VirtualBox

Ticket #17684: VBoxHardening.log

File VBoxHardening.log, 346.4 KB (added by rafinnerty, 6 years ago)

VBoxHardening.log

Line 
1798.f6c: Log file opened: 5.2.8r121009 g_hStartupLog=000000000000006c g_uNtVerCombined=0xa03fab00
2798.f6c: \SystemRoot\System32\ntdll.dll:
3798.f6c: CreationTime: 2018-04-11T13:18:17.374861500Z
4798.f6c: LastWriteTime: 2018-03-13T07:02:15.839353900Z
5798.f6c: ChangeTime: 2018-04-11T14:16:47.914510200Z
6798.f6c: FileAttributes: 0x20
7798.f6c: Size: 0x1dd100
8798.f6c: NT Headers: 0xe0
9798.f6c: Timestamp: 0xe508fc03
10798.f6c: Machine: 0x8664 - amd64
11798.f6c: Timestamp: 0xe508fc03
12798.f6c: Image Version: 10.0
13798.f6c: SizeOfImage: 0x1e0000 (1966080)
14798.f6c: Resource Dir: 0x174000 LB 0x6a1d8
15798.f6c: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
16798.f6c: [Raw version resource data: 0x1740f0 LB 0x380, codepage 0x0 (reserved 0x0)]
17798.f6c: ProductName: Microsoft® Windows® Operating System
18798.f6c: ProductVersion: 10.0.16299.334
19798.f6c: FileVersion: 10.0.16299.334 (WinBuild.160101.0800)
20798.f6c: FileDescription: NT Layer DLL
21798.f6c: \SystemRoot\System32\kernel32.dll:
22798.f6c: CreationTime: 2017-09-29T13:42:04.954227600Z
23798.f6c: LastWriteTime: 2017-09-29T13:42:04.954227600Z
24798.f6c: ChangeTime: 2018-04-11T14:17:44.610006000Z
25798.f6c: FileAttributes: 0x20
26798.f6c: Size: 0xab868
27798.f6c: NT Headers: 0xe8
28798.f6c: Timestamp: 0xc2cf900
29798.f6c: Machine: 0x8664 - amd64
30798.f6c: Timestamp: 0xc2cf900
31798.f6c: Image Version: 10.0
32798.f6c: SizeOfImage: 0xae000 (712704)
33798.f6c: Resource Dir: 0xac000 LB 0x520
34798.f6c: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
35798.f6c: [Raw version resource data: 0xac0b0 LB 0x3a4, codepage 0x0 (reserved 0x0)]
36798.f6c: ProductName: Microsoft® Windows® Operating System
37798.f6c: ProductVersion: 10.0.16299.15
38798.f6c: FileVersion: 10.0.16299.15 (WinBuild.160101.0800)
39798.f6c: FileDescription: Windows NT BASE API Client DLL
40798.f6c: \SystemRoot\System32\KernelBase.dll:
41798.f6c: CreationTime: 2018-04-11T13:18:12.592545800Z
42798.f6c: LastWriteTime: 2018-03-30T05:08:26.893801200Z
43798.f6c: ChangeTime: 2018-04-11T14:17:47.885705500Z
44798.f6c: FileAttributes: 0x20
45798.f6c: Size: 0x265c00
46798.f6c: NT Headers: 0xf0
47798.f6c: Timestamp: 0x6369e29f
48798.f6c: Machine: 0x8664 - amd64
49798.f6c: Timestamp: 0x6369e29f
50798.f6c: Image Version: 10.0
51798.f6c: SizeOfImage: 0x266000 (2514944)
52798.f6c: Resource Dir: 0x245000 LB 0x548
53798.f6c: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
54798.f6c: [Raw version resource data: 0x2450b0 LB 0x3bc, codepage 0x0 (reserved 0x0)]
55798.f6c: ProductName: Microsoft® Windows® Operating System
56798.f6c: ProductVersion: 10.0.16299.371
57798.f6c: FileVersion: 10.0.16299.371 (WinBuild.160101.0800)
58798.f6c: FileDescription: Windows NT BASE API Client DLL
59798.f6c: \SystemRoot\System32\apisetschema.dll:
60798.f6c: CreationTime: 2017-09-29T13:42:07.095026600Z
61798.f6c: LastWriteTime: 2017-09-29T13:42:07.095026600Z
62798.f6c: ChangeTime: 2018-04-12T18:46:56.532224100Z
63798.f6c: FileAttributes: 0x20
64798.f6c: Size: 0x1b398
65798.f6c: NT Headers: 0xc8
66798.f6c: Timestamp: 0xf30abf31
67798.f6c: Machine: 0x8664 - amd64
68798.f6c: Timestamp: 0xf30abf31
69798.f6c: Image Version: 10.0
70798.f6c: SizeOfImage: 0x1c000 (114688)
71798.f6c: Resource Dir: 0x1b000 LB 0x408
72798.f6c: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
73798.f6c: [Raw version resource data: 0x1b060 LB 0x3a8, codepage 0x0 (reserved 0x0)]
74798.f6c: ProductName: Microsoft® Windows® Operating System
75798.f6c: ProductVersion: 10.0.16299.15
76798.f6c: FileVersion: 10.0.16299.15 (WinBuild.160101.0800)
77798.f6c: FileDescription: ApiSet Schema DLL
78798.f6c: NtOpenDirectoryObject failed on \Driver: 0xc0000022
79798.f6c: supR3HardenedWinFindAdversaries: 0x4
80798.f6c: \SystemRoot\System32\drivers\aswHwid.sys:
81798.f6c: CreationTime: 2018-04-10T14:29:19.657340600Z
82798.f6c: LastWriteTime: 2018-04-10T14:29:09.883548700Z
83798.f6c: ChangeTime: 2018-04-10T14:29:17.677979500Z
84798.f6c: FileAttributes: 0x20
85798.f6c: Size: 0xb778
86798.f6c: NT Headers: 0xf0
87798.f6c: Timestamp: 0x5ab01504
88798.f6c: Machine: 0x8664 - amd64
89798.f6c: Timestamp: 0x5ab01504
90798.f6c: Image Version: 6.0
91798.f6c: SizeOfImage: 0xa000 (40960)
92798.f6c: Resource Dir: 0x8000 LB 0x388
93798.f6c: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
94798.f6c: [Raw version resource data: 0x8060 LB 0x324, codepage 0x0 (reserved 0x0)]
95798.f6c: ProductName: Avast Antivirus
96798.f6c: ProductVersion: 18.3.3848.0
97798.f6c: FileVersion: 18.3.3848.0
98798.f6c: FileDescription: Avast HWID
99798.f6c: \SystemRoot\System32\drivers\aswMonFlt.sys:
100798.f6c: CreationTime: 2018-04-10T14:29:19.660341900Z
101798.f6c: LastWriteTime: 2018-04-12T18:29:27.419544000Z
102798.f6c: ChangeTime: 2018-04-12T18:29:27.419544000Z
103798.f6c: FileAttributes: 0x20
104798.f6c: Size: 0x23f18
105798.f6c: NT Headers: 0xe0
106798.f6c: Timestamp: 0x5acc4cc6
107798.f6c: Machine: 0x8664 - amd64
108798.f6c: Timestamp: 0x5acc4cc6
109798.f6c: Image Version: 6.0
110798.f6c: SizeOfImage: 0x28000 (163840)
111798.f6c: Resource Dir: 0x26000 LB 0x3b8
112798.f6c: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
113798.f6c: [Raw version resource data: 0x26060 LB 0x354, codepage 0x0 (reserved 0x0)]
114798.f6c: ProductName: Avast Antivirus
115798.f6c: ProductVersion: 18.3.3860.315
116798.f6c: FileVersion: 18.3.3860.315
117798.f6c: FileDescription: Avast File System Minifilter for Windows 2003/Vista
118798.f6c: \SystemRoot\System32\drivers\aswRdr2.sys:
119798.f6c: CreationTime: 2018-04-10T14:29:19.651340300Z
120798.f6c: LastWriteTime: 2018-04-10T14:29:09.495929000Z
121798.f6c: ChangeTime: 2018-04-10T14:29:17.677979500Z
122798.f6c: FileAttributes: 0x20
123798.f6c: Size: 0x1b2f8
124798.f6c: NT Headers: 0xe8
125798.f6c: Timestamp: 0x5ab0151a
126798.f6c: Machine: 0x8664 - amd64
127798.f6c: Timestamp: 0x5ab0151a
128798.f6c: Image Version: 6.1
129798.f6c: SizeOfImage: 0x1a000 (106496)
130798.f6c: Resource Dir: 0x18000 LB 0x398
131798.f6c: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
132798.f6c: [Raw version resource data: 0x18060 LB 0x334, codepage 0x0 (reserved 0x0)]
133798.f6c: ProductName: Avast Antivirus
134798.f6c: ProductVersion: 18.3.3848.0
135798.f6c: FileVersion: 18.3.3848.0 built by: WinDDK
136798.f6c: FileDescription: Avast WFP Redirect Driver
137798.f6c: \SystemRoot\System32\drivers\aswRvrt.sys:
138798.f6c: CreationTime: 2018-04-10T14:29:19.663341600Z
139798.f6c: LastWriteTime: 2018-04-10T14:29:09.971060300Z
140798.f6c: ChangeTime: 2018-04-10T14:29:17.678980200Z
141798.f6c: FileAttributes: 0x20
142798.f6c: Size: 0x14990
143798.f6c: NT Headers: 0xe0
144798.f6c: Timestamp: 0x5ab01509
145798.f6c: Machine: 0x8664 - amd64
146798.f6c: Timestamp: 0x5ab01509
147798.f6c: Image Version: 6.0
148798.f6c: SizeOfImage: 0x13000 (77824)
149798.f6c: Resource Dir: 0x11000 LB 0x388
150798.f6c: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
151798.f6c: [Raw version resource data: 0x11060 LB 0x328, codepage 0x0 (reserved 0x0)]
152798.f6c: ProductName: Avast Antivirus
153798.f6c: ProductVersion: 18.3.3848.0
154798.f6c: FileVersion: 18.3.3848.0
155798.f6c: FileDescription: Avast Revert
156798.f6c: \SystemRoot\System32\drivers\aswSnx.sys:
157798.f6c: CreationTime: 2018-04-10T14:29:19.647339900Z
158798.f6c: LastWriteTime: 2018-04-10T14:28:52.602921100Z
159798.f6c: ChangeTime: 2018-04-10T14:29:17.678980200Z
160798.f6c: FileAttributes: 0x20
161798.f6c: Size: 0xfaa88
162798.f6c: NT Headers: 0xe8
163798.f6c: Timestamp: 0x5ab01532
164798.f6c: Machine: 0x8664 - amd64
165798.f6c: Timestamp: 0x5ab01532
166798.f6c: Image Version: 6.0
167798.f6c: SizeOfImage: 0xf8000 (1015808)
168798.f6c: Resource Dir: 0xf0000 LB 0x378
169798.f6c: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
170798.f6c: [Raw version resource data: 0xf0060 LB 0x314, codepage 0x0 (reserved 0x0)]
171798.f6c: ProductName: Avast Antivirus
172798.f6c: ProductVersion: 18.3.3848.0
173798.f6c: FileVersion: 18.3.3848.0
174798.f6c: FileDescription: Avast Virtualization Driver
175798.f6c: \SystemRoot\System32\drivers\aswsp.sys:
176798.f6c: CreationTime: 2018-04-10T14:29:19.666341600Z
177798.f6c: LastWriteTime: 2018-04-10T14:29:10.031568000Z
178798.f6c: ChangeTime: 2018-04-10T14:29:17.678980200Z
179798.f6c: FileAttributes: 0x20
180798.f6c: Size: 0x706e8
181798.f6c: NT Headers: 0xe0
182798.f6c: Timestamp: 0x5ab01527
183798.f6c: Machine: 0x8664 - amd64
184798.f6c: Timestamp: 0x5ab01527
185798.f6c: Image Version: 6.0
186798.f6c: SizeOfImage: 0x72000 (466944)
187798.f6c: Resource Dir: 0x70000 LB 0x370
188798.f6c: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
189798.f6c: [Raw version resource data: 0x70060 LB 0x310, codepage 0x0 (reserved 0x0)]
190798.f6c: ProductName: Avast Antivirus
191798.f6c: ProductVersion: 18.3.3848.0
192798.f6c: FileVersion: 18.3.3848.0
193798.f6c: FileDescription: Avast self protection module
194798.f6c: \SystemRoot\System32\drivers\aswStm.sys:
195798.f6c: CreationTime: 2018-04-10T14:29:19.672342400Z
196798.f6c: LastWriteTime: 2018-04-10T14:29:10.356890200Z
197798.f6c: ChangeTime: 2018-04-10T14:29:17.679979600Z
198798.f6c: FileAttributes: 0x20
199798.f6c: Size: 0x32498
200798.f6c: NT Headers: 0x110
201798.f6c: Timestamp: 0x5ab019af
202798.f6c: Machine: 0x8664 - amd64
203798.f6c: Timestamp: 0x5ab019af
204798.f6c: Image Version: 10.0
205798.f6c: SizeOfImage: 0x33000 (208896)
206798.f6c: Resource Dir: 0x31000 LB 0x350
207798.f6c: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x405)]
208798.f6c: [Raw version resource data: 0x31060 LB 0x2f0, codepage 0x0 (reserved 0x0)]
209798.f6c: ProductName: Avast Antivirus
210798.f6c: ProductVersion: 18.3.3848.0
211798.f6c: FileVersion: 18.3.3848.0
212798.f6c: FileDescription: Stream Filter
213798.f6c: \SystemRoot\System32\drivers\aswVmm.sys:
214798.f6c: CreationTime: 2018-04-10T14:29:19.669342100Z
215798.f6c: LastWriteTime: 2018-04-10T14:29:10.107077500Z
216798.f6c: ChangeTime: 2018-04-10T14:29:17.679979600Z
217798.f6c: FileAttributes: 0x20
218798.f6c: Size: 0x5ce70
219798.f6c: NT Headers: 0xe8
220798.f6c: Timestamp: 0x5ab0150d
221798.f6c: Machine: 0x8664 - amd64
222798.f6c: Timestamp: 0x5ab0150d
223798.f6c: Image Version: 6.0
224798.f6c: SizeOfImage: 0x5b000 (372736)
225798.f6c: Resource Dir: 0x58000 LB 0x390
226798.f6c: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
227798.f6c: [Raw version resource data: 0x58060 LB 0x330, codepage 0x0 (reserved 0x0)]
228798.f6c: ProductName: Avast Antivirus
229798.f6c: ProductVersion: 18.3.3848.0
230798.f6c: FileVersion: 18.3.3848.0
231798.f6c: FileDescription: Avast VM Monitor
232798.f6c: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
233798.f6c: Calling main()
234798.f6c: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
235798.f6c: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
236798.f6c: SUPR3HardenedMain: Respawn #1
237798.f6c: System32: \Device\HarddiskVolume2\Windows\System32
238798.f6c: WinSxS: \Device\HarddiskVolume2\Windows\WinSxS
239798.f6c: KnownDllPath: C:\WINDOWS\System32
240798.f6c: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
241798.f6c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe)
242798.f6c: supR3HardNtEnableThreadCreation:
243798.f6c: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffbe9c19280 pvNtTerminateThread=00007ffbe9c40d10
244798.f6c: supR3HardenedWinDoReSpawn(1): New child 14c.1da8 [kernel32].
245798.f6c: supR3HardNtChildGatherData: PebBaseAddress=0000000000651000 cbPeb=0x388
246798.f6c: supR3HardNtPuChFindNtdll: uNtDllParentAddr=00007ffbe9ba0000 uNtDllChildAddr=00007ffbe9ba0000
247798.f6c: supR3HardenedWinSetupChildInit: uLdrInitThunk=00007ffbe9c19280
248798.f6c: supR3HardenedWinSetupChildInit: Start child.
249798.f6c: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
250798.f6c: supR3HardNtChildPurify: Startup delay kludge #1/0: 517 ms, 55 sleeps
251798.f6c: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
252798.f6c: *0000000000000000-000000000056ffff 0x0001/0x0000 0x0000000
253798.f6c: *0000000000570000-000000000058ffff 0x0004/0x0004 0x0020000
254798.f6c: *0000000000590000-00000000005a8fff 0x0002/0x0002 0x0040000
255798.f6c: 00000000005a9000-00000000005affff 0x0001/0x0000 0x0000000
256798.f6c: *00000000005b0000-00000000005b3fff 0x0002/0x0002 0x0040000
257798.f6c: 00000000005b4000-00000000005bffff 0x0001/0x0000 0x0000000
258798.f6c: *00000000005c0000-00000000005c0fff 0x0004/0x0004 0x0020000
259798.f6c: 00000000005c1000-00000000005fffff 0x0001/0x0000 0x0000000
260798.f6c: *0000000000600000-0000000000650fff 0x0000/0x0004 0x0020000
261798.f6c: 0000000000651000-0000000000653fff 0x0004/0x0004 0x0020000
262798.f6c: 0000000000654000-00000000007fffff 0x0000/0x0004 0x0020000
263798.f6c: *0000000000800000-00000000008fafff 0x0000/0x0004 0x0020000
264798.f6c: 00000000008fb000-00000000008fdfff 0x0104/0x0004 0x0020000
265798.f6c: 00000000008fe000-00000000008fffff 0x0004/0x0004 0x0020000
266798.f6c: 0000000000900000-000000007ffdffff 0x0001/0x0000 0x0000000
267798.f6c: *000000007ffe0000-000000007ffe0fff 0x0002/0x0002 0x0020000
268798.f6c: *000000007ffe1000-000000007ffeffff 0x0000/0x0002 0x0020000
269798.f6c: 000000007fff0000-00007ff68bb1ffff 0x0001/0x0000 0x0000000
270798.f6c: *00007ff68bb20000-00007ff68bb42fff 0x0002/0x0002 0x0040000
271798.f6c: 00007ff68bb43000-00007ff68bceffff 0x0001/0x0000 0x0000000
272798.f6c: *00007ff68bcf0000-00007ff68bcf0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
273798.f6c: 00007ff68bcf1000-00007ff68bd61fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
274798.f6c: 00007ff68bd62000-00007ff68bd62fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
275798.f6c: 00007ff68bd63000-00007ff68bda8fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
276798.f6c: 00007ff68bda9000-00007ff68bda9fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
277798.f6c: 00007ff68bdaa000-00007ff68bdaafff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
278798.f6c: 00007ff68bdab000-00007ff68bdaffff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
279798.f6c: 00007ff68bdb0000-00007ff68bdb0fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
280798.f6c: 00007ff68bdb1000-00007ff68bdb1fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
281798.f6c: 00007ff68bdb2000-00007ff68bdb5fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
282798.f6c: 00007ff68bdb6000-00007ff68bdfdfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
283798.f6c: 00007ff68bdfe000-00007ffbe9b9ffff 0x0001/0x0000 0x0000000
284798.f6c: *00007ffbe9ba0000-00007ffbe9ba0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
285798.f6c: 00007ffbe9ba1000-00007ffbe9cb2fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
286798.f6c: 00007ffbe9cb3000-00007ffbe9cf8fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
287798.f6c: 00007ffbe9cf9000-00007ffbe9d00fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
288798.f6c: 00007ffbe9d01000-00007ffbe9d0efff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
289798.f6c: 00007ffbe9d0f000-00007ffbe9d0ffff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
290798.f6c: 00007ffbe9d10000-00007ffbe9d12fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
291798.f6c: 00007ffbe9d13000-00007ffbe9d7ffff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
292798.f6c: 00007ffbe9d80000-00007ffffffdffff 0x0001/0x0000 0x0000000
293798.f6c: *00007ffffffe0000-00007ffffffeffff 0x0001/0x0002 0x0020000
294798.f6c: VirtualBox.exe: timestamp 0x5a942b95 (rc=VINF_SUCCESS)
295798.f6c: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
296798.f6c: '\Device\HarddiskVolume2\Windows\System32\ntdll.dll' has no imports
297798.f6c: supR3HardNtChildPurify: Done after 543 ms and 0 fixes (loop #0).
29814c.1da8: Log file opened: 5.2.8r121009 g_hStartupLog=0000000000000004 g_uNtVerCombined=0xa03fab00
29914c.1da8: supR3HardenedVmProcessInit: uNtDllAddr=00007ffbe9ba0000 g_uNtVerCombined=0xa03fab00
300798.f6c: supR3HardNtEnableThreadCreation:
30114c.1da8: ntdll.dll: timestamp 0xe508fc03 (rc=VINF_SUCCESS)
30214c.1da8: New simple heap: #1 0000000000a00000 LB 0x400000 (for 1966080 allocation)
30314c.1da8: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
30414c.1da8: System32: \Device\HarddiskVolume2\Windows\System32
30514c.1da8: WinSxS: \Device\HarddiskVolume2\Windows\WinSxS
30614c.1da8: KnownDllPath: C:\WINDOWS\System32
30714c.1da8: supR3HardenedVmProcessInit: Opening vboxdrv stub...
30814c.1da8: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
30914c.1da8: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
31014c.1da8: Registered Dll notification callback with NTDLL.
31114c.1da8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\kernel32.dll)
31214c.1da8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\kernel32.dll
31314c.1da8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\KERNEL32.DLL (Input=KERNEL32.DLL, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000004001:<flags> [calling]
31414c.1da8: supR3HardenedDllNotificationCallback: load 00007ffbe65e0000 LB 0x00266000 C:\WINDOWS\System32\KERNELBASE.dll [fFlags=0x0]
31514c.1da8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\KernelBase.dll)
31614c.1da8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\KernelBase.dll
31714c.1da8: supR3HardenedDllNotificationCallback: load 00007ffbe99b0000 LB 0x000ae000 C:\WINDOWS\System32\KERNEL32.DLL [fFlags=0x0]
31814c.1da8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
31914c.1da8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe99b0000 'C:\WINDOWS\System32\KERNEL32.DLL'
32014c.1da8: supR3HardenedDllNotificationCallback: load 00007ff68bcf0000 LB 0x0010e000 C:\Program Files\Oracle\VirtualBox\VirtualBox.exe [fFlags=0x0]
32114c.1da8: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
32214c.1da8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe)
32314c.1da8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
32414c.1da8: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffbe9c19280 pvNtTerminateThread=00007ffbe9c40d10
325798.f6c: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 78 ms.
