VirtualBox

Ticket #18387: win10_VBoxHardening.log

File win10_VBoxHardening.log, 326.1 KB (added by nathaniel515, 6 years ago)
Line 
15c38.ba4: Log file opened: 6.0.4r128413 g_hStartupLog=0000000000000070 g_uNtVerCombined=0xa0456300
25c38.ba4: \SystemRoot\System32\ntdll.dll:
35c38.ba4: CreationTime: 2018-12-30T02:31:21.439974200Z
45c38.ba4: LastWriteTime: 2018-12-30T02:31:21.455594900Z
55c38.ba4: ChangeTime: 2019-01-08T21:05:01.868444500Z
65c38.ba4: FileAttributes: 0x20
75c38.ba4: Size: 0x1e7010
85c38.ba4: NT Headers: 0xe0
95c38.ba4: Timestamp: 0xe8b54827
105c38.ba4: Machine: 0x8664 - amd64
115c38.ba4: Timestamp: 0xe8b54827
125c38.ba4: Image Version: 10.0
135c38.ba4: SizeOfImage: 0x1ed000 (2019328)
145c38.ba4: Resource Dir: 0x17d000 LB 0x6ea08
155c38.ba4: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
165c38.ba4: [Raw version resource data: 0x17d0f0 LB 0x380, codepage 0x0 (reserved 0x0)]
175c38.ba4: ProductName: Microsoft® Windows® Operating System
185c38.ba4: ProductVersion: 10.0.17763.194
195c38.ba4: FileVersion: 10.0.17763.194 (WinBuild.160101.0800)
205c38.ba4: FileDescription: NT Layer DLL
215c38.ba4: \SystemRoot\System32\kernel32.dll:
225c38.ba4: CreationTime: 2018-09-15T07:28:44.342269900Z
235c38.ba4: LastWriteTime: 2018-09-15T07:28:44.342269900Z
245c38.ba4: ChangeTime: 2018-12-30T02:37:12.140802400Z
255c38.ba4: FileAttributes: 0x20
265c38.ba4: Size: 0xb1380
275c38.ba4: NT Headers: 0xe8
285c38.ba4: Timestamp: 0x65614da1
295c38.ba4: Machine: 0x8664 - amd64
305c38.ba4: Timestamp: 0x65614da1
315c38.ba4: Image Version: 10.0
325c38.ba4: SizeOfImage: 0xb3000 (733184)
335c38.ba4: Resource Dir: 0xb1000 LB 0x520
345c38.ba4: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
355c38.ba4: [Raw version resource data: 0xb10b0 LB 0x3a4, codepage 0x0 (reserved 0x0)]
365c38.ba4: ProductName: Microsoft® Windows® Operating System
375c38.ba4: ProductVersion: 10.0.17763.1
385c38.ba4: FileVersion: 10.0.17763.1 (WinBuild.160101.0800)
395c38.ba4: FileDescription: Windows NT BASE API Client DLL
405c38.ba4: \SystemRoot\System32\KernelBase.dll:
415c38.ba4: CreationTime: 2018-12-30T02:31:21.205655900Z
425c38.ba4: LastWriteTime: 2018-12-30T02:31:21.236896100Z
435c38.ba4: ChangeTime: 2019-01-08T21:05:01.867446600Z
445c38.ba4: FileAttributes: 0x20
455c38.ba4: Size: 0x293cc8
465c38.ba4: NT Headers: 0xf8
475c38.ba4: Timestamp: 0x1659a33b
485c38.ba4: Machine: 0x8664 - amd64
495c38.ba4: Timestamp: 0x1659a33b
505c38.ba4: Image Version: 10.0
515c38.ba4: SizeOfImage: 0x293000 (2699264)
525c38.ba4: Resource Dir: 0x26f000 LB 0x548
535c38.ba4: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
545c38.ba4: [Raw version resource data: 0x26f0b0 LB 0x3bc, codepage 0x0 (reserved 0x0)]
555c38.ba4: ProductName: Microsoft® Windows® Operating System
565c38.ba4: ProductVersion: 10.0.17763.134
575c38.ba4: FileVersion: 10.0.17763.134 (WinBuild.160101.0800)
585c38.ba4: FileDescription: Windows NT BASE API Client DLL
595c38.ba4: \SystemRoot\System32\apisetschema.dll:
605c38.ba4: CreationTime: 2018-09-15T07:28:25.403122600Z
615c38.ba4: LastWriteTime: 2018-09-15T07:28:25.403122600Z
625c38.ba4: ChangeTime: 2018-12-30T02:29:00.950166300Z
635c38.ba4: FileAttributes: 0x20
645c38.ba4: Size: 0x1c738
655c38.ba4: NT Headers: 0xd0
665c38.ba4: Timestamp: 0x33775897
675c38.ba4: Machine: 0x8664 - amd64
685c38.ba4: Timestamp: 0x33775897
695c38.ba4: Image Version: 10.0
705c38.ba4: SizeOfImage: 0x1d000 (118784)
715c38.ba4: Resource Dir: 0x1c000 LB 0x408
725c38.ba4: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
735c38.ba4: [Raw version resource data: 0x1c060 LB 0x3a8, codepage 0x0 (reserved 0x0)]
745c38.ba4: ProductName: Microsoft® Windows® Operating System
755c38.ba4: ProductVersion: 10.0.17763.1
765c38.ba4: FileVersion: 10.0.17763.1 (WinBuild.160101.0800)
775c38.ba4: FileDescription: ApiSet Schema DLL
785c38.ba4: NtOpenDirectoryObject failed on \Driver: 0xc0000022
795c38.ba4: supR3HardenedWinFindAdversaries: 0x8000
805c38.ba4: \SystemRoot\System32\drivers\cyprotectdrv64.sys:
815c38.ba4: CreationTime: 2018-12-30T23:56:45.646933300Z
825c38.ba4: LastWriteTime: 2019-01-07T19:47:35.388882000Z
835c38.ba4: ChangeTime: 2019-01-30T22:49:57.834123800Z
845c38.ba4: FileAttributes: 0x20
855c38.ba4: Size: 0x332a8
865c38.ba4: NT Headers: 0xf8
875c38.ba4: Timestamp: 0x5c05c934
885c38.ba4: Machine: 0x8664 - amd64
895c38.ba4: Timestamp: 0x5c05c934
905c38.ba4: Image Version: 6.1
915c38.ba4: SizeOfImage: 0x134000 (1261568)
925c38.ba4: Resource Dir: 0x132000 LB 0x2f0
935c38.ba4: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
945c38.ba4: [Raw version resource data: 0x132060 LB 0x28c, codepage 0x0 (reserved 0x0)]
955c38.ba4: ProductName: CylancePROTECT
965c38.ba4: ProductVersion: 2.0.1510.8
975c38.ba4: FileVersion: 2.0.1510.8
985c38.ba4: FileDescription: Cylance Protect Driver
995c38.ba4: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox'
1005c38.ba4: Calling main()
1015c38.ba4: SUPR3HardenedMain: pszProgName=VirtualBoxVM fFlags=0x2
1025c38.ba4: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox'
1035c38.ba4: SUPR3HardenedMain: Respawn #1
1045c38.ba4: System32: \Device\HarddiskVolume4\Windows\System32
1055c38.ba4: WinSxS: \Device\HarddiskVolume4\Windows\WinSxS
1065c38.ba4: KnownDllPath: C:\WINDOWS\System32
1075c38.ba4: '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
1085c38.ba4: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe)
1095c38.ba4: supR3HardNtEnableThreadCreation:
1105c38.ba4: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffcbb1e5640 pvNtTerminateThread=00007ffcbb2100b0
1115c38.ba4: supR3HardenedWinDoReSpawn(1): New child 410c.4b50 [kernel32].
