VirtualBox

Ticket #17837: VBoxHardening.log

File VBoxHardening.log, 358.8 KB (added by Herb Siegel, 6 years ago)
Line 
112ac.890: Log file opened: 5.2.12r122591 g_hStartupLog=0000000000000068 g_uNtVerCombined=0xa042ee00
212ac.890: \SystemRoot\System32\ntdll.dll:
312ac.890: CreationTime: 2018-06-13T00:04:48.619830200Z
412ac.890: LastWriteTime: 2018-06-08T09:29:38.672295100Z
512ac.890: ChangeTime: 2018-06-13T12:36:30.318409700Z
612ac.890: FileAttributes: 0x20
712ac.890: Size: 0x1db2d8
812ac.890: NT Headers: 0xe8
912ac.890: Timestamp: 0x6529f37c
1012ac.890: Machine: 0x8664 - amd64
1112ac.890: Timestamp: 0x6529f37c
1212ac.890: Image Version: 10.0
1312ac.890: SizeOfImage: 0x1e1000 (1970176)
1412ac.890: Resource Dir: 0x174000 LB 0x6b338
1512ac.890: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
1612ac.890: [Raw version resource data: 0x1740f0 LB 0x380, codepage 0x0 (reserved 0x0)]
1712ac.890: ProductName: Microsoft® Windows® Operating System
1812ac.890: ProductVersion: 10.0.17134.112
1912ac.890: FileVersion: 10.0.17134.112 (WinBuild.160101.0800)
2012ac.890: FileDescription: NT Layer DLL
2112ac.890: \SystemRoot\System32\kernel32.dll:
2212ac.890: CreationTime: 2018-04-11T23:34:33.430805800Z
2312ac.890: LastWriteTime: 2018-04-11T23:34:33.430805800Z
2412ac.890: ChangeTime: 2018-05-16T03:28:28.576163900Z
2512ac.890: FileAttributes: 0x20
2612ac.890: Size: 0xafef8
2712ac.890: NT Headers: 0xe8
2812ac.890: Timestamp: 0x5f488a51
2912ac.890: Machine: 0x8664 - amd64
3012ac.890: Timestamp: 0x5f488a51
3112ac.890: Image Version: 10.0
3212ac.890: SizeOfImage: 0xb2000 (729088)
3312ac.890: Resource Dir: 0xb0000 LB 0x520
3412ac.890: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
3512ac.890: [Raw version resource data: 0xb00b0 LB 0x3a4, codepage 0x0 (reserved 0x0)]
3612ac.890: ProductName: Microsoft® Windows® Operating System
3712ac.890: ProductVersion: 10.0.17134.1
3812ac.890: FileVersion: 10.0.17134.1 (WinBuild.160101.0800)
3912ac.890: FileDescription: Windows NT BASE API Client DLL
4012ac.890: \SystemRoot\System32\KernelBase.dll:
4112ac.890: CreationTime: 2018-06-13T00:05:08.838861900Z
4212ac.890: LastWriteTime: 2018-06-08T09:29:25.975552800Z
4312ac.890: ChangeTime: 2018-06-13T12:36:29.907759300Z
4412ac.890: FileAttributes: 0x20
4512ac.890: Size: 0x2739d8
4612ac.890: NT Headers: 0xf8
4712ac.890: Timestamp: 0xf2b2cb6c
4812ac.890: Machine: 0x8664 - amd64
4912ac.890: Timestamp: 0xf2b2cb6c
5012ac.890: Image Version: 10.0
5112ac.890: SizeOfImage: 0x273000 (2568192)
5212ac.890: Resource Dir: 0x251000 LB 0x548
5312ac.890: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
5412ac.890: [Raw version resource data: 0x2510b0 LB 0x3bc, codepage 0x0 (reserved 0x0)]
5512ac.890: ProductName: Microsoft® Windows® Operating System
5612ac.890: ProductVersion: 10.0.17134.112
5712ac.890: FileVersion: 10.0.17134.112 (WinBuild.160101.0800)
5812ac.890: FileDescription: Windows NT BASE API Client DLL
5912ac.890: \SystemRoot\System32\apisetschema.dll:
6012ac.890: CreationTime: 2018-04-11T23:34:37.197833800Z
6112ac.890: LastWriteTime: 2018-04-11T23:34:37.197833800Z
6212ac.890: ChangeTime: 2018-05-16T04:20:54.698218700Z
6312ac.890: FileAttributes: 0x20
6412ac.890: Size: 0x1bd98
6512ac.890: NT Headers: 0xd0
6612ac.890: Timestamp: 0xd02ff418
6712ac.890: Machine: 0x8664 - amd64
6812ac.890: Timestamp: 0xd02ff418
6912ac.890: Image Version: 10.0
7012ac.890: SizeOfImage: 0x1c000 (114688)
7112ac.890: Resource Dir: 0x1b000 LB 0x408
7212ac.890: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
7312ac.890: [Raw version resource data: 0x1b060 LB 0x3a8, codepage 0x0 (reserved 0x0)]
7412ac.890: ProductName: Microsoft® Windows® Operating System
7512ac.890: ProductVersion: 10.0.17134.1
7612ac.890: FileVersion: 10.0.17134.1 (WinBuild.160101.0800)
7712ac.890: FileDescription: ApiSet Schema DLL
7812ac.890: NtOpenDirectoryObject failed on \Driver: 0xc0000022
7912ac.890: supR3HardenedWinFindAdversaries: 0x0
8012ac.890: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
8112ac.890: Calling main()
8212ac.890: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
8312ac.890: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
8412ac.890: SUPR3HardenedMain: Respawn #1
8512ac.890: System32: \Device\HarddiskVolume2\Windows\System32
8612ac.890: WinSxS: \Device\HarddiskVolume2\Windows\WinSxS
8712ac.890: KnownDllPath: C:\Windows\System32
8812ac.890: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
8912ac.890: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe)
9012ac.890: supR3HardNtEnableThreadCreation:
9112ac.890: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffc3b6b2fc0 pvNtTerminateThread=00007ffc3b6da900
9212ac.890: supR3HardenedWinDoReSpawn(1): New child 70.13c8 [kernel32].
9312ac.890: supR3HardNtChildGatherData: PebBaseAddress=0000000000332000 cbPeb=0x388
9412ac.890: supR3HardNtPuChFindNtdll: uNtDllParentAddr=00007ffc3b640000 uNtDllChildAddr=00007ffc3b640000
9512ac.890: supR3HardenedWinSetupChildInit: uLdrInitThunk=00007ffc3b6b2fc0
9612ac.890: supR3HardenedWinSetupChildInit: Start child.
9712ac.890: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
9812ac.890: supR3HardNtChildPurify: Startup delay kludge #1/0: 266 ms, 17 sleeps
9912ac.890: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
10012ac.890: *0000000000000000-00000000000dffff 0x0001/0x0000 0x0000000
10112ac.890: *00000000000e0000-00000000000fffff 0x0004/0x0004 0x0020000
10212ac.890: *0000000000100000-0000000000118fff 0x0002/0x0002 0x0040000
10312ac.890: 0000000000119000-000000000011ffff 0x0001/0x0000 0x0000000
10412ac.890: *0000000000120000-0000000000123fff 0x0002/0x0002 0x0040000
10512ac.890: 0000000000124000-000000000012ffff 0x0001/0x0000 0x0000000
10612ac.890: *0000000000130000-0000000000130fff 0x0004/0x0004 0x0020000
10712ac.890: 0000000000131000-00000000001fffff 0x0001/0x0000 0x0000000
10812ac.890: *0000000000200000-0000000000331fff 0x0000/0x0004 0x0020000
10912ac.890: 0000000000332000-0000000000334fff 0x0004/0x0004 0x0020000
11012ac.890: 0000000000335000-00000000003fffff 0x0000/0x0004 0x0020000
11112ac.890: *0000000000400000-00000000004fafff 0x0000/0x0004 0x0020000
11212ac.890: 00000000004fb000-00000000004fdfff 0x0104/0x0004 0x0020000
11312ac.890: 00000000004fe000-00000000004fffff 0x0004/0x0004 0x0020000
11412ac.890: 0000000000500000-000000007ffdffff 0x0001/0x0000 0x0000000
11512ac.890: *000000007ffe0000-000000007ffe0fff 0x0002/0x0002 0x0020000
11612ac.890: 000000007ffe1000-00007ff5b307ffff 0x0001/0x0000 0x0000000
11712ac.890: *00007ff5b3080000-00007ff5b30a2fff 0x0002/0x0002 0x0040000
11812ac.890: 00007ff5b30a3000-00007ff6c35affff 0x0001/0x0000 0x0000000
11912ac.890: *00007ff6c35b0000-00007ff6c35b0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
12012ac.890: 00007ff6c35b1000-00007ff6c3621fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
12112ac.890: 00007ff6c3622000-00007ff6c3622fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
12212ac.890: 00007ff6c3623000-00007ff6c3668fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
12312ac.890: 00007ff6c3669000-00007ff6c3669fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
12412ac.890: 00007ff6c366a000-00007ff6c366afff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
12512ac.890: 00007ff6c366b000-00007ff6c366ffff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
12612ac.890: 00007ff6c3670000-00007ff6c3670fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
12712ac.890: 00007ff6c3671000-00007ff6c3671fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
12812ac.890: 00007ff6c3672000-00007ff6c3675fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
12912ac.890: 00007ff6c3676000-00007ff6c36bdfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
13012ac.890: 00007ff6c36be000-00007ffc3b63ffff 0x0001/0x0000 0x0000000
13112ac.890: *00007ffc3b640000-00007ffc3b640fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
13212ac.890: 00007ffc3b641000-00007ffc3b74ffff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
13312ac.890: 00007ffc3b750000-00007ffc3b795fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
13412ac.890: 00007ffc3b796000-00007ffc3b7a0fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
13512ac.890: 00007ffc3b7a1000-00007ffc3b7aefff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
13612ac.890: 00007ffc3b7af000-00007ffc3b7affff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
13712ac.890: 00007ffc3b7b0000-00007ffc3b7b2fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
13812ac.890: 00007ffc3b7b3000-00007ffc3b820fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
13912ac.890: 00007ffc3b821000-00007ffffffeffff 0x0001/0x0000 0x0000000
14012ac.890: VirtualBox.exe: timestamp 0x5af2c2c3 (rc=VINF_SUCCESS)
14112ac.890: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
14212ac.890: '\Device\HarddiskVolume2\Windows\System32\ntdll.dll' has no imports
14312ac.890: supR3HardNtChildPurify: Done after 344 ms and 0 fixes (loop #0).
14470.13c8: Log file opened: 5.2.12r122591 g_hStartupLog=0000000000000004 g_uNtVerCombined=0xa042ee00
14570.13c8: supR3HardenedVmProcessInit: uNtDllAddr=00007ffc3b640000 g_uNtVerCombined=0xa042ee00
14670.13c8: ntdll.dll: timestamp 0x6529f37c (rc=VINF_SUCCESS)
14770.13c8: New simple heap: #1 0000000000600000 LB 0x400000 (for 1970176 allocation)
14812ac.890: supR3HardNtEnableThreadCreation:
14970.13c8: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
15070.13c8: System32: \Device\HarddiskVolume2\Windows\System32
15170.13c8: WinSxS: \Device\HarddiskVolume2\Windows\WinSxS
15270.13c8: KnownDllPath: C:\Windows\System32
15370.13c8: supR3HardenedVmProcessInit: Opening vboxdrv stub...
15470.13c8: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
15570.13c8: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
15670.13c8: Registered Dll notification callback with NTDLL.
15770.13c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\kernel32.dll)
15870.13c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\kernel32.dll
15970.13c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\KERNEL32.DLL (Input=KERNEL32.DLL, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000004001:<flags> [calling]
16070.13c8: supR3HardenedDllNotificationCallback: load 00007ffc385c0000 LB 0x00273000 C:\Windows\System32\KERNELBASE.dll [fFlags=0x0]
16170.13c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\KernelBase.dll)
16270.13c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\KernelBase.dll
16370.13c8: supR3HardenedDllNotificationCallback: load 00007ffc38ea0000 LB 0x000b2000 C:\Windows\System32\KERNEL32.DLL [fFlags=0x0]
16470.13c8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
16570.13c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc38ea0000 'C:\Windows\System32\KERNEL32.DLL'
16670.13c8: supR3HardenedDllNotificationCallback: load 00007ff6c35b0000 LB 0x0010e000 C:\Program Files\Oracle\VirtualBox\VirtualBox.exe [fFlags=0x0]
16770.13c8: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
16870.13c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe)
16970.13c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
17070.13c8: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffc3b6b2fc0 pvNtTerminateThread=00007ffc3b6da900
17112ac.890: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 141 ms.
17270.13c8: \SystemRoot\System32\ntdll.dll:
17370.13c8: CreationTime: 2018-06-13T00:04:48.619830200Z
17470.13c8: LastWriteTime: 2018-06-08T09:29:38.672295100Z
17570.13c8: ChangeTime: 2018-06-13T12:36:30.318409700Z
17670.13c8: FileAttributes: 0x20
17770.13c8: Size: 0x1db2d8
17870.13c8: NT Headers: 0xe8
17970.13c8: Timestamp: 0x6529f37c
18070.13c8: Machine: 0x8664 - amd64
18170.13c8: Timestamp: 0x6529f37c
18270.13c8: Image Version: 10.0
18370.13c8: SizeOfImage: 0x1e1000 (1970176)
18470.13c8: Resource Dir: 0x174000 LB 0x6b338
18570.13c8: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
18670.13c8: [Raw version resource data: 0x1740f0 LB 0x380, codepage 0x0 (reserved 0x0)]
18770.13c8: ProductName: Microsoft® Windows® Operating System
18870.13c8: ProductVersion: 10.0.17134.112
18970.13c8: FileVersion: 10.0.17134.112 (WinBuild.160101.0800)
19070.13c8: FileDescription: NT Layer DLL
19170.13c8: \SystemRoot\System32\kernel32.dll:
19270.13c8: CreationTime: 2018-04-11T23:34:33.430805800Z
19370.13c8: LastWriteTime: 2018-04-11T23:34:33.430805800Z
19470.13c8: ChangeTime: 2018-05-16T03:28:28.576163900Z
19570.13c8: FileAttributes: 0x20
19670.13c8: Size: 0xafef8
19770.13c8: NT Headers: 0xe8
19870.13c8: Timestamp: 0x5f488a51
19970.13c8: Machine: 0x8664 - amd64
20070.13c8: Timestamp: 0x5f488a51
20170.13c8: Image Version: 10.0
20270.13c8: SizeOfImage: 0xb2000 (729088)
20370.13c8: Resource Dir: 0xb0000 LB 0x520
20470.13c8: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
20570.13c8: [Raw version resource data: 0xb00b0 LB 0x3a4, codepage 0x0 (reserved 0x0)]
20670.13c8: ProductName: Microsoft® Windows® Operating System
20770.13c8: ProductVersion: 10.0.17134.1
20870.13c8: FileVersion: 10.0.17134.1 (WinBuild.160101.0800)
20970.13c8: FileDescription: Windows NT BASE API Client DLL
21070.13c8: \SystemRoot\System32\KernelBase.dll:
21170.13c8: CreationTime: 2018-06-13T00:05:08.838861900Z
21270.13c8: LastWriteTime: 2018-06-08T09:29:25.975552800Z
21370.13c8: ChangeTime: 2018-06-13T12:36:29.907759300Z
21470.13c8: FileAttributes: 0x20
21570.13c8: Size: 0x2739d8
21670.13c8: NT Headers: 0xf8
21770.13c8: Timestamp: 0xf2b2cb6c
21870.13c8: Machine: 0x8664 - amd64
21970.13c8: Timestamp: 0xf2b2cb6c
22070.13c8: Image Version: 10.0
22170.13c8: SizeOfImage: 0x273000 (2568192)
22270.13c8: Resource Dir: 0x251000 LB 0x548
22370.13c8: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
22470.13c8: [Raw version resource data: 0x2510b0 LB 0x3bc, codepage 0x0 (reserved 0x0)]
22570.13c8: ProductName: Microsoft® Windows® Operating System
22670.13c8: ProductVersion: 10.0.17134.112
22770.13c8: FileVersion: 10.0.17134.112 (WinBuild.160101.0800)
22870.13c8: FileDescription: Windows NT BASE API Client DLL
22970.13c8: \SystemRoot\System32\apisetschema.dll:
23070.13c8: CreationTime: 2018-04-11T23:34:37.197833800Z
23170.13c8: LastWriteTime: 2018-04-11T23:34:37.197833800Z
23270.13c8: ChangeTime: 2018-05-16T04:20:54.698218700Z
23370.13c8: FileAttributes: 0x20
23470.13c8: Size: 0x1bd98
23570.13c8: NT Headers: 0xd0
23670.13c8: Timestamp: 0xd02ff418
23770.13c8: Machine: 0x8664 - amd64
23870.13c8: Timestamp: 0xd02ff418
23970.13c8: Image Version: 10.0
24070.13c8: SizeOfImage: 0x1c000 (114688)
24170.13c8: Resource Dir: 0x1b000 LB 0x408
24270.13c8: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
24370.13c8: [Raw version resource data: 0x1b060 LB 0x3a8, codepage 0x0 (reserved 0x0)]
24470.13c8: ProductName: Microsoft® Windows® Operating System
24570.13c8: ProductVersion: 10.0.17134.1
24670.13c8: FileVersion: 10.0.17134.1 (WinBuild.160101.0800)
24770.13c8: FileDescription: ApiSet Schema DLL
24870.13c8: NtOpenDirectoryObject failed on \Driver: 0xc0000022
24970.13c8: supR3HardenedWinFindAdversaries: 0x0
25070.13c8: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
25170.13c8: Calling main()
25270.13c8: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
25370.13c8: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
25470.13c8: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
25570.13c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe)
25670.13c8: SUPR3HardenedMain: Respawn #2
25770.13c8: supR3HardNtEnableThreadCreation:
25870.13c8: '\Device\HarddiskVolume2\Windows\System32\ntdll.dll' has no imports
25970.13c8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ntdll.dll)
26070.13c8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ntdll.dll
26170.13c8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\ntdll.dll (Input=ntdll.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
26270.13c8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3b640000 'C:\Windows\System32\ntdll.dll'
26370.13c8: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffc3b6b2fc0 pvNtTerminateThread=00007ffc3b6da900
26470.13c8: supR3HardenedWinDoReSpawn(2): New child 1c3c.1868 [kernel32].