32614c.1da8: \SystemRoot\System32\ntdll.dll:
32714c.1da8: CreationTime: 2018-04-11T13:18:17.374861500Z
32814c.1da8: LastWriteTime: 2018-03-13T07:02:15.839353900Z
32914c.1da8: ChangeTime: 2018-04-11T14:16:47.914510200Z
33014c.1da8: FileAttributes: 0x20
33114c.1da8: Size: 0x1dd100
33214c.1da8: NT Headers: 0xe0
33314c.1da8: Timestamp: 0xe508fc03
33414c.1da8: Machine: 0x8664 - amd64
33514c.1da8: Timestamp: 0xe508fc03
33614c.1da8: Image Version: 10.0
33714c.1da8: SizeOfImage: 0x1e0000 (1966080)
33814c.1da8: Resource Dir: 0x174000 LB 0x6a1d8
33914c.1da8: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
34014c.1da8: [Raw version resource data: 0x1740f0 LB 0x380, codepage 0x0 (reserved 0x0)]
34114c.1da8: ProductName: Microsoft® Windows® Operating System
34214c.1da8: ProductVersion: 10.0.16299.334
34314c.1da8: FileVersion: 10.0.16299.334 (WinBuild.160101.0800)
34414c.1da8: FileDescription: NT Layer DLL
34514c.1da8: \SystemRoot\System32\kernel32.dll:
34614c.1da8: CreationTime: 2017-09-29T13:42:04.954227600Z
34714c.1da8: LastWriteTime: 2017-09-29T13:42:04.954227600Z
34814c.1da8: ChangeTime: 2018-04-11T14:17:44.610006000Z
34914c.1da8: FileAttributes: 0x20
35014c.1da8: Size: 0xab868
35114c.1da8: NT Headers: 0xe8
35214c.1da8: Timestamp: 0xc2cf900
35314c.1da8: Machine: 0x8664 - amd64
35414c.1da8: Timestamp: 0xc2cf900
35514c.1da8: Image Version: 10.0
35614c.1da8: SizeOfImage: 0xae000 (712704)
35714c.1da8: Resource Dir: 0xac000 LB 0x520
35814c.1da8: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
35914c.1da8: [Raw version resource data: 0xac0b0 LB 0x3a4, codepage 0x0 (reserved 0x0)]
36014c.1da8: ProductName: Microsoft® Windows® Operating System
36114c.1da8: ProductVersion: 10.0.16299.15
36214c.1da8: FileVersion: 10.0.16299.15 (WinBuild.160101.0800)
36314c.1da8: FileDescription: Windows NT BASE API Client DLL
36414c.1da8: \SystemRoot\System32\KernelBase.dll:
36514c.1da8: CreationTime: 2018-04-11T13:18:12.592545800Z
36614c.1da8: LastWriteTime: 2018-03-30T05:08:26.893801200Z
36714c.1da8: ChangeTime: 2018-04-11T14:17:47.885705500Z
36814c.1da8: FileAttributes: 0x20
36914c.1da8: Size: 0x265c00
37014c.1da8: NT Headers: 0xf0
37114c.1da8: Timestamp: 0x6369e29f
37214c.1da8: Machine: 0x8664 - amd64
37314c.1da8: Timestamp: 0x6369e29f
37414c.1da8: Image Version: 10.0
37514c.1da8: SizeOfImage: 0x266000 (2514944)
37614c.1da8: Resource Dir: 0x245000 LB 0x548
37714c.1da8: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
37814c.1da8: [Raw version resource data: 0x2450b0 LB 0x3bc, codepage 0x0 (reserved 0x0)]
37914c.1da8: ProductName: Microsoft® Windows® Operating System
38014c.1da8: ProductVersion: 10.0.16299.371
38114c.1da8: FileVersion: 10.0.16299.371 (WinBuild.160101.0800)
38214c.1da8: FileDescription: Windows NT BASE API Client DLL
38314c.1da8: \SystemRoot\System32\apisetschema.dll:
38414c.1da8: CreationTime: 2017-09-29T13:42:07.095026600Z
38514c.1da8: LastWriteTime: 2017-09-29T13:42:07.095026600Z
38614c.1da8: ChangeTime: 2018-04-12T18:46:56.532224100Z
38714c.1da8: FileAttributes: 0x20
38814c.1da8: Size: 0x1b398
38914c.1da8: NT Headers: 0xc8
39014c.1da8: Timestamp: 0xf30abf31
39114c.1da8: Machine: 0x8664 - amd64
39214c.1da8: Timestamp: 0xf30abf31
39314c.1da8: Image Version: 10.0
39414c.1da8: SizeOfImage: 0x1c000 (114688)
39514c.1da8: Resource Dir: 0x1b000 LB 0x408
39614c.1da8: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
39714c.1da8: [Raw version resource data: 0x1b060 LB 0x3a8, codepage 0x0 (reserved 0x0)]
39814c.1da8: ProductName: Microsoft® Windows® Operating System
39914c.1da8: ProductVersion: 10.0.16299.15
40014c.1da8: FileVersion: 10.0.16299.15 (WinBuild.160101.0800)
40114c.1da8: FileDescription: ApiSet Schema DLL
40214c.1da8: NtOpenDirectoryObject failed on \Driver: 0xc0000022
40314c.1da8: supR3HardenedWinFindAdversaries: 0x4
40414c.1da8: \SystemRoot\System32\drivers\aswHwid.sys:
40514c.1da8: CreationTime: 2018-04-10T14:29:19.657340600Z
40614c.1da8: LastWriteTime: 2018-04-10T14:29:09.883548700Z
40714c.1da8: ChangeTime: 2018-04-10T14:29:17.677979500Z
40814c.1da8: FileAttributes: 0x20
40914c.1da8: Size: 0xb778
41014c.1da8: NT Headers: 0xf0
41114c.1da8: Timestamp: 0x5ab01504
41214c.1da8: Machine: 0x8664 - amd64
41314c.1da8: Timestamp: 0x5ab01504
41414c.1da8: Image Version: 6.0
41514c.1da8: SizeOfImage: 0xa000 (40960)
41614c.1da8: Resource Dir: 0x8000 LB 0x388
41714c.1da8: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
41814c.1da8: [Raw version resource data: 0x8060 LB 0x324, codepage 0x0 (reserved 0x0)]
41914c.1da8: ProductName: Avast Antivirus
42014c.1da8: ProductVersion: 18.3.3848.0
42114c.1da8: FileVersion: 18.3.3848.0
42214c.1da8: FileDescription: Avast HWID
42314c.1da8: \SystemRoot\System32\drivers\aswMonFlt.sys:
42414c.1da8: CreationTime: 2018-04-10T14:29:19.660341900Z
42514c.1da8: LastWriteTime: 2018-04-12T18:29:27.419544000Z
42614c.1da8: ChangeTime: 2018-04-12T18:29:27.419544000Z
42714c.1da8: FileAttributes: 0x20
42814c.1da8: Size: 0x23f18
42914c.1da8: NT Headers: 0xe0
43014c.1da8: Timestamp: 0x5acc4cc6
43114c.1da8: Machine: 0x8664 - amd64
43214c.1da8: Timestamp: 0x5acc4cc6
43314c.1da8: Image Version: 6.0
43414c.1da8: SizeOfImage: 0x28000 (163840)
43514c.1da8: Resource Dir: 0x26000 LB 0x3b8
43614c.1da8: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
43714c.1da8: [Raw version resource data: 0x26060 LB 0x354, codepage 0x0 (reserved 0x0)]
43814c.1da8: ProductName: Avast Antivirus
43914c.1da8: ProductVersion: 18.3.3860.315
44014c.1da8: FileVersion: 18.3.3860.315
44114c.1da8: FileDescription: Avast File System Minifilter for Windows 2003/Vista
44214c.1da8: \SystemRoot\System32\drivers\aswRdr2.sys:
44314c.1da8: CreationTime: 2018-04-10T14:29:19.651340300Z
44414c.1da8: LastWriteTime: 2018-04-10T14:29:09.495929000Z
44514c.1da8: ChangeTime: 2018-04-10T14:29:17.677979500Z
44614c.1da8: FileAttributes: 0x20
44714c.1da8: Size: 0x1b2f8
44814c.1da8: NT Headers: 0xe8
44914c.1da8: Timestamp: 0x5ab0151a
45014c.1da8: Machine: 0x8664 - amd64
45114c.1da8: Timestamp: 0x5ab0151a
45214c.1da8: Image Version: 6.1
45314c.1da8: SizeOfImage: 0x1a000 (106496)
45414c.1da8: Resource Dir: 0x18000 LB 0x398
45514c.1da8: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
45614c.1da8: [Raw version resource data: 0x18060 LB 0x334, codepage 0x0 (reserved 0x0)]
45714c.1da8: ProductName: Avast Antivirus
45814c.1da8: ProductVersion: 18.3.3848.0
45914c.1da8: FileVersion: 18.3.3848.0 built by: WinDDK
46014c.1da8: FileDescription: Avast WFP Redirect Driver
46114c.1da8: \SystemRoot\System32\drivers\aswRvrt.sys:
46214c.1da8: CreationTime: 2018-04-10T14:29:19.663341600Z
46314c.1da8: LastWriteTime: 2018-04-10T14:29:09.971060300Z
46414c.1da8: ChangeTime: 2018-04-10T14:29:17.678980200Z
46514c.1da8: FileAttributes: 0x20
46614c.1da8: Size: 0x14990
46714c.1da8: NT Headers: 0xe0
46814c.1da8: Timestamp: 0x5ab01509
46914c.1da8: Machine: 0x8664 - amd64
47014c.1da8: Timestamp: 0x5ab01509
47114c.1da8: Image Version: 6.0
47214c.1da8: SizeOfImage: 0x13000 (77824)
47314c.1da8: Resource Dir: 0x11000 LB 0x388
47414c.1da8: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
47514c.1da8: [Raw version resource data: 0x11060 LB 0x328, codepage 0x0 (reserved 0x0)]
47614c.1da8: ProductName: Avast Antivirus
47714c.1da8: ProductVersion: 18.3.3848.0
47814c.1da8: FileVersion: 18.3.3848.0
47914c.1da8: FileDescription: Avast Revert
48014c.1da8: \SystemRoot\System32\drivers\aswSnx.sys:
48114c.1da8: CreationTime: 2018-04-10T14:29:19.647339900Z
48214c.1da8: LastWriteTime: 2018-04-10T14:28:52.602921100Z
48314c.1da8: ChangeTime: 2018-04-10T14:29:17.678980200Z
48414c.1da8: FileAttributes: 0x20
48514c.1da8: Size: 0xfaa88
48614c.1da8: NT Headers: 0xe8
48714c.1da8: Timestamp: 0x5ab01532
48814c.1da8: Machine: 0x8664 - amd64
48914c.1da8: Timestamp: 0x5ab01532
49014c.1da8: Image Version: 6.0
49114c.1da8: SizeOfImage: 0xf8000 (1015808)
49214c.1da8: Resource Dir: 0xf0000 LB 0x378
49314c.1da8: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
49414c.1da8: [Raw version resource data: 0xf0060 LB 0x314, codepage 0x0 (reserved 0x0)]
49514c.1da8: ProductName: Avast Antivirus
49614c.1da8: ProductVersion: 18.3.3848.0
49714c.1da8: FileVersion: 18.3.3848.0
49814c.1da8: FileDescription: Avast Virtualization Driver
49914c.1da8: \SystemRoot\System32\drivers\aswsp.sys:
50014c.1da8: CreationTime: 2018-04-10T14:29:19.666341600Z
50114c.1da8: LastWriteTime: 2018-04-10T14:29:10.031568000Z
50214c.1da8: ChangeTime: 2018-04-10T14:29:17.678980200Z
50314c.1da8: FileAttributes: 0x20
50414c.1da8: Size: 0x706e8
50514c.1da8: NT Headers: 0xe0
50614c.1da8: Timestamp: 0x5ab01527
50714c.1da8: Machine: 0x8664 - amd64
50814c.1da8: Timestamp: 0x5ab01527
50914c.1da8: Image Version: 6.0
51014c.1da8: SizeOfImage: 0x72000 (466944)
51114c.1da8: Resource Dir: 0x70000 LB 0x370
51214c.1da8: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
51314c.1da8: [Raw version resource data: 0x70060 LB 0x310, codepage 0x0 (reserved 0x0)]
51414c.1da8: ProductName: Avast Antivirus
51514c.1da8: ProductVersion: 18.3.3848.0
51614c.1da8: FileVersion: 18.3.3848.0
51714c.1da8: FileDescription: Avast self protection module
51814c.1da8: \SystemRoot\System32\drivers\aswStm.sys:
51914c.1da8: CreationTime: 2018-04-10T14:29:19.672342400Z
52014c.1da8: LastWriteTime: 2018-04-10T14:29:10.356890200Z
52114c.1da8: ChangeTime: 2018-04-10T14:29:17.679979600Z
52214c.1da8: FileAttributes: 0x20
52314c.1da8: Size: 0x32498
52414c.1da8: NT Headers: 0x110
52514c.1da8: Timestamp: 0x5ab019af
52614c.1da8: Machine: 0x8664 - amd64
52714c.1da8: Timestamp: 0x5ab019af
52814c.1da8: Image Version: 10.0
52914c.1da8: SizeOfImage: 0x33000 (208896)
53014c.1da8: Resource Dir: 0x31000 LB 0x350
53114c.1da8: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x405)]
53214c.1da8: [Raw version resource data: 0x31060 LB 0x2f0, codepage 0x0 (reserved 0x0)]
53314c.1da8: ProductName: Avast Antivirus
53414c.1da8: ProductVersion: 18.3.3848.0
53514c.1da8: FileVersion: 18.3.3848.0
53614c.1da8: FileDescription: Stream Filter
53714c.1da8: \SystemRoot\System32\drivers\aswVmm.sys:
53814c.1da8: CreationTime: 2018-04-10T14:29:19.669342100Z
53914c.1da8: LastWriteTime: 2018-04-10T14:29:10.107077500Z
54014c.1da8: ChangeTime: 2018-04-10T14:29:17.679979600Z
54114c.1da8: FileAttributes: 0x20
54214c.1da8: Size: 0x5ce70
54314c.1da8: NT Headers: 0xe8
54414c.1da8: Timestamp: 0x5ab0150d
54514c.1da8: Machine: 0x8664 - amd64
54614c.1da8: Timestamp: 0x5ab0150d
54714c.1da8: Image Version: 6.0
54814c.1da8: SizeOfImage: 0x5b000 (372736)
54914c.1da8: Resource Dir: 0x58000 LB 0x390
55014c.1da8: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
55114c.1da8: [Raw version resource data: 0x58060 LB 0x330, codepage 0x0 (reserved 0x0)]
55214c.1da8: ProductName: Avast Antivirus
55314c.1da8: ProductVersion: 18.3.3848.0
55414c.1da8: FileVersion: 18.3.3848.0
55514c.1da8: FileDescription: Avast VM Monitor
55614c.1da8: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
55714c.1da8: Calling main()
55814c.1da8: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
55914c.1da8: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
56014c.1da8: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
56114c.1da8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe)
56214c.1da8: SUPR3HardenedMain: Respawn #2
56314c.1da8: supR3HardNtEnableThreadCreation:
56414c.1da8: '\Device\HarddiskVolume2\Windows\System32\ntdll.dll' has no imports
56514c.1da8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ntdll.dll)
56614c.1da8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ntdll.dll
56714c.1da8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\ntdll.dll (Input=ntdll.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
56814c.1da8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe9ba0000 'C:\WINDOWS\System32\ntdll.dll'
56914c.1da8: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffbe9c19280 pvNtTerminateThread=00007ffbe9c40d10
57014c.1da8: supR3HardenedWinDoReSpawn(2): New child 1cf0.41c [kernel32].
57114c.1da8: supR3HardenedWinReSpawn: NtSetInformationThread/ThreadHideFromDebugger failed: 0xc0000022 (harmless)
57214c.1da8: supR3HardNtChildGatherData: PebBaseAddress=00000000004ae000 cbPeb=0x388
57314c.1da8: supR3HardNtPuChFindNtdll: uNtDllParentAddr=00007ffbe9ba0000 uNtDllChildAddr=00007ffbe9ba0000
57414c.1da8: supR3HardenedWinSetupChildInit: uLdrInitThunk=00007ffbe9c19280
57514c.1da8: supR3HardenedWinSetupChildInit: Start child.
57614c.1da8: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
57714c.1da8: supR3HardNtChildPurify: Startup delay kludge #1/0: 515 ms, 45 sleeps
57814c.1da8: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
57914c.1da8: *0000000000000000-000000000020ffff 0x0001/0x0000 0x0000000
58014c.1da8: *0000000000210000-000000000022ffff 0x0004/0x0004 0x0020000
58114c.1da8: *0000000000230000-0000000000248fff 0x0002/0x0002 0x0040000
58214c.1da8: 0000000000249000-000000000024ffff 0x0001/0x0000 0x0000000
58314c.1da8: *0000000000250000-000000000034afff 0x0000/0x0004 0x0020000
58414c.1da8: 000000000034b000-000000000034dfff 0x0104/0x0004 0x0020000
58514c.1da8: 000000000034e000-000000000034ffff 0x0004/0x0004 0x0020000
58614c.1da8: *0000000000350000-0000000000353fff 0x0002/0x0002 0x0040000
58714c.1da8: 0000000000354000-000000000035ffff 0x0001/0x0000 0x0000000
58814c.1da8: *0000000000360000-0000000000360fff 0x0004/0x0004 0x0020000
58914c.1da8: 0000000000361000-00000000003fffff 0x0001/0x0000 0x0000000
59014c.1da8: *0000000000400000-00000000004adfff 0x0000/0x0004 0x0020000
59114c.1da8: 00000000004ae000-00000000004b0fff 0x0004/0x0004 0x0020000
59214c.1da8: 00000000004b1000-00000000005fffff 0x0000/0x0004 0x0020000
59314c.1da8: 0000000000600000-000000007ffdffff 0x0001/0x0000 0x0000000
59414c.1da8: *000000007ffe0000-000000007ffe0fff 0x0002/0x0002 0x0020000
59514c.1da8: *000000007ffe1000-000000007ffeffff 0x0000/0x0002 0x0020000
59614c.1da8: 000000007fff0000-00007ff68b91ffff 0x0001/0x0000 0x0000000
59714c.1da8: *00007ff68b920000-00007ff68b942fff 0x0002/0x0002 0x0040000
59814c.1da8: 00007ff68b943000-00007ff68bceffff 0x0001/0x0000 0x0000000
59914c.1da8: *00007ff68bcf0000-00007ff68bcf0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
60014c.1da8: 00007ff68bcf1000-00007ff68bd61fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
60114c.1da8: 00007ff68bd62000-00007ff68bd62fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
60214c.1da8: 00007ff68bd63000-00007ff68bda8fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
60314c.1da8: 00007ff68bda9000-00007ff68bda9fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
60414c.1da8: 00007ff68bdaa000-00007ff68bdaafff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
60514c.1da8: 00007ff68bdab000-00007ff68bdaffff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
60614c.1da8: 00007ff68bdb0000-00007ff68bdb0fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
60714c.1da8: 00007ff68bdb1000-00007ff68bdb1fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
60814c.1da8: 00007ff68bdb2000-00007ff68bdb5fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
60914c.1da8: 00007ff68bdb6000-00007ff68bdfdfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
61014c.1da8: 00007ff68bdfe000-00007ffbe9b9ffff 0x0001/0x0000 0x0000000
61114c.1da8: *00007ffbe9ba0000-00007ffbe9ba0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
61214c.1da8: 00007ffbe9ba1000-00007ffbe9cb2fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
61314c.1da8: 00007ffbe9cb3000-00007ffbe9cf8fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
61414c.1da8: 00007ffbe9cf9000-00007ffbe9d00fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
61514c.1da8: 00007ffbe9d01000-00007ffbe9d0efff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
61614c.1da8: 00007ffbe9d0f000-00007ffbe9d0ffff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
61714c.1da8: 00007ffbe9d10000-00007ffbe9d12fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
61814c.1da8: 00007ffbe9d13000-00007ffbe9d7ffff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
61914c.1da8: 00007ffbe9d80000-00007ffffffdffff 0x0001/0x0000 0x0000000
62014c.1da8: *00007ffffffe0000-00007ffffffeffff 0x0001/0x0002 0x0020000
62114c.1da8: VirtualBox.exe: timestamp 0x5a942b95 (rc=VINF_SUCCESS)
62214c.1da8: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
62314c.1da8: '\Device\HarddiskVolume2\Windows\System32\ntdll.dll' has no imports
62414c.1da8: supR3HardNtChildPurify: Done after 547 ms and 0 fixes (loop #0).
62514c.1da8: supR3HardenedEarlyCompact: Removed heap 1 (0x00000000a00000 LB 0x400000)
6261cf0.41c: Log file opened: 5.2.8r121009 g_hStartupLog=0000000000000004 g_uNtVerCombined=0xa03fab00
62714c.1da8: supR3HardNtEnableThreadCreation:
6281cf0.41c: supR3HardenedVmProcessInit: uNtDllAddr=00007ffbe9ba0000 g_uNtVerCombined=0xa03fab00
6291cf0.41c: ntdll.dll: timestamp 0xe508fc03 (rc=VINF_SUCCESS)
6301cf0.41c: New simple heap: #1 0000000000700000 LB 0x400000 (for 1966080 allocation)
6311cf0.41c: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
6321cf0.41c: System32: \Device\HarddiskVolume2\Windows\System32
6331cf0.41c: WinSxS: \Device\HarddiskVolume2\Windows\WinSxS
6341cf0.41c: KnownDllPath: C:\WINDOWS\System32
6351cf0.41c: supR3HardenedVmProcessInit: Opening vboxdrv...