1125c38.ba4: supR3HardNtChildGatherData: PebBaseAddress=0000000000d35000 cbPeb=0x388
1135c38.ba4: supR3HardNtPuChFindNtdll: uNtDllParentAddr=00007ffcbb170000 uNtDllChildAddr=00007ffcbb170000
1145c38.ba4: supR3HardenedWinSetupChildInit: uLdrInitThunk=00007ffcbb1e5640
1155c38.ba4: supR3HardenedWinSetupChildInit: Start child.
1165c38.ba4: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
1175c38.ba4: supR3HardNtChildPurify: Startup delay kludge #1/0: 513 ms, 59 sleeps
1185c38.ba4: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
1195c38.ba4: *0000000000000000-0000000000b8ffff 0x0001/0x0000 0x0000000
1205c38.ba4: *0000000000b90000-0000000000baffff 0x0004/0x0004 0x0020000
1215c38.ba4: *0000000000bb0000-0000000000bc9fff 0x0002/0x0002 0x0040000
1225c38.ba4: 0000000000bca000-0000000000bcffff 0x0001/0x0000 0x0000000
1235c38.ba4: *0000000000bd0000-0000000000bd3fff 0x0002/0x0002 0x0040000
1245c38.ba4: 0000000000bd4000-0000000000bdffff 0x0001/0x0000 0x0000000
1255c38.ba4: *0000000000be0000-0000000000be1fff 0x0004/0x0004 0x0020000
1265c38.ba4: 0000000000be2000-0000000000bfffff 0x0001/0x0000 0x0000000
1275c38.ba4: *0000000000c00000-0000000000d34fff 0x0000/0x0004 0x0020000
1285c38.ba4: 0000000000d35000-0000000000d37fff 0x0004/0x0004 0x0020000
1295c38.ba4: 0000000000d38000-0000000000dfffff 0x0000/0x0004 0x0020000
1305c38.ba4: *0000000000e00000-0000000000efafff 0x0000/0x0004 0x0020000
1315c38.ba4: 0000000000efb000-0000000000efdfff 0x0104/0x0004 0x0020000
1325c38.ba4: 0000000000efe000-0000000000efffff 0x0004/0x0004 0x0020000
1335c38.ba4: 0000000000f00000-000000007ffdffff 0x0001/0x0000 0x0000000
1345c38.ba4: *000000007ffe0000-000000007ffe0fff 0x0002/0x0002 0x0020000
1355c38.ba4: 000000007ffe1000-000000007ffe6fff 0x0001/0x0000 0x0000000
1365c38.ba4: *000000007ffe7000-000000007ffe7fff 0x0002/0x0002 0x0020000
1375c38.ba4: 000000007ffe8000-00007ff5e081ffff 0x0001/0x0000 0x0000000
1385c38.ba4: *00007ff5e0820000-00007ff5e0820fff 0x0002/0x0002 0x0040000
1395c38.ba4: 00007ff5e0821000-00007ff5e082ffff 0x0001/0x0000 0x0000000
1405c38.ba4: *00007ff5e0830000-00007ff5e0852fff 0x0002/0x0002 0x0040000
1415c38.ba4: 00007ff5e0853000-00007ff7d61fffff 0x0001/0x0000 0x0000000
1425c38.ba4: *00007ff7d6200000-00007ff7d6200fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
1435c38.ba4: 00007ff7d6201000-00007ff7d6273fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
1445c38.ba4: 00007ff7d6274000-00007ff7d6274fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
1455c38.ba4: 00007ff7d6275000-00007ff7d62bbfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
1465c38.ba4: 00007ff7d62bc000-00007ff7d62bcfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
1475c38.ba4: 00007ff7d62bd000-00007ff7d62bdfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
1485c38.ba4: 00007ff7d62be000-00007ff7d62c2fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
1495c38.ba4: 00007ff7d62c3000-00007ff7d62c3fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
1505c38.ba4: 00007ff7d62c4000-00007ff7d62c4fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
1515c38.ba4: 00007ff7d62c5000-00007ff7d62c8fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
1525c38.ba4: 00007ff7d62c9000-00007ff7d6311fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
1535c38.ba4: 00007ff7d6312000-00007ffcbb16ffff 0x0001/0x0000 0x0000000
1545c38.ba4: *00007ffcbb170000-00007ffcbb170fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
1555c38.ba4: 00007ffcbb171000-00007ffcbb287fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
1565c38.ba4: 00007ffcbb288000-00007ffcbb2cefff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
1575c38.ba4: 00007ffcbb2cf000-00007ffcbb2d9fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
1585c38.ba4: 00007ffcbb2da000-00007ffcbb2e7fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
1595c38.ba4: 00007ffcbb2e8000-00007ffcbb2e8fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
1605c38.ba4: 00007ffcbb2e9000-00007ffcbb2ebfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
1615c38.ba4: 00007ffcbb2ec000-00007ffcbb35cfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
1625c38.ba4: 00007ffcbb35d000-00007ffffffeffff 0x0001/0x0000 0x0000000
1635c38.ba4: VirtualBoxVM.exe: timestamp 0x5c4b51f3 (rc=VINF_SUCCESS)
1645c38.ba4: '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
1655c38.ba4: '\Device\HarddiskVolume4\Windows\System32\ntdll.dll' has no imports
1665c38.ba4: supR3HardNtChildPurify: Done after 578 ms and 0 fixes (loop #0).
167410c.4b50: Log file opened: 6.0.4r128413 g_hStartupLog=0000000000000004 g_uNtVerCombined=0xa0456300
168410c.4b50: supR3HardenedVmProcessInit: uNtDllAddr=00007ffcbb170000 g_uNtVerCombined=0xa0456300
169410c.4b50: ntdll.dll: timestamp 0xe8b54827 (rc=VINF_SUCCESS)
170410c.4b50: New simple heap: #1 0000000001000000 LB 0x400000 (for 2019328 allocation)
1715c38.ba4: supR3HardNtEnableThreadCreation:
172410c.4b50: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox'
173410c.4b50: System32: \Device\HarddiskVolume4\Windows\System32
174410c.4b50: WinSxS: \Device\HarddiskVolume4\Windows\WinSxS
175410c.4b50: KnownDllPath: C:\WINDOWS\System32
176410c.4b50: supR3HardenedVmProcessInit: Opening vboxdrv stub...
177410c.4b50: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
178410c.4b50: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
179410c.4b50: Registered Dll notification callback with NTDLL.
180410c.4b50: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\kernel32.dll)
181410c.4b50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\kernel32.dll
182410c.4b50: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\KERNEL32.DLL (Input=KERNEL32.DLL, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000004001:<flags> [calling]
183410c.4b50: supR3HardenedDllNotificationCallback: load 00007ffcb80b0000 LB 0x00293000 C:\WINDOWS\System32\KERNELBASE.dll [fFlags=0x0]
184410c.4b50: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\KernelBase.dll)
185410c.4b50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\KernelBase.dll
186410c.4b50: supR3HardenedDllNotificationCallback: load 00007ffcba7c0000 LB 0x000b3000 C:\WINDOWS\System32\KERNEL32.DLL [fFlags=0x0]
187410c.4b50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
188410c.4b50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcba7c0000 'C:\WINDOWS\System32\KERNEL32.DLL'
189410c.4b50: supR3HardenedDllNotificationCallback: load 00007ff7d6200000 LB 0x00112000 C:\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe [fFlags=0x0]
190410c.4b50: '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
191410c.4b50: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe)
192410c.4b50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
193410c.4b50: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffcbb1e5640 pvNtTerminateThread=00007ffcbb2100b0
1945c38.ba4: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 83 ms.