26570.13c8: supR3HardenedWinReSpawn: NtSetInformationThread/ThreadHideFromDebugger failed: 0xc0000022 (harmless)
26670.13c8: supR3HardNtChildGatherData: PebBaseAddress=000000000088b000 cbPeb=0x388
26770.13c8: supR3HardNtPuChFindNtdll: uNtDllParentAddr=00007ffc3b640000 uNtDllChildAddr=00007ffc3b640000
26870.13c8: supR3HardenedWinSetupChildInit: uLdrInitThunk=00007ffc3b6b2fc0
26970.13c8: supR3HardenedWinSetupChildInit: Start child.
27070.13c8: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
27170.13c8: supR3HardNtChildPurify: Startup delay kludge #1/0: 266 ms, 16 sleeps
27270.13c8: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
27370.13c8: *0000000000000000-00000000006affff 0x0001/0x0000 0x0000000
27470.13c8: *00000000006b0000-00000000006cffff 0x0004/0x0004 0x0020000
27570.13c8: *00000000006d0000-00000000006e8fff 0x0002/0x0002 0x0040000
27670.13c8: 00000000006e9000-00000000006effff 0x0001/0x0000 0x0000000
27770.13c8: *00000000006f0000-00000000007eafff 0x0000/0x0004 0x0020000
27870.13c8: 00000000007eb000-00000000007edfff 0x0104/0x0004 0x0020000
27970.13c8: 00000000007ee000-00000000007effff 0x0004/0x0004 0x0020000
28070.13c8: *00000000007f0000-00000000007f3fff 0x0002/0x0002 0x0040000
28170.13c8: 00000000007f4000-00000000007fffff 0x0001/0x0000 0x0000000
28270.13c8: *0000000000800000-000000000088afff 0x0000/0x0004 0x0020000
28370.13c8: 000000000088b000-000000000088dfff 0x0004/0x0004 0x0020000
28470.13c8: 000000000088e000-00000000009fffff 0x0000/0x0004 0x0020000
28570.13c8: *0000000000a00000-0000000000a00fff 0x0004/0x0004 0x0020000
28670.13c8: 0000000000a01000-000000007ffdffff 0x0001/0x0000 0x0000000
28770.13c8: *000000007ffe0000-000000007ffe0fff 0x0002/0x0002 0x0020000
28870.13c8: 000000007ffe1000-00007ff5fb81ffff 0x0001/0x0000 0x0000000
28970.13c8: *00007ff5fb820000-00007ff5fb842fff 0x0002/0x0002 0x0040000
29070.13c8: 00007ff5fb843000-00007ff6c35affff 0x0001/0x0000 0x0000000
29170.13c8: *00007ff6c35b0000-00007ff6c35b0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
29270.13c8: 00007ff6c35b1000-00007ff6c3621fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
29370.13c8: 00007ff6c3622000-00007ff6c3622fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
29470.13c8: 00007ff6c3623000-00007ff6c3668fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
29570.13c8: 00007ff6c3669000-00007ff6c3669fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
29670.13c8: 00007ff6c366a000-00007ff6c366afff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
29770.13c8: 00007ff6c366b000-00007ff6c366ffff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
29870.13c8: 00007ff6c3670000-00007ff6c3670fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
29970.13c8: 00007ff6c3671000-00007ff6c3671fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
30070.13c8: 00007ff6c3672000-00007ff6c3675fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
30170.13c8: 00007ff6c3676000-00007ff6c36bdfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
30270.13c8: 00007ff6c36be000-00007ffc3b63ffff 0x0001/0x0000 0x0000000
30370.13c8: *00007ffc3b640000-00007ffc3b640fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
30470.13c8: 00007ffc3b641000-00007ffc3b74ffff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
30570.13c8: 00007ffc3b750000-00007ffc3b795fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
30670.13c8: 00007ffc3b796000-00007ffc3b7a0fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
30770.13c8: 00007ffc3b7a1000-00007ffc3b7aefff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
30870.13c8: 00007ffc3b7af000-00007ffc3b7affff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
30970.13c8: 00007ffc3b7b0000-00007ffc3b7b2fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
31070.13c8: 00007ffc3b7b3000-00007ffc3b820fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
31170.13c8: 00007ffc3b821000-00007ffffffeffff 0x0001/0x0000 0x0000000
31270.13c8: VirtualBox.exe: timestamp 0x5af2c2c3 (rc=VINF_SUCCESS)
31370.13c8: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
31470.13c8: '\Device\HarddiskVolume2\Windows\System32\ntdll.dll' has no imports
31570.13c8: supR3HardNtChildPurify: Done after 328 ms and 0 fixes (loop #0).
3161c3c.1868: Log file opened: 5.2.12r122591 g_hStartupLog=0000000000000004 g_uNtVerCombined=0xa042ee00
3171c3c.1868: supR3HardenedVmProcessInit: uNtDllAddr=00007ffc3b640000 g_uNtVerCombined=0xa042ee00
3181c3c.1868: ntdll.dll: timestamp 0x6529f37c (rc=VINF_SUCCESS)
3191c3c.1868: New simple heap: #1 0000000000b10000 LB 0x400000 (for 1970176 allocation)
32070.13c8: supR3HardenedEarlyCompact: Removed heap 1 (0x00000000600000 LB 0x400000)
32170.13c8: supR3HardNtEnableThreadCreation:
3221c3c.1868: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
3231c3c.1868: System32: \Device\HarddiskVolume2\Windows\System32
3241c3c.1868: WinSxS: \Device\HarddiskVolume2\Windows\WinSxS
3251c3c.1868: KnownDllPath: C:\Windows\System32
3261c3c.1868: supR3HardenedVmProcessInit: Opening vboxdrv...
3271c3c.1868: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
3281c3c.1868: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
3291c3c.1868: Registered Dll notification callback with NTDLL.
3301c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\kernel32.dll)
3311c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\kernel32.dll
3321c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\KERNEL32.DLL (Input=KERNEL32.DLL, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000004001:<flags> [calling]
3331c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc385c0000 LB 0x00273000 C:\Windows\System32\KERNELBASE.dll [fFlags=0x0]
3341c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\KernelBase.dll)
3351c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\KernelBase.dll
3361c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc38ea0000 LB 0x000b2000 C:\Windows\System32\KERNEL32.DLL [fFlags=0x0]
3371c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
3381c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc38ea0000 'C:\Windows\System32\KERNEL32.DLL'
3391c3c.1868: supR3HardenedDllNotificationCallback: load 00007ff6c35b0000 LB 0x0010e000 C:\Program Files\Oracle\VirtualBox\VirtualBox.exe [fFlags=0x0]
3401c3c.1868: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
3411c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe)
3421c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
3431c3c.1868: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffc3b6b2fc0 pvNtTerminateThread=00007ffc3b6da900
34470.13c8: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 219 ms.
3451c3c.1868: \SystemRoot\System32\ntdll.dll:
3461c3c.1868: CreationTime: 2018-06-13T00:04:48.619830200Z
3471c3c.1868: LastWriteTime: 2018-06-08T09:29:38.672295100Z
3481c3c.1868: ChangeTime: 2018-06-13T12:36:30.318409700Z
3491c3c.1868: FileAttributes: 0x20
3501c3c.1868: Size: 0x1db2d8
3511c3c.1868: NT Headers: 0xe8
3521c3c.1868: Timestamp: 0x6529f37c
3531c3c.1868: Machine: 0x8664 - amd64
3541c3c.1868: Timestamp: 0x6529f37c
3551c3c.1868: Image Version: 10.0
3561c3c.1868: SizeOfImage: 0x1e1000 (1970176)
3571c3c.1868: Resource Dir: 0x174000 LB 0x6b338
3581c3c.1868: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
3591c3c.1868: [Raw version resource data: 0x1740f0 LB 0x380, codepage 0x0 (reserved 0x0)]
3601c3c.1868: ProductName: Microsoft® Windows® Operating System
3611c3c.1868: ProductVersion: 10.0.17134.112
3621c3c.1868: FileVersion: 10.0.17134.112 (WinBuild.160101.0800)
3631c3c.1868: FileDescription: NT Layer DLL
3641c3c.1868: \SystemRoot\System32\kernel32.dll:
3651c3c.1868: CreationTime: 2018-04-11T23:34:33.430805800Z
3661c3c.1868: LastWriteTime: 2018-04-11T23:34:33.430805800Z
3671c3c.1868: ChangeTime: 2018-05-16T03:28:28.576163900Z
3681c3c.1868: FileAttributes: 0x20
3691c3c.1868: Size: 0xafef8
3701c3c.1868: NT Headers: 0xe8
3711c3c.1868: Timestamp: 0x5f488a51
3721c3c.1868: Machine: 0x8664 - amd64
3731c3c.1868: Timestamp: 0x5f488a51
3741c3c.1868: Image Version: 10.0
3751c3c.1868: SizeOfImage: 0xb2000 (729088)
3761c3c.1868: Resource Dir: 0xb0000 LB 0x520
3771c3c.1868: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
3781c3c.1868: [Raw version resource data: 0xb00b0 LB 0x3a4, codepage 0x0 (reserved 0x0)]
3791c3c.1868: ProductName: Microsoft® Windows® Operating System
3801c3c.1868: ProductVersion: 10.0.17134.1
3811c3c.1868: FileVersion: 10.0.17134.1 (WinBuild.160101.0800)
3821c3c.1868: FileDescription: Windows NT BASE API Client DLL
3831c3c.1868: \SystemRoot\System32\KernelBase.dll:
3841c3c.1868: CreationTime: 2018-06-13T00:05:08.838861900Z
3851c3c.1868: LastWriteTime: 2018-06-08T09:29:25.975552800Z
3861c3c.1868: ChangeTime: 2018-06-13T12:36:29.907759300Z
3871c3c.1868: FileAttributes: 0x20
3881c3c.1868: Size: 0x2739d8
3891c3c.1868: NT Headers: 0xf8
3901c3c.1868: Timestamp: 0xf2b2cb6c
3911c3c.1868: Machine: 0x8664 - amd64
3921c3c.1868: Timestamp: 0xf2b2cb6c
3931c3c.1868: Image Version: 10.0
3941c3c.1868: SizeOfImage: 0x273000 (2568192)
3951c3c.1868: Resource Dir: 0x251000 LB 0x548
3961c3c.1868: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
3971c3c.1868: [Raw version resource data: 0x2510b0 LB 0x3bc, codepage 0x0 (reserved 0x0)]
3981c3c.1868: ProductName: Microsoft® Windows® Operating System
3991c3c.1868: ProductVersion: 10.0.17134.112
4001c3c.1868: FileVersion: 10.0.17134.112 (WinBuild.160101.0800)
4011c3c.1868: FileDescription: Windows NT BASE API Client DLL
4021c3c.1868: \SystemRoot\System32\apisetschema.dll:
4031c3c.1868: CreationTime: 2018-04-11T23:34:37.197833800Z
4041c3c.1868: LastWriteTime: 2018-04-11T23:34:37.197833800Z
4051c3c.1868: ChangeTime: 2018-05-16T04:20:54.698218700Z
4061c3c.1868: FileAttributes: 0x20
4071c3c.1868: Size: 0x1bd98
4081c3c.1868: NT Headers: 0xd0
4091c3c.1868: Timestamp: 0xd02ff418
4101c3c.1868: Machine: 0x8664 - amd64
4111c3c.1868: Timestamp: 0xd02ff418
4121c3c.1868: Image Version: 10.0
4131c3c.1868: SizeOfImage: 0x1c000 (114688)
4141c3c.1868: Resource Dir: 0x1b000 LB 0x408
4151c3c.1868: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
4161c3c.1868: [Raw version resource data: 0x1b060 LB 0x3a8, codepage 0x0 (reserved 0x0)]
4171c3c.1868: ProductName: Microsoft® Windows® Operating System
4181c3c.1868: ProductVersion: 10.0.17134.1
4191c3c.1868: FileVersion: 10.0.17134.1 (WinBuild.160101.0800)
4201c3c.1868: FileDescription: ApiSet Schema DLL
4211c3c.1868: NtOpenDirectoryObject failed on \Driver: 0xc0000022
4221c3c.1868: supR3HardenedWinFindAdversaries: 0x0
4231c3c.1868: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
4241c3c.1868: Calling main()
4251c3c.1868: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
4261c3c.1868: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
4271c3c.1868: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
4281c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe)
4291c3c.1868: SUPR3HardenedMain: Final process, opening VBoxDrv...
4301c3c.1868: supR3HardenedEarlyCompact: Removed heap 1 (0x00000000b10000 LB 0x400000)
4311c3c.1868: supR3HardNtEnableThreadCreation:
4321c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll)
4331c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll
4341c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
4351c3c.1868: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
4361c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc20ff0000 LB 0x00005000 C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL [fFlags=0x0]
4371c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
4381c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
4391c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
4401c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc20ff0000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
4411c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
4421c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
4431c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc20ff0000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
4441c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc20ff0000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
4451c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
4461c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msasn1.dll'.
4471c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'crypt32.dll'.
4481c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #27 'rpcrt4.dll'.
4491c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\wintrust.dll)
4501c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wintrust.dll
4511c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
4521c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
4531c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll)
4541c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
4551c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
4561c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume2\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
4571c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #34 'msasn1.dll'.
4581c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\crypt32.dll)
4591c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\crypt32.dll
4601c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
4611c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume2\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
4621c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\msasn1.dll)
4631c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msasn1.dll
4641c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
4651c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
4661c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\msvcrt.dll)
4671c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
4681c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
4691c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume2\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
4701c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
4711c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
4721c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc38c50000 LB 0x0009e000 C:\Windows\System32\msvcrt.dll [fFlags=0x0]
4731c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
4741c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc37960000 LB 0x00012000 C:\Windows\System32\MSASN1.dll [fFlags=0x0]
4751c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
4761c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc37a10000 LB 0x000fa000 C:\Windows\System32\ucrtbase.dll [fFlags=0x0]
4771c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ucrtbase.dll)
4781c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ucrtbase.dll
4791c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc382a0000 LB 0x001e2000 C:\Windows\System32\CRYPT32.dll [fFlags=0x0]
4801c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
4811c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc38d70000 LB 0x00124000 C:\Windows\System32\RPCRT4.dll [fFlags=0x0]
4821c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
4831c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc39290000 LB 0x0005b000 C:\Windows\System32\sechost.dll [fFlags=0x0]
4841c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'rpcrt4.dll'.
4851c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\sechost.dll)
4861c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\sechost.dll
4871c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc3b3d0000 LB 0x000a1000 C:\Windows\System32\advapi32.dll [fFlags=0x0]
4881c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
4891c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'sechost.dll'.
4901c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #27 'rpcrt4.dll'.
4911c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\advapi32.dll)
4921c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\advapi32.dll
4931c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc38240000 LB 0x00057000 C:\Windows\System32\Wintrust.dll [fFlags=0x0]
4941c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
4951c3c.1868: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
4961c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
4971c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc385c0000 'api-ms-win-core-synch-l1-2-0'
4981c3c.1868: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-fibers-l1-1-1) -> 0x0, fPresent=1
4991c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
5001c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc385c0000 'api-ms-win-core-fibers-l1-1-1'
5011c3c.1868: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-fibers-l1-1-1) -> 0x0, fPresent=1
5021c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
5031c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc385c0000 'api-ms-win-core-fibers-l1-1-1'
5041c3c.1868: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
5051c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
5061c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc385c0000 'api-ms-win-core-synch-l1-2-0'
5071c3c.1868: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-l1-2-1) -> 0x0, fPresent=1
5081c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-l1-2-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
5091c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc385c0000 'api-ms-win-core-localization-l1-2-1'
5101c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc38240000 'C:\Windows\system32\Wintrust.dll'
5111c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\bcrypt.dll)
5121c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\bcrypt.dll
5131c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
5141c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
5151c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
5161c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'sechost.dll'...
5171c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'sechost.dll' -> '\Device\HarddiskVolume2\Windows\System32\sechost.dll' [rcNtRedir=0xc0150008]
5181c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\sechost.dll [lacks WinVerifyTrust]
5191c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
5201c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
5211c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
5221c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
5231c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
5241c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
5251c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\bcrypt.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
5261c3c.1868: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
5271c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc374b0000 LB 0x00025000 C:\Windows\system32\bcrypt.dll [fFlags=0x0]
5281c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
5291c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc374b0000 'C:\Windows\system32\bcrypt.dll'
5301c3c.1868: bcrypt.dll loaded at 00007ffc374b0000, BCryptOpenAlgorithmProvider at 00007ffc374b2770, preloading providers:
5311c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll)
5321c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll
5331c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\bcryptprimitives.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
5341c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc38490000 LB 0x0007a000 C:\Windows\System32\bcryptprimitives.dll [fFlags=0x0]
5351c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
5361c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc38490000 'C:\Windows\system32\bcryptprimitives.dll'
5371c3c.1868: BCryptOpenAlgorithmProvider(,'MD2',0,0) -> 0x0 (hAlgo=0000000000f64f00)
5381c3c.1868: BCryptOpenAlgorithmProvider(,'MD4',0,0) -> 0x0 (hAlgo=0000000000f6eee0)
5391c3c.1868: BCryptOpenAlgorithmProvider(,'MD5',0,0) -> 0x0 (hAlgo=0000000000f6f9c0)
5401c3c.1868: BCryptOpenAlgorithmProvider(,'SHA1',0,0) -> 0x0 (hAlgo=0000000000f6fc90)
5411c3c.1868: BCryptOpenAlgorithmProvider(,'SHA256',0,0) -> 0x0 (hAlgo=0000000000f6ff60)
5421c3c.1868: BCryptOpenAlgorithmProvider(,'SHA512',0,0) -> 0x0 (hAlgo=0000000000f70230)
5431c3c.1868: BCryptOpenAlgorithmProvider(,'RSA',0,0) -> 0x0 (hAlgo=0000000000f70500)
5441c3c.1868: BCryptOpenAlgorithmProvider(,'DSA',0,0) -> 0x0 (hAlgo=0000000000f707d0)
5451c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\cryptsp.dll)
5461c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cryptsp.dll
5471c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc37380000 LB 0x00017000 C:\Windows\SYSTEM32\CRYPTSP.dll [fFlags=0x0]
5481c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cryptsp.dll [lacks WinVerifyTrust]
5491c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'bcrypt.dll'.
5501c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\rsaenh.dll)
5511c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\rsaenh.dll
5521c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
5531c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume2\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
5541c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
5551c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
5561c3c.1868: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
5571c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc36db0000 LB 0x00033000 C:\Windows\system32\rsaenh.dll [fFlags=0x0]
5581c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
5591c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
5601c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'bcryptprimitives.dll'.
5611c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\cryptbase.dll)
5621c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cryptbase.dll
5631c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc373a0000 LB 0x0000b000 C:\Windows\SYSTEM32\CRYPTBASE.dll [fFlags=0x0]
5641c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cryptbase.dll [lacks WinVerifyTrust]
5651c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
5661c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcryptprimitives.dll'...