6361cf0.41c: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
6371cf0.41c: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
6381cf0.41c: Registered Dll notification callback with NTDLL.
6391cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\kernel32.dll)
6401cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\kernel32.dll
6411cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\KERNEL32.DLL (Input=KERNEL32.DLL, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000004001:<flags> [calling]
6421cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbe65e0000 LB 0x00266000 C:\WINDOWS\System32\KERNELBASE.dll [fFlags=0x0]
6431cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\KernelBase.dll)
6441cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\KernelBase.dll
6451cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbe99b0000 LB 0x000ae000 C:\WINDOWS\System32\KERNEL32.DLL [fFlags=0x0]
6461cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
6471cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe99b0000 'C:\WINDOWS\System32\KERNEL32.DLL'
6481cf0.41c: supR3HardenedDllNotificationCallback: load 00007ff68bcf0000 LB 0x0010e000 C:\Program Files\Oracle\VirtualBox\VirtualBox.exe [fFlags=0x0]
6491cf0.41c: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
6501cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe)
6511cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
6521cf0.41c: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffbe9c19280 pvNtTerminateThread=00007ffbe9c40d10
65314c.1da8: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 86 ms.
6541cf0.41c: \SystemRoot\System32\ntdll.dll:
6551cf0.41c: CreationTime: 2018-04-11T13:18:17.374861500Z
6561cf0.41c: LastWriteTime: 2018-03-13T07:02:15.839353900Z
6571cf0.41c: ChangeTime: 2018-04-11T14:16:47.914510200Z
6581cf0.41c: FileAttributes: 0x20
6591cf0.41c: Size: 0x1dd100
6601cf0.41c: NT Headers: 0xe0
6611cf0.41c: Timestamp: 0xe508fc03
6621cf0.41c: Machine: 0x8664 - amd64
6631cf0.41c: Timestamp: 0xe508fc03
6641cf0.41c: Image Version: 10.0
6651cf0.41c: SizeOfImage: 0x1e0000 (1966080)
6661cf0.41c: Resource Dir: 0x174000 LB 0x6a1d8
6671cf0.41c: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
6681cf0.41c: [Raw version resource data: 0x1740f0 LB 0x380, codepage 0x0 (reserved 0x0)]
6691cf0.41c: ProductName: Microsoft® Windows® Operating System
6701cf0.41c: ProductVersion: 10.0.16299.334
6711cf0.41c: FileVersion: 10.0.16299.334 (WinBuild.160101.0800)
6721cf0.41c: FileDescription: NT Layer DLL
6731cf0.41c: \SystemRoot\System32\kernel32.dll:
6741cf0.41c: CreationTime: 2017-09-29T13:42:04.954227600Z
6751cf0.41c: LastWriteTime: 2017-09-29T13:42:04.954227600Z
6761cf0.41c: ChangeTime: 2018-04-11T14:17:44.610006000Z
6771cf0.41c: FileAttributes: 0x20
6781cf0.41c: Size: 0xab868
6791cf0.41c: NT Headers: 0xe8
6801cf0.41c: Timestamp: 0xc2cf900
6811cf0.41c: Machine: 0x8664 - amd64
6821cf0.41c: Timestamp: 0xc2cf900
6831cf0.41c: Image Version: 10.0
6841cf0.41c: SizeOfImage: 0xae000 (712704)
6851cf0.41c: Resource Dir: 0xac000 LB 0x520
6861cf0.41c: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
6871cf0.41c: [Raw version resource data: 0xac0b0 LB 0x3a4, codepage 0x0 (reserved 0x0)]
6881cf0.41c: ProductName: Microsoft® Windows® Operating System
6891cf0.41c: ProductVersion: 10.0.16299.15
6901cf0.41c: FileVersion: 10.0.16299.15 (WinBuild.160101.0800)
6911cf0.41c: FileDescription: Windows NT BASE API Client DLL
6921cf0.41c: \SystemRoot\System32\KernelBase.dll:
6931cf0.41c: CreationTime: 2018-04-11T13:18:12.592545800Z
6941cf0.41c: LastWriteTime: 2018-03-30T05:08:26.893801200Z
6951cf0.41c: ChangeTime: 2018-04-11T14:17:47.885705500Z
6961cf0.41c: FileAttributes: 0x20
6971cf0.41c: Size: 0x265c00
6981cf0.41c: NT Headers: 0xf0
6991cf0.41c: Timestamp: 0x6369e29f
7001cf0.41c: Machine: 0x8664 - amd64
7011cf0.41c: Timestamp: 0x6369e29f
7021cf0.41c: Image Version: 10.0
7031cf0.41c: SizeOfImage: 0x266000 (2514944)
7041cf0.41c: Resource Dir: 0x245000 LB 0x548
7051cf0.41c: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
7061cf0.41c: [Raw version resource data: 0x2450b0 LB 0x3bc, codepage 0x0 (reserved 0x0)]
7071cf0.41c: ProductName: Microsoft® Windows® Operating System
7081cf0.41c: ProductVersion: 10.0.16299.371
7091cf0.41c: FileVersion: 10.0.16299.371 (WinBuild.160101.0800)
7101cf0.41c: FileDescription: Windows NT BASE API Client DLL
7111cf0.41c: \SystemRoot\System32\apisetschema.dll:
7121cf0.41c: CreationTime: 2017-09-29T13:42:07.095026600Z
7131cf0.41c: LastWriteTime: 2017-09-29T13:42:07.095026600Z
7141cf0.41c: ChangeTime: 2018-04-12T18:46:56.532224100Z
7151cf0.41c: FileAttributes: 0x20
7161cf0.41c: Size: 0x1b398
7171cf0.41c: NT Headers: 0xc8
7181cf0.41c: Timestamp: 0xf30abf31
7191cf0.41c: Machine: 0x8664 - amd64
7201cf0.41c: Timestamp: 0xf30abf31
7211cf0.41c: Image Version: 10.0
7221cf0.41c: SizeOfImage: 0x1c000 (114688)
7231cf0.41c: Resource Dir: 0x1b000 LB 0x408
7241cf0.41c: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
7251cf0.41c: [Raw version resource data: 0x1b060 LB 0x3a8, codepage 0x0 (reserved 0x0)]
7261cf0.41c: ProductName: Microsoft® Windows® Operating System
7271cf0.41c: ProductVersion: 10.0.16299.15
7281cf0.41c: FileVersion: 10.0.16299.15 (WinBuild.160101.0800)
7291cf0.41c: FileDescription: ApiSet Schema DLL
7301cf0.41c: NtOpenDirectoryObject failed on \Driver: 0xc0000022
7311cf0.41c: supR3HardenedWinFindAdversaries: 0x4
7321cf0.41c: \SystemRoot\System32\drivers\aswHwid.sys:
7331cf0.41c: CreationTime: 2018-04-10T14:29:19.657340600Z
7341cf0.41c: LastWriteTime: 2018-04-10T14:29:09.883548700Z
7351cf0.41c: ChangeTime: 2018-04-10T14:29:17.677979500Z
7361cf0.41c: FileAttributes: 0x20
7371cf0.41c: Size: 0xb778
7381cf0.41c: NT Headers: 0xf0
7391cf0.41c: Timestamp: 0x5ab01504
7401cf0.41c: Machine: 0x8664 - amd64
7411cf0.41c: Timestamp: 0x5ab01504
7421cf0.41c: Image Version: 6.0
7431cf0.41c: SizeOfImage: 0xa000 (40960)
7441cf0.41c: Resource Dir: 0x8000 LB 0x388
7451cf0.41c: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
7461cf0.41c: [Raw version resource data: 0x8060 LB 0x324, codepage 0x0 (reserved 0x0)]
7471cf0.41c: ProductName: Avast Antivirus
7481cf0.41c: ProductVersion: 18.3.3848.0
7491cf0.41c: FileVersion: 18.3.3848.0
7501cf0.41c: FileDescription: Avast HWID
7511cf0.41c: \SystemRoot\System32\drivers\aswMonFlt.sys:
7521cf0.41c: CreationTime: 2018-04-10T14:29:19.660341900Z
7531cf0.41c: LastWriteTime: 2018-04-12T18:29:27.419544000Z
7541cf0.41c: ChangeTime: 2018-04-12T18:29:27.419544000Z
7551cf0.41c: FileAttributes: 0x20
7561cf0.41c: Size: 0x23f18
7571cf0.41c: NT Headers: 0xe0
7581cf0.41c: Timestamp: 0x5acc4cc6
7591cf0.41c: Machine: 0x8664 - amd64
7601cf0.41c: Timestamp: 0x5acc4cc6
7611cf0.41c: Image Version: 6.0
7621cf0.41c: SizeOfImage: 0x28000 (163840)
7631cf0.41c: Resource Dir: 0x26000 LB 0x3b8
7641cf0.41c: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
7651cf0.41c: [Raw version resource data: 0x26060 LB 0x354, codepage 0x0 (reserved 0x0)]
7661cf0.41c: ProductName: Avast Antivirus
7671cf0.41c: ProductVersion: 18.3.3860.315
7681cf0.41c: FileVersion: 18.3.3860.315
7691cf0.41c: FileDescription: Avast File System Minifilter for Windows 2003/Vista
7701cf0.41c: \SystemRoot\System32\drivers\aswRdr2.sys:
7711cf0.41c: CreationTime: 2018-04-10T14:29:19.651340300Z
7721cf0.41c: LastWriteTime: 2018-04-10T14:29:09.495929000Z
7731cf0.41c: ChangeTime: 2018-04-10T14:29:17.677979500Z
7741cf0.41c: FileAttributes: 0x20
7751cf0.41c: Size: 0x1b2f8
7761cf0.41c: NT Headers: 0xe8
7771cf0.41c: Timestamp: 0x5ab0151a
7781cf0.41c: Machine: 0x8664 - amd64
7791cf0.41c: Timestamp: 0x5ab0151a
7801cf0.41c: Image Version: 6.1
7811cf0.41c: SizeOfImage: 0x1a000 (106496)
7821cf0.41c: Resource Dir: 0x18000 LB 0x398
7831cf0.41c: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
7841cf0.41c: [Raw version resource data: 0x18060 LB 0x334, codepage 0x0 (reserved 0x0)]
7851cf0.41c: ProductName: Avast Antivirus
7861cf0.41c: ProductVersion: 18.3.3848.0
7871cf0.41c: FileVersion: 18.3.3848.0 built by: WinDDK
7881cf0.41c: FileDescription: Avast WFP Redirect Driver
7891cf0.41c: \SystemRoot\System32\drivers\aswRvrt.sys:
7901cf0.41c: CreationTime: 2018-04-10T14:29:19.663341600Z
7911cf0.41c: LastWriteTime: 2018-04-10T14:29:09.971060300Z
7921cf0.41c: ChangeTime: 2018-04-10T14:29:17.678980200Z
7931cf0.41c: FileAttributes: 0x20
7941cf0.41c: Size: 0x14990
7951cf0.41c: NT Headers: 0xe0
7961cf0.41c: Timestamp: 0x5ab01509
7971cf0.41c: Machine: 0x8664 - amd64
7981cf0.41c: Timestamp: 0x5ab01509
7991cf0.41c: Image Version: 6.0
8001cf0.41c: SizeOfImage: 0x13000 (77824)
8011cf0.41c: Resource Dir: 0x11000 LB 0x388
8021cf0.41c: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
8031cf0.41c: [Raw version resource data: 0x11060 LB 0x328, codepage 0x0 (reserved 0x0)]
8041cf0.41c: ProductName: Avast Antivirus
8051cf0.41c: ProductVersion: 18.3.3848.0
8061cf0.41c: FileVersion: 18.3.3848.0
8071cf0.41c: FileDescription: Avast Revert
8081cf0.41c: \SystemRoot\System32\drivers\aswSnx.sys:
8091cf0.41c: CreationTime: 2018-04-10T14:29:19.647339900Z
8101cf0.41c: LastWriteTime: 2018-04-10T14:28:52.602921100Z
8111cf0.41c: ChangeTime: 2018-04-10T14:29:17.678980200Z
8121cf0.41c: FileAttributes: 0x20
8131cf0.41c: Size: 0xfaa88
8141cf0.41c: NT Headers: 0xe8
8151cf0.41c: Timestamp: 0x5ab01532
8161cf0.41c: Machine: 0x8664 - amd64
8171cf0.41c: Timestamp: 0x5ab01532
8181cf0.41c: Image Version: 6.0
8191cf0.41c: SizeOfImage: 0xf8000 (1015808)
8201cf0.41c: Resource Dir: 0xf0000 LB 0x378
8211cf0.41c: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
8221cf0.41c: [Raw version resource data: 0xf0060 LB 0x314, codepage 0x0 (reserved 0x0)]
8231cf0.41c: ProductName: Avast Antivirus
8241cf0.41c: ProductVersion: 18.3.3848.0
8251cf0.41c: FileVersion: 18.3.3848.0
8261cf0.41c: FileDescription: Avast Virtualization Driver
8271cf0.41c: \SystemRoot\System32\drivers\aswsp.sys:
8281cf0.41c: CreationTime: 2018-04-10T14:29:19.666341600Z
8291cf0.41c: LastWriteTime: 2018-04-10T14:29:10.031568000Z
8301cf0.41c: ChangeTime: 2018-04-10T14:29:17.678980200Z
8311cf0.41c: FileAttributes: 0x20
8321cf0.41c: Size: 0x706e8
8331cf0.41c: NT Headers: 0xe0
8341cf0.41c: Timestamp: 0x5ab01527
8351cf0.41c: Machine: 0x8664 - amd64
8361cf0.41c: Timestamp: 0x5ab01527
8371cf0.41c: Image Version: 6.0
8381cf0.41c: SizeOfImage: 0x72000 (466944)
8391cf0.41c: Resource Dir: 0x70000 LB 0x370
8401cf0.41c: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
8411cf0.41c: [Raw version resource data: 0x70060 LB 0x310, codepage 0x0 (reserved 0x0)]
8421cf0.41c: ProductName: Avast Antivirus
8431cf0.41c: ProductVersion: 18.3.3848.0
8441cf0.41c: FileVersion: 18.3.3848.0
8451cf0.41c: FileDescription: Avast self protection module
8461cf0.41c: \SystemRoot\System32\drivers\aswStm.sys:
8471cf0.41c: CreationTime: 2018-04-10T14:29:19.672342400Z
8481cf0.41c: LastWriteTime: 2018-04-10T14:29:10.356890200Z
8491cf0.41c: ChangeTime: 2018-04-10T14:29:17.679979600Z
8501cf0.41c: FileAttributes: 0x20
8511cf0.41c: Size: 0x32498
8521cf0.41c: NT Headers: 0x110
8531cf0.41c: Timestamp: 0x5ab019af
8541cf0.41c: Machine: 0x8664 - amd64
8551cf0.41c: Timestamp: 0x5ab019af
8561cf0.41c: Image Version: 10.0
8571cf0.41c: SizeOfImage: 0x33000 (208896)
8581cf0.41c: Resource Dir: 0x31000 LB 0x350
8591cf0.41c: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x405)]
8601cf0.41c: [Raw version resource data: 0x31060 LB 0x2f0, codepage 0x0 (reserved 0x0)]
8611cf0.41c: ProductName: Avast Antivirus
8621cf0.41c: ProductVersion: 18.3.3848.0
8631cf0.41c: FileVersion: 18.3.3848.0
8641cf0.41c: FileDescription: Stream Filter
8651cf0.41c: \SystemRoot\System32\drivers\aswVmm.sys:
8661cf0.41c: CreationTime: 2018-04-10T14:29:19.669342100Z
8671cf0.41c: LastWriteTime: 2018-04-10T14:29:10.107077500Z
8681cf0.41c: ChangeTime: 2018-04-10T14:29:17.679979600Z
8691cf0.41c: FileAttributes: 0x20
8701cf0.41c: Size: 0x5ce70
8711cf0.41c: NT Headers: 0xe8
8721cf0.41c: Timestamp: 0x5ab0150d
8731cf0.41c: Machine: 0x8664 - amd64
8741cf0.41c: Timestamp: 0x5ab0150d
8751cf0.41c: Image Version: 6.0
8761cf0.41c: SizeOfImage: 0x5b000 (372736)
8771cf0.41c: Resource Dir: 0x58000 LB 0x390
8781cf0.41c: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
8791cf0.41c: [Raw version resource data: 0x58060 LB 0x330, codepage 0x0 (reserved 0x0)]
8801cf0.41c: ProductName: Avast Antivirus
8811cf0.41c: ProductVersion: 18.3.3848.0
8821cf0.41c: FileVersion: 18.3.3848.0
8831cf0.41c: FileDescription: Avast VM Monitor
8841cf0.41c: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
8851cf0.41c: Calling main()
8861cf0.41c: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
8871cf0.41c: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
8881cf0.41c: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
8891cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe)
8901cf0.41c: SUPR3HardenedMain: Final process, opening VBoxDrv...
8911cf0.41c: supR3HardenedEarlyCompact: Removed heap 1 (0x00000000700000 LB 0x400000)
8921cf0.41c: supR3HardNtEnableThreadCreation:
8931cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll)
8941cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll
8951cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
8961cf0.41c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
8971cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbb4dd0000 LB 0x00005000 C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL [fFlags=0x0]
8981cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
8991cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
9001cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
9011cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbb4dd0000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
9021cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
9031cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
9041cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbb4dd0000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
9051cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbb4dd0000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
9061cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
9071cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msasn1.dll'.
9081cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'crypt32.dll'.
9091cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #27 'rpcrt4.dll'.
9101cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\wintrust.dll)
9111cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wintrust.dll
9121cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
9131cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
9141cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll)
9151cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
9161cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
9171cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume2\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
9181cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #33 'msasn1.dll'.
9191cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\crypt32.dll)
9201cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\crypt32.dll
9211cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
9221cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume2\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
9231cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\msasn1.dll)
9241cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msasn1.dll
9251cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
9261cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
9271cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\msvcrt.dll)
9281cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
9291cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
9301cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume2\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
9311cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
9321cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
9331cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbe9600000 LB 0x0009d000 C:\WINDOWS\System32\msvcrt.dll [fFlags=0x0]
9341cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
9351cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbe5f10000 LB 0x00012000 C:\WINDOWS\System32\MSASN1.dll [fFlags=0x0]
9361cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
9371cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbe6480000 LB 0x000f6000 C:\WINDOWS\System32\ucrtbase.dll [fFlags=0x0]
9381cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ucrtbase.dll)
9391cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ucrtbase.dll
9401cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbe6160000 LB 0x001ce000 C:\WINDOWS\System32\CRYPT32.dll [fFlags=0x0]
9411cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
9421cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbe96b0000 LB 0x0011f000 C:\WINDOWS\System32\RPCRT4.dll [fFlags=0x0]
9431cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
9441cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbe92a0000 LB 0x0005b000 C:\WINDOWS\System32\sechost.dll [fFlags=0x0]
9451cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'rpcrt4.dll'.
9461cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\sechost.dll)
9471cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\sechost.dll
9481cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbe7630000 LB 0x000a1000 C:\WINDOWS\System32\advapi32.dll [fFlags=0x0]
9491cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
9501cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'sechost.dll'.
9511cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #27 'rpcrt4.dll'.
9521cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\advapi32.dll)
9531cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\advapi32.dll
9541cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbe6580000 LB 0x00058000 C:\WINDOWS\System32\Wintrust.dll [fFlags=0x0]
9551cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
9561cf0.41c: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
9571cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
9581cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe65e0000 'api-ms-win-core-synch-l1-2-0'
9591cf0.41c: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-fibers-l1-1-1) -> 0x0, fPresent=1
9601cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
9611cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe65e0000 'api-ms-win-core-fibers-l1-1-1'
9621cf0.41c: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-fibers-l1-1-1) -> 0x0, fPresent=1
9631cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
9641cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe65e0000 'api-ms-win-core-fibers-l1-1-1'
9651cf0.41c: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
9661cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
9671cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe65e0000 'api-ms-win-core-synch-l1-2-0'
9681cf0.41c: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-l1-2-1) -> 0x0, fPresent=1
9691cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-l1-2-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
9701cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe65e0000 'api-ms-win-core-localization-l1-2-1'
9711cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6580000 'C:\WINDOWS\system32\Wintrust.dll'
9721cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\bcrypt.dll)
9731cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\bcrypt.dll
9741cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
9751cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
9761cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
9771cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'sechost.dll'...