195410c.4b50: \SystemRoot\System32\ntdll.dll:
196410c.4b50: CreationTime: 2018-12-30T02:31:21.439974200Z
197410c.4b50: LastWriteTime: 2018-12-30T02:31:21.455594900Z
198410c.4b50: ChangeTime: 2019-01-08T21:05:01.868444500Z
199410c.4b50: FileAttributes: 0x20
200410c.4b50: Size: 0x1e7010
201410c.4b50: NT Headers: 0xe0
202410c.4b50: Timestamp: 0xe8b54827
203410c.4b50: Machine: 0x8664 - amd64
204410c.4b50: Timestamp: 0xe8b54827
205410c.4b50: Image Version: 10.0
206410c.4b50: SizeOfImage: 0x1ed000 (2019328)
207410c.4b50: Resource Dir: 0x17d000 LB 0x6ea08
208410c.4b50: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
209410c.4b50: [Raw version resource data: 0x17d0f0 LB 0x380, codepage 0x0 (reserved 0x0)]
210410c.4b50: ProductName: Microsoft® Windows® Operating System
211410c.4b50: ProductVersion: 10.0.17763.194
212410c.4b50: FileVersion: 10.0.17763.194 (WinBuild.160101.0800)
213410c.4b50: FileDescription: NT Layer DLL
214410c.4b50: \SystemRoot\System32\kernel32.dll:
215410c.4b50: CreationTime: 2018-09-15T07:28:44.342269900Z
216410c.4b50: LastWriteTime: 2018-09-15T07:28:44.342269900Z
217410c.4b50: ChangeTime: 2018-12-30T02:37:12.140802400Z
218410c.4b50: FileAttributes: 0x20
219410c.4b50: Size: 0xb1380
220410c.4b50: NT Headers: 0xe8
221410c.4b50: Timestamp: 0x65614da1
222410c.4b50: Machine: 0x8664 - amd64
223410c.4b50: Timestamp: 0x65614da1
224410c.4b50: Image Version: 10.0
225410c.4b50: SizeOfImage: 0xb3000 (733184)
226410c.4b50: Resource Dir: 0xb1000 LB 0x520
227410c.4b50: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
228410c.4b50: [Raw version resource data: 0xb10b0 LB 0x3a4, codepage 0x0 (reserved 0x0)]
229410c.4b50: ProductName: Microsoft® Windows® Operating System
230410c.4b50: ProductVersion: 10.0.17763.1
231410c.4b50: FileVersion: 10.0.17763.1 (WinBuild.160101.0800)
232410c.4b50: FileDescription: Windows NT BASE API Client DLL
233410c.4b50: \SystemRoot\System32\KernelBase.dll:
234410c.4b50: CreationTime: 2018-12-30T02:31:21.205655900Z
235410c.4b50: LastWriteTime: 2018-12-30T02:31:21.236896100Z
236410c.4b50: ChangeTime: 2019-01-08T21:05:01.867446600Z
237410c.4b50: FileAttributes: 0x20
238410c.4b50: Size: 0x293cc8
239410c.4b50: NT Headers: 0xf8
240410c.4b50: Timestamp: 0x1659a33b
241410c.4b50: Machine: 0x8664 - amd64
242410c.4b50: Timestamp: 0x1659a33b
243410c.4b50: Image Version: 10.0
244410c.4b50: SizeOfImage: 0x293000 (2699264)
245410c.4b50: Resource Dir: 0x26f000 LB 0x548
246410c.4b50: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
247410c.4b50: [Raw version resource data: 0x26f0b0 LB 0x3bc, codepage 0x0 (reserved 0x0)]
248410c.4b50: ProductName: Microsoft® Windows® Operating System
249410c.4b50: ProductVersion: 10.0.17763.134
250410c.4b50: FileVersion: 10.0.17763.134 (WinBuild.160101.0800)
251410c.4b50: FileDescription: Windows NT BASE API Client DLL
252410c.4b50: \SystemRoot\System32\apisetschema.dll:
253410c.4b50: CreationTime: 2018-09-15T07:28:25.403122600Z
254410c.4b50: LastWriteTime: 2018-09-15T07:28:25.403122600Z
255410c.4b50: ChangeTime: 2018-12-30T02:29:00.950166300Z
256410c.4b50: FileAttributes: 0x20
257410c.4b50: Size: 0x1c738
258410c.4b50: NT Headers: 0xd0
259410c.4b50: Timestamp: 0x33775897
260410c.4b50: Machine: 0x8664 - amd64
261410c.4b50: Timestamp: 0x33775897
262410c.4b50: Image Version: 10.0
263410c.4b50: SizeOfImage: 0x1d000 (118784)
264410c.4b50: Resource Dir: 0x1c000 LB 0x408
265410c.4b50: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
266410c.4b50: [Raw version resource data: 0x1c060 LB 0x3a8, codepage 0x0 (reserved 0x0)]
267410c.4b50: ProductName: Microsoft® Windows® Operating System
268410c.4b50: ProductVersion: 10.0.17763.1
269410c.4b50: FileVersion: 10.0.17763.1 (WinBuild.160101.0800)
270410c.4b50: FileDescription: ApiSet Schema DLL
271410c.4b50: NtOpenDirectoryObject failed on \Driver: 0xc0000022
272410c.4b50: supR3HardenedWinFindAdversaries: 0x8000
273410c.4b50: \SystemRoot\System32\drivers\cyprotectdrv64.sys:
274410c.4b50: CreationTime: 2018-12-30T23:56:45.646933300Z
275410c.4b50: LastWriteTime: 2019-01-07T19:47:35.388882000Z
276410c.4b50: ChangeTime: 2019-01-30T22:49:57.834123800Z
277410c.4b50: FileAttributes: 0x20
278410c.4b50: Size: 0x332a8
279410c.4b50: NT Headers: 0xf8
280410c.4b50: Timestamp: 0x5c05c934
281410c.4b50: Machine: 0x8664 - amd64
282410c.4b50: Timestamp: 0x5c05c934
283410c.4b50: Image Version: 6.1
284410c.4b50: SizeOfImage: 0x134000 (1261568)
285410c.4b50: Resource Dir: 0x132000 LB 0x2f0
286410c.4b50: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
287410c.4b50: [Raw version resource data: 0x132060 LB 0x28c, codepage 0x0 (reserved 0x0)]
288410c.4b50: ProductName: CylancePROTECT
289410c.4b50: ProductVersion: 2.0.1510.8
290410c.4b50: FileVersion: 2.0.1510.8
291410c.4b50: FileDescription: Cylance Protect Driver
292410c.4b50: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox'
293410c.4b50: Calling main()
294410c.4b50: SUPR3HardenedMain: pszProgName=VirtualBoxVM fFlags=0x2
295410c.4b50: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox'
296410c.4b50: '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
297410c.4b50: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe)
298410c.4b50: SUPR3HardenedMain: Respawn #2
299410c.4b50: supR3HardNtEnableThreadCreation:
300410c.4b50: supR3HardenedDllNotificationCallback: load 00007ffcb9140000 LB 0x00122000 C:\WINDOWS\System32\RPCRT4.dll [fFlags=0x0]
301410c.4b50: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll)
302410c.4b50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll
303410c.4b50: supR3HardenedDllNotificationCallback: load 00007ffcbad70000 LB 0x0009e000 C:\WINDOWS\System32\sechost.dll [fFlags=0x0]
304410c.4b50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'rpcrt4.dll'.
305410c.4b50: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\sechost.dll)
306410c.4b50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\sechost.dll
307410c.4b50: '\Device\HarddiskVolume4\Windows\System32\ntdll.dll' has no imports
308410c.4b50: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\ntdll.dll)
309410c.4b50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\ntdll.dll
310410c.4b50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
311410c.4b50: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
312410c.4b50: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
313410c.4b50: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\ntdll.dll (Input=ntdll.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
314410c.4b50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcbb170000 'C:\WINDOWS\System32\ntdll.dll'
315410c.4b50: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffcbb1e5640 pvNtTerminateThread=00007ffcbb2100b0
316410c.4b50: supR3HardenedWinDoReSpawn(2): New child 3c64.1644 [kernel32].