5671c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcryptprimitives.dll' -> '\Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll' [rcNtRedir=0xc0150008]
5681c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
5691c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
5701c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc38ea0000 'C:\Windows\System32\kernel32.dll'
5711c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
5721c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (Input=WINTRUST.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
5731c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc38240000 'C:\Windows\System32\WINTRUST.DLL'
5741c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
5751c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\CRYPT32.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
5761c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\CRYPT32.dll'
5771c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc38cf0000 LB 0x0001d000 C:\Windows\System32\imagehlp.dll [fFlags=0x0]
5781c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\imagehlp.dll)
5791c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\imagehlp.dll
5801c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
5811c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
5821c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
5831c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
5841c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'rpcrt4.dll'.
5851c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\gpapi.dll)
5861c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\gpapi.dll
5871c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc36690000 LB 0x00022000 C:\Windows\SYSTEM32\gpapi.dll [fFlags=0x0]
5881c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gpapi.dll [lacks WinVerifyTrust]
5891c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc379f0000 LB 0x0001f000 C:\Windows\System32\profapi.dll [fFlags=0x0]
5901c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\profapi.dll)
5911c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\profapi.dll
5921c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
5931c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'crypt32.dll'.
5941c3c.1868: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\cryptnet.dll)
5951c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cryptnet.dll
5961c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
5971c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume2\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
5981c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
5991c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
6001c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
6011c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
6021c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
6031c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
6041c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
6051c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
6061c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
6071c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
6081c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\cryptnet.dll (Input=cryptnet.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
6091c3c.1868: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6101c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc1f020000 LB 0x0002e000 C:\Windows\System32\cryptnet.dll [fFlags=0x0]
6111c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6121c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6131c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
6141c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc1f020000 'C:\Windows\System32\cryptnet.dll'
6151c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6161c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
6171c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc1f020000 'C:\Windows\System32\cryptnet.dll'
6181c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6191c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
6201c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc1f020000 'C:\Windows\System32\cryptnet.dll'
6211c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6221c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
6231c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc1f020000 'C:\Windows\System32\cryptnet.dll'
6241c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6251c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
6261c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc1f020000 'C:\Windows\System32\cryptnet.dll'
6271c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6281c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
6291c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc1f020000 'C:\Windows\System32\cryptnet.dll'
6301c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6311c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc1f020000 'C:\Windows\System32\cryptnet.dll'
6321c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6331c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc1f020000 'C:\Windows\System32\cryptnet.dll'
6341c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6351c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc1f020000 'C:\Windows\System32\cryptnet.dll'
6361c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6371c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc1f020000 'C:\Windows\System32\cryptnet.dll'
6381c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6391c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc1f020000 'C:\Windows\System32\cryptnet.dll'
6401c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc1f020000 'C:\Windows\System32\cryptnet.dll'
6411c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6421c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc1f020000 'C:\Windows\System32\cryptnet.dll'
6431c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
6441c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
6451c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
6461c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
6471c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
6481c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
6491c3c.1868: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000000 pwszName=\SystemRoot\System32\ntdll.dll
6501c3c.1868: supR3HardNtViCallWinVerifyTrustCatFile: New context 0000000000fe7760
6511c3c.1868: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000fe7760
6521c3c.1868: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=0AE8B48C4DE4B2B892A7EA6050127B678C7A2213
6531c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
6541c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\rpcrt4.dll (Input=rpcrt4.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
6551c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc38d70000 'C:\Windows\System32\rpcrt4.dll'
6561c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
6571c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
6581c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
6591c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
6601c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
6611c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
6621c3c.1868: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_1173_for_KB4284835~31bf3856ad364e35~amd64~~10.0.1.7.cat'; file='\SystemRoot\System32\ntdll.dll'
6631c3c.1868: g_pfnWinVerifyTrust=00007ffc38249940
6641c3c.1868: supR3HardenedScreenImage/preload: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [redoing WinVerifyTrust]
6651c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
6661c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
6671c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
6681c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
6691c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
6701c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
6711c3c.1868: supR3HardenedScreenImage/preload: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\crypt32.dll'
6721c3c.1868: supR3HardenedScreenImage/preload: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [redoing WinVerifyTrust]
6731c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
6741c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
6751c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
6761c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll
6771c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
6781c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
6791c3c.1868: supR3HardenedScreenImage/preload: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\wintrust.dll'
6801c3c.1868: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000038c pwszName=\Device\HarddiskVolume2\Windows\System32\cryptnet.dll
6811c3c.1868: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000fe7760
6821c3c.1868: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000fe7760
6831c3c.1868: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2EB3B5899525BF398A932A3B6257F3B13169332E
6841c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
6851c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
6861c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
6871c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
6881c3c.1868: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0015~31bf3856ad364e35~amd64~~10.0.17134.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\cryptnet.dll'
6891c3c.1868: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
6901c3c.1868: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\cryptnet.dll'
6911c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
6921c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
6931c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
6941c3c.1868: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\profapi.dll'
6951c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
6961c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
6971c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
6981c3c.1868: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\gpapi.dll'
6991c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
7001c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
7011c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
7021c3c.1868: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\imagehlp.dll'
7031c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
7041c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
7051c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
7061c3c.1868: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\cryptbase.dll'
7071c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
7081c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
7091c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
7101c3c.1868: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\rsaenh.dll'
7111c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
7121c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
7131c3c.1868: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\cryptsp.dll'
7141c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
7151c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll
7161c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
7171c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
7181c3c.1868: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll'
7191c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll
7201c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
7211c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
7221c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
7231c3c.1868: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\bcrypt.dll'
7241c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
7251c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
7261c3c.1868: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\advapi32.dll'
7271c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
7281c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
7291c3c.1868: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\sechost.dll'
7301c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
7311c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
7321c3c.1868: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\ucrtbase.dll'
7331c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
7341c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
7351c3c.1868: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll'
7361c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
7371c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
7381c3c.1868: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\msasn1.dll'
7391c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
7401c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
7411c3c.1868: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll'
7421c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
7431c3c.1868: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll'
7441c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
7451c3c.1868: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe'
7461c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
7471c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
7481c3c.1868: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\KernelBase.dll'
7491c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
7501c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
7511c3c.1868: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\kernel32.dll'
7521c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\system32\crypt32.dll'
7531c3c.1868: supR3HardenedWinIsDesiredRootCA: Adding 0x13e9e2f1555eba00 C=US, ST=TX, L=Austin, O=Rapid7, CN=MetasploitSelfSignedCA
7541c3c.1868: supR3HardenedWinIsDesiredRootCA: Adding 0x3d98ab22bb04a300 C=IE, O=Baltimore, OU=CyberTrust, CN=Baltimore CyberTrust Root
7551c3c.1868: supR3HardenedWinIsDesiredRootCA: Adding 0x5ad46780fa5df300 DC=com, DC=microsoft, CN=Microsoft Root Certificate Authority
7561c3c.1868: supR3HardenedWinIsDesiredRootCA: Adding 0xea5386456178582b C=ZA, ST=Western Cape, L=Durbanville, O=Thawte, OU=Thawte Certification, CN=Thawte Timestamping CA
7571c3c.1868: supR3HardenedWinIsDesiredRootCA: Adding 0x560ad29254e89100 C=GB, ST=Greater Manchester, L=Salford, O=COMODO CA Limited, CN=COMODO RSA Certification Authority
7581c3c.1868: supR3HardenedWinIsDesiredRootCA: Adding 0xf27194c5fa02d100 C=EN, CN=0a45729c75089f2b 2
7591c3c.1868: supR3HardenedWinIsDesiredRootCA: Adding 0x3be670c1bd02a900 OU=Copyright (c) 1997 Microsoft Corp., OU=Microsoft Corporation, CN=Microsoft Root Authority
7601c3c.1868: supR3HardenedWinIsDesiredRootCA: Adding 0xe991ee72b03db500 C=US, O=Symantec Corporation, CN=Symantec Enterprise Mobile Root for Microsoft
7611c3c.1868: supR3HardenedWinIsDesiredRootCA: Adding 0x4d3835aa4180b200 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2011
7621c3c.1868: supR3HardenedWinIsDesiredRootCA: Adding 0xa4ed27664a6cbd00 CN=DSA Root CA
7631c3c.1868: supR3HardenedWinIsDesiredRootCA: Adding 0x646e3fe3ba08df00 C=US, O=MSFT, CN=Microsoft Authenticode(tm) Root Authority
7641c3c.1868: supR3HardenedWinIsDesiredRootCA: Adding 0xd4fbe673e5ccc600 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA
7651c3c.1868: supR3HardenedWinIsDesiredRootCA: Adding 0x6bf371f60ee2bd00 C=US, ST=TX, L=Austin, O=Rapid7, CN=MetasploitSelfSignedCA
7661c3c.1868: supR3HardenedWinIsDesiredRootCA: Adding 0xece4e4289e08b900 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010
7671c3c.1868: supR3HardenedWinIsDesiredRootCA: Adding 0x43a9cc371ff5385a O=Microsoft Trust Network, OU=Microsoft Corporation, OU=Microsoft Time Stamping Service Root, OU=Copyright (c) 1997 Microsoft Corp.
7681c3c.1868: supR3HardenedWinIsDesiredRootCA: Adding 0x41776d193ac2ce00 C=US, ST=TX, L=Austin, O=Rapid7, CN=MetasploitSelfSignedCA
7691c3c.1868: supR3HardenedWinIsDesiredRootCA: Adding 0x2e2d2c7c68f0202e O=VeriSign Trust Network, OU=VeriSign, Inc., OU=VeriSign Time Stamping Service Root, OU=NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.
7701c3c.1868: supR3HardenedWinIsDesiredRootCA: Adding 0x146cf3d438f3c400 C=US, ST=TX, L=Austin, O=Rapid7, CN=MetasploitSelfSignedCA
7711c3c.1868: supR3HardenedWinIsDesiredRootCA: Adding 0xa12b07674f1bf600 C=US, O=AffirmTrust, CN=AffirmTrust Commercial
7721c3c.1868: supR3HardenedWinIsDesiredRootCA: Adding 0xd8dbfb2c27bfb200 C=US, O=thawte, Inc., OU=Certification Services Division, OU=(c) 2008 thawte, Inc. - For authorized use only, CN=thawte Primary Root CA - G3
7731c3c.1868: supR3HardenedWinIsDesiredRootCA: Adding 0x61a3a33f81aace00 C=US, ST=UT, L=Salt Lake City, O=The USERTRUST Network, OU=http://www.usertrust.com, CN=UTN-USERFirst-Object
7741c3c.1868: supR3HardenedWinIsDesiredRootCA: Adding 0x6b7bdc34cd37bb00 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root G2
7751c3c.1868: supR3HardenedWinIsDesiredRootCA: Adding 0x57ba5395b561bf00 C=BM, O=QuoVadis Limited, OU=Root Certification Authority, CN=QuoVadis Root Certification Authority
7761c3c.1868: supR3HardenedWinIsDesiredRootCA: Adding 0xf4fd306318ccda00 C=US, O=GeoTrust Inc., CN=GeoTrust Global CA
7771c3c.1868: supR3HardenedWinIsDesiredRootCA: Adding 0x83085097e9afdf00 O=Digital Signature Trust Co., CN=DST Root CA X3
7781c3c.1868: supR3HardenedWinIsDesiredRootCA: Adding 0x780679907625cc00 OU=GlobalSign Root CA - R3, O=GlobalSign, CN=GlobalSign
7791c3c.1868: supR3HardenedWinIsDesiredRootCA: Adding 0x3d98ab22bb04a300 C=IE, O=Baltimore, OU=CyberTrust, CN=Baltimore CyberTrust Root
7801c3c.1868: supR3HardenedWinIsDesiredRootCA: Adding 0xa0ee62086758b15d C=US, O=Equifax, OU=Equifax Secure Certificate Authority
7811c3c.1868: supR3HardenedWinIsDesiredRootCA: Adding 0x8ff6fc03c1edbd00 C=US, ST=Arizona, L=Scottsdale, O=Starfield Technologies, Inc., CN=Starfield Root Certificate Authority - G2
7821c3c.1868: supR3HardenedWinIsDesiredRootCA: Adding 0xc6fa4243b695b600 C=US, O=Entrust, Inc., OU=www.entrust.net/CPS is incorporated by reference, OU=(c) 2006 Entrust, Inc., CN=Entrust Root Certification Authority
7831c3c.1868: supR3HardenedWinIsDesiredRootCA: Adding 0xa3ce8d99e60eda00 C=BE, O=GlobalSign nv-sa, OU=Root CA, CN=GlobalSign Root CA
7841c3c.1868: supR3HardenedWinIsDesiredRootCA: Adding 0xa671e9fec832b700 C=US, O=Starfield Technologies, Inc., OU=Starfield Class 2 Certification Authority
7851c3c.1868: supR3HardenedWinIsDesiredRootCA: Adding 0xa8de7211e13be200 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root CA
7861c3c.1868: supR3HardenedWinIsDesiredRootCA: Adding 0xd45980fbf0a0ac00 C=US, O=thawte, Inc., OU=Certification Services Division, OU=(c) 2006 thawte, Inc. - For authorized use only, CN=thawte Primary Root CA
7871c3c.1868: supR3HardenedWinIsDesiredRootCA: Adding 0xc9edb72b684ba00 C=US, O=Entrust, Inc., OU=See www.entrust.net/legal-terms, OU=(c) 2009 Entrust, Inc. - for authorized use only, CN=Entrust Root Certification Authority - G2
7881c3c.1868: supR3HardenedWinIsDesiredRootCA: Adding 0xf5cd95e581a4ab00 C=US, O=SecureTrust Corporation, CN=SecureTrust CA
7891c3c.1868: supR3HardenedWinIsDesiredRootCA: Adding 0x6f2ebe0e24cfa600 OU=GlobalSign Root CA - R2, O=GlobalSign, CN=GlobalSign
7901c3c.1868: supR3HardenedWinIsDesiredRootCA: Adding 0x14018a1bf29e595c C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority
7911c3c.1868: supR3HardenedWinIsDesiredRootCA: Adding 0x9e5bc2d78b6a3636 C=ZA, ST=Western Cape, L=Cape Town, O=Thawte Consulting cc, OU=Certification Services Division, CN=Thawte Premium Server CA, Email=premium-server@thawte.com
7921c3c.1868: supR3HardenedWinIsDesiredRootCA: Adding 0x7c4fd32ec1b1ce00 C=PL, O=Unizeto Sp. z o.o., CN=Certum CA
7931c3c.1868: supR3HardenedWinIsDesiredRootCA: Adding 0xd4fbe673e5ccc600 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA
7941c3c.1868: supR3HardenedWinIsDesiredRootCA: Adding 0x1b8578514b74ac00 C=US, O=WFA Hotspot 2.0, CN=Hotspot 2.0 Trust Root CA - 03
7951c3c.1868: supR3HardenedWinIsDesiredRootCA: Adding 0xb28612a94b4dad00 O=Entrust.net, OU=www.entrust.net/CPS_2048 incorp. by ref. (limits liab.), OU=(c) 1999 Entrust.net Limited, CN=Entrust.net Certification Authority (2048)
7961c3c.1868: supR3HardenedWinIsDesiredRootCA: Adding 0x357a29080824af00 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2006 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G5
7971c3c.1868: supR3HardenedWinIsDesiredRootCA: Adding 0x59faf1086271bf00 C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com, Inc., CN=Go Daddy Root Certificate Authority - G2
7981c3c.1868: supR3HardenedWinIsDesiredRootCA: Adding 0x3401b15e3761c700 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2008 VeriSign, Inc. - For authorized use only, CN=VeriSign Universal Root Certification Authority
7991c3c.1868: supR3HardenedWinIsDesiredRootCA: Adding 0x491857ead79dde00 C=US, O=The Go Daddy Group, Inc., OU=Go Daddy Class 2 Certification Authority
8001c3c.1868: supR3HardenedWinIsDesiredRootCA: Adding 0xdc1801b225aea100 C=BM, O=QuoVadis Limited, CN=QuoVadis Root CA 2 G3
8011c3c.1868: supR3HardenedWinIsDesiredRootCA: Adding 0xc2ba72a37dfbe300 C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Trusted Network CA
8021c3c.1868: supR3HardenedWinIsDesiredRootCA: Adding 0x8043e4ce150ead00 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID Root CA
8031c3c.1868: supR3HardenedWinIsDesiredRootCA: Adding 0x331d58625ee2dc00 C=US, O=GeoTrust Inc., OU=(c) 2008 GeoTrust Inc. - For authorized use only, CN=GeoTrust Primary Certification Authority - G3
8041c3c.1868: supR3HardenedWinIsDesiredRootCA: Adding 0xf2e6331af7b700 C=SE, O=AddTrust AB, OU=AddTrust External TTP Network, CN=AddTrust External CA Root
8051c3c.1868: supR3HardenedWinRetrieveTrustedRootCAs: cAdded=52
8061c3c.1868: SUPR3HardenedMain: Load Runtime...
8071c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
8081c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
8091c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
8101c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ws2_32.dll'.
8111c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'rpcrt4.dll'.
8121c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll) WinVerifyTrust
8131c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
8141c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
8151c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
8161c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
8171c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
8181c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
8191c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
8201c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
8211c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'rpcrt4.dll'.
8221c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ws2_32.dll) WinVerifyTrust
8231c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
8241c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
8251c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
8261c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
8271c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
8281c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
8291c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
8301c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
8311c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll) WinVerifyTrust
8321c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
8331c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
8341c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
8351c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
8361c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
8371c3c.1868: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll'.
8381c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll)
8391c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
8401c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
8411c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll) WinVerifyTrust
8421c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000a01:<flags> [calling]
8431c3c.1868: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
8441c3c.1868: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll [avoiding WinVerifyTrust]
8451c3c.1868: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
8461c3c.1868: supR3HardenedDllNotificationCallback: load 0000000054da0000 LB 0x000d2000 C:\Program Files\Oracle\VirtualBox\MSVCR100.dll [fFlags=0x0]
8471c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll [avoiding WinVerifyTrust]
8481c3c.1868: supR3HardenedDllNotificationCallback: load 0000000054d00000 LB 0x00098000 C:\Program Files\Oracle\VirtualBox\MSVCP100.dll [fFlags=0x0]
8491c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
8501c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc3b570000 LB 0x0006c000 C:\Windows\System32\WS2_32.dll [fFlags=0x0]
8511c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
8521c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc11190000 LB 0x00590000 C:\Program Files\Oracle\VirtualBox\VBoxRT.dll [fFlags=0x0]
8531c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
8541c3c.1868: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll'.