9781cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'sechost.dll' -> '\Device\HarddiskVolume2\Windows\System32\sechost.dll' [rcNtRedir=0xc0150008]
9791cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\sechost.dll [lacks WinVerifyTrust]
9801cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
9811cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
9821cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
9831cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
9841cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
9851cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
9861cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\bcrypt.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
9871cf0.41c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
9881cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbe5a50000 LB 0x00025000 C:\WINDOWS\system32\bcrypt.dll [fFlags=0x0]
9891cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
9901cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5a50000 'C:\WINDOWS\system32\bcrypt.dll'
9911cf0.41c: bcrypt.dll loaded at 00007ffbe5a50000, BCryptOpenAlgorithmProvider at 00007ffbe5a52590, preloading providers:
9921cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll)
9931cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll
9941cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\bcryptprimitives.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
9951cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbe6850000 LB 0x00072000 C:\WINDOWS\System32\bcryptprimitives.dll [fFlags=0x0]
9961cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
9971cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6850000 'C:\WINDOWS\system32\bcryptprimitives.dll'
9981cf0.41c: BCryptOpenAlgorithmProvider(,'MD2',0,0) -> 0x0 (hAlgo=0000000002cf78d0)
9991cf0.41c: BCryptOpenAlgorithmProvider(,'MD4',0,0) -> 0x0 (hAlgo=0000000002cffbe0)
10001cf0.41c: BCryptOpenAlgorithmProvider(,'MD5',0,0) -> 0x0 (hAlgo=0000000002cffeb0)
10011cf0.41c: BCryptOpenAlgorithmProvider(,'SHA1',0,0) -> 0x0 (hAlgo=0000000002d00180)
10021cf0.41c: BCryptOpenAlgorithmProvider(,'SHA256',0,0) -> 0x0 (hAlgo=0000000002d00450)
10031cf0.41c: BCryptOpenAlgorithmProvider(,'SHA512',0,0) -> 0x0 (hAlgo=0000000002d00720)
10041cf0.41c: BCryptOpenAlgorithmProvider(,'RSA',0,0) -> 0x0 (hAlgo=0000000002d009f0)
10051cf0.41c: BCryptOpenAlgorithmProvider(,'DSA',0,0) -> 0x0 (hAlgo=0000000002d00cc0)
10061cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
10071cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
10081cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6580000 'C:\Windows\System32\WINTRUST.DLL'
10091cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
10101cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
10111cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6580000 'C:\Windows\System32\WINTRUST.DLL'
10121cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
10131cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
10141cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6580000 'C:\Windows\System32\WINTRUST.DLL'
10151cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
10161cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
10171cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6580000 'C:\Windows\System32\WINTRUST.DLL'
10181cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
10191cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
10201cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6580000 'C:\Windows\System32\WINTRUST.DLL'
10211cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
10221cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
10231cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6580000 'C:\Windows\System32\WINTRUST.DLL'
10241cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
10251cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
10261cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6580000 'C:\Windows\System32\WINTRUST.DLL'
10271cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\cryptsp.dll)
10281cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cryptsp.dll
10291cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbe5940000 LB 0x00017000 C:\WINDOWS\SYSTEM32\CRYPTSP.dll [fFlags=0x0]
10301cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cryptsp.dll [lacks WinVerifyTrust]
10311cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'bcrypt.dll'.
10321cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\rsaenh.dll)
10331cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\rsaenh.dll
10341cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
10351cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume2\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
10361cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
10371cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
10381cf0.41c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
10391cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbe5380000 LB 0x00033000 C:\WINDOWS\system32\rsaenh.dll [fFlags=0x0]
10401cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
10411cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
10421cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'bcryptprimitives.dll'.
10431cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\cryptbase.dll)
10441cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cryptbase.dll
10451cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbe5960000 LB 0x0000b000 C:\WINDOWS\SYSTEM32\CRYPTBASE.dll [fFlags=0x0]
10461cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cryptbase.dll [lacks WinVerifyTrust]
10471cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
10481cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcryptprimitives.dll'...
10491cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcryptprimitives.dll' -> '\Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll' [rcNtRedir=0xc0150008]
10501cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
10511cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
10521cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe99b0000 'C:\WINDOWS\System32\kernel32.dll'
10531cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
10541cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6580000 'C:\Windows\System32\WINTRUST.DLL'
10551cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
10561cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\CRYPT32.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
10571cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\CRYPT32.dll'
10581cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbe9840000 LB 0x0001d000 C:\WINDOWS\System32\imagehlp.dll [fFlags=0x0]
10591cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\imagehlp.dll)
10601cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\imagehlp.dll
10611cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
10621cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
10631cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
10641cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
10651cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'rpcrt4.dll'.
10661cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\gpapi.dll)
10671cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\gpapi.dll
10681cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbe4cd0000 LB 0x00022000 C:\WINDOWS\SYSTEM32\gpapi.dll [fFlags=0x0]
10691cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gpapi.dll [lacks WinVerifyTrust]
10701cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbe5f30000 LB 0x0001b000 C:\WINDOWS\System32\profapi.dll [fFlags=0x0]
10711cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\profapi.dll)
10721cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\profapi.dll
10731cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
10741cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'crypt32.dll'.
10751cf0.41c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\cryptnet.dll)
10761cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cryptnet.dll
10771cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
10781cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume2\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
10791cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
10801cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
10811cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
10821cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
10831cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
10841cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
10851cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
10861cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
10871cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
10881cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
10891cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (Input=cryptnet.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
10901cf0.41c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
10911cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbcd910000 LB 0x0002f000 C:\WINDOWS\System32\cryptnet.dll [fFlags=0x0]
10921cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
10931cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
10941cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
10951cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcd910000 'C:\WINDOWS\System32\cryptnet.dll'
10961cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
10971cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
10981cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcd910000 'C:\WINDOWS\System32\cryptnet.dll'
10991cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
11001cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
11011cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcd910000 'C:\WINDOWS\System32\cryptnet.dll'
11021cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
11031cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
11041cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcd910000 'C:\WINDOWS\System32\cryptnet.dll'
11051cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
11061cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
11071cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcd910000 'C:\WINDOWS\System32\cryptnet.dll'
11081cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
11091cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
11101cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcd910000 'C:\WINDOWS\System32\cryptnet.dll'
11111cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
11121cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcd910000 'C:\WINDOWS\System32\cryptnet.dll'
11131cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
11141cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcd910000 'C:\WINDOWS\System32\cryptnet.dll'
11151cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
11161cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcd910000 'C:\WINDOWS\System32\cryptnet.dll'
11171cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
11181cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcd910000 'C:\WINDOWS\System32\cryptnet.dll'
11191cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
11201cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcd910000 'C:\WINDOWS\System32\cryptnet.dll'
11211cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcd910000 'C:\WINDOWS\System32\cryptnet.dll'
11221cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
11231cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcd910000 'C:\Windows\System32\cryptnet.dll'
11241cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
11251cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
11261cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
11271cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
11281cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
11291cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
11301cf0.41c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000000 pwszName=\SystemRoot\System32\ntdll.dll
11311cf0.41c: supR3HardNtViCallWinVerifyTrustCatFile: New context 0000000002d2b930
11321cf0.41c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000002d2b930
11331cf0.41c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=85A51F72F9C3F195FA917546F5E7071F27ED535A
11341cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
11351cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\rpcrt4.dll (Input=rpcrt4.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
11361cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe96b0000 'C:\WINDOWS\System32\rpcrt4.dll'
11371cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
11381cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6580000 'C:\Windows\System32\WINTRUST.DLL'
11391cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
11401cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6580000 'C:\Windows\System32\WINTRUST.DLL'
11411cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
11421cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6580000 'C:\Windows\System32\WINTRUST.DLL'
11431cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
11441cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6580000 'C:\Windows\System32\WINTRUST.DLL'
11451cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
11461cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6580000 'C:\Windows\System32\WINTRUST.DLL'
11471cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
11481cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6580000 'C:\Windows\System32\WINTRUST.DLL'
11491cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
11501cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
11511cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6580000 'C:\Windows\System32\WINTRUST.DLL'
11521cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
11531cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
11541cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
11551cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
11561cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
11571cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
11581cf0.41c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_1126_for_KB4093112~31bf3856ad364e35~amd64~~10.0.1.3.cat'; file='\SystemRoot\System32\ntdll.dll'
11591cf0.41c: g_pfnWinVerifyTrust=00007ffbe6586bc0
11601cf0.41c: supR3HardenedScreenImage/preload: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [redoing WinVerifyTrust]
11611cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
11621cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
11631cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
11641cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
11651cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
11661cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
11671cf0.41c: supR3HardenedScreenImage/preload: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\crypt32.dll'
11681cf0.41c: supR3HardenedScreenImage/preload: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [redoing WinVerifyTrust]
11691cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
11701cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
11711cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
11721cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll
11731cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
11741cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
11751cf0.41c: supR3HardenedScreenImage/preload: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\wintrust.dll'
11761cf0.41c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000390 pwszName=\Device\HarddiskVolume2\Windows\System32\cryptnet.dll
11771cf0.41c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000002d2b930
11781cf0.41c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000002d2b930
11791cf0.41c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=5A0BC1B38B9F5EE15493A1BB6ABB29D2FFBB4119
11801cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
11811cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
11821cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
11831cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
11841cf0.41c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0015~31bf3856ad364e35~amd64~~10.0.16299.15.cat'; file='\Device\HarddiskVolume2\Windows\System32\cryptnet.dll'
11851cf0.41c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
11861cf0.41c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\cryptnet.dll'
11871cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
11881cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
11891cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
11901cf0.41c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\profapi.dll'
11911cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
11921cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
11931cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
11941cf0.41c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\gpapi.dll'
11951cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
11961cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
11971cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
11981cf0.41c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\imagehlp.dll'
11991cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
12001cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
12011cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
12021cf0.41c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\cryptbase.dll'
12031cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
12041cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
12051cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
12061cf0.41c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\rsaenh.dll'
12071cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
12081cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
12091cf0.41c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\cryptsp.dll'
12101cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
12111cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll
12121cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
12131cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
12141cf0.41c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll'
12151cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll
12161cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
12171cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
12181cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
12191cf0.41c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\bcrypt.dll'
12201cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
12211cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
12221cf0.41c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\advapi32.dll'
12231cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
12241cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
12251cf0.41c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\sechost.dll'
12261cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
12271cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
12281cf0.41c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\ucrtbase.dll'
12291cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
12301cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
12311cf0.41c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll'
12321cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
12331cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
12341cf0.41c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\msasn1.dll'
12351cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
12361cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
12371cf0.41c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll'
12381cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
12391cf0.41c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll'
12401cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
12411cf0.41c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe'
12421cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
12431cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
12441cf0.41c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\KernelBase.dll'
12451cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
12461cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
12471cf0.41c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\kernel32.dll'
12481cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\system32\crypt32.dll'
12491cf0.41c: supR3HardenedWinIsDesiredRootCA: Adding 0x5ad46780fa5df300 DC=com, DC=microsoft, CN=Microsoft Root Certificate Authority
12501cf0.41c: supR3HardenedWinIsDesiredRootCA: Adding 0xea5386456178582b C=ZA, ST=Western Cape, L=Durbanville, O=Thawte, OU=Thawte Certification, CN=Thawte Timestamping CA
12511cf0.41c: supR3HardenedWinIsDesiredRootCA: Adding 0x3be670c1bd02a900 OU=Copyright (c) 1997 Microsoft Corp., OU=Microsoft Corporation, CN=Microsoft Root Authority
12521cf0.41c: supR3HardenedWinIsDesiredRootCA: Adding 0xe991ee72b03db500 C=US, O=Symantec Corporation, CN=Symantec Enterprise Mobile Root for Microsoft
12531cf0.41c: supR3HardenedWinIsDesiredRootCA: Adding 0x4d3835aa4180b200 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2011
12541cf0.41c: supR3HardenedWinIsDesiredRootCA: Adding 0x646e3fe3ba08df00 C=US, O=MSFT, CN=Microsoft Authenticode(tm) Root Authority
12551cf0.41c: supR3HardenedWinIsDesiredRootCA: Adding 0x66343f4a0108be00 CN=DESKTOP-0K1AETK
12561cf0.41c: supR3HardenedWinIsDesiredRootCA: Adding 0xece4e4289e08b900 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010
12571cf0.41c: supR3HardenedWinIsDesiredRootCA: Adding 0x43a9cc371ff5385a O=Microsoft Trust Network, OU=Microsoft Corporation, OU=Microsoft Time Stamping Service Root, OU=Copyright (c) 1997 Microsoft Corp.
12581cf0.41c: supR3HardenedWinIsDesiredRootCA: Adding 0xd0d2830c08c0bd00 O=AO Kaspersky Lab, CN=Kaspersky Anti-Virus Personal Root Certificate
12591cf0.41c: supR3HardenedWinIsDesiredRootCA: Adding 0x2e2d2c7c68f0202e O=VeriSign Trust Network, OU=VeriSign, Inc., OU=VeriSign Time Stamping Service Root, OU=NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.
12601cf0.41c: supR3HardenedWinIsDesiredRootCA: Adding 0xd1744d9f343cae00 OU=generated by Avast Antivirus for SSL/TLS scanning, O=Avast Web/Mail Shield, CN=Avast Web/Mail Shield Root
12611cf0.41c: supR3HardenedWinIsDesiredRootCA: Adding 0xd8dbfb2c27bfb200 C=US, O=thawte, Inc., OU=Certification Services Division, OU=(c) 2008 thawte, Inc. - For authorized use only, CN=thawte Primary Root CA - G3
12621cf0.41c: supR3HardenedWinIsDesiredRootCA: Adding 0x61a3a33f81aace00 C=US, ST=UT, L=Salt Lake City, O=The USERTRUST Network, OU=http://www.usertrust.com, CN=UTN-USERFirst-Object
12631cf0.41c: supR3HardenedWinIsDesiredRootCA: Adding 0x6b7bdc34cd37bb00 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root G2
12641cf0.41c: supR3HardenedWinIsDesiredRootCA: Adding 0xf4fd306318ccda00 C=US, O=GeoTrust Inc., CN=GeoTrust Global CA
12651cf0.41c: supR3HardenedWinIsDesiredRootCA: Adding 0x83085097e9afdf00 O=Digital Signature Trust Co., CN=DST Root CA X3
12661cf0.41c: supR3HardenedWinIsDesiredRootCA: Adding 0x780679907625cc00 OU=GlobalSign Root CA - R3, O=GlobalSign, CN=GlobalSign
12671cf0.41c: supR3HardenedWinIsDesiredRootCA: Adding 0x3d98ab22bb04a300 C=IE, O=Baltimore, OU=CyberTrust, CN=Baltimore CyberTrust Root
12681cf0.41c: supR3HardenedWinIsDesiredRootCA: Adding 0xa0ee62086758b15d C=US, O=Equifax, OU=Equifax Secure Certificate Authority
12691cf0.41c: supR3HardenedWinIsDesiredRootCA: Adding 0xd944bca189a00 C=BM, O=QuoVadis Limited, CN=QuoVadis Root CA 2
12701cf0.41c: supR3HardenedWinIsDesiredRootCA: Adding 0x8ff6fc03c1edbd00 C=US, ST=Arizona, L=Scottsdale, O=Starfield Technologies, Inc., CN=Starfield Root Certificate Authority - G2
12711cf0.41c: supR3HardenedWinIsDesiredRootCA: Adding 0xc6fa4243b695b600 C=US, O=Entrust, Inc., OU=www.entrust.net/CPS is incorporated by reference, OU=(c) 2006 Entrust, Inc., CN=Entrust Root Certification Authority
12721cf0.41c: supR3HardenedWinIsDesiredRootCA: Adding 0xa3ce8d99e60eda00 C=BE, O=GlobalSign nv-sa, OU=Root CA, CN=GlobalSign Root CA
12731cf0.41c: supR3HardenedWinIsDesiredRootCA: Adding 0x560ad29254e89100 C=GB, ST=Greater Manchester, L=Salford, O=COMODO CA Limited, CN=COMODO RSA Certification Authority
12741cf0.41c: supR3HardenedWinIsDesiredRootCA: Adding 0xa671e9fec832b700 C=US, O=Starfield Technologies, Inc., OU=Starfield Class 2 Certification Authority
12751cf0.41c: supR3HardenedWinIsDesiredRootCA: Adding 0xa8de7211e13be200 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root CA
12761cf0.41c: supR3HardenedWinIsDesiredRootCA: Adding 0x7ae89c50f0b6a00f C=US, O=GTE Corporation, OU=GTE CyberTrust Solutions, Inc., CN=GTE CyberTrust Global Root
12771cf0.41c: supR3HardenedWinIsDesiredRootCA: Adding 0xd45980fbf0a0ac00 C=US, O=thawte, Inc., OU=Certification Services Division, OU=(c) 2006 thawte, Inc. - For authorized use only, CN=thawte Primary Root CA
12781cf0.41c: supR3HardenedWinIsDesiredRootCA: Adding 0xc9edb72b684ba00 C=US, O=Entrust, Inc., OU=See www.entrust.net/legal-terms, OU=(c) 2009 Entrust, Inc. - for authorized use only, CN=Entrust Root Certification Authority - G2
12791cf0.41c: supR3HardenedWinIsDesiredRootCA: Adding 0xf5cd95e581a4ab00 C=US, O=SecureTrust Corporation, CN=SecureTrust CA
12801cf0.41c: supR3HardenedWinIsDesiredRootCA: Adding 0x6f2ebe0e24cfa600 OU=GlobalSign Root CA - R2, O=GlobalSign, CN=GlobalSign
12811cf0.41c: supR3HardenedWinIsDesiredRootCA: Adding 0x14018a1bf29e595c C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority
12821cf0.41c: supR3HardenedWinIsDesiredRootCA: Adding 0x9e5bc2d78b6a3636 C=ZA, ST=Western Cape, L=Cape Town, O=Thawte Consulting cc, OU=Certification Services Division, CN=Thawte Premium Server CA, Email=premium-server@thawte.com
12831cf0.41c: supR3HardenedWinIsDesiredRootCA: Adding 0x7c4fd32ec1b1ce00 C=PL, O=Unizeto Sp. z o.o., CN=Certum CA
12841cf0.41c: supR3HardenedWinIsDesiredRootCA: Adding 0xd4fbe673e5ccc600 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA
12851cf0.41c: supR3HardenedWinIsDesiredRootCA: Adding 0x1b8578514b74ac00 C=US, O=WFA Hotspot 2.0, CN=Hotspot 2.0 Trust Root CA - 03
12861cf0.41c: supR3HardenedWinIsDesiredRootCA: Adding 0xb28612a94b4dad00 O=Entrust.net, OU=www.entrust.net/CPS_2048 incorp. by ref. (limits liab.), OU=(c) 1999 Entrust.net Limited, CN=Entrust.net Certification Authority (2048)
12871cf0.41c: supR3HardenedWinIsDesiredRootCA: Adding 0x357a29080824af00 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2006 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G5
12881cf0.41c: supR3HardenedWinIsDesiredRootCA: Adding 0x59faf1086271bf00 C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com, Inc., CN=Go Daddy Root Certificate Authority - G2
12891cf0.41c: supR3HardenedWinIsDesiredRootCA: Adding 0x466cbc09db88c100 C=IL, O=StartCom Ltd., OU=Secure Digital Certificate Signing, CN=StartCom Certification Authority
12901cf0.41c: supR3HardenedWinIsDesiredRootCA: Adding 0x3401b15e3761c700 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2008 VeriSign, Inc. - For authorized use only, CN=VeriSign Universal Root Certification Authority
12911cf0.41c: supR3HardenedWinIsDesiredRootCA: Adding 0x7cd4ff7b15b8be00 C=US, O=GeoTrust Inc., CN=GeoTrust Primary Certification Authority
12921cf0.41c: supR3HardenedWinIsDesiredRootCA: Adding 0x491857ead79dde00 C=US, O=The Go Daddy Group, Inc., OU=Go Daddy Class 2 Certification Authority
12931cf0.41c: supR3HardenedWinIsDesiredRootCA: Adding 0xdc1801b225aea100 C=BM, O=QuoVadis Limited, CN=QuoVadis Root CA 2 G3
12941cf0.41c: supR3HardenedWinIsDesiredRootCA: Adding 0xc2ba72a37dfbe300 C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Trusted Network CA
12951cf0.41c: supR3HardenedWinIsDesiredRootCA: Adding 0x8043e4ce150ead00 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID Root CA
12961cf0.41c: supR3HardenedWinIsDesiredRootCA: Adding 0x331d58625ee2dc00 C=US, O=GeoTrust Inc., OU=(c) 2008 GeoTrust Inc. - For authorized use only, CN=GeoTrust Primary Certification Authority - G3
12971cf0.41c: supR3HardenedWinIsDesiredRootCA: Adding 0xf2e6331af7b700 C=SE, O=AddTrust AB, OU=AddTrust External TTP Network, CN=AddTrust External CA Root
12981cf0.41c: supR3HardenedWinRetrieveTrustedRootCAs: cAdded=49
12991cf0.41c: SUPR3HardenedMain: Load Runtime...
13001cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
13011cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
13021cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
13031cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ws2_32.dll'.
13041cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'rpcrt4.dll'.
13051cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll) WinVerifyTrust
13061cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
13071cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
13081cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
13091cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
13101cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
13111cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
13121cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
13131cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
13141cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'rpcrt4.dll'.
13151cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ws2_32.dll) WinVerifyTrust
13161cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
13171cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
13181cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
13191cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
13201cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
13211cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
13221cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
13231cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
13241cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll) WinVerifyTrust
13251cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
13261cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
13271cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
13281cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
13291cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
13301cf0.41c: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll'.
13311cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll)
13321cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
13331cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
13341cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll) WinVerifyTrust
13351cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000a01:<flags> [calling]
13361cf0.41c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
13371cf0.41c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll [avoiding WinVerifyTrust]
13381cf0.41c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
13391cf0.41c: supR3HardenedDllNotificationCallback: load 0000000064660000 LB 0x000d2000 C:\Program Files\Oracle\VirtualBox\MSVCR100.dll [fFlags=0x0]
13401cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll [avoiding WinVerifyTrust]
13411cf0.41c: supR3HardenedDllNotificationCallback: load 00000000645c0000 LB 0x00098000 C:\Program Files\Oracle\VirtualBox\MSVCP100.dll [fFlags=0x0]
13421cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
13431cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbe7a40000 LB 0x0006c000 C:\WINDOWS\System32\WS2_32.dll [fFlags=0x0]
13441cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
13451cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbb3340000 LB 0x00590000 C:\Program Files\Oracle\VirtualBox\VBoxRT.dll [fFlags=0x0]
13461cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
13471cf0.41c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll'.