317410c.4b50: supR3HardenedWinReSpawn: NtSetInformationThread/ThreadHideFromDebugger failed: 0xc0000022 (harmless)
318410c.4b50: supR3HardNtChildGatherData: PebBaseAddress=000000000086d000 cbPeb=0x388
319410c.4b50: supR3HardNtPuChFindNtdll: uNtDllParentAddr=00007ffcbb170000 uNtDllChildAddr=00007ffcbb170000
320410c.4b50: supR3HardenedWinSetupChildInit: uLdrInitThunk=00007ffcbb1e5640
321410c.4b50: supR3HardenedWinSetupChildInit: Start child.
322410c.4b50: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
323410c.4b50: supR3HardNtChildPurify: Startup delay kludge #1/0: 518 ms, 60 sleeps
324410c.4b50: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
325410c.4b50: *0000000000000000-00000000007affff 0x0001/0x0000 0x0000000
326410c.4b50: *00000000007b0000-00000000007cffff 0x0004/0x0004 0x0020000
327410c.4b50: *00000000007d0000-00000000007e9fff 0x0002/0x0002 0x0040000
328410c.4b50: 00000000007ea000-00000000007effff 0x0001/0x0000 0x0000000
329410c.4b50: *00000000007f0000-00000000007f3fff 0x0002/0x0002 0x0040000
330410c.4b50: 00000000007f4000-00000000007fffff 0x0001/0x0000 0x0000000
331410c.4b50: *0000000000800000-000000000086cfff 0x0000/0x0004 0x0020000
332410c.4b50: 000000000086d000-000000000086ffff 0x0004/0x0004 0x0020000
333410c.4b50: 0000000000870000-00000000009fffff 0x0000/0x0004 0x0020000
334410c.4b50: *0000000000a00000-0000000000afafff 0x0000/0x0004 0x0020000
335410c.4b50: 0000000000afb000-0000000000afdfff 0x0104/0x0004 0x0020000
336410c.4b50: 0000000000afe000-0000000000afffff 0x0004/0x0004 0x0020000
337410c.4b50: *0000000000b00000-0000000000b01fff 0x0004/0x0004 0x0020000
338410c.4b50: 0000000000b02000-000000007ffdffff 0x0001/0x0000 0x0000000
339410c.4b50: *000000007ffe0000-000000007ffe0fff 0x0002/0x0002 0x0020000
340410c.4b50: 000000007ffe1000-000000007ffe6fff 0x0001/0x0000 0x0000000
341410c.4b50: *000000007ffe7000-000000007ffe7fff 0x0002/0x0002 0x0020000
342410c.4b50: 000000007ffe8000-00007ff54a87ffff 0x0001/0x0000 0x0000000
343410c.4b50: *00007ff54a880000-00007ff54a880fff 0x0002/0x0002 0x0040000
344410c.4b50: 00007ff54a881000-00007ff54a88ffff 0x0001/0x0000 0x0000000
345410c.4b50: *00007ff54a890000-00007ff54a8b2fff 0x0002/0x0002 0x0040000
346410c.4b50: 00007ff54a8b3000-00007ff7d61fffff 0x0001/0x0000 0x0000000
347410c.4b50: *00007ff7d6200000-00007ff7d6200fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
348410c.4b50: 00007ff7d6201000-00007ff7d6273fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
349410c.4b50: 00007ff7d6274000-00007ff7d6274fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
350410c.4b50: 00007ff7d6275000-00007ff7d62bbfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
351410c.4b50: 00007ff7d62bc000-00007ff7d62bcfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
352410c.4b50: 00007ff7d62bd000-00007ff7d62bdfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
353410c.4b50: 00007ff7d62be000-00007ff7d62c2fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
354410c.4b50: 00007ff7d62c3000-00007ff7d62c3fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
355410c.4b50: 00007ff7d62c4000-00007ff7d62c4fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
356410c.4b50: 00007ff7d62c5000-00007ff7d62c8fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
357410c.4b50: 00007ff7d62c9000-00007ff7d6311fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
358410c.4b50: 00007ff7d6312000-00007ffcbb16ffff 0x0001/0x0000 0x0000000
359410c.4b50: *00007ffcbb170000-00007ffcbb170fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
360410c.4b50: 00007ffcbb171000-00007ffcbb287fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
361410c.4b50: 00007ffcbb288000-00007ffcbb2cefff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
362410c.4b50: 00007ffcbb2cf000-00007ffcbb2d9fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
363410c.4b50: 00007ffcbb2da000-00007ffcbb2e7fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
364410c.4b50: 00007ffcbb2e8000-00007ffcbb2e8fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
365410c.4b50: 00007ffcbb2e9000-00007ffcbb2ebfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
366410c.4b50: 00007ffcbb2ec000-00007ffcbb35cfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
367410c.4b50: 00007ffcbb35d000-00007ffffffeffff 0x0001/0x0000 0x0000000
368410c.4b50: VirtualBoxVM.exe: timestamp 0x5c4b51f3 (rc=VINF_SUCCESS)
369410c.4b50: '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
370410c.4b50: '\Device\HarddiskVolume4\Windows\System32\ntdll.dll' has no imports
371410c.4b50: supR3HardNtChildPurify: Done after 590 ms and 0 fixes (loop #0).
3723c64.1644: Log file opened: 6.0.4r128413 g_hStartupLog=0000000000000004 g_uNtVerCombined=0xa0456300
3733c64.1644: supR3HardenedVmProcessInit: uNtDllAddr=00007ffcbb170000 g_uNtVerCombined=0xa0456300
3743c64.1644: ntdll.dll: timestamp 0xe8b54827 (rc=VINF_SUCCESS)
3753c64.1644: New simple heap: #1 0000000000c10000 LB 0x400000 (for 2019328 allocation)
3763c64.1644: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox'
3773c64.1644: System32: \Device\HarddiskVolume4\Windows\System32
3783c64.1644: WinSxS: \Device\HarddiskVolume4\Windows\WinSxS
3793c64.1644: KnownDllPath: C:\WINDOWS\System32
3803c64.1644: supR3HardenedVmProcessInit: Opening vboxdrv...
381410c.4b50: supR3HardenedEarlyCompact: Removed heap 1 (0x00000001000000 LB 0x400000)
382410c.4b50: supR3HardNtEnableThreadCreation:
3833c64.1644: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
3843c64.1644: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
3853c64.1644: Registered Dll notification callback with NTDLL.
3863c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\kernel32.dll)
3873c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\kernel32.dll
3883c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\KERNEL32.DLL (Input=KERNEL32.DLL, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000004001:<flags> [calling]
3893c64.1644: supR3HardenedDllNotificationCallback: load 00007ffcb80b0000 LB 0x00293000 C:\WINDOWS\System32\KERNELBASE.dll [fFlags=0x0]
3903c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\KernelBase.dll)
3913c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\KernelBase.dll
3923c64.1644: supR3HardenedDllNotificationCallback: load 00007ffcba7c0000 LB 0x000b3000 C:\WINDOWS\System32\KERNEL32.DLL [fFlags=0x0]
3933c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
3943c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcba7c0000 'C:\WINDOWS\System32\KERNEL32.DLL'
3953c64.1644: supR3HardenedDllNotificationCallback: load 00007ff7d6200000 LB 0x00112000 C:\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe [fFlags=0x0]
3963c64.1644: '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
3973c64.1644: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe)
3983c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
3993c64.1644: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffcbb1e5640 pvNtTerminateThread=00007ffcbb2100b0
400410c.4b50: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 93 ms.