8551c3c.1868: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
8561c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
8571c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
8581c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
8591c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
8601c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
8611c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
8621c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
8631c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
8641c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
8651c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
8661c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
8671c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
8681c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
8691c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
8701c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
8711c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
8721c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
8731c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
8741c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
8751c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
8761c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
8771c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
8781c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
8791c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
8801c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
8811c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
8821c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
8831c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
8841c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
8851c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
8861c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
8871c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
8881c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
8891c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
8901c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
8911c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
8921c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
8931c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
8941c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
8951c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
8961c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
8971c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
8981c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
8991c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
9001c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
9011c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9021c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9031c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9041c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9051c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll
9061c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
9071c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc38240000 'C:\Windows\system32\Wintrust.dll'
9081c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
9091c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
9101c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll
9111c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
9121c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
9131c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
9141c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\system32\crypt32.dll'
9151c3c.1868: SUPR3HardenedMain: Load TrustedMain...
9161c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
9171c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'opengl32.dll'.
9181c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
9191c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msvcp100.dll'.
9201c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcr100.dll'.
9211c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qt5corevbox.dll'.
9221c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'qt5guivbox.dll'.
9231c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'qt5widgetsvbox.dll'.
9241c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'qt5printsupportvbox.dll'.
9251c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'qt5openglvbox.dll'.
9261c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'user32.dll'.
9271c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'advapi32.dll'.
9281c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'shell32.dll'.
9291c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'ole32.dll'.
9301c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'oleaut32.dll'.
9311c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #15 'winmm.dll'.
9321c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.dll) WinVerifyTrust
9331c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.dll
9341c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
9351c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
9361c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
9371c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
9381c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'winmmbase.dll'.
9391c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msvcrt.dll'.
9401c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\winmm.dll) WinVerifyTrust
9411c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\winmm.dll
9421c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
9431c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
9441c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
9451c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
9461c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
9471c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmmbase.dll'...
9481c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmmbase.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmmbase.dll' [rcNtRedir=0xc0150008]
9491c3c.1868: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\winmmbase.dll'.
9501c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
9511c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\winmmbase.dll)
9521c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\winmmbase.dll
9531c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
9541c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
9551c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
9561c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
9571c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll
9581c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
9591c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
9601c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
9611c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'combase.dll'.
9621c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'rpcrt4.dll'.
9631c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\oleaut32.dll) WinVerifyTrust
9641c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
9651c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
9661c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
9671c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
9681c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
9691c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
9701c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
9711c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume2\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
9721c3c.1868: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\combase.dll'.
9731c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rpcrt4.dll'.
9741c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #45 'bcryptprimitives.dll'.
9751c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\combase.dll)
9761c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\combase.dll
9771c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
9781c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
9791c3c.1868: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\msvcp_win.dll'.
9801c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\msvcp_win.dll)
9811c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msvcp_win.dll
9821c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcryptprimitives.dll'...
9831c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcryptprimitives.dll' -> '\Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll' [rcNtRedir=0xc0150008]
9841c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll
9851c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
9861c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
9871c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
9881c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
9891c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'rpcrt4.dll'.
9901c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #48 'gdi32.dll'.
9911c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #49 'user32.dll'.
9921c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #50 'combase.dll'.
9931c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ole32.dll) WinVerifyTrust
9941c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ole32.dll
9951c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
9961c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
9971c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
9981c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume2\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
9991c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\combase.dll [lacks WinVerifyTrust]
10001c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
10011c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
10021c3c.1868: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\user32.dll'.
10031c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'win32u.dll'.
10041c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #34 'gdi32.dll'.
10051c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\user32.dll)
10061c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\user32.dll
10071c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
10081c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
10091c3c.1868: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\gdi32.dll'.
10101c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\gdi32.dll)
10111c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\gdi32.dll
10121c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
10131c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
10141c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
10151c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
10161c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
10171c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
10181c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume2\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
10191c3c.1868: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\win32u.dll'.
10201c3c.1868: '\Device\HarddiskVolume2\Windows\System32\win32u.dll' has no imports
10211c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\win32u.dll)
10221c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\win32u.dll
10231c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
10241c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
10251c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
10261c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #74 'user32.dll'.
10271c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #76 'gdi32.dll'.
10281c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\shell32.dll) WinVerifyTrust
10291c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\shell32.dll
10301c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
10311c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
10321c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
10331c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
10341c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
10351c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll [redoing WinVerifyTrust]
10361c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
10371c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
10381c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
10391c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
10401c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
10411c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
10421c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
10431c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
10441c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
10451c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
10461c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
10471c3c.1868: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\user32.dll'
10481c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5openglvbox.dll'...
10491c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5openglvbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5openglvbox.dll' [rcNtRedir=0xc0150008]
10501c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
10511c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'qt5widgetsvbox.dll'.
10521c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'qt5guivbox.dll'.
10531c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5corevbox.dll'.
10541c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcr100.dll'.
10551c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll) WinVerifyTrust
10561c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll
10571c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5printsupportvbox.dll'...
10581c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5printsupportvbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5printsupportvbox.dll' [rcNtRedir=0xc0150008]
10591c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
10601c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
10611c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
10621c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
10631c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
10641c3c.1868: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll'.
10651c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
10661c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'shell32.dll'.
10671c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ole32.dll'.
10681c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
10691c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ws2_32.dll'.
10701c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'mpr.dll'.
10711c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'msvcp100.dll'.
10721c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'msvcr100.dll'.
10731c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll)
10741c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
10751c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
10761c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
10771c3c.1868: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll'.
10781c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ole32.dll'.
10791c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'opengl32.dll'.
10801c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
10811c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
10821c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qt5corevbox.dll'.
10831c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcp100.dll'.
10841c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msvcr100.dll'.
10851c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll)
10861c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
10871c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
10881c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
10891c3c.1868: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll'.
10901c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
10911c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
10921c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5guivbox.dll'.
10931c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qt5corevbox.dll'.
10941c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'shell32.dll'.
10951c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcp100.dll'.
10961c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msvcr100.dll'.
10971c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll)
10981c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll
10991c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
11001c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
11011c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
11021c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
11031c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
11041c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
11051c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
11061c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
11071c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
11081c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
11091c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
11101c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [lacks WinVerifyTrust]
11111c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
11121c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
11131c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll [lacks WinVerifyTrust]
11141c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
11151c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
11161c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll
11171c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
11181c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
11191c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
11201c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
11211c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
11221c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
11231c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
11241c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
11251c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
11261c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
11271c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
11281c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [lacks WinVerifyTrust]
11291c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
11301c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
11311c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll
11321c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
11331c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
11341c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
11351c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
11361c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
11371c3c.1868: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume2\Windows\System32\opengl32.dll'.
11381c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
11391c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'advapi32.dll'.
11401c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
11411c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
11421c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'glu32.dll'.
11431c3c.1868: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\opengl32.dll)
11441c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\opengl32.dll
11451c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
11461c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
11471c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
11481c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
11491c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
11501c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
11511c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
11521c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
11531c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
11541c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mpr.dll'...
11551c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'mpr.dll' -> '\Device\HarddiskVolume2\Windows\System32\mpr.dll' [rcNtRedir=0xc0150008]
11561c3c.1868: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\mpr.dll'.
11571c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\mpr.dll)
11581c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\mpr.dll
11591c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
11601c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
11611c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
11621c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
11631c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
11641c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
11651c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
11661c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
11671c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
11681c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
11691c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
11701c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
11711c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
11721c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
11731c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll
11741c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'glu32.dll'...
11751c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'glu32.dll' -> '\Device\HarddiskVolume2\Windows\System32\glu32.dll' [rcNtRedir=0xc0150008]
11761c3c.1868: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume2\Windows\System32\glu32.dll'.
11771c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
11781c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
11791c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'opengl32.dll'.
11801c3c.1868: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\glu32.dll)
11811c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\glu32.dll
11821c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
11831c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
11841c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
11851c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
11861c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
11871c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll
11881c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
11891c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
11901c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
11911c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
11921c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
11931c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
11941c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
11951c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
11961c3c.1868: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll [lacks WinVerifyTrust]
11971c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
11981c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
11991c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll
12001c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
12011c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
12021c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
12031c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
12041c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
12051c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5widgetsvbox.dll'.
12061c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qt5guivbox.dll'.
12071c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qt5corevbox.dll'.
12081c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'winspool.drv'.
12091c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'comdlg32.dll'.
12101c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'msvcr100.dll'.
12111c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5PrintSupportVBox.dll) WinVerifyTrust
12121c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5PrintSupportVBox.dll
12131c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
12141c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
12151c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll [redoing WinVerifyTrust]
12161c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
12171c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
12181c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
12191c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comdlg32.dll'...
12201c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'comdlg32.dll' -> '\Device\HarddiskVolume2\Windows\System32\comdlg32.dll' [rcNtRedir=0xc0150008]
12211c3c.1868: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume2\Windows\System32\comdlg32.dll'.
12221c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
12231c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #35 'user32.dll'.
12241c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #36 'shlwapi.dll'.
12251c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #37 'gdi32.dll'.
12261c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #38 'comctl32.dll'.
12271c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #39 'shell32.dll'.
12281c3c.1868: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\comdlg32.dll)
12291c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\comdlg32.dll
12301c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winspool.drv'...
12311c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'winspool.drv' -> '\Device\HarddiskVolume2\Windows\System32\winspool.drv' [rcNtRedir=0xc0150008]
12321c3c.1868: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume2\Windows\System32\winspool.drv'.
12331c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
12341c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #24 'propsys.dll'.
12351c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #29 'iphlpapi.dll'.
12361c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #38 'bcrypt.dll'.
12371c3c.1868: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\winspool.drv)
12381c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\winspool.drv
12391c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
12401c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
12411c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [lacks WinVerifyTrust]
12421c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
12431c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
12441c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll [lacks WinVerifyTrust]
12451c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
12461c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
12471c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll [lacks WinVerifyTrust]
12481c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
12491c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
12501c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll
12511c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
12521c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
12531c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
12541c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
12551c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume2\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
12561c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll
12571c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'iphlpapi.dll'...
12581c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'iphlpapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\iphlpapi.dll' [rcNtRedir=0xc0150008]
12591c3c.1868: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL'.
12601c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL)
12611c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL
12621c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'propsys.dll'...
12631c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'propsys.dll' -> '\Device\HarddiskVolume2\Windows\System32\propsys.dll' [rcNtRedir=0xc0150008]
12641c3c.1868: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\propsys.dll'.
12651c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
12661c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #15 'oleaut32.dll'.
12671c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #31 'rpcrt4.dll'.
12681c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\propsys.dll)
12691c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\propsys.dll
12701c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
12711c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
12721c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
12731c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
12741c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
12751c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comctl32.dll'...
12761c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'comctl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\comctl32.dll' [rcNtRedir=0x0]
12771c3c.1868: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\comctl32.dll'.
12781c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'advapi32.dll'.
12791c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
12801c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
12811c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\comctl32.dll)
12821c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\comctl32.dll
12831c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
12841c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
12851c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
12861c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
12871c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
12881c3c.1868: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll'.
12891c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
12901c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #44 'gdi32.dll'.
12911c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #45 'user32.dll'.
12921c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\shlwapi.dll)
12931c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\shlwapi.dll
12941c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
12951c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
12961c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
12971c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
12981c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
12991c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
13001c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
13011c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
13021c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
13031c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
13041c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
13051c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
13061c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
13071c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
13081c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
13091c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
13101c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
13111c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
13121c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
13131c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
13141c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
13151c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
13161c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
13171c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
13181c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
13191c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
13201c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
13211c3c.1868: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll'
13221c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
13231c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
13241c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll [redoing WinVerifyTrust]
13251c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
13261c3c.1868: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll'
13271c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
13281c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
13291c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [redoing WinVerifyTrust]
13301c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
13311c3c.1868: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll'
13321c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
13331c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
13341c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll [redoing WinVerifyTrust]
13351c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
13361c3c.1868: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll'
13371c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
13381c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
13391c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
13401c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
13411c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
13421c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
13431c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
13441c3c.1868: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll [redoing WinVerifyTrust]
13451c3c.1868: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004a4 pwszName=\Device\HarddiskVolume2\Windows\System32\opengl32.dll
13461c3c.1868: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000fe7760
13471c3c.1868: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000fe7760
13481c3c.1868: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=19A1CD90C2208B3BD0567A538CC10CADA852F417
13491c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
13501c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
13511c3c.1868: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package00112~31bf3856ad364e35~amd64~~10.0.17134.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\opengl32.dll'
13521c3c.1868: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
13531c3c.1868: supR3HardenedScreenImage/Imports: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\opengl32.dll'
13541c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VirtualBox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000a01:<flags> [calling]
13551c3c.1868: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.dll
13561c3c.1868: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
13571c3c.1868: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
13581c3c.1868: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
13591c3c.1868: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll
13601c3c.1868: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5PrintSupportVBox.dll
13611c3c.1868: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll
13621c3c.1868: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
13631c3c.1868: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\glu32.dll [avoiding WinVerifyTrust]
13641c3c.1868: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\mpr.dll [avoiding WinVerifyTrust]
13651c3c.1868: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\winspool.drv [avoiding WinVerifyTrust]
13661c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'advapi32.dll'.
13671c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
13681c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
13691c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.17134.112_none_f94f898130982b3f\comctl32.dll)
13701c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.17134.112_none_f94f898130982b3f\comctl32.dll
13711c3c.1868: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmmbase.dll [avoiding WinVerifyTrust]
13721c3c.1868: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\propsys.dll [avoiding WinVerifyTrust]
13731c3c.1868: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL [avoiding WinVerifyTrust]
13741c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc37b10000 LB 0x00020000 C:\Windows\System32\win32u.dll [fFlags=0x0]
13751c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\win32u.dll [avoiding WinVerifyTrust]
13761c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc38a30000 LB 0x0009f000 C:\Windows\System32\msvcp_win.dll [fFlags=0x0]
13771c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcp_win.dll [avoiding WinVerifyTrust]
13781c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc38890000 LB 0x00192000 C:\Windows\System32\gdi32full.dll [fFlags=0x0]
13791c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
13801c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #33 'gdi32.dll'.
13811c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #35 'user32.dll'.
13821c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #36 'win32u.dll'.
13831c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\gdi32full.dll)
13841c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\gdi32full.dll
13851c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc3ac20000 LB 0x00028000 C:\Windows\System32\GDI32.dll [fFlags=0x0]
13861c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [avoiding WinVerifyTrust]
13871c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc3b240000 LB 0x00190000 C:\Windows\System32\USER32.dll [fFlags=0x0]
13881c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc19170000 LB 0x0002c000 C:\Windows\SYSTEM32\GLU32.dll [fFlags=0x0]
13891c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\glu32.dll [avoiding WinVerifyTrust]
13901c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc10f90000 LB 0x00120000 C:\Windows\SYSTEM32\OPENGL32.dll [fFlags=0x0]
13911c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
13921c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc38840000 LB 0x00049000 C:\Windows\System32\cfgmgr32.dll [fFlags=0x0]
13931c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll)
13941c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll
13951c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc38f60000 LB 0x00323000 C:\Windows\System32\combase.dll [fFlags=0x0]
13961c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\combase.dll [avoiding WinVerifyTrust]
13971c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc39550000 LB 0x000a9000 C:\Windows\System32\shcore.dll [fFlags=0x0]
13981c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
13991c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #37 'rpcrt4.dll'.
14001c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #44 'combase.dll'.
14011c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\SHCore.dll)
14021c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\SHCore.dll
14031c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc3ab20000 LB 0x00051000 C:\Windows\System32\shlwapi.dll [fFlags=0x0]
14041c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll [avoiding WinVerifyTrust]
14051c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc37980000 LB 0x00011000 C:\Windows\System32\kernel.appcore.dll [fFlags=0x0]
14061c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'msvcrt.dll'.
14071c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'rpcrt4.dll'.
14081c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\kernel.appcore.dll)
14091c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\kernel.appcore.dll
14101c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc379a0000 LB 0x0004c000 C:\Windows\System32\powrprof.dll [fFlags=0x0]
14111c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'rpcrt4.dll'.
14121c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\powrprof.dll)
14131c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\powrprof.dll
14141c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc37950000 LB 0x0000a000 C:\Windows\System32\FLTLIB.DLL [fFlags=0x0]
14151c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\fltLib.dll)
14161c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\fltLib.dll
14171c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc37b30000 LB 0x0070d000 C:\Windows\System32\windows.storage.dll [fFlags=0x0]
14181c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
14191c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'rpcrt4.dll'.
14201c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #54 'combase.dll'.
14211c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #58 'profapi.dll'.
14221c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #81 'fltlib.dll'.
14231c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\windows.storage.dll)
14241c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\windows.storage.dll
14251c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc39600000 LB 0x01440000 C:\Windows\System32\SHELL32.dll [fFlags=0x0]
14261c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
14271c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc38ad0000 LB 0x00151000 C:\Windows\System32\ole32.dll [fFlags=0x0]
14281c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
14291c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc1d8c0000 LB 0x0001a000 C:\Windows\SYSTEM32\MPR.dll [fFlags=0x0]
14301c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\mpr.dll [avoiding WinVerifyTrust]
14311c3c.1868: supR3HardenedDllNotificationCallback: load 0000000054790000 LB 0x00565000 C:\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [fFlags=0x0]
14321c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
14331c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc0e370000 LB 0x005f7000 C:\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll [fFlags=0x0]
14341c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
14351c3c.1868: supR3HardenedDllNotificationCallback: load 0000000054220000 LB 0x00561000 C:\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll [fFlags=0x0]
14361c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll
14371c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc392f0000 LB 0x000c2000 C:\Windows\System32\OLEAUT32.dll [fFlags=0x0]
14381c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
14391c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc34800000 LB 0x001b4000 C:\Windows\SYSTEM32\PROPSYS.dll [fFlags=0x0]
14401c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\propsys.dll [avoiding WinVerifyTrust]
14411c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc36f50000 LB 0x00038000 C:\Windows\SYSTEM32\IPHLPAPI.DLL [fFlags=0x0]
14421c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL [avoiding WinVerifyTrust]
14431c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc33840000 LB 0x00084000 C:\Windows\SYSTEM32\WINSPOOL.DRV [fFlags=0x0]
14441c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\winspool.drv [avoiding WinVerifyTrust]
14451c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc14f00000 LB 0x000a7000 C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.17134.112_none_f94f898130982b3f\COMCTL32.dll [fFlags=0x0]
14461c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.17134.112_none_f94f898130982b3f\comctl32.dll [avoiding WinVerifyTrust]
14471c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc3b480000 LB 0x000ed000 C:\Windows\System32\COMDLG32.dll [fFlags=0x0]
14481c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\comdlg32.dll [avoiding WinVerifyTrust]
14491c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc17150000 LB 0x00051000 C:\Program Files\Oracle\VirtualBox\Qt5PrintSupportVBox.dll [fFlags=0x0]
14501c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5PrintSupportVBox.dll
14511c3c.1868: supR3HardenedDllNotificationCallback: load 00000000541c0000 LB 0x00054000 C:\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll [fFlags=0x0]
14521c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll
14531c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc355a0000 LB 0x0002a000 C:\Windows\SYSTEM32\WINMMBASE.dll [fFlags=0x0]
14541c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmmbase.dll [avoiding WinVerifyTrust]
14551c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc355d0000 LB 0x00023000 C:\Windows\SYSTEM32\WINMM.dll [fFlags=0x0]
14561c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
14571c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc0e970000 LB 0x00a06000 C:\Program Files\Oracle\VirtualBox\VirtualBox.dll [fFlags=0x0]
14581c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.dll
14591c3c.1868: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\windows.storage.dll'.