13481cf0.41c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
13491cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
13501cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
13511cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbb3340000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13521cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
13531cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
13541cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbb3340000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13551cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
13561cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
13571cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbb3340000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13581cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
13591cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
13601cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbb3340000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13611cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
13621cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
13631cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbb3340000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13641cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
13651cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
13661cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbb3340000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13671cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbb3340000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13681cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbb3340000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13691cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbb3340000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13701cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbb3340000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13711cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbb3340000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13721cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbb3340000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13731cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbb3340000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13741cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
13751cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
13761cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbb3340000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13771cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbb3340000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13781cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbb3340000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13791cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbb3340000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13801cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbb3340000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13811cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbb3340000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13821cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbb3340000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13831cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbb3340000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13841cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbb3340000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13851cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbb3340000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13861cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbb3340000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13871cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbb3340000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13881cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbb3340000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13891cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbb3340000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13901cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbb3340000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13911cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbb3340000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13921cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
13931cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
13941cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbb3340000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13951cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbb3340000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13961cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbb3340000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13971cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbb3340000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13981cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6580000 'C:\WINDOWS\system32\Wintrust.dll'
13991cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
14001cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
14011cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll
14021cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
14031cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
14041cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
14051cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\system32\crypt32.dll'
14061cf0.41c: SUPR3HardenedMain: Load TrustedMain...
14071cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
14081cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'opengl32.dll'.
14091cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
14101cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msvcp100.dll'.
14111cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcr100.dll'.
14121cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qt5corevbox.dll'.
14131cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'qt5guivbox.dll'.
14141cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'qt5widgetsvbox.dll'.
14151cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'qt5printsupportvbox.dll'.
14161cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'qt5openglvbox.dll'.
14171cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'user32.dll'.
14181cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'advapi32.dll'.
14191cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'shell32.dll'.
14201cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'ole32.dll'.
14211cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'oleaut32.dll'.
14221cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #15 'winmm.dll'.
14231cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.dll) WinVerifyTrust
14241cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.dll
14251cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
14261cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
14271cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
14281cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
14291cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'winmmbase.dll'.
14301cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msvcrt.dll'.
14311cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\winmm.dll) WinVerifyTrust
14321cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\winmm.dll
14331cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
14341cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
14351cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
14361cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
14371cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
14381cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmmbase.dll'...
14391cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmmbase.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmmbase.dll' [rcNtRedir=0xc0150008]
14401cf0.41c: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\winmmbase.dll'.
14411cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
14421cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\winmmbase.dll)
14431cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\winmmbase.dll
14441cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
14451cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
14461cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
14471cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
14481cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll
14491cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
14501cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
14511cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
14521cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'combase.dll'.
14531cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'rpcrt4.dll'.
14541cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\oleaut32.dll) WinVerifyTrust
14551cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
14561cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
14571cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
14581cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
14591cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
14601cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
14611cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
14621cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume2\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
14631cf0.41c: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\combase.dll'.
14641cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rpcrt4.dll'.
14651cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #45 'bcryptprimitives.dll'.
14661cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\combase.dll)
14671cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\combase.dll
14681cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
14691cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
14701cf0.41c: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\msvcp_win.dll'.
14711cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\msvcp_win.dll)
14721cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msvcp_win.dll
14731cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcryptprimitives.dll'...
14741cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcryptprimitives.dll' -> '\Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll' [rcNtRedir=0xc0150008]
14751cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll
14761cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
14771cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
14781cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
14791cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
14801cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #22 'rpcrt4.dll'.
14811cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #46 'gdi32.dll'.
14821cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #47 'user32.dll'.
14831cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #48 'combase.dll'.
14841cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ole32.dll) WinVerifyTrust
14851cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ole32.dll
14861cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
14871cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
14881cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
14891cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume2\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
14901cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\combase.dll [lacks WinVerifyTrust]
14911cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
14921cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
14931cf0.41c: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\user32.dll'.
14941cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'win32u.dll'.
14951cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #34 'gdi32.dll'.
14961cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\user32.dll)
14971cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\user32.dll
14981cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
14991cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
15001cf0.41c: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\gdi32.dll'.
15011cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\gdi32.dll)
15021cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\gdi32.dll
15031cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
15041cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
15051cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
15061cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
15071cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
15081cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
15091cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume2\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
15101cf0.41c: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\win32u.dll'.
15111cf0.41c: '\Device\HarddiskVolume2\Windows\System32\win32u.dll' has no imports
15121cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\win32u.dll)
15131cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\win32u.dll
15141cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
15151cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
15161cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
15171cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #73 'user32.dll'.
15181cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #75 'gdi32.dll'.
15191cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\shell32.dll) WinVerifyTrust
15201cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\shell32.dll
15211cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
15221cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
15231cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
15241cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
15251cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
15261cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll [redoing WinVerifyTrust]
15271cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
15281cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
15291cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
15301cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
15311cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
15321cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
15331cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
15341cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
15351cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
15361cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
15371cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
15381cf0.41c: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\user32.dll'
15391cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5openglvbox.dll'...
15401cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5openglvbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5openglvbox.dll' [rcNtRedir=0xc0150008]
15411cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
15421cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'qt5widgetsvbox.dll'.
15431cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'qt5guivbox.dll'.
15441cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5corevbox.dll'.
15451cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcr100.dll'.
15461cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll) WinVerifyTrust
15471cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll
15481cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5printsupportvbox.dll'...
15491cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5printsupportvbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5printsupportvbox.dll' [rcNtRedir=0xc0150008]
15501cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
15511cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
15521cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
15531cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
15541cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
15551cf0.41c: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll'.
15561cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
15571cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'shell32.dll'.
15581cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ole32.dll'.
15591cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
15601cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ws2_32.dll'.
15611cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'mpr.dll'.
15621cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'msvcp100.dll'.
15631cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'msvcr100.dll'.
15641cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll)
15651cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
15661cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
15671cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
15681cf0.41c: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll'.
15691cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ole32.dll'.
15701cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'opengl32.dll'.
15711cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
15721cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
15731cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qt5corevbox.dll'.
15741cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcp100.dll'.
15751cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msvcr100.dll'.
15761cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll)
15771cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
15781cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
15791cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
15801cf0.41c: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll'.
15811cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
15821cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
15831cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5guivbox.dll'.
15841cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qt5corevbox.dll'.
15851cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'shell32.dll'.
15861cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcp100.dll'.
15871cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msvcr100.dll'.
15881cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll)
15891cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll
15901cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
15911cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
15921cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
15931cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
15941cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
15951cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
15961cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
15971cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
15981cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
15991cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
16001cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
16011cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [lacks WinVerifyTrust]
16021cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
16031cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
16041cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll [lacks WinVerifyTrust]
16051cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
16061cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
16071cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll
16081cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
16091cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
16101cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
16111cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
16121cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
16131cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
16141cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
16151cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
16161cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
16171cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
16181cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
16191cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [lacks WinVerifyTrust]
16201cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
16211cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
16221cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll
16231cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
16241cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
16251cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
16261cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
16271cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
16281cf0.41c: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume2\Windows\System32\opengl32.dll'.
16291cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
16301cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'advapi32.dll'.
16311cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
16321cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
16331cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'glu32.dll'.
16341cf0.41c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\opengl32.dll)
16351cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\opengl32.dll
16361cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
16371cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
16381cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
16391cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
16401cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
16411cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
16421cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
16431cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
16441cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
16451cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mpr.dll'...
16461cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'mpr.dll' -> '\Device\HarddiskVolume2\Windows\System32\mpr.dll' [rcNtRedir=0xc0150008]
16471cf0.41c: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\mpr.dll'.
16481cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\mpr.dll)
16491cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\mpr.dll
16501cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
16511cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
16521cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
16531cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
16541cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
16551cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
16561cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
16571cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
16581cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
16591cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
16601cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
16611cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
16621cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
16631cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
16641cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll
16651cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'glu32.dll'...
16661cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'glu32.dll' -> '\Device\HarddiskVolume2\Windows\System32\glu32.dll' [rcNtRedir=0xc0150008]
16671cf0.41c: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume2\Windows\System32\glu32.dll'.
16681cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
16691cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
16701cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'opengl32.dll'.
16711cf0.41c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\glu32.dll)
16721cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\glu32.dll
16731cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
16741cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
16751cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
16761cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
16771cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
16781cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll
16791cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
16801cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
16811cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
16821cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
16831cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
16841cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
16851cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
16861cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
16871cf0.41c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll [lacks WinVerifyTrust]
16881cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
16891cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
16901cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll
16911cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
16921cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
16931cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
16941cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
16951cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
16961cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5widgetsvbox.dll'.
16971cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qt5guivbox.dll'.
16981cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qt5corevbox.dll'.
16991cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'winspool.drv'.
17001cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'comdlg32.dll'.
17011cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'msvcr100.dll'.
17021cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5PrintSupportVBox.dll) WinVerifyTrust
17031cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5PrintSupportVBox.dll
17041cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
17051cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
17061cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll [redoing WinVerifyTrust]
17071cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
17081cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
17091cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
17101cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comdlg32.dll'...
17111cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'comdlg32.dll' -> '\Device\HarddiskVolume2\Windows\System32\comdlg32.dll' [rcNtRedir=0xc0150008]
17121cf0.41c: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume2\Windows\System32\comdlg32.dll'.
17131cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
17141cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #36 'user32.dll'.
17151cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #37 'shlwapi.dll'.
17161cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #38 'gdi32.dll'.
17171cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #39 'comctl32.dll'.
17181cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #40 'shell32.dll'.
17191cf0.41c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\comdlg32.dll)
17201cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\comdlg32.dll
17211cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winspool.drv'...
17221cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'winspool.drv' -> '\Device\HarddiskVolume2\Windows\System32\winspool.drv' [rcNtRedir=0xc0150008]
17231cf0.41c: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume2\Windows\System32\winspool.drv'.
17241cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
17251cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'iphlpapi.dll'.
17261cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #34 'bcrypt.dll'.
17271cf0.41c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\winspool.drv)
17281cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\winspool.drv
17291cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
17301cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
17311cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [lacks WinVerifyTrust]
17321cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
17331cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
17341cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll [lacks WinVerifyTrust]
17351cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
17361cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
17371cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll [lacks WinVerifyTrust]
17381cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
17391cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
17401cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll
17411cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
17421cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
17431cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
17441cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
17451cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume2\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
17461cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll
17471cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'iphlpapi.dll'...
17481cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'iphlpapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\iphlpapi.dll' [rcNtRedir=0xc0150008]
17491cf0.41c: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL'.
17501cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL)
17511cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL
17521cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
17531cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
17541cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
17551cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
17561cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
17571cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comctl32.dll'...
17581cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'comctl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\comctl32.dll' [rcNtRedir=0x0]
17591cf0.41c: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\comctl32.dll'.
17601cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'advapi32.dll'.
17611cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
17621cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
17631cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\comctl32.dll)
17641cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\comctl32.dll
17651cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
17661cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
17671cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
17681cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
17691cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
17701cf0.41c: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll'.
17711cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
17721cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #45 'gdi32.dll'.
17731cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #46 'user32.dll'.
17741cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\shlwapi.dll)
17751cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\shlwapi.dll
17761cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
17771cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
17781cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
17791cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
17801cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
17811cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
17821cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
17831cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
17841cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
17851cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
17861cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
17871cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
17881cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
17891cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
17901cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
17911cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
17921cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
17931cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
17941cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
17951cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
17961cf0.41c: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll'
17971cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
17981cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
17991cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll [redoing WinVerifyTrust]
18001cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
18011cf0.41c: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll'
18021cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
18031cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
18041cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [redoing WinVerifyTrust]
18051cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
18061cf0.41c: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll'
18071cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
18081cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
18091cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll [redoing WinVerifyTrust]
18101cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
18111cf0.41c: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll'
18121cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
18131cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
18141cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
18151cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
18161cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
18171cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
18181cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
18191cf0.41c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll [redoing WinVerifyTrust]
18201cf0.41c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000430 pwszName=\Device\HarddiskVolume2\Windows\System32\opengl32.dll
18211cf0.41c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000002d2b930
18221cf0.41c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000002d2b930
18231cf0.41c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=F39C902102F30859FF82648A950427FCB81FB124
18241cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
18251cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
18261cf0.41c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package00111~31bf3856ad364e35~amd64~~10.0.16299.15.cat'; file='\Device\HarddiskVolume2\Windows\System32\opengl32.dll'
18271cf0.41c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
18281cf0.41c: supR3HardenedScreenImage/Imports: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\opengl32.dll'
18291cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VirtualBox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000a01:<flags> [calling]
18301cf0.41c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.dll
18311cf0.41c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
18321cf0.41c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
18331cf0.41c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
18341cf0.41c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll
18351cf0.41c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5PrintSupportVBox.dll
18361cf0.41c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll
18371cf0.41c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
18381cf0.41c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\glu32.dll [avoiding WinVerifyTrust]
18391cf0.41c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\mpr.dll [avoiding WinVerifyTrust]
18401cf0.41c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\winspool.drv [avoiding WinVerifyTrust]
18411cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'advapi32.dll'.
18421cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
18431cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
18441cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.16299.371_none_887d866e4ab76531\comctl32.dll)
18451cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.16299.371_none_887d866e4ab76531\comctl32.dll
18461cf0.41c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmmbase.dll [avoiding WinVerifyTrust]
18471cf0.41c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL [avoiding WinVerifyTrust]
18481cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbe5fa0000 LB 0x00020000 C:\WINDOWS\System32\win32u.dll [fFlags=0x0]
18491cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\win32u.dll [avoiding WinVerifyTrust]
18501cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbe6330000 LB 0x0009b000 C:\WINDOWS\System32\msvcp_win.dll [fFlags=0x0]
18511cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcp_win.dll [avoiding WinVerifyTrust]
18521cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbe5fc0000 LB 0x00193000 C:\WINDOWS\System32\gdi32full.dll [fFlags=0x0]
18531cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
18541cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #33 'gdi32.dll'.
18551cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #35 'user32.dll'.
18561cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #36 'win32u.dll'.
18571cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\gdi32full.dll)
18581cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\gdi32full.dll
18591cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbe71b0000 LB 0x00028000 C:\WINDOWS\System32\GDI32.dll [fFlags=0x0]
18601cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [avoiding WinVerifyTrust]
18611cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbe9300000 LB 0x0018f000 C:\WINDOWS\System32\USER32.dll [fFlags=0x0]
18621cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbb4d40000 LB 0x0002c000 C:\WINDOWS\SYSTEM32\GLU32.dll [fFlags=0x0]
18631cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\glu32.dll [avoiding WinVerifyTrust]
18641cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbb2210000 LB 0x0011e000 C:\WINDOWS\SYSTEM32\OPENGL32.dll [fFlags=0x0]
18651cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
18661cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbe7020000 LB 0x0004a000 C:\WINDOWS\System32\cfgmgr32.dll [fFlags=0x0]
18671cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll)
18681cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll
18691cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbe8f90000 LB 0x00308000 C:\WINDOWS\System32\combase.dll [fFlags=0x0]
18701cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\combase.dll [avoiding WinVerifyTrust]
18711cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbe7070000 LB 0x000a6000 C:\WINDOWS\System32\shcore.dll [fFlags=0x0]
18721cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
18731cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #37 'rpcrt4.dll'.
18741cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #44 'combase.dll'.
18751cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\SHCore.dll)
18761cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\SHCore.dll
18771cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbe7150000 LB 0x00051000 C:\WINDOWS\System32\shlwapi.dll [fFlags=0x0]
18781cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll [avoiding WinVerifyTrust]
18791cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbe5ef0000 LB 0x00011000 C:\WINDOWS\System32\kernel.appcore.dll [fFlags=0x0]
18801cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'msvcrt.dll'.
18811cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'rpcrt4.dll'.
18821cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\kernel.appcore.dll)
18831cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\kernel.appcore.dll
18841cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbe5f50000 LB 0x0004c000 C:\WINDOWS\System32\powrprof.dll [fFlags=0x0]
18851cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'rpcrt4.dll'.
18861cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\powrprof.dll)
18871cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\powrprof.dll
18881cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbe68d0000 LB 0x00747000 C:\WINDOWS\System32\windows.storage.dll [fFlags=0x0]
18891cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
18901cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'rpcrt4.dll'.
18911cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #55 'combase.dll'.
18921cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #75 'profapi.dll'.
18931cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\windows.storage.dll)
18941cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\windows.storage.dll
18951cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbe7b50000 LB 0x01436000 C:\WINDOWS\System32\SHELL32.dll [fFlags=0x0]
18961cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
18971cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbe9860000 LB 0x00149000 C:\WINDOWS\System32\ole32.dll [fFlags=0x0]
18981cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
18991cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbd7620000 LB 0x0001b000 C:\WINDOWS\SYSTEM32\MPR.dll [fFlags=0x0]
19001cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\mpr.dll [avoiding WinVerifyTrust]
19011cf0.41c: supR3HardenedDllNotificationCallback: load 0000000064050000 LB 0x00565000 C:\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [fFlags=0x0]
19021cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
19031cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbb2330000 LB 0x005f7000 C:\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll [fFlags=0x0]
19041cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
19051cf0.41c: supR3HardenedDllNotificationCallback: load 0000000063ae0000 LB 0x00561000 C:\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll [fFlags=0x0]
19061cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll
19071cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbe5510000 LB 0x00039000 C:\WINDOWS\SYSTEM32\IPHLPAPI.DLL [fFlags=0x0]
19081cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL [avoiding WinVerifyTrust]
19091cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbe0db0000 LB 0x00086000 C:\WINDOWS\SYSTEM32\WINSPOOL.DRV [fFlags=0x0]
19101cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\winspool.drv [avoiding WinVerifyTrust]
19111cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbde190000 LB 0x000a6000 C:\WINDOWS\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.16299.371_none_887d866e4ab76531\COMCTL32.dll [fFlags=0x0]
19121cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.16299.371_none_887d866e4ab76531\comctl32.dll [avoiding WinVerifyTrust]
19131cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbe9a60000 LB 0x0010a000 C:\WINDOWS\System32\COMDLG32.dll [fFlags=0x0]
19141cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\comdlg32.dll [avoiding WinVerifyTrust]
19151cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbb4d70000 LB 0x00051000 C:\Program Files\Oracle\VirtualBox\Qt5PrintSupportVBox.dll [fFlags=0x0]
19161cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5PrintSupportVBox.dll
19171cf0.41c: supR3HardenedDllNotificationCallback: load 0000000063a80000 LB 0x00054000 C:\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll [fFlags=0x0]
19181cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll
19191cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbe7760000 LB 0x000c5000 C:\WINDOWS\System32\OLEAUT32.dll [fFlags=0x0]
19201cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
19211cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbe2f60000 LB 0x0002a000 C:\WINDOWS\SYSTEM32\WINMMBASE.dll [fFlags=0x0]
19221cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmmbase.dll [avoiding WinVerifyTrust]
19231cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbe2f90000 LB 0x00023000 C:\WINDOWS\SYSTEM32\WINMM.dll [fFlags=0x0]
19241cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
19251cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbb2930000 LB 0x00a06000 C:\Program Files\Oracle\VirtualBox\VirtualBox.dll [fFlags=0x0]
19261cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.dll
19271cf0.41c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\windows.storage.dll'.
19281cf0.41c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\windows.storage.dll' [rescheduled]
19291cf0.41c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\powrprof.dll'.
19301cf0.41c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\powrprof.dll' [rescheduled]
19311cf0.41c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\kernel.appcore.dll'.
19321cf0.41c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\kernel.appcore.dll' [rescheduled]
19331cf0.41c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\SHCore.dll'.
19341cf0.41c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\SHCore.dll' [rescheduled]
19351cf0.41c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll'.
19361cf0.41c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll' [rescheduled]
19371cf0.41c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\gdi32full.dll'.
19381cf0.41c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\gdi32full.dll' [rescheduled]
19391cf0.41c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.16299.371_none_887d866e4ab76531\comctl32.dll'.
19401cf0.41c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.16299.371_none_887d866e4ab76531\comctl32.dll' [rescheduled]
19411cf0.41c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll'.
19421cf0.41c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll' [rescheduled]
19431cf0.41c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\comctl32.dll'.
19441cf0.41c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\comctl32.dll' [rescheduled]
19451cf0.41c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL'.
19461cf0.41c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL' [rescheduled]
19471cf0.41c: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume2\Windows\System32\winspool.drv'.
19481cf0.41c: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\winspool.drv' [rescheduled]
19491cf0.41c: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume2\Windows\System32\comdlg32.dll'.
19501cf0.41c: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\comdlg32.dll' [rescheduled]
19511cf0.41c: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume2\Windows\System32\glu32.dll'.
19521cf0.41c: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\glu32.dll' [rescheduled]
19531cf0.41c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\mpr.dll'.
19541cf0.41c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\mpr.dll' [rescheduled]
19551cf0.41c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\win32u.dll'.
19561cf0.41c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\win32u.dll' [rescheduled]
19571cf0.41c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\gdi32.dll'.
19581cf0.41c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rescheduled]
19591cf0.41c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\msvcp_win.dll'.
19601cf0.41c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\msvcp_win.dll' [rescheduled]
19611cf0.41c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\combase.dll'.
19621cf0.41c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\combase.dll' [rescheduled]
19631cf0.41c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\winmmbase.dll'.
19641cf0.41c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\winmmbase.dll' [rescheduled]
19651cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll
19661cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'profapi.dll'...
19671cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'profapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\profapi.dll' [rcNtRedir=0xc0150008]
19681cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\profapi.dll
19691cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
19701cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume2\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
19711cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\combase.dll [redoing WinVerifyTrust]
19721cf0.41c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\combase.dll'.
19731cf0.41c: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume2\Windows\System32\combase.dll
19741cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
19751cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
19761cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
19771cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
19781cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
19791cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
19801cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
19811cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
19821cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
19831cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
19841cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
19851cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume2\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
19861cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\combase.dll [redoing WinVerifyTrust]
19871cf0.41c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\combase.dll'.