4013c64.1644: \SystemRoot\System32\ntdll.dll:
4023c64.1644: CreationTime: 2018-12-30T02:31:21.439974200Z
4033c64.1644: LastWriteTime: 2018-12-30T02:31:21.455594900Z
4043c64.1644: ChangeTime: 2019-01-08T21:05:01.868444500Z
4053c64.1644: FileAttributes: 0x20
4063c64.1644: Size: 0x1e7010
4073c64.1644: NT Headers: 0xe0
4083c64.1644: Timestamp: 0xe8b54827
4093c64.1644: Machine: 0x8664 - amd64
4103c64.1644: Timestamp: 0xe8b54827
4113c64.1644: Image Version: 10.0
4123c64.1644: SizeOfImage: 0x1ed000 (2019328)
4133c64.1644: Resource Dir: 0x17d000 LB 0x6ea08
4143c64.1644: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
4153c64.1644: [Raw version resource data: 0x17d0f0 LB 0x380, codepage 0x0 (reserved 0x0)]
4163c64.1644: ProductName: Microsoft® Windows® Operating System
4173c64.1644: ProductVersion: 10.0.17763.194
4183c64.1644: FileVersion: 10.0.17763.194 (WinBuild.160101.0800)
4193c64.1644: FileDescription: NT Layer DLL
4203c64.1644: \SystemRoot\System32\kernel32.dll:
4213c64.1644: CreationTime: 2018-09-15T07:28:44.342269900Z
4223c64.1644: LastWriteTime: 2018-09-15T07:28:44.342269900Z
4233c64.1644: ChangeTime: 2018-12-30T02:37:12.140802400Z
4243c64.1644: FileAttributes: 0x20
4253c64.1644: Size: 0xb1380
4263c64.1644: NT Headers: 0xe8
4273c64.1644: Timestamp: 0x65614da1
4283c64.1644: Machine: 0x8664 - amd64
4293c64.1644: Timestamp: 0x65614da1
4303c64.1644: Image Version: 10.0
4313c64.1644: SizeOfImage: 0xb3000 (733184)
4323c64.1644: Resource Dir: 0xb1000 LB 0x520
4333c64.1644: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
4343c64.1644: [Raw version resource data: 0xb10b0 LB 0x3a4, codepage 0x0 (reserved 0x0)]
4353c64.1644: ProductName: Microsoft® Windows® Operating System
4363c64.1644: ProductVersion: 10.0.17763.1
4373c64.1644: FileVersion: 10.0.17763.1 (WinBuild.160101.0800)
4383c64.1644: FileDescription: Windows NT BASE API Client DLL
4393c64.1644: \SystemRoot\System32\KernelBase.dll:
4403c64.1644: CreationTime: 2018-12-30T02:31:21.205655900Z
4413c64.1644: LastWriteTime: 2018-12-30T02:31:21.236896100Z
4423c64.1644: ChangeTime: 2019-01-08T21:05:01.867446600Z
4433c64.1644: FileAttributes: 0x20
4443c64.1644: Size: 0x293cc8
4453c64.1644: NT Headers: 0xf8
4463c64.1644: Timestamp: 0x1659a33b
4473c64.1644: Machine: 0x8664 - amd64
4483c64.1644: Timestamp: 0x1659a33b
4493c64.1644: Image Version: 10.0
4503c64.1644: SizeOfImage: 0x293000 (2699264)
4513c64.1644: Resource Dir: 0x26f000 LB 0x548
4523c64.1644: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
4533c64.1644: [Raw version resource data: 0x26f0b0 LB 0x3bc, codepage 0x0 (reserved 0x0)]
4543c64.1644: ProductName: Microsoft® Windows® Operating System
4553c64.1644: ProductVersion: 10.0.17763.134
4563c64.1644: FileVersion: 10.0.17763.134 (WinBuild.160101.0800)
4573c64.1644: FileDescription: Windows NT BASE API Client DLL
4583c64.1644: \SystemRoot\System32\apisetschema.dll:
4593c64.1644: CreationTime: 2018-09-15T07:28:25.403122600Z
4603c64.1644: LastWriteTime: 2018-09-15T07:28:25.403122600Z
4613c64.1644: ChangeTime: 2018-12-30T02:29:00.950166300Z
4623c64.1644: FileAttributes: 0x20
4633c64.1644: Size: 0x1c738
4643c64.1644: NT Headers: 0xd0
4653c64.1644: Timestamp: 0x33775897
4663c64.1644: Machine: 0x8664 - amd64
4673c64.1644: Timestamp: 0x33775897
4683c64.1644: Image Version: 10.0
4693c64.1644: SizeOfImage: 0x1d000 (118784)
4703c64.1644: Resource Dir: 0x1c000 LB 0x408
4713c64.1644: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
4723c64.1644: [Raw version resource data: 0x1c060 LB 0x3a8, codepage 0x0 (reserved 0x0)]
4733c64.1644: ProductName: Microsoft® Windows® Operating System
4743c64.1644: ProductVersion: 10.0.17763.1
4753c64.1644: FileVersion: 10.0.17763.1 (WinBuild.160101.0800)
4763c64.1644: FileDescription: ApiSet Schema DLL
4773c64.1644: NtOpenDirectoryObject failed on \Driver: 0xc0000022
4783c64.1644: supR3HardenedWinFindAdversaries: 0x8000
4793c64.1644: \SystemRoot\System32\drivers\cyprotectdrv64.sys:
4803c64.1644: CreationTime: 2018-12-30T23:56:45.646933300Z
4813c64.1644: LastWriteTime: 2019-01-07T19:47:35.388882000Z
4823c64.1644: ChangeTime: 2019-01-30T22:49:57.834123800Z
4833c64.1644: FileAttributes: 0x20
4843c64.1644: Size: 0x332a8
4853c64.1644: NT Headers: 0xf8
4863c64.1644: Timestamp: 0x5c05c934
4873c64.1644: Machine: 0x8664 - amd64
4883c64.1644: Timestamp: 0x5c05c934
4893c64.1644: Image Version: 6.1
4903c64.1644: SizeOfImage: 0x134000 (1261568)
4913c64.1644: Resource Dir: 0x132000 LB 0x2f0
4923c64.1644: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
4933c64.1644: [Raw version resource data: 0x132060 LB 0x28c, codepage 0x0 (reserved 0x0)]
4943c64.1644: ProductName: CylancePROTECT
4953c64.1644: ProductVersion: 2.0.1510.8
4963c64.1644: FileVersion: 2.0.1510.8
4973c64.1644: FileDescription: Cylance Protect Driver
4983c64.1644: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox'
4993c64.1644: Calling main()
5003c64.1644: SUPR3HardenedMain: pszProgName=VirtualBoxVM fFlags=0x2
5013c64.1644: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox'
5023c64.1644: '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
5033c64.1644: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe)
5043c64.1644: SUPR3HardenedMain: Final process, opening VBoxDrv...
5053c64.1644: supR3HardenedEarlyCompact: Removed heap 1 (0x00000000c10000 LB 0x400000)
5063c64.1644: supR3HardNtEnableThreadCreation:
5073c64.1644: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSupLib.dll)
5083c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSupLib.dll
5093c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
5103c64.1644: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
5113c64.1644: supR3HardenedDllNotificationCallback: load 00007ffcb4790000 LB 0x00005000 C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL [fFlags=0x0]
5123c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
5133c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
5143c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
5153c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb4790000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
5163c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
5173c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
5183c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb4790000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
5193c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb4790000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
5203c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
5213c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msasn1.dll'.
5223c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'crypt32.dll'.
5233c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #27 'rpcrt4.dll'.
5243c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\wintrust.dll)
5253c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\wintrust.dll
5263c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
5273c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
5283c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll)
5293c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll
5303c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
5313c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume4\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
5323c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #34 'msasn1.dll'.