14601c3c.1868: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\windows.storage.dll' [rescheduled]
14611c3c.1868: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\fltLib.dll'.
14621c3c.1868: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\fltLib.dll' [rescheduled]
14631c3c.1868: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\powrprof.dll'.
14641c3c.1868: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\powrprof.dll' [rescheduled]
14651c3c.1868: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\kernel.appcore.dll'.
14661c3c.1868: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\kernel.appcore.dll' [rescheduled]
14671c3c.1868: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\SHCore.dll'.
14681c3c.1868: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\SHCore.dll' [rescheduled]
14691c3c.1868: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll'.
14701c3c.1868: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll' [rescheduled]
14711c3c.1868: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\gdi32full.dll'.
14721c3c.1868: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\gdi32full.dll' [rescheduled]
14731c3c.1868: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.17134.112_none_f94f898130982b3f\comctl32.dll'.
14741c3c.1868: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.17134.112_none_f94f898130982b3f\comctl32.dll' [rescheduled]
14751c3c.1868: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll'.
14761c3c.1868: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll' [rescheduled]
14771c3c.1868: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\comctl32.dll'.
14781c3c.1868: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\comctl32.dll' [rescheduled]
14791c3c.1868: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\propsys.dll'.
14801c3c.1868: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\propsys.dll' [rescheduled]
14811c3c.1868: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL'.
14821c3c.1868: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL' [rescheduled]
14831c3c.1868: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume2\Windows\System32\winspool.drv'.
14841c3c.1868: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\winspool.drv' [rescheduled]
14851c3c.1868: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume2\Windows\System32\comdlg32.dll'.
14861c3c.1868: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\comdlg32.dll' [rescheduled]
14871c3c.1868: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume2\Windows\System32\glu32.dll'.
14881c3c.1868: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\glu32.dll' [rescheduled]
14891c3c.1868: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\mpr.dll'.
14901c3c.1868: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\mpr.dll' [rescheduled]
14911c3c.1868: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\win32u.dll'.
14921c3c.1868: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\win32u.dll' [rescheduled]
14931c3c.1868: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\gdi32.dll'.
14941c3c.1868: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rescheduled]
14951c3c.1868: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\msvcp_win.dll'.
14961c3c.1868: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\msvcp_win.dll' [rescheduled]
14971c3c.1868: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\combase.dll'.
14981c3c.1868: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\combase.dll' [rescheduled]
14991c3c.1868: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\winmmbase.dll'.
15001c3c.1868: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\winmmbase.dll' [rescheduled]
15011c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll
15021c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'fltlib.dll'...
15031c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'fltlib.dll' -> '\Device\HarddiskVolume2\Windows\System32\fltlib.dll' [rcNtRedir=0xc0150008]
15041c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\fltLib.dll [redoing WinVerifyTrust]
15051c3c.1868: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\fltLib.dll'.
15061c3c.1868: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume2\Windows\System32\fltLib.dll
15071c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'profapi.dll'...
15081c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'profapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\profapi.dll' [rcNtRedir=0xc0150008]
15091c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\profapi.dll
15101c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
15111c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume2\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
15121c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\combase.dll [redoing WinVerifyTrust]
15131c3c.1868: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\combase.dll'.
15141c3c.1868: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume2\Windows\System32\combase.dll
15151c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
15161c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
15171c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
15181c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
15191c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
15201c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
15211c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
15221c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
15231c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
15241c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
15251c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
15261c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume2\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
15271c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\combase.dll [redoing WinVerifyTrust]
15281c3c.1868: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\combase.dll'.
15291c3c.1868: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume2\Windows\System32\combase.dll
15301c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
15311c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
15321c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
15331c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
15341c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
15351c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
15361c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume2\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
15371c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\win32u.dll [redoing WinVerifyTrust]
15381c3c.1868: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\win32u.dll'.
15391c3c.1868: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume2\Windows\System32\win32u.dll
15401c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
15411c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
15421c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
15431c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
15441c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [redoing WinVerifyTrust]
15451c3c.1868: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\gdi32.dll'.
15461c3c.1868: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume2\Windows\System32\gdi32.dll
15471c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
15481c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
15491c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcp_win.dll [redoing WinVerifyTrust]
15501c3c.1868: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\msvcp_win.dll'.
15511c3c.1868: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume2\Windows\System32\msvcp_win.dll
15521c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
15531c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
15541c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
15551c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
15561c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [redoing WinVerifyTrust]
15571c3c.1868: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\gdi32.dll'.
15581c3c.1868: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume2\Windows\System32\gdi32.dll
15591c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
15601c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
15611c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
15621c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\kernel32.dll (Input=kernel32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
15631c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc38ea0000 'C:\Windows\System32\kernel32.dll'
15641c3c.1868: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-string-l1-1-0) -> 0x0, fPresent=1
15651c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-string-l1-1-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
15661c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc385c0000 'api-ms-win-core-string-l1-1-0'
15671c3c.1868: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-datetime-l1-1-1) -> 0x0, fPresent=1
15681c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-datetime-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
15691c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc385c0000 'api-ms-win-core-datetime-l1-1-1'
15701c3c.1868: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-obsolete-l1-2-0) -> 0x0, fPresent=1
15711c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-obsolete-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
15721c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc385c0000 'api-ms-win-core-localization-obsolete-l1-2-0'
15731c3c.1868: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\imm32.dll'.
15741c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'user32.dll'.
15751c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'win32u.dll'.
15761c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\imm32.dll)
15771c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\imm32.dll
15781c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
15791c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume2\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
15801c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\win32u.dll [redoing WinVerifyTrust]
15811c3c.1868: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\win32u.dll'.
15821c3c.1868: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume2\Windows\System32\win32u.dll
15831c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
15841c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
15851c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\IMM32.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
15861c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc3b5e0000 LB 0x0002d000 C:\Windows\System32\IMM32.DLL [fFlags=0x0]
15871c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\imm32.dll [avoiding WinVerifyTrust]
15881c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3b5e0000 'C:\Windows\system32\IMM32.DLL'
15891c3c.1868: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\imm32.dll'.
15901c3c.1868: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\imm32.dll' [rescheduled]
15911c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\imm32.dll [redoing WinVerifyTrust]
15921c3c.1868: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\imm32.dll'.
15931c3c.1868: supR3HardenedScreenImage/LdrLoadDll: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume2\Windows\System32\imm32.dll
15941c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\imm32.dll (Input=imm32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
15951c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3b5e0000 'C:\Windows\System32\imm32.dll'
15961c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
15971c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\ADVAPI32.DLL (Input=ADVAPI32.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
15981c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3b3d0000 'C:\Windows\System32\ADVAPI32.DLL'
15991c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc0e970000 'C:\Program Files\Oracle\VirtualBox\VirtualBox.dll'
16001c3c.1868: SUPR3HardenedMain: Calling TrustedMain (00007ffc0e9714f0)...
16011c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
16021c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
16031c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'ole32.dll'.
16041c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
16051c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'imm32.dll'.
16061c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'winmm.dll'.
16071c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'oleaut32.dll'.
16081c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'shell32.dll'.
16091c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'advapi32.dll'.
16101c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'qt5guivbox.dll'.
16111c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'qt5corevbox.dll'.
16121c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'msvcr100.dll'.
16131c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\platforms\qwindows.dll) WinVerifyTrust
16141c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\platforms\qwindows.dll
16151c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
16161c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
16171c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
16181c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
16191c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
16201c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
16211c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
16221c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
16231c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
16241c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
16251c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
16261c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
16271c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
16281c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
16291c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
16301c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
16311c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
16321c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
16331c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
16341c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
16351c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
16361c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume2\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
16371c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\imm32.dll [redoing WinVerifyTrust]
16381c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
16391c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
16401c3c.1868: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\imm32.dll'
16411c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
16421c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
16431c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll
16441c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
16451c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
16461c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
16471c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
16481c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
16491c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [redoing WinVerifyTrust]
16501c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
16511c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
16521c3c.1868: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\gdi32.dll'
16531c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\platforms\qwindows.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
16541c3c.1868: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\platforms\qwindows.dll
16551c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc10e60000 LB 0x0012e000 C:\Program Files\Oracle\VirtualBox\platforms\qwindows.dll [fFlags=0x0]
16561c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\platforms\qwindows.dll
16571c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc10e60000 'C:\Program Files\Oracle\VirtualBox\platforms\qwindows.dll'
16581c3c.1868: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000065c pwszName=\Device\HarddiskVolume2\Windows\System32\uxtheme.dll
16591c3c.1868: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000fe7760
16601c3c.1868: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000fe7760
16611c3c.1868: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=15C67EA66CCB2DD0FE18A5AB58A7BA1C113BBA6A
16621c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
16631c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
16641c3c.1868: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package00115~31bf3856ad364e35~amd64~~10.0.17134.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\uxtheme.dll'
16651c3c.1868: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
16661c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
16671c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #33 'gdi32.dll'.
16681c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #34 'user32.dll'.
16691c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\uxtheme.dll) WinVerifyTrust
16701c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
16711c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
16721c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
16731c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
16741c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
16751c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
16761c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
16771c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
16781c3c.1868: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
16791c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc36010000 LB 0x00098000 C:\Windows\system32\uxtheme.dll [fFlags=0x0]
16801c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
16811c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36010000 'C:\Windows\system32\uxtheme.dll'
16821c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3b240000 'C:\Windows\system32\user32.dll'
16831c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
16841c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
16851c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc39600000 'C:\Windows\system32\shell32.dll'
16861c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\SHCore.dll [redoing WinVerifyTrust]
16871c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
16881c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
16891c3c.1868: supR3HardenedScreenImage/LdrLoadDll: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\SHCore.dll'
16901c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\SHCore.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
16911c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc39550000 'C:\Windows\system32\SHCore.dll'
16921c3c.1868: supR3HardenedMonitor_LdrLoadDll: error opening 'C:\Windows\system32\wintab32.dll': 0 (NtPath=\??\C:\Windows\system32\wintab32.dll; Input=C:\Windows\system32\wintab32.dll; rcNtGetDll=0x0
16931c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000034 'C:\Windows\system32\wintab32.dll'
16941c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
16951c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #21 'win32u.dll'.
16961c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #22 'user32.dll'.
16971c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'gdi32.dll'.
16981c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\dwmapi.dll)
16991c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\dwmapi.dll
17001c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc360e0000 LB 0x00029000 C:\Windows\system32\dwmapi.dll [fFlags=0x0]
17011c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dwmapi.dll [avoiding WinVerifyTrust]
17021c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
17031c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
17041c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
17051c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
17061c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
17071c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume2\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
17081c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\win32u.dll [lacks WinVerifyTrust]
17091c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
17101c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
17111c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
17121c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
17131c3c.1868: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\dwmapi.dll'
17141c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
17151c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\winmm.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
17161c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc355d0000 'C:\Windows\system32\winmm.dll'
17171c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
17181c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\winmm.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
17191c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc355d0000 'C:\Windows\system32\winmm.dll'
17201c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
17211c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
17221c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc39600000 'C:\Windows\system32\shell32.dll'
17231c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
17241c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
17251c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36010000 'C:\Windows\system32\uxtheme.dll'
17261c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
17271c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\advapi32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
17281c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3b3d0000 'C:\Windows\system32\advapi32.dll'
17291c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
17301c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
17311c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'rpcrt4.dll'.
17321c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #28 'profapi.dll'.
17331c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\userenv.dll) WinVerifyTrust
17341c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\userenv.dll
17351c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'profapi.dll'...
17361c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'profapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\profapi.dll' [rcNtRedir=0xc0150008]
17371c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\profapi.dll
17381c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
17391c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
17401c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
17411c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\userenv.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
17421c3c.1868: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\userenv.dll
17431c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc37880000 LB 0x00028000 C:\Windows\system32\userenv.dll [fFlags=0x0]
17441c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\userenv.dll
17451c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc37880000 'C:\Windows\system32\userenv.dll'
17461c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll
17471c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\kernel32.dll (Input=kernel32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
17481c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc38ea0000 'C:\Windows\System32\kernel32.dll'
17491c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc3ab80000 LB 0x000a0000 C:\Windows\System32\clbcatq.dll [fFlags=0x0]
17501c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
17511c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #28 'rpcrt4.dll'.
17521c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\clbcatq.dll)
17531c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\clbcatq.dll
17541c3c.1fc8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
17551c3c.1fc8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
17561c3c.1fc8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
17571c3c.1fc8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
17581c3c.1fc8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
17591c3c.1fc8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
17601c3c.1fc8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\clbcatq.dll'
17611c3c.1fc8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
17621c3c.1fc8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
17631c3c.1fc8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
17641c3c.1fc8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
17651c3c.1fc8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
17661c3c.1fc8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ole32.dll'.
17671c3c.1fc8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'oleaut32.dll'.
17681c3c.1fc8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxC.dll) WinVerifyTrust
17691c3c.1fc8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxC.dll
17701c3c.1fc8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
17711c3c.1fc8: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
17721c3c.1fc8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
17731c3c.1fc8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
17741c3c.1fc8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
17751c3c.1fc8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
17761c3c.1fc8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
17771c3c.1fc8: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
17781c3c.1fc8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
17791c3c.1fc8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
17801c3c.1fc8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
17811c3c.1fc8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
17821c3c.1fc8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
17831c3c.1fc8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
17841c3c.1fc8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
17851c3c.1fc8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxC.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
17861c3c.1fc8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxC.dll
17871c3c.1fc8: supR3HardenedDllNotificationCallback: load 00007ffc0d5d0000 LB 0x00546000 C:\Program Files\Oracle\VirtualBox\VBoxC.dll [fFlags=0x0]
17881c3c.1fc8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxC.dll
17891c3c.1fc8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc0d5d0000 'C:\Program Files\Oracle\VirtualBox\VBoxC.dll'
17901c3c.1fc8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
17911c3c.1fc8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
17921c3c.1fc8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
17931c3c.1fc8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
17941c3c.1fc8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'shlwapi.dll'.
17951c3c.1fc8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ole32.dll'.
17961c3c.1fc8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'oleaut32.dll'.
17971c3c.1fc8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
17981c3c.1fc8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll) WinVerifyTrust
17991c3c.1fc8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll
18001c3c.1fc8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
18011c3c.1fc8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
18021c3c.1fc8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
18031c3c.1fc8: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
18041c3c.1fc8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
18051c3c.1fc8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
18061c3c.1fc8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
18071c3c.1fc8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
18081c3c.1fc8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
18091c3c.1fc8: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
18101c3c.1fc8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll [redoing WinVerifyTrust]
18111c3c.1fc8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
18121c3c.1fc8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
18131c3c.1fc8: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll'
18141c3c.1fc8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
18151c3c.1fc8: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
18161c3c.1fc8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
18171c3c.1fc8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
18181c3c.1fc8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
18191c3c.1fc8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
18201c3c.1fc8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
18211c3c.1fc8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll
18221c3c.1fc8: supR3HardenedDllNotificationCallback: load 00007ffc10da0000 LB 0x000ba000 C:\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll [fFlags=0x0]
18231c3c.1fc8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll
18241c3c.1fc8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc10da0000 'C:\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll'
18251c3c.1fc8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
18261c3c.1fc8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\oleaut32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
18271c3c.1fc8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc392f0000 'C:\Windows\System32\oleaut32.dll'
18281c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll
18291c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\gdi32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
18301c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ac20000 'C:\Windows\system32\gdi32.dll'
18311c3c.1cb0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
18321c3c.1cb0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
18331c3c.1cb0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
18341c3c.1cb0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
18351c3c.1cb0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
18361c3c.1cb0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMainVM.dll) WinVerifyTrust
18371c3c.1cb0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMainVM.dll
18381c3c.1cb0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
18391c3c.1cb0: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
18401c3c.1cb0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
18411c3c.1cb0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
18421c3c.1cb0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMainVM.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
18431c3c.1cb0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMainVM.dll
18441c3c.1cb0: supR3HardenedDllNotificationCallback: load 00007ffc2f530000 LB 0x0000e000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMainVM.DLL [fFlags=0x0]
18451c3c.1cb0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMainVM.dll
18461c3c.1cb0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc2f530000 'C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMainVM.DLL'
18471c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
18481c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
18491c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc39600000 'C:\Windows\system32\shell32.dll'
18501c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
18511c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
18521c3c.1868: '\Device\HarddiskVolume2\Windows\System32\ntdll.dll' has no imports
18531c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ntdll.dll) WinVerifyTrust
18541c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ntdll.dll
18551c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\ntdll.dll (Input=ntdll.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
18561c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3b640000 'C:\Windows\System32\ntdll.dll'
18571c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc393d0000 LB 0x00175000 C:\Windows\System32\MSCTF.dll [fFlags=0x0]
18581c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
18591c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'oleaut32.dll'.
18601c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #38 'user32.dll'.
18611c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #39 'gdi32.dll'.
18621c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #40 'imm32.dll'.
18631c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\msctf.dll)
18641c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msctf.dll
18651c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
18661c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume2\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
18671c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\imm32.dll
18681c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
18691c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
18701c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
18711c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
18721c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
18731c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
18741c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
18751c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
18761c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
18771c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
18781c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
18791c3c.1868: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\msctf.dll'
18801c3c.1868: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000a2c pwszName=\Device\HarddiskVolume2\Windows\System32\DataExchange.dll
18811c3c.1868: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000fe7760
18821c3c.1868: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000fe7760
18831c3c.1868: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=07B480615AD13C4A3DD6B7A2F86ED35195B9CA49
18841c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
18851c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
18861c3c.1868: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0010~31bf3856ad364e35~amd64~~10.0.17134.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\DataExchange.dll'
18871c3c.1868: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
18881c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
18891c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'shcore.dll'.
18901c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #29 'combase.dll'.
18911c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #34 'd3d11.dll'.
18921c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #35 'dcomp.dll'.
18931c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\DataExchange.dll) WinVerifyTrust
18941c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\DataExchange.dll
18951c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dcomp.dll'...