19881cf0.41c: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume2\Windows\System32\combase.dll
19891cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
19901cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
19911cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
19921cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
19931cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
19941cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume2\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
19951cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\win32u.dll [redoing WinVerifyTrust]
19961cf0.41c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\win32u.dll'.
19971cf0.41c: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume2\Windows\System32\win32u.dll
19981cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
19991cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
20001cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
20011cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
20021cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [redoing WinVerifyTrust]
20031cf0.41c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\gdi32.dll'.
20041cf0.41c: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume2\Windows\System32\gdi32.dll
20051cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
20061cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
20071cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcp_win.dll [redoing WinVerifyTrust]
20081cf0.41c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\msvcp_win.dll'.
20091cf0.41c: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume2\Windows\System32\msvcp_win.dll
20101cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
20111cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
20121cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
20131cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
20141cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [redoing WinVerifyTrust]
20151cf0.41c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\gdi32.dll'.
20161cf0.41c: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume2\Windows\System32\gdi32.dll
20171cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
20181cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
20191cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
20201cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\kernel32.dll (Input=kernel32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
20211cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe99b0000 'C:\WINDOWS\System32\kernel32.dll'
20221cf0.41c: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-string-l1-1-0) -> 0x0, fPresent=1
20231cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-string-l1-1-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
20241cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe65e0000 'api-ms-win-core-string-l1-1-0'
20251cf0.41c: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-datetime-l1-1-1) -> 0x0, fPresent=1
20261cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-datetime-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
20271cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe65e0000 'api-ms-win-core-datetime-l1-1-1'
20281cf0.41c: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-obsolete-l1-2-0) -> 0x0, fPresent=1
20291cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-obsolete-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
20301cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe65e0000 'api-ms-win-core-localization-obsolete-l1-2-0'
20311cf0.41c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\imm32.dll'.
20321cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'user32.dll'.
20331cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'win32u.dll'.
20341cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\imm32.dll)
20351cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\imm32.dll
20361cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
20371cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume2\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
20381cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\win32u.dll [redoing WinVerifyTrust]
20391cf0.41c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\win32u.dll'.
20401cf0.41c: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume2\Windows\System32\win32u.dll
20411cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
20421cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
20431cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\IMM32.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
20441cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbe7120000 LB 0x0002d000 C:\WINDOWS\System32\IMM32.DLL [fFlags=0x0]
20451cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\imm32.dll [avoiding WinVerifyTrust]
20461cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe7120000 'C:\WINDOWS\system32\IMM32.DLL'
20471cf0.41c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\imm32.dll'.
20481cf0.41c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\imm32.dll' [rescheduled]
20491cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\imm32.dll [redoing WinVerifyTrust]
20501cf0.41c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\imm32.dll'.
20511cf0.41c: supR3HardenedScreenImage/LdrLoadDll: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume2\Windows\System32\imm32.dll
20521cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\imm32.dll (Input=imm32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
20531cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe7120000 'C:\WINDOWS\System32\imm32.dll'
20541cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
20551cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\ADVAPI32.DLL (Input=ADVAPI32.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
20561cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe7630000 'C:\WINDOWS\System32\ADVAPI32.DLL'
20571cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbb2930000 'C:\Program Files\Oracle\VirtualBox\VirtualBox.dll'
20581cf0.41c: SUPR3HardenedMain: Calling TrustedMain (00007ffbb29314f0)...
20591cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
20601cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
20611cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'ole32.dll'.
20621cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
20631cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'imm32.dll'.
20641cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'winmm.dll'.
20651cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'oleaut32.dll'.
20661cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'shell32.dll'.
20671cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'advapi32.dll'.
20681cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'qt5guivbox.dll'.
20691cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'qt5corevbox.dll'.
20701cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'msvcr100.dll'.
20711cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\platforms\qwindows.dll) WinVerifyTrust
20721cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\platforms\qwindows.dll
20731cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
20741cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
20751cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
20761cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
20771cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
20781cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
20791cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
20801cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
20811cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
20821cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
20831cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
20841cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
20851cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
20861cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
20871cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
20881cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
20891cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
20901cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
20911cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
20921cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
20931cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
20941cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume2\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
20951cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\imm32.dll [redoing WinVerifyTrust]
20961cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
20971cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
20981cf0.41c: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\imm32.dll'
20991cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
21001cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
21011cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll
21021cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
21031cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
21041cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
21051cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
21061cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
21071cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [redoing WinVerifyTrust]
21081cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
21091cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
21101cf0.41c: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\gdi32.dll'
21111cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\platforms\qwindows.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
21121cf0.41c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\platforms\qwindows.dll
21131cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbbcf20000 LB 0x0012e000 C:\Program Files\Oracle\VirtualBox\platforms\qwindows.dll [fFlags=0x0]
21141cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\platforms\qwindows.dll
21151cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbbcf20000 'C:\Program Files\Oracle\VirtualBox\platforms\qwindows.dll'
21161cf0.41c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000658 pwszName=\Device\HarddiskVolume2\Windows\System32\uxtheme.dll
21171cf0.41c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000002d2b930
21181cf0.41c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000002d2b930
21191cf0.41c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=0AB199956403E78CE61C981F6BA97CA632BE55AC
21201cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
21211cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
21221cf0.41c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package00114~31bf3856ad364e35~amd64~~10.0.16299.15.cat'; file='\Device\HarddiskVolume2\Windows\System32\uxtheme.dll'
21231cf0.41c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
21241cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
21251cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #33 'gdi32.dll'.
21261cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #34 'user32.dll'.
21271cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\uxtheme.dll) WinVerifyTrust
21281cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
21291cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
21301cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
21311cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
21321cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
21331cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
21341cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
21351cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
21361cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
21371cf0.41c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
21381cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbe4520000 LB 0x00095000 C:\WINDOWS\system32\uxtheme.dll [fFlags=0x0]
21391cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
21401cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe4520000 'C:\WINDOWS\system32\uxtheme.dll'
21411cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe9300000 'C:\WINDOWS\system32\user32.dll'
21421cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
21431cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
21441cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe7b50000 'C:\WINDOWS\system32\shell32.dll'
21451cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\SHCore.dll [redoing WinVerifyTrust]
21461cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
21471cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
21481cf0.41c: supR3HardenedScreenImage/LdrLoadDll: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\SHCore.dll'
21491cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\SHCore.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
21501cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe7070000 'C:\WINDOWS\system32\SHCore.dll'
21511cf0.41c: supR3HardenedMonitor_LdrLoadDll: error opening 'C:\WINDOWS\system32\wintab32.dll': 0 (NtPath=\??\C:\WINDOWS\system32\wintab32.dll; Input=C:\WINDOWS\system32\wintab32.dll; rcNtGetDll=0x0
21521cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000034 'C:\WINDOWS\system32\wintab32.dll'
21531cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
21541cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #22 'win32u.dll'.
21551cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'user32.dll'.
21561cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #24 'gdi32.dll'.
21571cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\dwmapi.dll)
21581cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\dwmapi.dll
21591cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbe4790000 LB 0x0002a000 C:\WINDOWS\system32\dwmapi.dll [fFlags=0x0]
21601cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dwmapi.dll [avoiding WinVerifyTrust]
21611cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
21621cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
21631cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
21641cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
21651cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
21661cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume2\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
21671cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\win32u.dll [lacks WinVerifyTrust]
21681cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
21691cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
21701cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
21711cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
21721cf0.41c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\dwmapi.dll'
21731cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
21741cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\winmm.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
21751cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe2f90000 'C:\WINDOWS\system32\winmm.dll'
21761cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
21771cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\winmm.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
21781cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe2f90000 'C:\WINDOWS\system32\winmm.dll'
21791cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
21801cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
21811cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe7b50000 'C:\WINDOWS\system32\shell32.dll'
21821cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
21831cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
21841cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe4520000 'C:\WINDOWS\system32\uxtheme.dll'
21851cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
21861cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\advapi32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
21871cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe7630000 'C:\WINDOWS\system32\advapi32.dll'
21881cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
21891cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
21901cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'rpcrt4.dll'.
21911cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #27 'profapi.dll'.
21921cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\userenv.dll) WinVerifyTrust
21931cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\userenv.dll
21941cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'profapi.dll'...
21951cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'profapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\profapi.dll' [rcNtRedir=0xc0150008]
21961cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\profapi.dll
21971cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
21981cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
21991cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\userenv.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
22001cf0.41c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\userenv.dll
22011cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbe5e20000 LB 0x00029000 C:\WINDOWS\system32\userenv.dll [fFlags=0x0]
22021cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\userenv.dll
22031cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5e20000 'C:\WINDOWS\system32\userenv.dll'
22041cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll
22051cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\kernel32.dll (Input=kernel32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
22061cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe99b0000 'C:\WINDOWS\System32\kernel32.dll'
22071cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbe7ab0000 LB 0x0009e000 C:\WINDOWS\System32\clbcatq.dll [fFlags=0x0]
22081cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
22091cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #28 'rpcrt4.dll'.
22101cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\clbcatq.dll)
22111cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\clbcatq.dll
22121cf0.28b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
22131cf0.28b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
22141cf0.28b0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
22151cf0.28b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
22161cf0.28b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
22171cf0.28b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
22181cf0.28b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
22191cf0.28b0: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\clbcatq.dll'
22201cf0.28b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
22211cf0.28b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
22221cf0.28b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
22231cf0.28b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
22241cf0.28b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
22251cf0.28b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ole32.dll'.
22261cf0.28b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'oleaut32.dll'.
22271cf0.28b0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxC.dll) WinVerifyTrust
22281cf0.28b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxC.dll
22291cf0.28b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
22301cf0.28b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
22311cf0.28b0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
22321cf0.28b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
22331cf0.28b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
22341cf0.28b0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
22351cf0.28b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
22361cf0.28b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
22371cf0.28b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
22381cf0.28b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
22391cf0.28b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
22401cf0.28b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
22411cf0.28b0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
22421cf0.28b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
22431cf0.28b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
22441cf0.28b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxC.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
22451cf0.28b0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxC.dll
22461cf0.28b0: supR3HardenedDllNotificationCallback: load 00007ffbbc700000 LB 0x00545000 C:\Program Files\Oracle\VirtualBox\VBoxC.dll [fFlags=0x0]
22471cf0.28b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxC.dll
22481cf0.28b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbbc700000 'C:\Program Files\Oracle\VirtualBox\VBoxC.dll'
22491cf0.28b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
22501cf0.28b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
22511cf0.28b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
22521cf0.28b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
22531cf0.28b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'shlwapi.dll'.
22541cf0.28b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ole32.dll'.
22551cf0.28b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'oleaut32.dll'.
22561cf0.28b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
22571cf0.28b0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll) WinVerifyTrust
22581cf0.28b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll
22591cf0.28b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
22601cf0.28b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
22611cf0.28b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
22621cf0.28b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
22631cf0.28b0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
22641cf0.28b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
22651cf0.28b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
22661cf0.28b0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
22671cf0.28b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
22681cf0.28b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
22691cf0.28b0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll [redoing WinVerifyTrust]
22701cf0.28b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
22711cf0.28b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
22721cf0.28b0: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll'
22731cf0.28b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
22741cf0.28b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
22751cf0.28b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
22761cf0.28b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
22771cf0.28b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
22781cf0.28b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
22791cf0.28b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
22801cf0.28b0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll
22811cf0.28b0: supR3HardenedDllNotificationCallback: load 00007ffbbcc50000 LB 0x000ba000 C:\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll [fFlags=0x0]
22821cf0.28b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll
22831cf0.28b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbbcc50000 'C:\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll'
22841cf0.28b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
22851cf0.28b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\oleaut32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
22861cf0.28b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe7760000 'C:\Windows\System32\oleaut32.dll'
22871cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll
22881cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\gdi32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
22891cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe71b0000 'C:\WINDOWS\system32\gdi32.dll'
22901cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
22911cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
22921cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe7b50000 'C:\WINDOWS\system32\shell32.dll'
22931cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbe9490000 LB 0x00167000 C:\WINDOWS\System32\MSCTF.dll [fFlags=0x0]
22941cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
22951cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #19 'oleaut32.dll'.
22961cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #36 'user32.dll'.
22971cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #37 'gdi32.dll'.
22981cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #38 'imm32.dll'.
22991cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\msctf.dll)
23001cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msctf.dll
23011cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
23021cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume2\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
23031cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\imm32.dll
23041cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
23051cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
23061cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
23071cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
23081cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
23091cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
23101cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
23111cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
23121cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
23131cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
23141cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
23151cf0.41c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\msctf.dll'
23161cf0.41c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000a30 pwszName=\Device\HarddiskVolume2\Windows\System32\DataExchange.dll
23171cf0.41c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000002d2b930
23181cf0.41c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000002d2b930
23191cf0.41c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=87FA668FC207CB724FFDD342C6B5B8D273E3498D
23201cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
23211cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
23221cf0.41c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0010~31bf3856ad364e35~amd64~~10.0.16299.15.cat'; file='\Device\HarddiskVolume2\Windows\System32\DataExchange.dll'
23231cf0.41c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
23241cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
23251cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'shcore.dll'.
23261cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #28 'combase.dll'.
23271cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #31 'd3d11.dll'.
23281cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #32 'dcomp.dll'.
23291cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\DataExchange.dll) WinVerifyTrust
23301cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\DataExchange.dll
23311cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dcomp.dll'...
23321cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'dcomp.dll' -> '\Device\HarddiskVolume2\Windows\System32\dcomp.dll' [rcNtRedir=0xc0150008]
23331cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
23341cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
23351cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'win32u.dll'.
23361cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
23371cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\dcomp.dll) WinVerifyTrust
23381cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\dcomp.dll
23391cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'd3d11.dll'...
23401cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'd3d11.dll' -> '\Device\HarddiskVolume2\Windows\System32\d3d11.dll' [rcNtRedir=0xc0150008]
23411cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
23421cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
23431cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
23441cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume2\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
23451cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\win32u.dll [lacks WinVerifyTrust]
23461cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
23471cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
23481cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
23491cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'dxgi.dll'.
23501cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #35 'win32u.dll'.
23511cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\d3d11.dll) WinVerifyTrust
23521cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\d3d11.dll
23531cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
23541cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume2\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
23551cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\combase.dll [redoing WinVerifyTrust]
23561cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
23571cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume2\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
23581cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\win32u.dll [lacks WinVerifyTrust]
23591cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dxgi.dll'...
23601cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'dxgi.dll' -> '\Device\HarddiskVolume2\Windows\System32\dxgi.dll' [rcNtRedir=0xc0150008]
23611cf0.41c: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\dxgi.dll'.
23621cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
23631cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'win32u.dll'.
23641cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\dxgi.dll)
23651cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\dxgi.dll
23661cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
23671cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
23681cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
23691cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume2\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
23701cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\win32u.dll [lacks WinVerifyTrust]
23711cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
23721cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
23731cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
23741cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
23751cf0.41c: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\combase.dll'
23761cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shcore.dll'...
23771cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'shcore.dll' -> '\Device\HarddiskVolume2\Windows\System32\shcore.dll' [rcNtRedir=0xc0150008]
23781cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\SHCore.dll
23791cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
23801cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
23811cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\dataexchange.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
23821cf0.41c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\DataExchange.dll
23831cf0.41c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\d3d11.dll
23841cf0.41c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dcomp.dll
23851cf0.41c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dxgi.dll [avoiding WinVerifyTrust]
23861cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbe4d50000 LB 0x000af000 C:\WINDOWS\system32\dxgi.dll [fFlags=0x0]
23871cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dxgi.dll [avoiding WinVerifyTrust]
23881cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbe30b0000 LB 0x002e2000 C:\WINDOWS\system32\d3d11.dll [fFlags=0x0]
23891cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\d3d11.dll
23901cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbe3e70000 LB 0x00142000 C:\WINDOWS\system32\dcomp.dll [fFlags=0x0]
23911cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dcomp.dll
23921cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbca0d0000 LB 0x0004f000 C:\WINDOWS\system32\dataexchange.dll [fFlags=0x0]
23931cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\DataExchange.dll
23941cf0.41c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\dxgi.dll'.
23951cf0.41c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\dxgi.dll' [rescheduled]
23961cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe71b0000 'C:\WINDOWS\System32\gdi32.dll'
23971cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbca0d0000 'C:\WINDOWS\system32\dataexchange.dll'
23981cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
23991cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'rmclient.dll'.
24001cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #30 'rpcrt4.dll'.
24011cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #32 'bcrypt.dll'.
24021cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #45 'combase.dll'.
24031cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\twinapi.appcore.dll)
24041cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\twinapi.appcore.dll
24051cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
24061cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'rpcrt4.dll'.
24071cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\rmclient.dll)
24081cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\rmclient.dll
24091cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbe4880000 LB 0x00020000 C:\WINDOWS\system32\RMCLIENT.dll [fFlags=0x0]
24101cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rmclient.dll [avoiding WinVerifyTrust]
24111cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbe4910000 LB 0x0017b000 C:\WINDOWS\system32\twinapi.appcore.dll [fFlags=0x0]
24121cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\twinapi.appcore.dll [avoiding WinVerifyTrust]
24131cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
24141cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
24151cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
24161cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
24171cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
24181cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume2\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
24191cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\combase.dll
24201cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
24211cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume2\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
24221cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll
24231cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
24241cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
24251cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rmclient.dll'...
24261cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rmclient.dll' -> '\Device\HarddiskVolume2\Windows\System32\rmclient.dll' [rcNtRedir=0xc0150008]
24271cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rmclient.dll [lacks WinVerifyTrust]
24281cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
24291cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
24301cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
24311cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
24321cf0.41c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\rmclient.dll'
24331cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
24341cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
24351cf0.41c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\twinapi.appcore.dll'
24361cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msctf.dll
24371cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\MSCTF.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
24381cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe9490000 'C:\WINDOWS\System32\MSCTF.dll'
24391cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
24401cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\ole32.dll (Input=ole32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
24411cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe9860000 'C:\WINDOWS\System32\ole32.dll'
24421cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
24431cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\OLEAUT32.dll (Input=OLEAUT32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
24441cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe7760000 'C:\WINDOWS\System32\OLEAUT32.dll'
24451cf0.41c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000ad8 pwszName=\Device\HarddiskVolume2\Windows\System32\wbem\wbemprox.dll
24461cf0.41c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000002d2b930
24471cf0.41c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000002d2b930
24481cf0.41c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=AE2733DC030E44DCE443886E467FF179D2D68A91
24491cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll
24501cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
24511cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
24521cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
24531cf0.41c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package01~31bf3856ad364e35~amd64~~10.0.16299.15.cat'; file='\Device\HarddiskVolume2\Windows\System32\wbem\wbemprox.dll'
24541cf0.41c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
24551cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
24561cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ws2_32.dll'.
24571cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'wbemcomn.dll'.
24581cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\wbem\wbemprox.dll) WinVerifyTrust
24591cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wbem\wbemprox.dll
24601cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wbemcomn.dll'...
24611cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'wbemcomn.dll' -> '\Device\HarddiskVolume2\Windows\System32\wbemcomn.dll' [rcNtRedir=0xc0150008]
24621cf0.41c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000ae4 pwszName=\Device\HarddiskVolume2\Windows\System32\wbemcomn.dll
24631cf0.41c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000002d2b930
24641cf0.41c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000002d2b930
24651cf0.41c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=CA3F9D85214DB0270185C719B931C69440BA9C18
24661cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
24671cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
24681cf0.41c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package01~31bf3856ad364e35~amd64~~10.0.16299.15.cat'; file='\Device\HarddiskVolume2\Windows\System32\wbemcomn.dll'
24691cf0.41c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
24701cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
24711cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'bcrypt.dll'.
24721cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'ws2_32.dll'.
24731cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\wbemcomn.dll) WinVerifyTrust
24741cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wbemcomn.dll
24751cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
24761cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
24771cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
24781cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
24791cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
24801cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
24811cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
24821cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
24831cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
24841cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume2\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
24851cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll
24861cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
24871cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
24881cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\wbem\wbemprox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
24891cf0.41c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbem\wbemprox.dll
24901cf0.41c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbemcomn.dll
24911cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbdbc40000 LB 0x00081000 C:\WINDOWS\SYSTEM32\wbemcomn.dll [fFlags=0x0]
24921cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbemcomn.dll
24931cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbdbcd0000 LB 0x0000f000 C:\WINDOWS\system32\wbem\wbemprox.dll [fFlags=0x0]
24941cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbem\wbemprox.dll
24951cf0.41c: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(API-MS-Win-Core-LocalRegistry-L1-1-0.dll) -> 0x0, fPresent=1
24961cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Core-LocalRegistry-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
24971cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe65e0000 'API-MS-Win-Core-LocalRegistry-L1-1-0.dll'
24981cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbdbcd0000 'C:\WINDOWS\system32\wbem\wbemprox.dll'
24991cf0.41c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000ae8 pwszName=\Device\HarddiskVolume2\Windows\System32\wbem\wbemsvc.dll
25001cf0.41c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000002d2b930
25011cf0.41c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000002d2b930
25021cf0.41c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=4C70145BD7347C12AB1BF3946D40606389C4D331
25031cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
25041cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
25051cf0.41c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package01~31bf3856ad364e35~amd64~~10.0.16299.15.cat'; file='\Device\HarddiskVolume2\Windows\System32\wbem\wbemsvc.dll'
25061cf0.41c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
25071cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
25081cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'rpcrt4.dll'.