5333c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\crypt32.dll)
5343c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\crypt32.dll
5353c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
5363c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume4\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
5373c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\msasn1.dll)
5383c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\msasn1.dll
5393c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
5403c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
5413c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\msvcrt.dll)
5423c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\msvcrt.dll
5433c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
5443c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume4\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
5453c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
5463c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
5473c64.1644: supR3HardenedDllNotificationCallback: load 00007ffcb8aa0000 LB 0x0009e000 C:\WINDOWS\System32\msvcrt.dll [fFlags=0x0]
5483c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
5493c64.1644: supR3HardenedDllNotificationCallback: load 00007ffcb71d0000 LB 0x00012000 C:\WINDOWS\System32\MSASN1.dll [fFlags=0x0]
5503c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
5513c64.1644: supR3HardenedDllNotificationCallback: load 00007ffcb7d80000 LB 0x000fc000 C:\WINDOWS\System32\ucrtbase.dll [fFlags=0x0]
5523c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\ucrtbase.dll)
5533c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\ucrtbase.dll
5543c64.1644: supR3HardenedDllNotificationCallback: load 00007ffcb7e80000 LB 0x001db000 C:\WINDOWS\System32\CRYPT32.dll [fFlags=0x0]
5553c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
5563c64.1644: supR3HardenedDllNotificationCallback: load 00007ffcb9140000 LB 0x00122000 C:\WINDOWS\System32\RPCRT4.dll [fFlags=0x0]
5573c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
5583c64.1644: supR3HardenedDllNotificationCallback: load 00007ffcb7a10000 LB 0x00058000 C:\WINDOWS\System32\Wintrust.dll [fFlags=0x0]
5593c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
5603c64.1644: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
5613c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
5623c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb80b0000 'api-ms-win-core-synch-l1-2-0'
5633c64.1644: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-fibers-l1-1-1) -> 0x0, fPresent=1
5643c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
5653c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb80b0000 'api-ms-win-core-fibers-l1-1-1'
5663c64.1644: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-fibers-l1-1-1) -> 0x0, fPresent=1
5673c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
5683c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb80b0000 'api-ms-win-core-fibers-l1-1-1'
5693c64.1644: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
5703c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
5713c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb80b0000 'api-ms-win-core-synch-l1-2-0'
5723c64.1644: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-l1-2-1) -> 0x0, fPresent=1
5733c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-l1-2-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
5743c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb80b0000 'api-ms-win-core-localization-l1-2-1'
5753c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7a10000 'C:\WINDOWS\system32\Wintrust.dll'
5763c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\bcrypt.dll)
5773c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\bcrypt.dll
5783c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\bcrypt.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
5793c64.1644: supR3HardenedDllNotificationCallback: load 00007ffcb8370000 LB 0x00026000 C:\WINDOWS\System32\bcrypt.dll [fFlags=0x0]
5803c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
5813c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb8370000 'C:\WINDOWS\system32\bcrypt.dll'
5823c64.1644: bcrypt.dll loaded at 00007ffcb8370000, BCryptOpenAlgorithmProvider at 00007ffcb8374d60, preloading providers:
5833c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\bcryptprimitives.dll)
5843c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\bcryptprimitives.dll
5853c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\bcryptprimitives.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
5863c64.1644: supR3HardenedDllNotificationCallback: load 00007ffcb7240000 LB 0x0007e000 C:\WINDOWS\System32\bcryptprimitives.dll [fFlags=0x0]
5873c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
5883c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7240000 'C:\WINDOWS\system32\bcryptprimitives.dll'
5893c64.1644: BCryptOpenAlgorithmProvider(,'MD2',0,0) -> 0x0 (hAlgo=00000000011dedc0)
5903c64.1644: BCryptOpenAlgorithmProvider(,'MD4',0,0) -> 0x0 (hAlgo=00000000011dfb20)
5913c64.1644: BCryptOpenAlgorithmProvider(,'MD5',0,0) -> 0x0 (hAlgo=00000000011dfe20)
5923c64.1644: BCryptOpenAlgorithmProvider(,'SHA1',0,0) -> 0x0 (hAlgo=00000000011e0120)
5933c64.1644: BCryptOpenAlgorithmProvider(,'SHA256',0,0) -> 0x0 (hAlgo=00000000011e0420)
5943c64.1644: BCryptOpenAlgorithmProvider(,'SHA512',0,0) -> 0x0 (hAlgo=00000000011e0720)
5953c64.1644: BCryptOpenAlgorithmProvider(,'RSA',0,0) -> 0x0 (hAlgo=00000000011e0a20)
5963c64.1644: BCryptOpenAlgorithmProvider(,'DSA',0,0) -> 0x0 (hAlgo=00000000011e0d20)
5973c64.1644: supR3HardenedDllNotificationCallback: load 00007ffcb7d60000 LB 0x00017000 C:\WINDOWS\System32\CRYPTSP.dll [fFlags=0x0]
5983c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\cryptsp.dll)
5993c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\cryptsp.dll
6003c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'bcrypt.dll'.
6013c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\rsaenh.dll)
6023c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\rsaenh.dll
6033c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
6043c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume4\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
6053c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
6063c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
6073c64.1644: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
6083c64.1644: supR3HardenedDllNotificationCallback: load 00007ffcb6520000 LB 0x00033000 C:\WINDOWS\system32\rsaenh.dll [fFlags=0x0]
6093c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
6103c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
6113c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'bcryptprimitives.dll'.
6123c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\cryptbase.dll)
6133c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\cryptbase.dll
6143c64.1644: supR3HardenedDllNotificationCallback: load 00007ffcb6ad0000 LB 0x0000c000 C:\WINDOWS\SYSTEM32\CRYPTBASE.dll [fFlags=0x0]
6153c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\cryptbase.dll [lacks WinVerifyTrust]
6163c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
6173c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcryptprimitives.dll'...
6183c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcryptprimitives.dll' -> '\Device\HarddiskVolume4\Windows\System32\bcryptprimitives.dll' [rcNtRedir=0xc0150008]
6193c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
6203c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
6213c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcba7c0000 'C:\WINDOWS\System32\kernel32.dll'
6223c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
6233c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\WINTRUST.DLL (Input=WINTRUST.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
6243c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7a10000 'C:\WINDOWS\System32\WINTRUST.DLL'
6253c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
6263c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\CRYPT32.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
6273c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\CRYPT32.dll'
6283c64.1644: supR3HardenedDllNotificationCallback: load 00007ffcb87f0000 LB 0x0001d000 C:\WINDOWS\System32\imagehlp.dll [fFlags=0x0]
6293c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\imagehlp.dll)
6303c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\imagehlp.dll
6313c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
6323c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
6333c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
6343c64.1644: supR3HardenedDllNotificationCallback: load 00007ffcbad70000 LB 0x0009e000 C:\WINDOWS\System32\sechost.dll [fFlags=0x0]
6353c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'rpcrt4.dll'.
6363c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\sechost.dll)
6373c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\sechost.dll
6383c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
6393c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'rpcrt4.dll'.
6403c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\gpapi.dll)
6413c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\gpapi.dll
6423c64.1644: supR3HardenedDllNotificationCallback: load 00007ffcb5e20000 LB 0x00022000 C:\WINDOWS\SYSTEM32\gpapi.dll [fFlags=0x0]
6433c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gpapi.dll [lacks WinVerifyTrust]
6443c64.1644: supR3HardenedDllNotificationCallback: load 00007ffcb7210000 LB 0x00024000 C:\WINDOWS\System32\profapi.dll [fFlags=0x0]
6453c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\profapi.dll)
6463c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\profapi.dll
6473c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
6483c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'crypt32.dll'.