18961c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'dcomp.dll' -> '\Device\HarddiskVolume2\Windows\System32\dcomp.dll' [rcNtRedir=0xc0150008]
18971c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
18981c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
18991c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'win32u.dll'.
19001c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp_win.dll'.
19011c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #36 'oleaut32.dll'.
19021c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #37 'dxgi.dll'.
19031c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\dcomp.dll) WinVerifyTrust
19041c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\dcomp.dll
19051c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'd3d11.dll'...
19061c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'd3d11.dll' -> '\Device\HarddiskVolume2\Windows\System32\d3d11.dll' [rcNtRedir=0xc0150008]
19071c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll
19081c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dxgi.dll'...
19091c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'dxgi.dll' -> '\Device\HarddiskVolume2\Windows\System32\dxgi.dll' [rcNtRedir=0xc0150008]
19101c3c.1868: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\dxgi.dll'.
19111c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
19121c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'win32u.dll'.
19131c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\dxgi.dll)
19141c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\dxgi.dll
19151c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
19161c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
19171c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
19181c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
19191c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
19201c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcp_win.dll [lacks WinVerifyTrust]
19211c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
19221c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume2\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
19231c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\win32u.dll [lacks WinVerifyTrust]
19241c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
19251c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume2\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
19261c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\win32u.dll [lacks WinVerifyTrust]
19271c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
19281c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
19291c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
19301c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
19311c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
19321c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
19331c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'dxgi.dll'.
19341c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #35 'win32u.dll'.
19351c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\d3d11.dll) WinVerifyTrust
19361c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\d3d11.dll
19371c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
19381c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume2\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
19391c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\combase.dll [redoing WinVerifyTrust]
19401c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
19411c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume2\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
19421c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\win32u.dll [lacks WinVerifyTrust]
19431c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dxgi.dll'...
19441c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'dxgi.dll' -> '\Device\HarddiskVolume2\Windows\System32\dxgi.dll' [rcNtRedir=0xc0150008]
19451c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dxgi.dll [lacks WinVerifyTrust]
19461c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
19471c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
19481c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
19491c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
19501c3c.1868: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\combase.dll'
19511c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shcore.dll'...
19521c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'shcore.dll' -> '\Device\HarddiskVolume2\Windows\System32\shcore.dll' [rcNtRedir=0xc0150008]
19531c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\SHCore.dll
19541c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
19551c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
19561c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\dataexchange.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
19571c3c.1868: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\DataExchange.dll
19581c3c.1868: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\d3d11.dll
19591c3c.1868: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dcomp.dll
19601c3c.1868: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dxgi.dll [avoiding WinVerifyTrust]
19611c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc36710000 LB 0x000bb000 C:\Windows\system32\dxgi.dll [fFlags=0x0]
19621c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dxgi.dll [avoiding WinVerifyTrust]
19631c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc344f0000 LB 0x0030b000 C:\Windows\system32\d3d11.dll [fFlags=0x0]
19641c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\d3d11.dll
19651c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc356c0000 LB 0x0019c000 C:\Windows\system32\dcomp.dll [fFlags=0x0]
19661c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dcomp.dll
19671c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc18640000 LB 0x00058000 C:\Windows\system32\dataexchange.dll [fFlags=0x0]
19681c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\DataExchange.dll
19691c3c.1868: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\dxgi.dll'.
19701c3c.1868: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\dxgi.dll' [rescheduled]
19711c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ac20000 'C:\Windows\System32\gdi32.dll'
19721c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc18640000 'C:\Windows\system32\dataexchange.dll'
19731c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
19741c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'rmclient.dll'.
19751c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #30 'rpcrt4.dll'.
19761c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #44 'combase.dll'.
19771c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\twinapi.appcore.dll)
19781c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\twinapi.appcore.dll
19791c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
19801c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'rpcrt4.dll'.
19811c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\rmclient.dll)
19821c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\rmclient.dll
19831c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc361c0000 LB 0x00021000 C:\Windows\system32\RMCLIENT.dll [fFlags=0x0]
19841c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rmclient.dll [avoiding WinVerifyTrust]
19851c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc36270000 LB 0x001b8000 C:\Windows\system32\twinapi.appcore.dll [fFlags=0x0]
19861c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\twinapi.appcore.dll [avoiding WinVerifyTrust]
19871c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
19881c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #15 'coreuicomponents.dll'.
19891c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'coremessaging.dll'.
19901c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\TextInputFramework.dll)
19911c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\TextInputFramework.dll
19921c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
19931c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #35 'coremessaging.dll'.
19941c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #48 'shcore.dll'.
19951c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\CoreUIComponents.dll)
19961c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\CoreUIComponents.dll
19971c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
19981c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #24 'rpcrt4.dll'.
19991c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\CoreMessaging.dll)
20001c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\CoreMessaging.dll
20011c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ntmarta.dll)
20021c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ntmarta.dll
20031c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'combase.dll'.
20041c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #22 'rpcrt4.dll'.
20051c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #29 'bcryptprimitives.dll'.
20061c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\WinTypes.dll)
20071c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\WinTypes.dll
20081c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc36a40000 LB 0x00031000 C:\Windows\SYSTEM32\ntmarta.dll [fFlags=0x0]
20091c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ntmarta.dll [avoiding WinVerifyTrust]
20101c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc35860000 LB 0x000da000 C:\Windows\System32\CoreMessaging.dll [fFlags=0x0]
20111c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\CoreMessaging.dll [avoiding WinVerifyTrust]
20121c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc33b00000 LB 0x0014d000 C:\Windows\SYSTEM32\wintypes.dll [fFlags=0x0]
20131c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\WinTypes.dll [avoiding WinVerifyTrust]
20141c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc32be0000 LB 0x0031e000 C:\Windows\System32\CoreUIComponents.dll [fFlags=0x0]
20151c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\CoreUIComponents.dll [avoiding WinVerifyTrust]
20161c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc2f700000 LB 0x00098000 C:\Windows\System32\TextInputFramework.dll [fFlags=0x0]
20171c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\TextInputFramework.dll [avoiding WinVerifyTrust]
20181c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcryptprimitives.dll'...
20191c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcryptprimitives.dll' -> '\Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll' [rcNtRedir=0xc0150008]
20201c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll
20211c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
20221c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
20231c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
20241c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume2\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
20251c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\combase.dll
20261c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
20271c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
20281c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
20291c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
20301c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shcore.dll'...
20311c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'shcore.dll' -> '\Device\HarddiskVolume2\Windows\System32\shcore.dll' [rcNtRedir=0xc0150008]
20321c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\SHCore.dll
20331c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'coremessaging.dll'...
20341c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'coremessaging.dll' -> '\Device\HarddiskVolume2\Windows\System32\coremessaging.dll' [rcNtRedir=0xc0150008]
20351c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\CoreMessaging.dll [lacks WinVerifyTrust]
20361c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
20371c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
20381c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'coremessaging.dll'...
20391c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'coremessaging.dll' -> '\Device\HarddiskVolume2\Windows\System32\coremessaging.dll' [rcNtRedir=0xc0150008]
20401c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\CoreMessaging.dll [lacks WinVerifyTrust]
20411c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'coreuicomponents.dll'...
20421c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'coreuicomponents.dll' -> '\Device\HarddiskVolume2\Windows\System32\coreuicomponents.dll' [rcNtRedir=0xc0150008]
20431c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\CoreUIComponents.dll [lacks WinVerifyTrust]
20441c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
20451c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
20461c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
20471c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
20481c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
20491c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
20501c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
20511c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume2\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
20521c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\combase.dll
20531c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
20541c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
20551c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rmclient.dll'...
20561c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'rmclient.dll' -> '\Device\HarddiskVolume2\Windows\System32\rmclient.dll' [rcNtRedir=0xc0150008]
20571c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rmclient.dll [lacks WinVerifyTrust]
20581c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
20591c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
20601c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
20611c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
20621c3c.1868: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\WinTypes.dll'
20631c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
20641c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
20651c3c.1868: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\ntmarta.dll'
20661c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
20671c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
20681c3c.1868: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\CoreMessaging.dll'
20691c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
20701c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
20711c3c.1868: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\CoreUIComponents.dll'
20721c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
20731c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
20741c3c.1868: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\TextInputFramework.dll'
20751c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
20761c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
20771c3c.1868: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\rmclient.dll'
20781c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
20791c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
20801c3c.1868: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\twinapi.appcore.dll'
20811c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc392f0000 'C:\Windows\System32\OLEAUT32.DLL'
20821c3c.1868: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(ext-ms-win-rtcore-ntuser-window-ext-l1-1-0.dll) -> 0x0, fPresent=1
20831c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=ext-ms-win-rtcore-ntuser-window-ext-l1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
20841c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3b240000 'ext-ms-win-rtcore-ntuser-window-ext-l1-1-0.dll'
20851c3c.1868: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(ext-ms-win-rtcore-ntuser-integration-l1-1-0.dll) -> 0x0, fPresent=1
20861c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=ext-ms-win-rtcore-ntuser-integration-l1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
20871c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3b240000 'ext-ms-win-rtcore-ntuser-integration-l1-1-0.dll'
20881c3c.1868: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-com-l1-1-0.dll) -> 0x0, fPresent=1
20891c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-com-l1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
20901c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc38f60000 'api-ms-win-core-com-l1-1-0.dll'
20911c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msctf.dll
20921c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\MSCTF.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
20931c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc393d0000 'C:\Windows\System32\MSCTF.dll'
20941c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc39600000 'C:\Windows\system32\shell32.dll'
20951c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc39600000 'C:\Windows\system32\shell32.dll'
20961c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
20971c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\ole32.dll (Input=ole32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
20981c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc38ad0000 'C:\Windows\System32\ole32.dll'
20991c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc392f0000 'C:\Windows\System32\OLEAUT32.dll'
21001c3c.1868: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000b30 pwszName=\Device\HarddiskVolume2\Windows\System32\wbem\wbemprox.dll
21011c3c.1868: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000fe7760
21021c3c.1868: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000fe7760
21031c3c.1868: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=D49375F38056AA009353FFDCCD59474093558A8B
21041c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
21051c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
21061c3c.1868: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package02~31bf3856ad364e35~amd64~~10.0.17134.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\wbem\wbemprox.dll'
21071c3c.1868: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
21081c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
21091c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ws2_32.dll'.
21101c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'wbemcomn.dll'.
21111c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\wbem\wbemprox.dll) WinVerifyTrust
21121c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wbem\wbemprox.dll
21131c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wbemcomn.dll'...
21141c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'wbemcomn.dll' -> '\Device\HarddiskVolume2\Windows\System32\wbemcomn.dll' [rcNtRedir=0xc0150008]
21151c3c.1868: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000ad4 pwszName=\Device\HarddiskVolume2\Windows\System32\wbemcomn.dll
21161c3c.1868: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000fe7760
21171c3c.1868: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000fe7760
21181c3c.1868: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=85E1C37A6BD4306E57F09FFDB448860467295EFB
21191c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
21201c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
21211c3c.1868: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package02~31bf3856ad364e35~amd64~~10.0.17134.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\wbemcomn.dll'
21221c3c.1868: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
21231c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
21241c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'bcrypt.dll'.
21251c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'ws2_32.dll'.
21261c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\wbemcomn.dll) WinVerifyTrust
21271c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wbemcomn.dll
21281c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
21291c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
21301c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
21311c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
21321c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
21331c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
21341c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
21351c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
21361c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
21371c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume2\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
21381c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll
21391c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
21401c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
21411c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wbem\wbemprox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
21421c3c.1868: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbem\wbemprox.dll
21431c3c.1868: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbemcomn.dll
21441c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc2ce00000 LB 0x00083000 C:\Windows\SYSTEM32\wbemcomn.dll [fFlags=0x0]
21451c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbemcomn.dll
21461c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc24be0000 LB 0x00011000 C:\Windows\system32\wbem\wbemprox.dll [fFlags=0x0]
21471c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbem\wbemprox.dll
21481c3c.1868: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(API-MS-Win-Core-LocalRegistry-L1-1-0.dll) -> 0x0, fPresent=1
21491c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Core-LocalRegistry-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
21501c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc385c0000 'API-MS-Win-Core-LocalRegistry-L1-1-0.dll'
21511c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc24be0000 'C:\Windows\system32\wbem\wbemprox.dll'
21521c3c.1868: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000b88 pwszName=\Device\HarddiskVolume2\Windows\System32\wbem\wbemsvc.dll
21531c3c.1868: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000fe7760
21541c3c.1868: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000fe7760
21551c3c.1868: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=38422F12A30C69B303E7EBE427C8D87E3024ED12
21561c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
21571c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
21581c3c.1868: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package02~31bf3856ad364e35~amd64~~10.0.17134.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\wbem\wbemsvc.dll'
21591c3c.1868: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
21601c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
21611c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'rpcrt4.dll'.
21621c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\wbem\wbemsvc.dll) WinVerifyTrust
21631c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wbem\wbemsvc.dll
21641c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
21651c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
21661c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
21671c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
21681c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wbem\wbemsvc.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
21691c3c.1868: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbem\wbemsvc.dll
21701c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc261a0000 LB 0x00014000 C:\Windows\system32\wbem\wbemsvc.dll [fFlags=0x0]
21711c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbem\wbemsvc.dll
21721c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc261a0000 'C:\Windows\system32\wbem\wbemsvc.dll'
21731c3c.1868: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-l1-2-0.dll) -> 0x0, fPresent=1
21741c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-l1-2-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
21751c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc385c0000 'api-ms-win-core-localization-l1-2-0.dll'
21761c3c.1868: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-obsolete-l1-1-0.dll) -> 0x0, fPresent=1
21771c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-obsolete-l1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
21781c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc385c0000 'api-ms-win-core-localization-obsolete-l1-1-0.dll'
21791c3c.1868: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000b60 pwszName=\Device\HarddiskVolume2\Windows\System32\wbem\fastprox.dll
21801c3c.1868: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000fe7760
21811c3c.1868: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000fe7760
21821c3c.1868: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=07493B638EF356F68BE9306C76CDBF2D22198E5A
21831c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
21841c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
21851c3c.1868: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package02~31bf3856ad364e35~amd64~~10.0.17134.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\wbem\fastprox.dll'
21861c3c.1868: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
21871c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
21881c3c.1868: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #19 'wbemcomn.dll'.
21891c3c.1868: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\wbem\fastprox.dll) WinVerifyTrust
21901c3c.1868: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wbem\fastprox.dll
21911c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wbemcomn.dll'...
21921c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'wbemcomn.dll' -> '\Device\HarddiskVolume2\Windows\System32\wbemcomn.dll' [rcNtRedir=0xc0150008]
21931c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbemcomn.dll
21941c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
21951c3c.1868: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
21961c3c.1868: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
21971c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wbem\fastprox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
21981c3c.1868: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbem\fastprox.dll
21991c3c.1868: supR3HardenedDllNotificationCallback: load 00007ffc24a40000 LB 0x000f2000 C:\Windows\system32\wbem\fastprox.dll [fFlags=0x0]
22001c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbem\fastprox.dll
22011c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc24a40000 'C:\Windows\system32\wbem\fastprox.dll'
22021c3c.1cbc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
22031c3c.1cbc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
22041c3c.1cbc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrem.dll'.
22051c3c.1cbc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
22061c3c.1cbc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll) WinVerifyTrust
22071c3c.1cbc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
22081c3c.1cbc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
22091c3c.1cbc: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
22101c3c.1cbc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrem.dll'...
22111c3c.1cbc: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrem.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrem.dll' [rcNtRedir=0xc0150008]
22121c3c.1cbc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
22131c3c.1cbc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'vboxrt.dll'.
22141c3c.1cbc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
22151c3c.1cbc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcrt.dll'.
22161c3c.1cbc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxREM.dll) WinVerifyTrust
22171c3c.1cbc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxREM.dll
22181c3c.1cbc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
22191c3c.1cbc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
22201c3c.1cbc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
22211c3c.1cbc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
22221c3c.1cbc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
22231c3c.1cbc: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
22241c3c.1cbc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
22251c3c.1cbc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
22261c3c.1cbc: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
22271c3c.1cbc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
22281c3c.1cbc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
22291c3c.1cbc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxREM.dll
22301c3c.1cbc: supR3HardenedDllNotificationCallback: load 00000000540b0000 LB 0x0010b000 C:\Program Files\Oracle\VirtualBox\VBoxREM.dll [fFlags=0x0]
22311c3c.1cbc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxREM.dll
22321c3c.1cbc: supR3HardenedDllNotificationCallback: load 00007ffc08a00000 LB 0x002c9000 C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL [fFlags=0x0]
22331c3c.1cbc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
22341c3c.1cbc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc08a00000 'C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL'
22351c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
22361c3c.1f38: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000c78 pwszName=\Device\HarddiskVolume2\Windows\System32\NetSetupShim.dll
22371c3c.1f38: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000fe7760
22381c3c.1f38: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000fe7760
22391c3c.1f38: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=7A411B6D0C02AF0C9C29BAAEFDFE6EF0D86C921F
22401c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
22411c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
22421c3c.1f38: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package00112~31bf3856ad364e35~amd64~~10.0.17134.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\NetSetupShim.dll'
22431c3c.1f38: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
22441c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
22451c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #31 'rpcrt4.dll'.
22461c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #32 'oleaut32.dll'.
22471c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #34 'ws2_32.dll'.
22481c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #35 'netsetupapi.dll'.
22491c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #36 'setupapi.dll'.
22501c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #37 'devrtl.dll'.
22511c3c.1f38: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\NetSetupShim.dll) WinVerifyTrust
22521c3c.1f38: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\NetSetupShim.dll
22531c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'devrtl.dll'...
22541c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'devrtl.dll' -> '\Device\HarddiskVolume2\Windows\System32\devrtl.dll' [rcNtRedir=0xc0150008]
22551c3c.1f38: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000c0c pwszName=\Device\HarddiskVolume2\Windows\System32\devrtl.dll
22561c3c.1f38: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000fe7760
22571c3c.1f38: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000fe7760
22581c3c.1f38: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=D7E327D4544F33888FC8ADAE2BEEB7A40A76E7F8
22591c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
22601c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
22611c3c.1f38: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0015~31bf3856ad364e35~amd64~~10.0.17134.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\devrtl.dll'
22621c3c.1f38: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
22631c3c.1f38: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\devrtl.dll) WinVerifyTrust
22641c3c.1f38: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\devrtl.dll
22651c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
22661c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
22671c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
22681c3c.1f38: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll
22691c3c.1f38: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
22701c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
22711c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
22721c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #29 'rpcrt4.dll'.
22731c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #37 'cfgmgr32.dll'.
22741c3c.1f38: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\setupapi.dll) WinVerifyTrust
22751c3c.1f38: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\setupapi.dll
22761c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'netsetupapi.dll'...