25091cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\wbem\wbemsvc.dll) WinVerifyTrust
25101cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wbem\wbemsvc.dll
25111cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
25121cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
25131cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
25141cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
25151cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\wbem\wbemsvc.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
25161cf0.41c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbem\wbemsvc.dll
25171cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbdb930000 LB 0x00014000 C:\WINDOWS\system32\wbem\wbemsvc.dll [fFlags=0x0]
25181cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbem\wbemsvc.dll
25191cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbdb930000 'C:\WINDOWS\system32\wbem\wbemsvc.dll'
25201cf0.41c: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-l1-2-0.dll) -> 0x0, fPresent=1
25211cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-l1-2-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
25221cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe65e0000 'api-ms-win-core-localization-l1-2-0.dll'
25231cf0.41c: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-obsolete-l1-1-0.dll) -> 0x0, fPresent=1
25241cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-obsolete-l1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
25251cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe65e0000 'api-ms-win-core-localization-obsolete-l1-1-0.dll'
25261cf0.41c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000b14 pwszName=\Device\HarddiskVolume2\Windows\System32\wbem\fastprox.dll
25271cf0.41c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000002d2b930
25281cf0.41c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000002d2b930
25291cf0.41c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=336CDD3C969CEFC6CE8D502298ED123FE8D2F483
25301cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
25311cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
25321cf0.41c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package01~31bf3856ad364e35~amd64~~10.0.16299.15.cat'; file='\Device\HarddiskVolume2\Windows\System32\wbem\fastprox.dll'
25331cf0.41c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
25341cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
25351cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #19 'wbemcomn.dll'.
25361cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\wbem\fastprox.dll) WinVerifyTrust
25371cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wbem\fastprox.dll
25381cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wbemcomn.dll'...
25391cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'wbemcomn.dll' -> '\Device\HarddiskVolume2\Windows\System32\wbemcomn.dll' [rcNtRedir=0xc0150008]
25401cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbemcomn.dll
25411cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
25421cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
25431cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\wbem\fastprox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
25441cf0.41c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbem\fastprox.dll
25451cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbdb950000 LB 0x000f0000 C:\WINDOWS\system32\wbem\fastprox.dll [fFlags=0x0]
25461cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbem\fastprox.dll
25471cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbdb950000 'C:\WINDOWS\system32\wbem\fastprox.dll'
25481cf0.16b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
25491cf0.16b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
25501cf0.16b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrem.dll'.
25511cf0.16b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
25521cf0.16b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll) WinVerifyTrust
25531cf0.16b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
25541cf0.16b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
25551cf0.16b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
25561cf0.16b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrem.dll'...
25571cf0.16b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrem.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrem.dll' [rcNtRedir=0xc0150008]
25581cf0.16b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
25591cf0.16b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'vboxrt.dll'.
25601cf0.16b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
25611cf0.16b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcrt.dll'.
25621cf0.16b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxREM.dll) WinVerifyTrust
25631cf0.16b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxREM.dll
25641cf0.16b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
25651cf0.16b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
25661cf0.16b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
25671cf0.16b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
25681cf0.16b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
25691cf0.16b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
25701cf0.16b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
25711cf0.16b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
25721cf0.16b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
25731cf0.16b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
25741cf0.16b4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
25751cf0.16b4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxREM.dll
25761cf0.16b4: supR3HardenedDllNotificationCallback: load 00000000634f0000 LB 0x0010b000 C:\Program Files\Oracle\VirtualBox\VBoxREM.dll [fFlags=0x0]
25771cf0.16b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxREM.dll
25781cf0.16b4: supR3HardenedDllNotificationCallback: load 00007ffbb04a0000 LB 0x002c9000 C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL [fFlags=0x0]
25791cf0.16b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
25801cf0.16b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbb04a0000 'C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL'
25811cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
25821cf0.d04: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
25831cf0.d04: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
25841cf0.d04: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
25851cf0.d04: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
25861cf0.d04: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
25871cf0.d04: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll) WinVerifyTrust
25881cf0.d04: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll
25891cf0.d04: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
25901cf0.d04: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
25911cf0.d04: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
25921cf0.d04: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
25931cf0.d04: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
25941cf0.d04: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
25951cf0.d04: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
25961cf0.d04: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
25971cf0.d04: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
25981cf0.d04: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
25991cf0.d04: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll
26001cf0.d04: supR3HardenedDllNotificationCallback: load 00007ffbe2330000 LB 0x0000b000 C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL [fFlags=0x0]
26011cf0.d04: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll
26021cf0.d04: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe2330000 'C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL'
26031cf0.d04: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe9300000 'C:\WINDOWS\system32\User32.dll'
26041cf0.2fbc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
26051cf0.2fbc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
26061cf0.2fbc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
26071cf0.2fbc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
26081cf0.2fbc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll) WinVerifyTrust
26091cf0.2fbc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll
26101cf0.2fbc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
26111cf0.2fbc: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
26121cf0.2fbc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
26131cf0.2fbc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
26141cf0.2fbc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
26151cf0.2fbc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
26161cf0.2fbc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
26171cf0.2fbc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
26181cf0.2fbc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll
26191cf0.2fbc: supR3HardenedDllNotificationCallback: load 00007ffbde6f0000 LB 0x0000d000 C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL [fFlags=0x0]
26201cf0.2fbc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll
26211cf0.2fbc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbde6f0000 'C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL'
26221cf0.23e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
26231cf0.23e0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
26241cf0.23e0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
26251cf0.23e0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
26261cf0.23e0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll) WinVerifyTrust
26271cf0.23e0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll
26281cf0.23e0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
26291cf0.23e0: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
26301cf0.23e0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
26311cf0.23e0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
26321cf0.23e0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
26331cf0.23e0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
26341cf0.23e0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
26351cf0.23e0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll
26361cf0.23e0: supR3HardenedDllNotificationCallback: load 00007ffbde600000 LB 0x0000c000 C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL [fFlags=0x0]
26371cf0.23e0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll
26381cf0.23e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbde600000 'C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL'
26391cf0.600: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
26401cf0.600: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
26411cf0.600: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
26421cf0.600: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
26431cf0.600: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll) WinVerifyTrust
26441cf0.600: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll
26451cf0.600: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
26461cf0.600: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
26471cf0.600: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
26481cf0.600: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
26491cf0.600: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
26501cf0.600: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
26511cf0.600: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
26521cf0.600: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
26531cf0.600: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll
26541cf0.600: supR3HardenedDllNotificationCallback: load 00007ffbde5f0000 LB 0x0000b000 C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL [fFlags=0x0]
26551cf0.600: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll
26561cf0.600: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbde5f0000 'C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL'
26571cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe7b50000 'C:\WINDOWS\system32\Shell32.dll'
26581cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
26591cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
26601cf0.21fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
26611cf0.21fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
26621cf0.21fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
26631cf0.21fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vboxddu.dll'.
26641cf0.21fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'vboxdd2.dll'.
26651cf0.21fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
26661cf0.21fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'setupapi.dll'.
26671cf0.21fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'ws2_32.dll'.
26681cf0.21fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'ole32.dll'.
26691cf0.21fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'iphlpapi.dll'.
26701cf0.21fc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD.dll) WinVerifyTrust
26711cf0.21fc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD.dll
26721cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'iphlpapi.dll'...
26731cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'iphlpapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\iphlpapi.dll' [rcNtRedir=0xc0150008]
26741cf0.21fc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL [redoing WinVerifyTrust]
26751cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
26761cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
26771cf0.21fc: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL'
26781cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
26791cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
26801cf0.21fc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
26811cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
26821cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
26831cf0.21fc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
26841cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
26851cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
26861cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
26871cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
26881cf0.21fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
26891cf0.21fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #29 'rpcrt4.dll'.
26901cf0.21fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #37 'cfgmgr32.dll'.
26911cf0.21fc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\setupapi.dll) WinVerifyTrust
26921cf0.21fc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\setupapi.dll
26931cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
26941cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
26951cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxdd2.dll'...
26961cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxdd2.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxdd2.dll' [rcNtRedir=0xc0150008]
26971cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
26981cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
26991cf0.21fc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll [lacks WinVerifyTrust]
27001cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
27011cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
27021cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
27031cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
27041cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
27051cf0.21fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
27061cf0.21fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
27071cf0.21fc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD2.dll) WinVerifyTrust
27081cf0.21fc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD2.dll
27091cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxddu.dll'...
27101cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxddu.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxddu.dll' [rcNtRedir=0xc0150008]
27111cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
27121cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
27131cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
27141cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
27151cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
27161cf0.21fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
27171cf0.21fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
27181cf0.21fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
27191cf0.21fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'setupapi.dll'.
27201cf0.21fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'advapi32.dll'.
27211cf0.21fc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDDU.dll) WinVerifyTrust
27221cf0.21fc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDDU.dll
27231cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
27241cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
27251cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
27261cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
27271cf0.21fc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
27281cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
27291cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
27301cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
27311cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
27321cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
27331cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
27341cf0.21fc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\setupapi.dll
27351cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
27361cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
27371cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
27381cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
27391cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
27401cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
27411cf0.21fc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxDD.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
27421cf0.21fc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD.dll
27431cf0.21fc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDDU.dll
27441cf0.21fc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD2.dll
27451cf0.21fc: supR3HardenedDllNotificationCallback: load 00007ffbe71e0000 LB 0x0044e000 C:\WINDOWS\System32\SETUPAPI.dll [fFlags=0x0]
27461cf0.21fc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\setupapi.dll
27471cf0.21fc: supR3HardenedDllNotificationCallback: load 00007ffbbceb0000 LB 0x00063000 C:\Program Files\Oracle\VirtualBox\VBoxDDU.dll [fFlags=0x0]
27481cf0.21fc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDDU.dll
27491cf0.21fc: supR3HardenedDllNotificationCallback: load 00007ffbbecc0000 LB 0x0005d000 C:\Program Files\Oracle\VirtualBox\VBoxDD2.dll [fFlags=0x0]
27501cf0.21fc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD2.dll
27511cf0.21fc: supR3HardenedDllNotificationCallback: load 00007ffba5770000 LB 0x009c3000 C:\Program Files\Oracle\VirtualBox\VBoxDD.DLL [fFlags=0x0]
27521cf0.21fc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD.dll
27531cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffba5770000 'C:\Program Files\Oracle\VirtualBox\VBoxDD.DLL'
27541cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
27551cf0.21fc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxC.dll
27561cf0.21fc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxC.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
27571cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbbc700000 'C:\Program Files\Oracle\VirtualBox\VBoxC.DLL'
27581cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
27591cf0.21fc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD2.dll
27601cf0.21fc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxDD2.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
27611cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbbecc0000 'C:\Program Files\Oracle\VirtualBox\VBoxDD2.DLL'
27621cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
27631cf0.2818: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
27641cf0.2818: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
27651cf0.2818: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
27661cf0.2818: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
27671cf0.2818: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll) WinVerifyTrust
27681cf0.2818: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll
27691cf0.2818: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
27701cf0.2818: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
27711cf0.2818: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
27721cf0.2818: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
27731cf0.2818: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
27741cf0.2818: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
27751cf0.2818: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
27761cf0.2818: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
27771cf0.2818: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll
27781cf0.2818: supR3HardenedDllNotificationCallback: load 00007ffbdd990000 LB 0x0000d000 C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL [fFlags=0x0]
27791cf0.2818: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll
27801cf0.2818: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbdd990000 'C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL'
27811cf0.21fc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL
27821cf0.21fc: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\Iphlpapi.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
27831cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5510000 'C:\WINDOWS\system32\Iphlpapi.dll'
27841cf0.21fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rpcrt4.dll'.
27851cf0.21fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'nsi.dll'.
27861cf0.21fc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\winnsi.dll)
27871cf0.21fc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\winnsi.dll
27881cf0.21fc: supR3HardenedDllNotificationCallback: load 00007ffbe96a0000 LB 0x00008000 C:\WINDOWS\System32\NSI.dll [fFlags=0x0]
27891cf0.21fc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\nsi.dll)
27901cf0.21fc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\nsi.dll
27911cf0.21fc: supR3HardenedDllNotificationCallback: load 00007ffbe0c00000 LB 0x0000b000 C:\WINDOWS\SYSTEM32\WINNSI.DLL [fFlags=0x0]
27921cf0.21fc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winnsi.dll [avoiding WinVerifyTrust]
27931cf0.21fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rpcrt4.dll'.
27941cf0.21fc: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\dhcpcsvc6.dll)
27951cf0.21fc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\dhcpcsvc6.dll
27961cf0.21fc: supR3HardenedDllNotificationCallback: load 00007ffbdfb00000 LB 0x00016000 C:\WINDOWS\SYSTEM32\dhcpcsvc6.DLL [fFlags=0x0]
27971cf0.21fc: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\dhcpcsvc6.dll [avoiding WinVerifyTrust]
27981cf0.21fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rpcrt4.dll'.
27991cf0.21fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ws2_32.dll'.
28001cf0.21fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'nsi.dll'.
28011cf0.21fc: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\dhcpcsvc.dll)
28021cf0.21fc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\dhcpcsvc.dll
28031cf0.21fc: supR3HardenedDllNotificationCallback: load 00007ffbe0bc0000 LB 0x0001a000 C:\WINDOWS\SYSTEM32\dhcpcsvc.DLL [fFlags=0x0]
28041cf0.21fc: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\dhcpcsvc.dll [avoiding WinVerifyTrust]
28051cf0.21fc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000db0 pwszName=\Device\HarddiskVolume2\Windows\System32\dhcpcsvc.dll
28061cf0.21fc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000002d2b930
28071cf0.21fc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000002d2b930
28081cf0.21fc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=A0979042666D2FF6A450082A737154F788178270
28091cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
28101cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume2\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
28111cf0.21fc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\nsi.dll [lacks WinVerifyTrust]
28121cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
28131cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
28141cf0.21fc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
28151cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
28161cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
28171cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
28181cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
28191cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
28201cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume2\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
28211cf0.21fc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\nsi.dll [lacks WinVerifyTrust]
28221cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
28231cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
28241cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
28251cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
28261cf0.21fc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0015~31bf3856ad364e35~amd64~~10.0.16299.15.cat'; file='\Device\HarddiskVolume2\Windows\System32\dhcpcsvc.dll'
28271cf0.21fc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
28281cf0.21fc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\dhcpcsvc.dll'
28291cf0.21fc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000f50 pwszName=\Device\HarddiskVolume2\Windows\System32\dhcpcsvc6.dll
28301cf0.21fc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000002d2b930
28311cf0.21fc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000002d2b930
28321cf0.21fc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=839F90BCFF138802B805D9F6439239CC98023804
28331cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
28341cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
28351cf0.21fc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0015~31bf3856ad364e35~amd64~~10.0.16299.15.cat'; file='\Device\HarddiskVolume2\Windows\System32\dhcpcsvc6.dll'
28361cf0.21fc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
28371cf0.21fc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\dhcpcsvc6.dll'
28381cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
28391cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
28401cf0.21fc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\nsi.dll'
28411cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
28421cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
28431cf0.21fc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\winnsi.dll'
28441cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
28451cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
28461cf0.21fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
28471cf0.21fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'rpcrt4.dll'.
28481cf0.21fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #32 'devobj.dll'.
28491cf0.21fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #33 'propsys.dll'.
28501cf0.21fc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll) WinVerifyTrust
28511cf0.21fc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
28521cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'propsys.dll'...
28531cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'propsys.dll' -> '\Device\HarddiskVolume2\Windows\System32\propsys.dll' [rcNtRedir=0xc0150008]
28541cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
28551cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
28561cf0.21fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
28571cf0.21fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #15 'oleaut32.dll'.
28581cf0.21fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #31 'rpcrt4.dll'.
28591cf0.21fc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\propsys.dll) WinVerifyTrust
28601cf0.21fc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\propsys.dll
28611cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'devobj.dll'...
28621cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'devobj.dll' -> '\Device\HarddiskVolume2\Windows\System32\devobj.dll' [rcNtRedir=0xc0150008]
28631cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
28641cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
28651cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
28661cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
28671cf0.21fc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
28681cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
28691cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
28701cf0.21fc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
28711cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
28721cf0.21fc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll
28731cf0.21fc: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
28741cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
28751cf0.21fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'cfgmgr32.dll'.
28761cf0.21fc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\devobj.dll) WinVerifyTrust
28771cf0.21fc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\devobj.dll
28781cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
28791cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
28801cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
28811cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
28821cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
28831cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
28841cf0.21fc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll [redoing WinVerifyTrust]
28851cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
28861cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
28871cf0.21fc: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll'
28881cf0.21fc: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\MMDevApi.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
28891cf0.21fc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
28901cf0.21fc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\devobj.dll
28911cf0.21fc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\propsys.dll
28921cf0.21fc: supR3HardenedDllNotificationCallback: load 00007ffbe5d00000 LB 0x00027000 C:\WINDOWS\System32\DEVOBJ.dll [fFlags=0x0]
28931cf0.21fc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\devobj.dll
28941cf0.21fc: supR3HardenedDllNotificationCallback: load 00007ffbe2d10000 LB 0x001b1000 C:\WINDOWS\System32\PROPSYS.dll [fFlags=0x0]
28951cf0.21fc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\propsys.dll
28961cf0.21fc: supR3HardenedDllNotificationCallback: load 00007ffbdce30000 LB 0x0006f000 C:\WINDOWS\System32\MMDevApi.dll [fFlags=0x0]
28971cf0.21fc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
28981cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbdce30000 'C:\WINDOWS\System32\MMDevApi.dll'
28991cf0.21fc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000e3c pwszName=\Device\HarddiskVolume2\Windows\System32\dsound.dll
29001cf0.21fc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000002d2b930
29011cf0.21fc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000002d2b930
29021cf0.21fc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=149E0A5A40CD1471B9EF3D3043A8C754805FEC76
29031cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
29041cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
29051cf0.21fc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package~31bf3856ad364e35~amd64~~10.0.16299.15.cat'; file='\Device\HarddiskVolume2\Windows\System32\dsound.dll'
29061cf0.21fc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
29071cf0.21fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
29081cf0.21fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #32 'winmm.dll'.
29091cf0.21fc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\dsound.dll) WinVerifyTrust
29101cf0.21fc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\dsound.dll
29111cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
29121cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
29131cf0.21fc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
29141cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
29151cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
29161cf0.21fc: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
29171cf0.21fc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dsound.dll
29181cf0.21fc: supR3HardenedDllNotificationCallback: load 00007ffbb0770000 LB 0x0008f000 C:\WINDOWS\System32\dsound.dll [fFlags=0x0]
29191cf0.21fc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dsound.dll
29201cf0.21fc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dsound.dll
29211cf0.21fc: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
29221cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbb0770000 'C:\WINDOWS\System32\dsound.dll'
29231cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbb0770000 'C:\WINDOWS\System32\dsound.dll'
29241cf0.21fc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dsound.dll
29251cf0.21fc: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
29261cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbb0770000 'C:\WINDOWS\system32\dsound.dll'
29271cf0.21fc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
29281cf0.21fc: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\MMDEVAPI.DLL (Input=MMDEVAPI.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
29291cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbdce30000 'C:\WINDOWS\System32\MMDEVAPI.DLL'
29301cf0.21fc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
29311cf0.21fc: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\winmm.dll (Input=winmm.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
29321cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe2f90000 'C:\WINDOWS\System32\winmm.dll'
29331cf0.21fc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000001018 pwszName=\Device\HarddiskVolume2\Windows\System32\wdmaud.drv
29341cf0.21fc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000002d2b930
29351cf0.21fc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000002d2b930
29361cf0.21fc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=47392EB8EC6AC07C788B971D8BB592B6FD619920
29371cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
29381cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
29391cf0.21fc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package~31bf3856ad364e35~amd64~~10.0.16299.15.cat'; file='\Device\HarddiskVolume2\Windows\System32\wdmaud.drv'
29401cf0.21fc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
29411cf0.21fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
29421cf0.21fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'mmdevapi.dll'.
29431cf0.21fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #27 'ksuser.dll'.
29441cf0.21fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #28 'avrt.dll'.
29451cf0.21fc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\wdmaud.drv) WinVerifyTrust
29461cf0.21fc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
29471cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'avrt.dll'...
29481cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'avrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\avrt.dll' [rcNtRedir=0xc0150008]
29491cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
29501cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
29511cf0.21fc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\avrt.dll) WinVerifyTrust
29521cf0.21fc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\avrt.dll
29531cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ksuser.dll'...
29541cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'ksuser.dll' -> '\Device\HarddiskVolume2\Windows\System32\ksuser.dll' [rcNtRedir=0xc0150008]
29551cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
29561cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
29571cf0.21fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
29581cf0.21fc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ksuser.dll) WinVerifyTrust
29591cf0.21fc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ksuser.dll
29601cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mmdevapi.dll'...
29611cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'mmdevapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\mmdevapi.dll' [rcNtRedir=0xc0150008]
29621cf0.21fc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
29631cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
29641cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
29651cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
29661cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
29671cf0.21fc: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
29681cf0.21fc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
29691cf0.21fc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ksuser.dll
29701cf0.21fc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\avrt.dll
29711cf0.21fc: supR3HardenedDllNotificationCallback: load 00007ffbdc290000 LB 0x00009000 C:\WINDOWS\SYSTEM32\ksuser.dll [fFlags=0x0]
29721cf0.21fc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ksuser.dll
29731cf0.21fc: supR3HardenedDllNotificationCallback: load 00007ffbe2660000 LB 0x0000a000 C:\WINDOWS\SYSTEM32\AVRT.dll [fFlags=0x0]
29741cf0.21fc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\avrt.dll
29751cf0.21fc: supR3HardenedDllNotificationCallback: load 00007ffbc1d60000 LB 0x00042000 C:\WINDOWS\System32\wdmaud.drv [fFlags=0x0]
29761cf0.21fc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
29771cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbc1d60000 'C:\WINDOWS\System32\wdmaud.drv'
29781cf0.21fc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
29791cf0.21fc: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
29801cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbc1d60000 'C:\WINDOWS\System32\wdmaud.drv'
29811cf0.21fc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
29821cf0.21fc: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
29831cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbc1d60000 'C:\WINDOWS\System32\wdmaud.drv'
29841cf0.21fc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
29851cf0.21fc: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
29861cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbc1d60000 'C:\WINDOWS\System32\wdmaud.drv'
29871cf0.21fc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
29881cf0.21fc: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
29891cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbc1d60000 'C:\WINDOWS\System32\wdmaud.drv'
29901cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
29911cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
29921cf0.21fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
29931cf0.21fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'rpcrt4.dll'.