6493c64.1644: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\System32\cryptnet.dll)
6503c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\cryptnet.dll
6513c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
6523c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume4\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
6533c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
6543c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
6553c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
6563c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
6573c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
6583c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
6593c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
6603c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
6613c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
6623c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
6633c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
6643c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
6653c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
6663c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (Input=cryptnet.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
6673c64.1644: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6683c64.1644: supR3HardenedDllNotificationCallback: load 00007ffc9cfa0000 LB 0x0002f000 C:\WINDOWS\System32\cryptnet.dll [fFlags=0x0]
6693c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6703c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6713c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
6723c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc9cfa0000 'C:\WINDOWS\System32\cryptnet.dll'
6733c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6743c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
6753c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc9cfa0000 'C:\WINDOWS\System32\cryptnet.dll'
6763c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6773c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
6783c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc9cfa0000 'C:\WINDOWS\System32\cryptnet.dll'
6793c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6803c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
6813c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc9cfa0000 'C:\WINDOWS\System32\cryptnet.dll'
6823c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6833c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
6843c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc9cfa0000 'C:\WINDOWS\System32\cryptnet.dll'
6853c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6863c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
6873c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc9cfa0000 'C:\WINDOWS\System32\cryptnet.dll'
6883c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6893c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc9cfa0000 'C:\WINDOWS\System32\cryptnet.dll'
6903c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6913c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc9cfa0000 'C:\WINDOWS\System32\cryptnet.dll'
6923c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6933c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc9cfa0000 'C:\WINDOWS\System32\cryptnet.dll'
6943c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6953c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc9cfa0000 'C:\WINDOWS\System32\cryptnet.dll'
6963c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
6973c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc9cfa0000 'C:\WINDOWS\System32\cryptnet.dll'
6983c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc9cfa0000 'C:\WINDOWS\System32\cryptnet.dll'
6993c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
7003c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc9cfa0000 'C:\Windows\System32\cryptnet.dll'
7013c64.1644: supR3HardenedDllNotificationCallback: load 00007ffcb8520000 LB 0x000a3000 C:\WINDOWS\System32\advapi32.dll [fFlags=0x0]
7023c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
7033c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'sechost.dll'.
7043c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #27 'rpcrt4.dll'.
7053c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\advapi32.dll)
7063c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\advapi32.dll
7073c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
7083c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
7093c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
7103c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
7113c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'sechost.dll'...
7123c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'sechost.dll' -> '\Device\HarddiskVolume4\Windows\System32\sechost.dll' [rcNtRedir=0xc0150008]
7133c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\sechost.dll [lacks WinVerifyTrust]
7143c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
7153c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
7163c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
7173c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
7183c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
7193c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
7203c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
7213c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
7223c64.1644: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000000 pwszName=\SystemRoot\System32\ntdll.dll
7233c64.1644: supR3HardNtViCallWinVerifyTrustCatFile: New context 00000000012655a0
7243c64.1644: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000012655a0
7253c64.1644: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=E118BAE0A2CBC497F05FE519F5B8FB6FCD99D346
7263c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
7273c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\rpcrt4.dll (Input=rpcrt4.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
7283c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb9140000 'C:\WINDOWS\System32\rpcrt4.dll'
7293c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
7303c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
7313c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
7323c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
7333c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
7343c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
7353c64.1644: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_352_for_KB4483235~31bf3856ad364e35~amd64~~10.0.1.1.cat'; file='\SystemRoot\System32\ntdll.dll'
7363c64.1644: g_pfnWinVerifyTrust=00007ffcb7a16370
7373c64.1644: supR3HardenedScreenImage/preload: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll [redoing WinVerifyTrust]
7383c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
7393c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
7403c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
7413c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
7423c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
7433c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
7443c64.1644: supR3HardenedScreenImage/preload: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\crypt32.dll'
7453c64.1644: supR3HardenedScreenImage/preload: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [redoing WinVerifyTrust]
7463c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
7473c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
7483c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
7493c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll
7503c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
7513c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
7523c64.1644: supR3HardenedScreenImage/preload: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\wintrust.dll'
7533c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
7543c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
7553c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
7563c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
7573c64.1644: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\advapi32.dll'
7583c64.1644: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000398 pwszName=\Device\HarddiskVolume4\Windows\System32\cryptnet.dll
7593c64.1644: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000012655a0
7603c64.1644: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000012655a0
7613c64.1644: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=A71FAF93E7F6555CF5752D6A603A870E378E49E6
7623c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
7633c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
7643c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
7653c64.1644: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0316~31bf3856ad364e35~amd64~~10.0.17763.1.cat'; file='\Device\HarddiskVolume4\Windows\System32\cryptnet.dll'
7663c64.1644: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
7673c64.1644: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\cryptnet.dll'
7683c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
7693c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
7703c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
7713c64.1644: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\profapi.dll'
7723c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
7733c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
7743c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
7753c64.1644: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\gpapi.dll'
7763c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
7773c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
7783c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
7793c64.1644: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\sechost.dll'
7803c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
7813c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
7823c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
7833c64.1644: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\imagehlp.dll'
7843c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
7853c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
7863c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
7873c64.1644: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\cryptbase.dll'
7883c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
7893c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
7903c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll
7913c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
7923c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
7933c64.1644: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\rsaenh.dll'
7943c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll
7953c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
7963c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
7973c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
7983c64.1644: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\cryptsp.dll'
7993c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
8003c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
8013c64.1644: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\bcryptprimitives.dll'
8023c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
8033c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
8043c64.1644: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\bcrypt.dll'
8053c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
8063c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
8073c64.1644: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\ucrtbase.dll'
8083c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
8093c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
8103c64.1644: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll'
8113c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
8123c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
8133c64.1644: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\msasn1.dll'
8143c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
8153c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
8163c64.1644: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll'
8173c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
8183c64.1644: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 24202) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSupLib.dll'
8193c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
8203c64.1644: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 24202) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe'
8213c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
8223c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
8233c64.1644: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\KernelBase.dll'
8243c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
8253c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
8263c64.1644: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\kernel32.dll'
8273c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\system32\crypt32.dll'
8283c64.1644: supR3HardenedWinIsDesiredRootCA: Adding 0x5ad46780fa5df300 DC=com, DC=microsoft, CN=Microsoft Root Certificate Authority
8293c64.1644: supR3HardenedWinIsDesiredRootCA: Adding 0xea5386456178582b C=ZA, ST=Western Cape, L=Durbanville, O=Thawte, OU=Thawte Certification, CN=Thawte Timestamping CA
8303c64.1644: supR3HardenedWinIsDesiredRootCA: Adding 0x3be670c1bd02a900 OU=Copyright (c) 1997 Microsoft Corp., OU=Microsoft Corporation, CN=Microsoft Root Authority
8313c64.1644: supR3HardenedWinIsDesiredRootCA: Adding 0xe991ee72b03db500 C=US, O=Symantec Corporation, CN=Symantec Enterprise Mobile Root for Microsoft
8323c64.1644: supR3HardenedWinIsDesiredRootCA: Adding 0x4d3835aa4180b200 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2011
8333c64.1644: supR3HardenedWinIsDesiredRootCA: Adding 0x646e3fe3ba08df00 C=US, O=MSFT, CN=Microsoft Authenticode(tm) Root Authority
8343c64.1644: supR3HardenedWinIsDesiredRootCA: Adding 0xeaf38b956934d200 CN=DESKTOP-TS00JCV
8353c64.1644: supR3HardenedWinIsDesiredRootCA: Adding 0xece4e4289e08b900 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010
8363c64.1644: supR3HardenedWinIsDesiredRootCA: Adding 0xf3bb4d7e894b420 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft ECC TS Root Certificate Authority 2018
8373c64.1644: supR3HardenedWinIsDesiredRootCA: Adding 0x43a9cc371ff5385a O=Microsoft Trust Network, OU=Microsoft Corporation, OU=Microsoft Time Stamping Service Root, OU=Copyright (c) 1997 Microsoft Corp.
8383c64.1644: supR3HardenedWinIsDesiredRootCA: Adding 0x2e2d2c7c68f0202e O=VeriSign Trust Network, OU=VeriSign, Inc., OU=VeriSign Time Stamping Service Root, OU=NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.
