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll [fFlags=0x0]
233013a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll
233113a8.fe0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5PrintSupportVBox.dll
233213a8.fe0: supR3HardenedDllNotificationCallback: load 000007fedf660000 LB 0x00051000 C:\Program Files\Oracle\VirtualBox\Qt5PrintSupportVBox.dll [fFlags=0x0]
233313a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5PrintSupportVBox.dll
233413a8.fe0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winspool.drv
233513a8.fe0: supR3HardenedDllNotificationCallback: load 000007fef8120000 LB 0x00071000 C:\Windows\system32\WINSPOOL.DRV [fFlags=0x0]
233613a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winspool.drv
233713a8.fe0: supR3HardenedDllNotificationCallback: load 000007fefe800000 LB 0x00097000 C:\Windows\system32\COMDLG32.dll [fFlags=0x0]
233813a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\comdlg32.dll
233913a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'advapi32.dll'.
234013a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
234113a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
234213a8.fe0: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_a4d6a923711520a9\comctl32.dll)
234313a8.fe0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_a4d6a923711520a9\comctl32.dll
234413a8.fe0: supR3HardenedDllNotificationCallback: load 000007fefa8b0000 LB 0x000a0000 C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_a4d6a923711520a9\COMCTL32.dll [fFlags=0x0]
234513a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_a4d6a923711520a9\comctl32.dll [avoiding WinVerifyTrust]
234613a8.fe0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll
234713a8.fe0: supR3HardenedDllNotificationCallback: load 0000000066900000 LB 0x00054000 C:\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll [fFlags=0x0]
234813a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll
234913a8.fe0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
235013a8.fe0: supR3HardenedDllNotificationCallback: load 000007fefa520000 LB 0x0003b000 C:\Windows\system32\WINMM.dll [fFlags=0x0]
235113a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
235213a8.fe0: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume2\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_a4d6a923711520a9\comctl32.dll'.
235313a8.fe0: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_a4d6a923711520a9\comctl32.dll' [rescheduled]
235413a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\imm32.dll
235513a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
235613a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
235713a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
235813a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
235913a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
236013a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
236113a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\imm32.dll (Input=imm32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000018b661:<flags> [calling]
236213a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe300000 'C:\Windows\system32\imm32.dll'
236313a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff760000 'C:\Windows\system32\ADVAPI32.DLL'
236413a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cryptbase.dll
236513a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptbase.dll (Input=cryptbase.dll, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
236613a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd430000 'C:\Windows\system32\cryptbase.dll'
236713a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fede0d0000 'C:\Program Files\Oracle\VirtualBox\VirtualBox.dll'
236813a8.fe0: SUPR3HardenedMain: Calling TrustedMain (000007fede0d14f0)...
236913a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
237013a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ole32.dll (Input=ole32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000018d941:<flags> [calling]
237113a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdbd0000 'C:\Windows\system32\ole32.dll'
237213a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff760000 'C:\Windows\system32\ADVAPI32.dll'
237313a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\profapi.dll
237413a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\profapi.dll (Input=profapi.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000018c021:<flags> [calling]
237513a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd500000 'C:\Windows\system32\profapi.dll'
237613a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
237713a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'ole32.dll'.
237813a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
237913a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'imm32.dll'.
238013a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'winmm.dll'.
238113a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'oleaut32.dll'.
238213a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'shell32.dll'.
238313a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'advapi32.dll'.
238413a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'qt5guivbox.dll'.
238513a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'qt5corevbox.dll'.
238613a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'msvcr100.dll'.
238713a8.fe0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\platforms\qwindows.dll) WinVerifyTrust
238813a8.fe0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\platforms\qwindows.dll
238913a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
239013a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
239113a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
239213a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
239313a8.fe0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
239413a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
239513a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
239613a8.fe0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
239713a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
239813a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
239913a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
240013a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
240113a8.fe0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
240213a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
240313a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
240413a8.fe0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
240513a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
240613a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
240713a8.fe0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
240813a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
240913a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume2\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
241013a8.fe0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\imm32.dll
241113a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
241213a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
241313a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
241413a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
241513a8.fe0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
241613a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
241713a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
241813a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\platforms\qwindows.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000018e311:<flags> [calling]
241913a8.fe0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\platforms\qwindows.dll
242013a8.fe0: supR3HardenedDllNotificationCallback: load 000007fed9470000 LB 0x0012e000 C:\Program Files\Oracle\VirtualBox\platforms\qwindows.dll [fFlags=0x0]
242113a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\platforms\qwindows.dll
242213a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fed9470000 'C:\Program Files\Oracle\VirtualBox\platforms\qwindows.dll'
242313a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cryptbase.dll
242413a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTBASE.dll (Input=CRYPTBASE.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000018e241:<flags> [calling]
242513a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd430000 'C:\Windows\system32\CRYPTBASE.dll'
242613a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000570 pwszName=\Device\HarddiskVolume2\Windows\System32\uxtheme.dll
242713a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000007ff4b0
242813a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000007ff4b0
242913a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=936D45CC7026757A151F62882B557DD75D5FCB21
243013a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\uxtheme.dll'
243113a8.fe0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
243213a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
243313a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
243413a8.fe0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'gdi32.dll'.
243513a8.fe0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\uxtheme.dll) WinVerifyTrust
243613a8.fe0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
243713a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
243813a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
243913a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
244013a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
244113a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
244213a8.fe0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
244313a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000018dd11:<flags> [calling]
244413a8.fe0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
244513a8.fe0: supR3HardenedDllNotificationCallback: load 000007fefbc00000 LB 0x00056000 C:\Windows\system32\uxtheme.dll [fFlags=0x0]
244613a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
244713a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbc00000 'C:\Windows\system32\uxtheme.dll'
244813a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
244913a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000018d751:<flags> [calling]
245013a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbc00000 'C:\Windows\system32\uxtheme.dll'
245113a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
245213a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000018d4c1:<flags> [calling]
245313a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbc00000 'C:\Windows\system32\uxtheme.dll'
245413a8.fe0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
245513a8.fe0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000018d4c1:<flags> [calling]
245613a8.fe0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbc00000 'C:\Windows\system32\uxtheme.dll'
24571c4c.1fcc: supR3HardNtChildWaitFor[2]: Quitting: ExitCode=0x1 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 961 ms, the end);
24584e4.2630: supR3HardNtChildWaitFor[1]: Quitting: ExitCode=0x1 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 1580 ms, the end);

© 2024 Oracle Support Privacy / Do Not Sell My Info Terms of Use Trademark Policy Automated Access Etiquette