22771c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'netsetupapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\netsetupapi.dll' [rcNtRedir=0xc0150008]
22781c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
22791c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
22801c3c.1f38: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll [lacks WinVerifyTrust]
22811c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
22821c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
22831c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
22841c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
22851c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
22861c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
22871c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
22881c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'rpcrt4.dll'.
22891c3c.1f38: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\NetSetupApi.dll) WinVerifyTrust
22901c3c.1f38: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\NetSetupApi.dll
22911c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
22921c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
22931c3c.1f38: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
22941c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
22951c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
22961c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
22971c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
22981c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
22991c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
23001c3c.1f38: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcp_win.dll [redoing WinVerifyTrust]
23011c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
23021c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
23031c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
23041c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
23051c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
23061c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
23071c3c.1f38: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\msvcp_win.dll'
23081c3c.1f38: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\NetSetupShim.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
23091c3c.1f38: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\NetSetupShim.dll
23101c3c.1f38: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\NetSetupApi.dll
23111c3c.1f38: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\devrtl.dll
23121c3c.1f38: supR3HardenedDllNotificationCallback: load 00007ffc2b9c0000 LB 0x00026000 C:\Windows\System32\NetSetupApi.dll [fFlags=0x0]
23131c3c.1f38: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\NetSetupApi.dll
23141c3c.1f38: supR3HardenedDllNotificationCallback: load 00007ffc3adf0000 LB 0x0044b000 C:\Windows\System32\setupapi.dll [fFlags=0x0]
23151c3c.1f38: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\setupapi.dll
23161c3c.1f38: supR3HardenedDllNotificationCallback: load 00007ffc25e50000 LB 0x00013000 C:\Windows\System32\DEVRTL.dll [fFlags=0x0]
23171c3c.1f38: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\devrtl.dll
23181c3c.1f38: supR3HardenedDllNotificationCallback: load 00007ffc25ba0000 LB 0x00081000 C:\Windows\System32\NetSetupShim.dll [fFlags=0x0]
23191c3c.1f38: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\NetSetupShim.dll
23201c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc25ba0000 'C:\Windows\System32\NetSetupShim.dll'
23211c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
23221c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
23231c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
23241c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'rpcrt4.dll'.
23251c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #24 'nsi.dll'.
23261c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'winnsi.dll'.
23271c3c.1f38: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\NetSetupEngine.dll) WinVerifyTrust
23281c3c.1f38: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\NetSetupEngine.dll
23291c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winnsi.dll'...
23301c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'winnsi.dll' -> '\Device\HarddiskVolume2\Windows\System32\winnsi.dll' [rcNtRedir=0xc0150008]
23311c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
23321c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
23331c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rpcrt4.dll'.
23341c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'nsi.dll'.
23351c3c.1f38: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\winnsi.dll) WinVerifyTrust
23361c3c.1f38: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\winnsi.dll
23371c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
23381c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume2\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
23391c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
23401c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume2\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
23411c3c.1f38: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\nsi.dll'.
23421c3c.1f38: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\nsi.dll)
23431c3c.1f38: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\nsi.dll
23441c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
23451c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
23461c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
23471c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
23481c3c.1f38: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\nsi.dll) WinVerifyTrust
23491c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
23501c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
23511c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
23521c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
23531c3c.1f38: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\NetSetupEngine.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
23541c3c.1f38: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\NetSetupEngine.dll
23551c3c.1f38: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winnsi.dll
23561c3c.1f38: supR3HardenedDllNotificationCallback: load 00007ffc38c30000 LB 0x00008000 C:\Windows\System32\NSI.dll [fFlags=0x0]
23571c3c.1f38: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\nsi.dll [avoiding WinVerifyTrust]
23581c3c.1f38: supR3HardenedDllNotificationCallback: load 00007ffc318b0000 LB 0x0000b000 C:\Windows\SYSTEM32\WINNSI.DLL [fFlags=0x0]
23591c3c.1f38: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winnsi.dll
23601c3c.1f38: supR3HardenedDllNotificationCallback: load 00007ffc0f440000 LB 0x000c6000 C:\Windows\System32\NetSetupEngine.dll [fFlags=0x0]
23611c3c.1f38: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\NetSetupEngine.dll
23621c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc0f440000 'C:\Windows\System32\NetSetupEngine.dll'
23631c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
23641c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
23651c3c.1f38: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\nsi.dll'
23661c3c.c88: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
23671c3c.c88: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
23681c3c.c88: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
23691c3c.c88: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
23701c3c.c88: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
23711c3c.c88: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll) WinVerifyTrust
23721c3c.c88: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll
23731c3c.c88: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
23741c3c.c88: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
23751c3c.c88: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
23761c3c.c88: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
23771c3c.c88: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
23781c3c.c88: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
23791c3c.c88: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
23801c3c.c88: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
23811c3c.c88: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
23821c3c.c88: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
23831c3c.c88: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll
23841c3c.c88: supR3HardenedDllNotificationCallback: load 00007ffc25980000 LB 0x0000b000 C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL [fFlags=0x0]
23851c3c.c88: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll
23861c3c.c88: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc25980000 'C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL'
23871c3c.c88: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3b240000 'C:\Windows\system32\User32.dll'
23881c3c.1688: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
23891c3c.1688: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
23901c3c.1688: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
23911c3c.1688: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
23921c3c.1688: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll) WinVerifyTrust
23931c3c.1688: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll
23941c3c.1688: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
23951c3c.1688: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
23961c3c.1688: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
23971c3c.1688: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
23981c3c.1688: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
23991c3c.1688: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
24001c3c.1688: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
24011c3c.1688: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
24021c3c.1688: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll
24031c3c.1688: supR3HardenedDllNotificationCallback: load 00007ffc25970000 LB 0x0000d000 C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL [fFlags=0x0]
24041c3c.1688: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll
24051c3c.1688: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc25970000 'C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL'
24061c3c.fb0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
24071c3c.fb0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
24081c3c.fb0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxoglhostcrutil.dll'.
24091c3c.fb0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
24101c3c.fb0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vboxvmm.dll'.
24111c3c.fb0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'vboxoglrenderspu.dll'.
24121c3c.fb0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'advapi32.dll'.
24131c3c.fb0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'ole32.dll'.
24141c3c.fb0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'oleaut32.dll'.
24151c3c.fb0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedCrOpenGL.dll) WinVerifyTrust
24161c3c.fb0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedCrOpenGL.dll
24171c3c.fb0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
24181c3c.fb0: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
24191c3c.fb0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
24201c3c.fb0: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
24211c3c.fb0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
24221c3c.fb0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
24231c3c.fb0: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
24241c3c.fb0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxoglrenderspu.dll'...
24251c3c.fb0: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxoglrenderspu.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxoglrenderspu.dll' [rcNtRedir=0xc0150008]
24261c3c.fb0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
24271c3c.fb0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
24281c3c.fb0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxoglhostcrutil.dll'.
24291c3c.fb0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
24301c3c.fb0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
24311c3c.fb0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
24321c3c.fb0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'advapi32.dll'.
24331c3c.fb0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLrenderspu.dll) WinVerifyTrust
24341c3c.fb0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLrenderspu.dll
24351c3c.fb0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
24361c3c.fb0: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
24371c3c.fb0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
24381c3c.fb0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
24391c3c.fb0: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
24401c3c.fb0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxoglhostcrutil.dll'...
24411c3c.fb0: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxoglhostcrutil.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxoglhostcrutil.dll' [rcNtRedir=0xc0150008]
24421c3c.fb0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
24431c3c.fb0: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
24441c3c.fb0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
24451c3c.fb0: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
24461c3c.fb0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
24471c3c.fb0: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
24481c3c.fb0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
24491c3c.fb0: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
24501c3c.fb0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxoglhostcrutil.dll'...
24511c3c.fb0: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxoglhostcrutil.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxoglhostcrutil.dll' [rcNtRedir=0xc0150008]
24521c3c.fb0: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLhostcrutil.dll'.
24531c3c.fb0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
24541c3c.fb0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
24551c3c.fb0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'shlwapi.dll'.
24561c3c.fb0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ws2_32.dll'.
24571c3c.fb0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLhostcrutil.dll)
24581c3c.fb0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLhostcrutil.dll
24591c3c.fb0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
24601c3c.fb0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
24611c3c.fb0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
24621c3c.fb0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
24631c3c.fb0: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
24641c3c.fb0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
24651c3c.fb0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
24661c3c.fb0: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
24671c3c.fb0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll
24681c3c.fb0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
24691c3c.fb0: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
24701c3c.fb0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
24711c3c.fb0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
24721c3c.fb0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
24731c3c.fb0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
24741c3c.fb0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
24751c3c.fb0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'shlwapi.dll'.
24761c3c.fb0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ws2_32.dll'.
24771c3c.fb0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLhostcrutil.dll) WinVerifyTrust
24781c3c.fb0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
24791c3c.fb0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
24801c3c.fb0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
24811c3c.fb0: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
24821c3c.fb0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
24831c3c.fb0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
24841c3c.fb0: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
24851c3c.fb0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll
24861c3c.fb0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
24871c3c.fb0: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
24881c3c.fb0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
24891c3c.fb0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
24901c3c.fb0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSharedCrOpenGL.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
24911c3c.fb0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedCrOpenGL.dll
24921c3c.fb0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLhostcrutil.dll [avoiding WinVerifyTrust]
24931c3c.fb0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLrenderspu.dll
24941c3c.fb0: supR3HardenedDllNotificationCallback: load 00007ffc11c30000 LB 0x0002f000 C:\Program Files\Oracle\VirtualBox\VBoxOGLhostcrutil.dll [fFlags=0x0]
24951c3c.fb0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLhostcrutil.dll [avoiding WinVerifyTrust]
24961c3c.fb0: supR3HardenedDllNotificationCallback: load 00007ffc11c00000 LB 0x00026000 C:\Program Files\Oracle\VirtualBox\VBoxOGLrenderspu.dll [fFlags=0x0]
24971c3c.fb0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLrenderspu.dll
24981c3c.fb0: supR3HardenedDllNotificationCallback: load 00007ffc0c2d0000 LB 0x00110000 C:\Program Files\Oracle\VirtualBox\VBoxSharedCrOpenGL.DLL [fFlags=0x0]
24991c3c.fb0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedCrOpenGL.dll
25001c3c.fb0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc0c2d0000 'C:\Program Files\Oracle\VirtualBox\VBoxSharedCrOpenGL.DLL'
25011c3c.fb0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
25021c3c.fb0: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLhostcrutil.dll'
25031c3c.fb0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLrenderspu.dll
25041c3c.fb0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxOGLrenderspu.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
25051c3c.fb0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11c00000 'C:\Program Files\Oracle\VirtualBox\VBoxOGLrenderspu.dll'
25061c3c.fb0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
25071c3c.fb0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
25081c3c.fb0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxoglhostcrutil.dll'.
25091c3c.fb0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLhosterrorspu.dll) WinVerifyTrust
25101c3c.fb0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLhosterrorspu.dll
25111c3c.fb0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxoglhostcrutil.dll'...
25121c3c.fb0: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxoglhostcrutil.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxoglhostcrutil.dll' [rcNtRedir=0xc0150008]
25131c3c.fb0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLhostcrutil.dll
25141c3c.fb0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
25151c3c.fb0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
25161c3c.fb0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxOGLhosterrorspu.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
25171c3c.fb0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLhosterrorspu.dll
25181c3c.fb0: supR3HardenedDllNotificationCallback: load 00007ffc258f0000 LB 0x0001a000 C:\Program Files\Oracle\VirtualBox\VBoxOGLhosterrorspu.dll [fFlags=0x0]
25191c3c.fb0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxOGLhosterrorspu.dll
25201c3c.fb0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc258f0000 'C:\Program Files\Oracle\VirtualBox\VBoxOGLhosterrorspu.dll'
25211c3c.fb0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
25221c3c.fb0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32/opengl32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
25231c3c.fb0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc10f90000 'C:\Windows\system32/opengl32.dll'
25241c3c.fb0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
25251c3c.fb0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\OPENGL32.dll (Input=OPENGL32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
25261c3c.fb0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc10f90000 'C:\Windows\System32\OPENGL32.dll'
25271c3c.fb0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc3ac20000 'C:\Windows\System32\gdi32.dll'
25281c3c.fb0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
25291c3c.fb0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\OPENGL32.dll (Input=OPENGL32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
25301c3c.fb0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc10f90000 'C:\Windows\System32\OPENGL32.dll'
25311c3c.fb0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
25321c3c.fb0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\OPENGL32.dll (Input=OPENGL32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
25331c3c.fb0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc10f90000 'C:\Windows\System32\OPENGL32.dll'
25341c3c.fb0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc10f90000 'C:\Windows\System32\OPENGL32.dll'
25351c3c.fb0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc10f90000 'C:\Windows\System32\OPENGL32.dll'
25361c3c.fb0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc10f90000 'C:\Windows\System32\OPENGL32.dll'
25371c3c.fb0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc10f90000 'C:\Windows\System32\OPENGL32.dll'
25381c3c.1d04: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
25391c3c.1d04: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
25401c3c.1d04: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
25411c3c.1d04: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
25421c3c.1d04: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll) WinVerifyTrust
25431c3c.1d04: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll
25441c3c.1d04: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
25451c3c.1d04: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
25461c3c.1d04: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
25471c3c.1d04: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
25481c3c.1d04: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
25491c3c.1d04: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
25501c3c.1d04: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
25511c3c.1d04: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll
25521c3c.1d04: supR3HardenedDllNotificationCallback: load 00007ffc25960000 LB 0x0000c000 C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL [fFlags=0x0]
25531c3c.1d04: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll
25541c3c.1d04: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc25960000 'C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL'
25551c3c.7ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
25561c3c.7ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
25571c3c.7ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
25581c3c.7ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
25591c3c.7ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll) WinVerifyTrust
25601c3c.7ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll
25611c3c.7ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
25621c3c.7ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
25631c3c.7ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
25641c3c.7ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
25651c3c.7ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
25661c3c.7ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
25671c3c.7ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
25681c3c.7ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll
25691c3c.7ac: supR3HardenedDllNotificationCallback: load 00007ffc258c0000 LB 0x0000b000 C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL [fFlags=0x0]
25701c3c.7ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll
25711c3c.7ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc258c0000 'C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL'
25721c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc39600000 'C:\Windows\system32\Shell32.dll'
25731c3c.1f38: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
25741c3c.1f38: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
25751c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc08a00000 'C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL'
25761c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
25771c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
25781c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
25791c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
25801c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ole32.dll'.
25811c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'oleaut32.dll'.
25821c3c.1f38: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll) WinVerifyTrust
25831c3c.1f38: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
25841c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
25851c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
25861c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
25871c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
25881c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
25891c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
25901c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
25911c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
25921c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
25931c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
25941c3c.1f38: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
25951c3c.1f38: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
25961c3c.1f38: supR3HardenedDllNotificationCallback: load 00007ffc10680000 LB 0x00041000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL [fFlags=0x0]
25971c3c.1f38: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
25981c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc10680000 'C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL'
25991c3c.1f38: supR3HardenedDllNotificationCallback: Unload 00007ffc10680000 LB 0x00041000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL [flags=0x0]
26001c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
26011c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
26021c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
26031c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
26041c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
26051c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
26061c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vboxddu.dll'.
26071c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'vboxdd2.dll'.
26081c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
26091c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'setupapi.dll'.
26101c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'ws2_32.dll'.
26111c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'ole32.dll'.
26121c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'iphlpapi.dll'.
26131c3c.1f38: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD.dll) WinVerifyTrust
26141c3c.1f38: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD.dll
26151c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'iphlpapi.dll'...
26161c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'iphlpapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\iphlpapi.dll' [rcNtRedir=0xc0150008]
26171c3c.1f38: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL [redoing WinVerifyTrust]
26181c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
26191c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
26201c3c.1f38: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL'
26211c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
26221c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
26231c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
26241c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
26251c3c.1f38: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
26261c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
26271c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
26281c3c.1f38: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\setupapi.dll
26291c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
26301c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
26311c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxdd2.dll'...
26321c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxdd2.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxdd2.dll' [rcNtRedir=0xc0150008]
26331c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
26341c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
26351c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
26361c3c.1f38: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD2.dll) WinVerifyTrust
26371c3c.1f38: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD2.dll
26381c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxddu.dll'...
26391c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxddu.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxddu.dll' [rcNtRedir=0xc0150008]
26401c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
26411c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
26421c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
26431c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
26441c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
26451c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
26461c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
26471c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
26481c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'setupapi.dll'.
26491c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'advapi32.dll'.