29941cf0.21fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'oleaut32.dll'.
29951cf0.21fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #55 'mmdevapi.dll'.
29961cf0.21fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #56 'avrt.dll'.
29971cf0.21fc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\AudioSes.dll) WinVerifyTrust
29981cf0.21fc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\AudioSes.dll
29991cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'avrt.dll'...
30001cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'avrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\avrt.dll' [rcNtRedir=0xc0150008]
30011cf0.21fc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\avrt.dll
30021cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mmdevapi.dll'...
30031cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'mmdevapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\mmdevapi.dll' [rcNtRedir=0xc0150008]
30041cf0.21fc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
30051cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
30061cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
30071cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
30081cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
30091cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
30101cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
30111cf0.21fc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcp_win.dll [redoing WinVerifyTrust]
30121cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
30131cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
30141cf0.21fc: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\msvcp_win.dll'
30151cf0.21fc: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\AUDIOSES.DLL (Input=AUDIOSES.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
30161cf0.21fc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\AudioSes.dll
30171cf0.21fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'combase.dll'.
30181cf0.21fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #21 'rpcrt4.dll'.
30191cf0.21fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #28 'bcryptprimitives.dll'.
30201cf0.21fc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\WinTypes.dll)
30211cf0.21fc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\WinTypes.dll
30221cf0.21fc: supR3HardenedDllNotificationCallback: load 00007ffbe1d00000 LB 0x00136000 C:\WINDOWS\SYSTEM32\wintypes.dll [fFlags=0x0]
30231cf0.21fc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\WinTypes.dll [avoiding WinVerifyTrust]
30241cf0.21fc: supR3HardenedDllNotificationCallback: load 00007ffbc15e0000 LB 0x00122000 C:\WINDOWS\System32\AUDIOSES.DLL [fFlags=0x0]
30251cf0.21fc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\AudioSes.dll
30261cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbc15e0000 'C:\WINDOWS\System32\AUDIOSES.DLL'
30271cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcryptprimitives.dll'...
30281cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcryptprimitives.dll' -> '\Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll' [rcNtRedir=0xc0150008]
30291cf0.21fc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll
30301cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
30311cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
30321cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
30331cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume2\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
30341cf0.21fc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\combase.dll
30351cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
30361cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
30371cf0.21fc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\WinTypes.dll'
30381cf0.21fc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
30391cf0.21fc: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
30401cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbc1d60000 'C:\WINDOWS\System32\wdmaud.drv'
30411cf0.21fc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
30421cf0.21fc: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
30431cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbc1d60000 'C:\WINDOWS\System32\wdmaud.drv'
30441cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbc1d60000 'C:\WINDOWS\System32\wdmaud.drv'
30451cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbc1d60000 'C:\WINDOWS\System32\wdmaud.drv'
30461cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbc1d60000 'C:\WINDOWS\System32\wdmaud.drv'
30471cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbc1d60000 'C:\WINDOWS\System32\wdmaud.drv'
30481cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbc1d60000 'C:\WINDOWS\System32\wdmaud.drv'
30491cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbc1d60000 'C:\WINDOWS\System32\wdmaud.drv'
30501cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbc1d60000 'C:\WINDOWS\System32\wdmaud.drv'
30511cf0.21fc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
30521cf0.21fc: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
30531cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbc1d60000 'C:\WINDOWS\System32\wdmaud.drv'
30541cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbc1d60000 'C:\WINDOWS\System32\wdmaud.drv'
30551cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbc1d60000 'C:\WINDOWS\System32\wdmaud.drv'
30561cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbc1d60000 'C:\WINDOWS\System32\wdmaud.drv'
30571cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbc1d60000 'C:\WINDOWS\System32\wdmaud.drv'
30581cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbc1d60000 'C:\WINDOWS\System32\wdmaud.drv'
30591cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbc1d60000 'C:\WINDOWS\System32\wdmaud.drv'
30601cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbc1d60000 'C:\WINDOWS\System32\wdmaud.drv'
30611cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbc1d60000 'C:\WINDOWS\System32\wdmaud.drv'
30621cf0.21fc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000d9c pwszName=\Device\HarddiskVolume2\Windows\System32\msacm32.drv
30631cf0.21fc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000002d2b930
30641cf0.21fc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000002d2b930
30651cf0.21fc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=8069FA07F8A743E03BD7E2DA392DE4429701D8E6
30661cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
30671cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
30681cf0.21fc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package~31bf3856ad364e35~amd64~~10.0.16299.15.cat'; file='\Device\HarddiskVolume2\Windows\System32\msacm32.drv'
30691cf0.21fc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
30701cf0.21fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
30711cf0.21fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'mmdevapi.dll'.
30721cf0.21fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'msacm32.dll'.
30731cf0.21fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'winmmbase.dll'.
30741cf0.21fc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\msacm32.drv) WinVerifyTrust
30751cf0.21fc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msacm32.drv
30761cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmmbase.dll'...
30771cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmmbase.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmmbase.dll' [rcNtRedir=0xc0150008]
30781cf0.21fc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmmbase.dll [redoing WinVerifyTrust]
30791cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
30801cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
30811cf0.21fc: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\winmmbase.dll'
30821cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msacm32.dll'...
30831cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msacm32.dll' -> '\Device\HarddiskVolume2\Windows\System32\msacm32.dll' [rcNtRedir=0xc0150008]
30841cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
30851cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
30861cf0.21fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
30871cf0.21fc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\msacm32.dll) WinVerifyTrust
30881cf0.21fc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msacm32.dll
30891cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mmdevapi.dll'...
30901cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'mmdevapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\mmdevapi.dll' [rcNtRedir=0xc0150008]
30911cf0.21fc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
30921cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
30931cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
30941cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
30951cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
30961cf0.21fc: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
30971cf0.21fc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
30981cf0.21fc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.dll
30991cf0.21fc: supR3HardenedDllNotificationCallback: load 00007ffbc2db0000 LB 0x0001c000 C:\WINDOWS\SYSTEM32\MSACM32.dll [fFlags=0x0]
31001cf0.21fc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.dll
31011cf0.21fc: supR3HardenedDllNotificationCallback: load 00007ffbdc280000 LB 0x0000c000 C:\WINDOWS\System32\msacm32.drv [fFlags=0x0]
31021cf0.21fc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
31031cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbdc280000 'C:\WINDOWS\System32\msacm32.drv'
31041cf0.21fc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
31051cf0.21fc: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
31061cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbdc280000 'C:\WINDOWS\System32\msacm32.drv'
31071cf0.21fc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
31081cf0.21fc: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
31091cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbdc280000 'C:\WINDOWS\System32\msacm32.drv'
31101cf0.21fc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
31111cf0.21fc: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
31121cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbdc280000 'C:\WINDOWS\System32\msacm32.drv'
31131cf0.21fc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
31141cf0.21fc: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
31151cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbdc280000 'C:\WINDOWS\System32\msacm32.drv'
31161cf0.21fc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
31171cf0.21fc: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
31181cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbdc280000 'C:\WINDOWS\System32\msacm32.drv'
31191cf0.21fc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
31201cf0.21fc: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
31211cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbdc280000 'C:\WINDOWS\System32\msacm32.drv'
31221cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbdc280000 'C:\WINDOWS\System32\msacm32.drv'
31231cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbdc280000 'C:\WINDOWS\System32\msacm32.drv'
31241cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbdc280000 'C:\WINDOWS\System32\msacm32.drv'
31251cf0.21fc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000001048 pwszName=\Device\HarddiskVolume2\Windows\System32\midimap.dll
31261cf0.21fc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000002d2b930
31271cf0.21fc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000002d2b930
31281cf0.21fc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=725292B88FCE45C617EE0258A333B14CA2D7EF04
31291cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
31301cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
31311cf0.21fc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package~31bf3856ad364e35~amd64~~10.0.16299.15.cat'; file='\Device\HarddiskVolume2\Windows\System32\midimap.dll'
31321cf0.21fc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
31331cf0.21fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
31341cf0.21fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'winmm.dll'.
31351cf0.21fc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\midimap.dll) WinVerifyTrust
31361cf0.21fc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\midimap.dll
31371cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
31381cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
31391cf0.21fc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
31401cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
31411cf0.21fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
31421cf0.21fc: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
31431cf0.21fc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\midimap.dll
31441cf0.21fc: supR3HardenedDllNotificationCallback: load 00007ffbcce50000 LB 0x0000a000 C:\WINDOWS\System32\midimap.dll [fFlags=0x0]
31451cf0.21fc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\midimap.dll
31461cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcce50000 'C:\WINDOWS\System32\midimap.dll'
31471cf0.21fc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\midimap.dll
31481cf0.21fc: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
31491cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcce50000 'C:\WINDOWS\System32\midimap.dll'
31501cf0.21fc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\midimap.dll
31511cf0.21fc: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
31521cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcce50000 'C:\WINDOWS\System32\midimap.dll'
31531cf0.21fc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\midimap.dll
31541cf0.21fc: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
31551cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcce50000 'C:\WINDOWS\System32\midimap.dll'
31561cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe2f90000 'C:\WINDOWS\System32\winmm.dll'
31571cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe2f90000 'C:\WINDOWS\System32\winmm.dll'
31581cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe2f90000 'C:\WINDOWS\System32\winmm.dll'
31591cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe2f90000 'C:\WINDOWS\System32\winmm.dll'
31601cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe2f90000 'C:\WINDOWS\System32\winmm.dll'
31611cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe2f90000 'C:\WINDOWS\System32\winmm.dll'
31621cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe2f90000 'C:\WINDOWS\System32\winmm.dll'
31631cf0.21fc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
31641cf0.21fc: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\winmm.dll (Input=winmm.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
31651cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe2f90000 'C:\WINDOWS\System32\winmm.dll'
31661cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe2f90000 'C:\WINDOWS\System32\winmm.dll'
31671cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe2f90000 'C:\WINDOWS\System32\winmm.dll'
31681cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe2f90000 'C:\WINDOWS\System32\winmm.dll'
31691cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe2f90000 'C:\WINDOWS\System32\winmm.dll'
31701cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe2f90000 'C:\WINDOWS\System32\winmm.dll'
31711cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe2f90000 'C:\WINDOWS\System32\winmm.dll'
31721cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe2f90000 'C:\WINDOWS\System32\winmm.dll'
31731cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe2f90000 'C:\WINDOWS\System32\winmm.dll'
31741cf0.21fc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dsound.dll
31751cf0.21fc: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
31761cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbb0770000 'C:\WINDOWS\system32\dsound.dll'
31771cf0.21fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe2f90000 'C:\WINDOWS\System32\winmm.dll'
31781cf0.cf4: '\Device\HarddiskVolume2\Windows\System32\tzres.dll' has no imports
31791cf0.cf4: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\tzres.dll)
31801cf0.cf4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\tzres.dll
31811cf0.cf4: supR3HardenedMonitor_NtCreateSection: NtMapViewOfSection failed on 00000000000012a0 (hFile=0000000000001298) with 0xc0000022 -> STATUS_TRUST_FAILURE
31821cf0.cf4: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\tzres.dll [avoiding WinVerifyTrust]
31831cf0.cf4: supR3HardenedMonitor_NtCreateSection: NtMapViewOfSection failed on 0000000000001298 (hFile=00000000000012a0) with 0xc0000022 -> STATUS_TRUST_FAILURE
31841cf0.cf4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000129c pwszName=\Device\HarddiskVolume2\Windows\System32\tzres.dll
31851cf0.cf4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000002d2b930
31861cf0.cf4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000002d2b930
31871cf0.cf4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=BCD6851397609F5A60EB791379F579F266921FA4
31881cf0.cf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
31891cf0.cf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
31901cf0.cf4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_638_for_KB4093112~31bf3856ad364e35~amd64~~10.0.1.3.cat'; file='\Device\HarddiskVolume2\Windows\System32\tzres.dll'
31911cf0.cf4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
31921cf0.cf4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\tzres.dll'
31931cf0.cf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
31941cf0.cf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
31951cf0.cf4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'ws2_32.dll'.
31961cf0.cf4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #22 'rpcrt4.dll'.
31971cf0.cf4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\mswsock.dll) WinVerifyTrust
31981cf0.cf4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\mswsock.dll
31991cf0.cf4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
32001cf0.cf4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
32011cf0.cf4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
32021cf0.cf4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
32031cf0.cf4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
32041cf0.cf4: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\mswsock.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
32051cf0.cf4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\mswsock.dll
32061cf0.cf4: supR3HardenedDllNotificationCallback: load 00007ffbe5780000 LB 0x00066000 C:\WINDOWS\system32\mswsock.dll [fFlags=0x0]
32071cf0.cf4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\mswsock.dll
32081cf0.cf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5780000 'C:\WINDOWS\system32\mswsock.dll'
32091cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
32101cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'coreuicomponents.dll'.
32111cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'coremessaging.dll'.
32121cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\TextInputFramework.dll)
32131cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\TextInputFramework.dll
32141cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
32151cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #35 'coremessaging.dll'.
32161cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #48 'shcore.dll'.
32171cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\CoreUIComponents.dll)
32181cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\CoreUIComponents.dll
32191cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
32201cf0.41c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #24 'rpcrt4.dll'.
32211cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\CoreMessaging.dll)
32221cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\CoreMessaging.dll
32231cf0.41c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ntmarta.dll)
32241cf0.41c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ntmarta.dll
32251cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbe5020000 LB 0x00031000 C:\WINDOWS\SYSTEM32\ntmarta.dll [fFlags=0x0]
32261cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ntmarta.dll [avoiding WinVerifyTrust]
32271cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbe33a0000 LB 0x000dc000 C:\WINDOWS\System32\CoreMessaging.dll [fFlags=0x0]
32281cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\CoreMessaging.dll [avoiding WinVerifyTrust]
32291cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbe1fd0000 LB 0x002ee000 C:\WINDOWS\System32\CoreUIComponents.dll [fFlags=0x0]
32301cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\CoreUIComponents.dll [avoiding WinVerifyTrust]
32311cf0.41c: supR3HardenedDllNotificationCallback: load 00007ffbd9dd0000 LB 0x00098000 C:\WINDOWS\System32\TextInputFramework.dll [fFlags=0x0]
32321cf0.41c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\TextInputFramework.dll [avoiding WinVerifyTrust]
32331cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
32341cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
32351cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
32361cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
32371cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shcore.dll'...
32381cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'shcore.dll' -> '\Device\HarddiskVolume2\Windows\System32\shcore.dll' [rcNtRedir=0xc0150008]
32391cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\SHCore.dll
32401cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'coremessaging.dll'...
32411cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'coremessaging.dll' -> '\Device\HarddiskVolume2\Windows\System32\coremessaging.dll' [rcNtRedir=0xc0150008]
32421cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\CoreMessaging.dll [lacks WinVerifyTrust]
32431cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
32441cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
32451cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'coremessaging.dll'...
32461cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'coremessaging.dll' -> '\Device\HarddiskVolume2\Windows\System32\coremessaging.dll' [rcNtRedir=0xc0150008]
32471cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\CoreMessaging.dll [lacks WinVerifyTrust]
32481cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'coreuicomponents.dll'...
32491cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'coreuicomponents.dll' -> '\Device\HarddiskVolume2\Windows\System32\coreuicomponents.dll' [rcNtRedir=0xc0150008]
32501cf0.41c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\CoreUIComponents.dll [lacks WinVerifyTrust]
32511cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
32521cf0.41c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
32531cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
32541cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6580000 'C:\Windows\System32\WINTRUST.DLL'
32551cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\CRYPT32.dll'
32561cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
32571cf0.41c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\ntmarta.dll'
32581cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
32591cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
32601cf0.41c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\CoreMessaging.dll'
32611cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
32621cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
32631cf0.41c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\CoreUIComponents.dll'
32641cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe5380000 'C:\WINDOWS\system32\rsaenh.dll'
32651cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe6160000 'C:\WINDOWS\System32\crypt32.dll'
32661cf0.41c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\TextInputFramework.dll'
32671cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe7760000 'C:\WINDOWS\System32\OLEAUT32.DLL'
32681cf0.41c: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(ext-ms-win-rtcore-ntuser-window-ext-l1-1-0.dll) -> 0x0, fPresent=1
32691cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=ext-ms-win-rtcore-ntuser-window-ext-l1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
32701cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe9300000 'ext-ms-win-rtcore-ntuser-window-ext-l1-1-0.dll'
32711cf0.41c: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(ext-ms-win-rtcore-ntuser-integration-l1-1-0.dll) -> 0x0, fPresent=1
32721cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=ext-ms-win-rtcore-ntuser-integration-l1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
32731cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe9300000 'ext-ms-win-rtcore-ntuser-integration-l1-1-0.dll'
32741cf0.41c: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-com-l1-1-0.dll) -> 0x0, fPresent=1
32751cf0.41c: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-com-l1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
32761cf0.41c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbe8f90000 'api-ms-win-core-com-l1-1-0.dll'
32771cf0.2818: supR3HardenedDllNotificationCallback: Unload 00007ffbdd990000 LB 0x0000d000 C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL [flags=0x0]
32781cf0.600: supR3HardenedDllNotificationCallback: Unload 00007ffbde5f0000 LB 0x0000b000 C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL [flags=0x0]
32791cf0.23e0: supR3HardenedDllNotificationCallback: Unload 00007ffbde600000 LB 0x0000c000 C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL [flags=0x0]
32801cf0.2fbc: supR3HardenedDllNotificationCallback: Unload 00007ffbde6f0000 LB 0x0000d000 C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL [flags=0x0]
32811cf0.d04: supR3HardenedDllNotificationCallback: Unload 00007ffbe2330000 LB 0x0000b000 C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL [flags=0x0]
32821cf0.21fc: supR3HardenedDllNotificationCallback: Unload 00007ffba5770000 LB 0x009c3000 C:\Program Files\Oracle\VirtualBox\VBoxDD.DLL [flags=0x0]
32831cf0.21fc: supR3HardenedDllNotificationCallback: Unload 00007ffbbceb0000 LB 0x00063000 C:\Program Files\Oracle\VirtualBox\VBoxDDU.dll [flags=0x0]
32841cf0.21fc: supR3HardenedDllNotificationCallback: Unload 00007ffbbecc0000 LB 0x0005d000 C:\Program Files\Oracle\VirtualBox\VBoxDD2.dll [flags=0x0]
32851cf0.21fc: supR3HardenedDllNotificationCallback: Unload 00007ffbe71e0000 LB 0x0044e000 C:\WINDOWS\System32\SETUPAPI.dll [flags=0x0]
32861cf0.41c: supR3HardenedDllNotificationCallback: Unload 00007ffbdb930000 LB 0x00014000 C:\WINDOWS\system32\wbem\wbemsvc.dll [flags=0x0]
32871cf0.41c: supR3HardenedDllNotificationCallback: Unload 00007ffbca0d0000 LB 0x0004f000 C:\WINDOWS\system32\dataexchange.dll [flags=0x0]
32881cf0.41c: supR3HardenedDllNotificationCallback: Unload 00007ffbe30b0000 LB 0x002e2000 C:\WINDOWS\system32\d3d11.dll [flags=0x0]
32891cf0.41c: supR3HardenedDllNotificationCallback: Unload 00007ffbe4d50000 LB 0x000af000 C:\WINDOWS\system32\dxgi.dll [flags=0x0]
32901cf0.41c: supR3HardenedDllNotificationCallback: Unload 00007ffbe3e70000 LB 0x00142000 C:\WINDOWS\system32\dcomp.dll [flags=0x0]
32911cf0.41c: supR3HardenedDllNotificationCallback: Unload 00007ffbe4910000 LB 0x0017b000 C:\WINDOWS\system32\twinapi.appcore.dll [flags=0x0]
32921cf0.41c: supR3HardenedDllNotificationCallback: Unload 00007ffbe4880000 LB 0x00020000 C:\WINDOWS\system32\RMCLIENT.dll [flags=0x0]
32931cf0.41c: supR3HardenedDllNotificationCallback: Unload 00007ffbdb950000 LB 0x000f0000 C:\WINDOWS\system32\wbem\fastprox.dll [flags=0x0]
32941cf0.41c: supR3HardenedDllNotificationCallback: Unload 00007ffbbcc50000 LB 0x000ba000 C:\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll [flags=0x0]
32951cf0.41c: supR3HardenedDllNotificationCallback: Unload 00007ffbdbcd0000 LB 0x0000f000 C:\WINDOWS\system32\wbem\wbemprox.dll [flags=0x0]
32961cf0.41c: supR3HardenedDllNotificationCallback: Unload 00007ffbdbc40000 LB 0x00081000 C:\WINDOWS\SYSTEM32\wbemcomn.dll [flags=0x0]
32971cf0.41c: supR3HardenedDllNotificationCallback: Unload 00007ffbbc700000 LB 0x00545000 C:\Program Files\Oracle\VirtualBox\VBoxC.dll [flags=0x0]
32981cf0.41c: Terminating the normal way: rcExit=0
329914c.1da8: supR3HardNtChildWaitFor[2]: Quitting: ExitCode=0x0 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 4500033 ms, the end);
3300798.f6c: supR3HardNtChildWaitFor[1]: Quitting: ExitCode=0x0 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 4500702 ms, the end);

© 2024 Oracle Support Privacy / Do Not Sell My Info Terms of Use Trademark Policy Automated Access Etiquette