26501c3c.1f38: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDDU.dll) WinVerifyTrust
26511c3c.1f38: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDDU.dll
26521c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
26531c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
26541c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
26551c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
26561c3c.1f38: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
26571c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
26581c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
26591c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
26601c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
26611c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
26621c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
26631c3c.1f38: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\setupapi.dll
26641c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
26651c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
26661c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
26671c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
26681c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
26691c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
26701c3c.1f38: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxDD.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
26711c3c.1f38: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD.dll
26721c3c.1f38: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDDU.dll
26731c3c.1f38: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD2.dll
26741c3c.1f38: supR3HardenedDllNotificationCallback: load 00007ffc16b30000 LB 0x00063000 C:\Program Files\Oracle\VirtualBox\VBoxDDU.dll [fFlags=0x0]
26751c3c.1f38: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDDU.dll
26761c3c.1f38: supR3HardenedDllNotificationCallback: load 00007ffc0f8c0000 LB 0x0005d000 C:\Program Files\Oracle\VirtualBox\VBoxDD2.dll [fFlags=0x0]
26771c3c.1f38: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD2.dll
26781c3c.1f38: supR3HardenedDllNotificationCallback: load 00007ffbee2d0000 LB 0x009c5000 C:\Program Files\Oracle\VirtualBox\VBoxDD.DLL [fFlags=0x0]
26791c3c.1f38: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD.dll
26801c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbee2d0000 'C:\Program Files\Oracle\VirtualBox\VBoxDD.DLL'
26811c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
26821c3c.1f38: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
26831c3c.1f38: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
26841c3c.1f38: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
26851c3c.1f38: supR3HardenedDllNotificationCallback: load 00007ffc10680000 LB 0x00041000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL [fFlags=0x0]
26861c3c.1f38: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
26871c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc10680000 'C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL'
26881c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
26891c3c.1f38: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxC.dll
26901c3c.1f38: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxC.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
26911c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc0d5d0000 'C:\Program Files\Oracle\VirtualBox\VBoxC.DLL'
26921c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
26931c3c.1f38: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD2.dll
26941c3c.1f38: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxDD2.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
26951c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc0f8c0000 'C:\Program Files\Oracle\VirtualBox\VBoxDD2.DLL'
26961c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
26971c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
26981c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
26991c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
27001c3c.1f38: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.dll) WinVerifyTrust
27011c3c.1f38: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.dll
27021c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
27031c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
27041c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
27051c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
27061c3c.1f38: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
27071c3c.1f38: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.dll
27081c3c.1f38: supR3HardenedDllNotificationCallback: load 00007ffc1fc40000 LB 0x0001f000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.DLL [fFlags=0x0]
27091c3c.1f38: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.dll
27101c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc1fc40000 'C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.DLL'
27111c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
27121c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
27131c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
27141c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
27151c3c.1f38: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.dll) WinVerifyTrust
27161c3c.1f38: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.dll
27171c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
27181c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
27191c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
27201c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
27211c3c.1f38: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
27221c3c.1f38: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.dll
27231c3c.1f38: supR3HardenedDllNotificationCallback: load 00007ffc1ac30000 LB 0x00018000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.DLL [fFlags=0x0]
27241c3c.1f38: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.dll
27251c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc1ac30000 'C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.DLL'
27261c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
27271c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
27281c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
27291c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
27301c3c.1f38: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.dll) WinVerifyTrust
27311c3c.1f38: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.dll
27321c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
27331c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
27341c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
27351c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
27361c3c.1f38: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
27371c3c.1f38: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.dll
27381c3c.1f38: supR3HardenedDllNotificationCallback: load 00007ffc10780000 LB 0x00018000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.DLL [fFlags=0x0]
27391c3c.1f38: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.dll
27401c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc10780000 'C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.DLL'
27411c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
27421c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
27431c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
27441c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
27451c3c.1f38: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.dll) WinVerifyTrust
27461c3c.1f38: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.dll
27471c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
27481c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
27491c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
27501c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
27511c3c.1f38: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
27521c3c.1f38: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.dll
27531c3c.1f38: supR3HardenedDllNotificationCallback: load 00007ffc10760000 LB 0x00019000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.DLL [fFlags=0x0]
27541c3c.1f38: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.dll
27551c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc10760000 'C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.DLL'
27561c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
27571c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
27581c3c.1454: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
27591c3c.1454: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
27601c3c.1454: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
27611c3c.1454: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
27621c3c.1454: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll) WinVerifyTrust
27631c3c.1454: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll
27641c3c.1454: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
27651c3c.1454: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
27661c3c.1454: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
27671c3c.1454: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
27681c3c.1454: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
27691c3c.1454: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
27701c3c.1454: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
27711c3c.1454: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
27721c3c.1454: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll
27731c3c.1454: supR3HardenedDllNotificationCallback: load 00007ffc258b0000 LB 0x0000d000 C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL [fFlags=0x0]
27741c3c.1454: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll
27751c3c.1454: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc258b0000 'C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL'
27761c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
27771c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
27781c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
27791c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
27801c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
27811c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
27821c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ws2_32.dll'.
27831c3c.1f38: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.dll) WinVerifyTrust
27841c3c.1f38: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.dll
27851c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
27861c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
27871c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
27881c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
27891c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
27901c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
27911c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
27921c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
27931c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
27941c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
27951c3c.1f38: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
27961c3c.1f38: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
27971c3c.1f38: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.dll
27981c3c.1f38: supR3HardenedDllNotificationCallback: load 00007ffc10240000 LB 0x000cc000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.DLL [fFlags=0x0]
27991c3c.1f38: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.dll
28001c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc10240000 'C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.DLL'
28011c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
28021c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
28031c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'rpcrt4.dll'.
28041c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #35 'devobj.dll'.
28051c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #36 'propsys.dll'.
28061c3c.1f38: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll) WinVerifyTrust
28071c3c.1f38: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
28081c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'propsys.dll'...
28091c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'propsys.dll' -> '\Device\HarddiskVolume2\Windows\System32\propsys.dll' [rcNtRedir=0xc0150008]
28101c3c.1f38: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\propsys.dll [redoing WinVerifyTrust]
28111c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
28121c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
28131c3c.1f38: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\propsys.dll'
28141c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'devobj.dll'...
28151c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'devobj.dll' -> '\Device\HarddiskVolume2\Windows\System32\devobj.dll' [rcNtRedir=0xc0150008]
28161c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
28171c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
28181c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'cfgmgr32.dll'.
28191c3c.1f38: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\devobj.dll) WinVerifyTrust
28201c3c.1f38: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\devobj.dll
28211c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
28221c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
28231c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
28241c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
28251c3c.1f38: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll [redoing WinVerifyTrust]
28261c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
28271c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
28281c3c.1f38: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll'
28291c3c.1f38: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\MMDevApi.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
28301c3c.1f38: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
28311c3c.1f38: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\devobj.dll
28321c3c.1f38: supR3HardenedDllNotificationCallback: load 00007ffc37760000 LB 0x00027000 C:\Windows\System32\DEVOBJ.dll [fFlags=0x0]
28331c3c.1f38: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\devobj.dll
28341c3c.1f38: supR3HardenedDllNotificationCallback: load 00007ffc31c20000 LB 0x00076000 C:\Windows\System32\MMDevApi.dll [fFlags=0x0]
28351c3c.1f38: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
28361c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc31c20000 'C:\Windows\System32\MMDevApi.dll'
28371c3c.1f38: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000001034 pwszName=\Device\HarddiskVolume2\Windows\System32\dsound.dll
28381c3c.1f38: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000fe7760
28391c3c.1f38: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000fe7760
28401c3c.1f38: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=5473BCFF580489A320314B844E6D3DC42BA47DE8
28411c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
28421c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
28431c3c.1f38: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package~31bf3856ad364e35~amd64~~10.0.17134.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\dsound.dll'
28441c3c.1f38: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
28451c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
28461c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #32 'winmm.dll'.
28471c3c.1f38: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\dsound.dll) WinVerifyTrust
28481c3c.1f38: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\dsound.dll
28491c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
28501c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
28511c3c.1f38: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
28521c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
28531c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
28541c3c.1f38: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
28551c3c.1f38: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dsound.dll
28561c3c.1f38: supR3HardenedDllNotificationCallback: load 00007ffc0c240000 LB 0x0008f000 C:\Windows\System32\dsound.dll [fFlags=0x0]
28571c3c.1f38: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dsound.dll
28581c3c.1f38: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dsound.dll
28591c3c.1f38: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
28601c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc0c240000 'C:\Windows\System32\dsound.dll'
28611c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc0c240000 'C:\Windows\System32\dsound.dll'
28621c3c.1f38: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dsound.dll
28631c3c.1f38: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
28641c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc0c240000 'C:\Windows\system32\dsound.dll'
28651c3c.1f38: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
28661c3c.1f38: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\MMDEVAPI.DLL (Input=MMDEVAPI.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
28671c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc31c20000 'C:\Windows\System32\MMDEVAPI.DLL'
28681c3c.1f38: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
28691c3c.1f38: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\winmm.dll (Input=winmm.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
28701c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc355d0000 'C:\Windows\System32\winmm.dll'
28711c3c.1f38: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000fac pwszName=\Device\HarddiskVolume2\Windows\System32\wdmaud.drv
28721c3c.1f38: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000fe7760
28731c3c.1f38: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000fe7760
28741c3c.1f38: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=177AADB38B3BB8D75072CC704861E1B81617F092
28751c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
28761c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
28771c3c.1f38: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package~31bf3856ad364e35~amd64~~10.0.17134.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\wdmaud.drv'
28781c3c.1f38: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
28791c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
28801c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'mmdevapi.dll'.
28811c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #27 'ksuser.dll'.
28821c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #28 'avrt.dll'.
28831c3c.1f38: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\wdmaud.drv) WinVerifyTrust
28841c3c.1f38: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
28851c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'avrt.dll'...
28861c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'avrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\avrt.dll' [rcNtRedir=0xc0150008]
28871c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
28881c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
28891c3c.1f38: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\avrt.dll) WinVerifyTrust
28901c3c.1f38: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\avrt.dll
28911c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ksuser.dll'...
28921c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'ksuser.dll' -> '\Device\HarddiskVolume2\Windows\System32\ksuser.dll' [rcNtRedir=0xc0150008]
28931c3c.1f38: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll
28941c3c.1f38: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
28951c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
28961c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
28971c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
28981c3c.1f38: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ksuser.dll) WinVerifyTrust
28991c3c.1f38: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ksuser.dll
29001c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mmdevapi.dll'...
29011c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'mmdevapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\mmdevapi.dll' [rcNtRedir=0xc0150008]
29021c3c.1f38: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
29031c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
29041c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
29051c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
29061c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
29071c3c.1f38: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
29081c3c.1f38: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
29091c3c.1f38: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ksuser.dll
29101c3c.1f38: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\avrt.dll
29111c3c.1f38: supR3HardenedDllNotificationCallback: load 00007ffc24b70000 LB 0x00009000 C:\Windows\SYSTEM32\ksuser.dll [fFlags=0x0]
29121c3c.1f38: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ksuser.dll
29131c3c.1f38: supR3HardenedDllNotificationCallback: load 00007ffc330c0000 LB 0x0000a000 C:\Windows\SYSTEM32\AVRT.dll [fFlags=0x0]
29141c3c.1f38: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\avrt.dll
29151c3c.1f38: supR3HardenedDllNotificationCallback: load 00007ffc10630000 LB 0x00044000 C:\Windows\System32\wdmaud.drv [fFlags=0x0]
29161c3c.1f38: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
29171c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc10630000 'C:\Windows\System32\wdmaud.drv'
29181c3c.1f38: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
29191c3c.1f38: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
29201c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc10630000 'C:\Windows\System32\wdmaud.drv'
29211c3c.1f38: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
29221c3c.1f38: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
29231c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc10630000 'C:\Windows\System32\wdmaud.drv'
29241c3c.1f38: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
29251c3c.1f38: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
29261c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc10630000 'C:\Windows\System32\wdmaud.drv'
29271c3c.1f38: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
29281c3c.1f38: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
29291c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc10630000 'C:\Windows\System32\wdmaud.drv'
29301c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
29311c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
29321c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
29331c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'rpcrt4.dll'.
29341c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'oleaut32.dll'.
29351c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #55 'mmdevapi.dll'.
29361c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #56 'avrt.dll'.
29371c3c.1f38: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\AudioSes.dll) WinVerifyTrust
29381c3c.1f38: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\AudioSes.dll
29391c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'avrt.dll'...
29401c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'avrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\avrt.dll' [rcNtRedir=0xc0150008]
29411c3c.1f38: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\avrt.dll
29421c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mmdevapi.dll'...
29431c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'mmdevapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\mmdevapi.dll' [rcNtRedir=0xc0150008]
29441c3c.1f38: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
29451c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
29461c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
29471c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
29481c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
29491c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
29501c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
29511c3c.1f38: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcp_win.dll
29521c3c.1f38: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\AUDIOSES.DLL (Input=AUDIOSES.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
29531c3c.1f38: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\AudioSes.dll
29541c3c.1f38: supR3HardenedDllNotificationCallback: load 00007ffc0fa40000 LB 0x0012c000 C:\Windows\System32\AUDIOSES.DLL [fFlags=0x0]
29551c3c.1f38: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\AudioSes.dll
29561c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc0fa40000 'C:\Windows\System32\AUDIOSES.DLL'
29571c3c.1f38: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
29581c3c.1f38: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
29591c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc10630000 'C:\Windows\System32\wdmaud.drv'
29601c3c.1f38: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
29611c3c.1f38: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
29621c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc10630000 'C:\Windows\System32\wdmaud.drv'
29631c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc10630000 'C:\Windows\System32\wdmaud.drv'
29641c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc10630000 'C:\Windows\System32\wdmaud.drv'
29651c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc10630000 'C:\Windows\System32\wdmaud.drv'
29661c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc10630000 'C:\Windows\System32\wdmaud.drv'
29671c3c.1f38: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000010dc pwszName=\Device\HarddiskVolume2\Windows\System32\msacm32.drv
29681c3c.1f38: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000fe7760
29691c3c.1f38: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000fe7760
29701c3c.1f38: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=7886E1CCA739C1E5ED73D45A3FBDDF8A54FC7C0F
29711c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
29721c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
29731c3c.1f38: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package~31bf3856ad364e35~amd64~~10.0.17134.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\msacm32.drv'
29741c3c.1f38: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
29751c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
29761c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'mmdevapi.dll'.
29771c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'msacm32.dll'.
29781c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'winmmbase.dll'.
29791c3c.1f38: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\msacm32.drv) WinVerifyTrust
29801c3c.1f38: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msacm32.drv
29811c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmmbase.dll'...
29821c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmmbase.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmmbase.dll' [rcNtRedir=0xc0150008]
29831c3c.1f38: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmmbase.dll [redoing WinVerifyTrust]
29841c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
29851c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
29861c3c.1f38: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\winmmbase.dll'
29871c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msacm32.dll'...
29881c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'msacm32.dll' -> '\Device\HarddiskVolume2\Windows\System32\msacm32.dll' [rcNtRedir=0xc0150008]
29891c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
29901c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
29911c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
29921c3c.1f38: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\msacm32.dll) WinVerifyTrust
29931c3c.1f38: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msacm32.dll
29941c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mmdevapi.dll'...
29951c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'mmdevapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\mmdevapi.dll' [rcNtRedir=0xc0150008]
29961c3c.1f38: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
29971c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
29981c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
29991c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
30001c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
30011c3c.1f38: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
30021c3c.1f38: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
30031c3c.1f38: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.dll
30041c3c.1f38: supR3HardenedDllNotificationCallback: load 00007ffc10610000 LB 0x0001c000 C:\Windows\SYSTEM32\MSACM32.dll [fFlags=0x0]
30051c3c.1f38: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.dll
30061c3c.1f38: supR3HardenedDllNotificationCallback: load 00007ffc11910000 LB 0x0000d000 C:\Windows\System32\msacm32.drv [fFlags=0x0]
30071c3c.1f38: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
30081c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11910000 'C:\Windows\System32\msacm32.drv'
30091c3c.1f38: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
30101c3c.1f38: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
30111c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11910000 'C:\Windows\System32\msacm32.drv'
30121c3c.1f38: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
30131c3c.1f38: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
30141c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11910000 'C:\Windows\System32\msacm32.drv'
30151c3c.1f38: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
30161c3c.1f38: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
30171c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11910000 'C:\Windows\System32\msacm32.drv'
30181c3c.1f38: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
30191c3c.1f38: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
30201c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11910000 'C:\Windows\System32\msacm32.drv'
30211c3c.1f38: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
30221c3c.1f38: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
30231c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11910000 'C:\Windows\System32\msacm32.drv'
30241c3c.1f38: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
30251c3c.1f38: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
30261c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11910000 'C:\Windows\System32\msacm32.drv'
30271c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11910000 'C:\Windows\System32\msacm32.drv'
30281c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11910000 'C:\Windows\System32\msacm32.drv'
30291c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc11910000 'C:\Windows\System32\msacm32.drv'
30301c3c.1f38: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000010c4 pwszName=\Device\HarddiskVolume2\Windows\System32\midimap.dll
30311c3c.1f38: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000fe7760
30321c3c.1f38: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000fe7760
30331c3c.1f38: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=1DAEA3709B4BD5475FA0919C8463CA4834E4BC26
30341c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
30351c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc382a0000 'C:\Windows\System32\crypt32.dll'
30361c3c.1f38: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package~31bf3856ad364e35~amd64~~10.0.17134.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\midimap.dll'
30371c3c.1f38: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
30381c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
30391c3c.1f38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'winmm.dll'.
30401c3c.1f38: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\midimap.dll) WinVerifyTrust
30411c3c.1f38: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\midimap.dll
30421c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
30431c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
30441c3c.1f38: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
30451c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
30461c3c.1f38: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
30471c3c.1f38: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
30481c3c.1f38: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\midimap.dll
30491c3c.1f38: supR3HardenedDllNotificationCallback: load 00007ffc10d70000 LB 0x0000a000 C:\Windows\System32\midimap.dll [fFlags=0x0]
30501c3c.1f38: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\midimap.dll
30511c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc10d70000 'C:\Windows\System32\midimap.dll'
30521c3c.1f38: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\midimap.dll
30531c3c.1f38: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
30541c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc10d70000 'C:\Windows\System32\midimap.dll'
30551c3c.1f38: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\midimap.dll
30561c3c.1f38: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
30571c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc10d70000 'C:\Windows\System32\midimap.dll'
30581c3c.1f38: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\midimap.dll
30591c3c.1f38: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
30601c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc10d70000 'C:\Windows\System32\midimap.dll'
30611c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc355d0000 'C:\Windows\System32\winmm.dll'
30621c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc355d0000 'C:\Windows\System32\winmm.dll'
30631c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc355d0000 'C:\Windows\System32\winmm.dll'
30641c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc355d0000 'C:\Windows\System32\winmm.dll'
30651c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc355d0000 'C:\Windows\System32\winmm.dll'
30661c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc355d0000 'C:\Windows\System32\winmm.dll'
30671c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc355d0000 'C:\Windows\System32\winmm.dll'
30681c3c.1f38: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
30691c3c.1f38: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\winmm.dll (Input=winmm.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
30701c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc355d0000 'C:\Windows\System32\winmm.dll'
30711c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc355d0000 'C:\Windows\System32\winmm.dll'
30721c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc355d0000 'C:\Windows\System32\winmm.dll'
30731c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc355d0000 'C:\Windows\System32\winmm.dll'
30741c3c.1f38: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dsound.dll
30751c3c.1f38: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
30761c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc0c240000 'C:\Windows\system32\dsound.dll'
30771c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc355d0000 'C:\Windows\System32\winmm.dll'
30781c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc08a00000 'C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL'
30791c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc39600000 'C:\Windows\system32\shell32.dll'
30801c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc39600000 'C:\Windows\system32\shell32.dll'
30811c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc39600000 'C:\Windows\system32\shell32.dll'
30821c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc39600000 'C:\Windows\system32\shell32.dll'
30831c3c.1868: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
30841c3c.1868: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
30851c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc39600000 'C:\Windows\system32\shell32.dll'
30861c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc39600000 'C:\Windows\system32\shell32.dll'
30871c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
30881c3c.1f38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc36db0000 'C:\Windows\system32\rsaenh.dll'
30891c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc39600000 'C:\Windows\system32\shell32.dll'
30901c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc39600000 'C:\Windows\system32\shell32.dll'
30911c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc39600000 'C:\Windows\system32\shell32.dll'
30921c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc39600000 'C:\Windows\system32\shell32.dll'
30931c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc39600000 'C:\Windows\system32\shell32.dll'
30941c3c.1868: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc39600000 'C:\Windows\system32\shell32.dll'

© 2024 Oracle Support Privacy / Do Not Sell My Info Terms of Use Trademark Policy Automated Access Etiquette