8393c64.1644: supR3HardenedWinIsDesiredRootCA: Adding 0xcec3d46562b9be8e C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft ECC Product Root Certificate Authority 2018
8403c64.1644: supR3HardenedWinIsDesiredRootCA: Adding 0xd8dbfb2c27bfb200 C=US, O=thawte, Inc., OU=Certification Services Division, OU=(c) 2008 thawte, Inc. - For authorized use only, CN=thawte Primary Root CA - G3
8413c64.1644: supR3HardenedWinIsDesiredRootCA: Adding 0x61a3a33f81aace00 C=US, ST=UT, L=Salt Lake City, O=The USERTRUST Network, OU=http://www.usertrust.com, CN=UTN-USERFirst-Object
8423c64.1644: supR3HardenedWinIsDesiredRootCA: Adding 0x6b7bdc34cd37bb00 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root G2
8433c64.1644: supR3HardenedWinIsDesiredRootCA: Adding 0x57ba5395b561bf00 C=BM, O=QuoVadis Limited, OU=Root Certification Authority, CN=QuoVadis Root Certification Authority
8443c64.1644: supR3HardenedWinIsDesiredRootCA: Adding 0xf4fd306318ccda00 C=US, O=GeoTrust Inc., CN=GeoTrust Global CA
8453c64.1644: supR3HardenedWinIsDesiredRootCA: Adding 0x83085097e9afdf00 O=Digital Signature Trust Co., CN=DST Root CA X3
8463c64.1644: supR3HardenedWinIsDesiredRootCA: Adding 0x780679907625cc00 OU=GlobalSign Root CA - R3, O=GlobalSign, CN=GlobalSign
8473c64.1644: supR3HardenedWinIsDesiredRootCA: Adding 0x3d98ab22bb04a300 C=IE, O=Baltimore, OU=CyberTrust, CN=Baltimore CyberTrust Root
8483c64.1644: supR3HardenedWinIsDesiredRootCA: Adding 0x9403a4b8727eb000 C=TW, O=TAIWAN-CA, OU=Root CA, CN=TWCA Root Certification Authority
8493c64.1644: supR3HardenedWinIsDesiredRootCA: Adding 0xd944bca189a00 C=BM, O=QuoVadis Limited, CN=QuoVadis Root CA 2
8503c64.1644: supR3HardenedWinIsDesiredRootCA: Adding 0x8ff6fc03c1edbd00 C=US, ST=Arizona, L=Scottsdale, O=Starfield Technologies, Inc., CN=Starfield Root Certificate Authority - G2
8513c64.1644: supR3HardenedWinIsDesiredRootCA: Adding 0xc6fa4243b695b600 C=US, O=Entrust, Inc., OU=www.entrust.net/CPS is incorporated by reference, OU=(c) 2006 Entrust, Inc., CN=Entrust Root Certification Authority
8523c64.1644: supR3HardenedWinIsDesiredRootCA: Adding 0xa3ce8d99e60eda00 C=BE, O=GlobalSign nv-sa, OU=Root CA, CN=GlobalSign Root CA
8533c64.1644: supR3HardenedWinIsDesiredRootCA: Adding 0x560ad29254e89100 C=GB, ST=Greater Manchester, L=Salford, O=COMODO CA Limited, CN=COMODO RSA Certification Authority
8543c64.1644: supR3HardenedWinIsDesiredRootCA: Adding 0xa671e9fec832b700 C=US, O=Starfield Technologies, Inc., OU=Starfield Class 2 Certification Authority
8553c64.1644: supR3HardenedWinIsDesiredRootCA: Adding 0xa8de7211e13be200 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root CA
8563c64.1644: supR3HardenedWinIsDesiredRootCA: Adding 0xd45980fbf0a0ac00 C=US, O=thawte, Inc., OU=Certification Services Division, OU=(c) 2006 thawte, Inc. - For authorized use only, CN=thawte Primary Root CA
8573c64.1644: supR3HardenedWinIsDesiredRootCA: Adding 0xef62113787ebace5 C=US, O=GeoTrust Inc., OU=(c) 2007 GeoTrust Inc. - For authorized use only, CN=GeoTrust Primary Certification Authority - G2
8583c64.1644: supR3HardenedWinIsDesiredRootCA: Adding 0xc9edb72b684ba00 C=US, O=Entrust, Inc., OU=See www.entrust.net/legal-terms, OU=(c) 2009 Entrust, Inc. - for authorized use only, CN=Entrust Root Certification Authority - G2
8593c64.1644: supR3HardenedWinIsDesiredRootCA: Adding 0xf5cd95e581a4ab00 C=US, O=SecureTrust Corporation, CN=SecureTrust CA
8603c64.1644: supR3HardenedWinIsDesiredRootCA: Adding 0x6f2ebe0e24cfa600 OU=GlobalSign Root CA - R2, O=GlobalSign, CN=GlobalSign
8613c64.1644: supR3HardenedWinIsDesiredRootCA: Adding 0x14018a1bf29e595c C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority
8623c64.1644: supR3HardenedWinIsDesiredRootCA: Adding 0x7c4fd32ec1b1ce00 C=PL, O=Unizeto Sp. z o.o., CN=Certum CA
8633c64.1644: supR3HardenedWinIsDesiredRootCA: Adding 0xd4fbe673e5ccc600 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA
8643c64.1644: supR3HardenedWinIsDesiredRootCA: Adding 0xef477acf4ab2d300 C=DE, O=D-Trust GmbH, CN=D-TRUST Root Class 3 CA 2 2009
8653c64.1644: supR3HardenedWinIsDesiredRootCA: Adding 0x1b8578514b74ac00 C=US, O=WFA Hotspot 2.0, CN=Hotspot 2.0 Trust Root CA - 03
8663c64.1644: supR3HardenedWinIsDesiredRootCA: Adding 0xb28612a94b4dad00 O=Entrust.net, OU=www.entrust.net/CPS_2048 incorp. by ref. (limits liab.), OU=(c) 1999 Entrust.net Limited, CN=Entrust.net Certification Authority (2048)
8673c64.1644: supR3HardenedWinIsDesiredRootCA: Adding 0x357a29080824af00 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2006 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G5
8683c64.1644: supR3HardenedWinIsDesiredRootCA: Adding 0x59faf1086271bf00 C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com, Inc., CN=Go Daddy Root Certificate Authority - G2
8693c64.1644: supR3HardenedWinIsDesiredRootCA: Adding 0x466cbc09db88c100 C=IL, O=StartCom Ltd., OU=Secure Digital Certificate Signing, CN=StartCom Certification Authority
8703c64.1644: supR3HardenedWinIsDesiredRootCA: Adding 0x3401b15e3761c700 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2008 VeriSign, Inc. - For authorized use only, CN=VeriSign Universal Root Certification Authority
8713c64.1644: supR3HardenedWinIsDesiredRootCA: Adding 0x491857ead79dde00 C=US, O=The Go Daddy Group, Inc., OU=Go Daddy Class 2 Certification Authority
8723c64.1644: supR3HardenedWinIsDesiredRootCA: Adding 0x1f78fc529cbacb00 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 1999 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G3
8733c64.1644: supR3HardenedWinIsDesiredRootCA: Adding 0xc2ba72a37dfbe300 C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Trusted Network CA
8743c64.1644: supR3HardenedWinIsDesiredRootCA: Adding 0x8043e4ce150ead00 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID Root CA
8753c64.1644: supR3HardenedWinIsDesiredRootCA: Adding 0xf2e6331af7b700 C=SE, O=AddTrust AB, OU=AddTrust External TTP Network, CN=AddTrust External CA Root
8763c64.1644: supR3HardenedWinRetrieveTrustedRootCAs: cAdded=48
8773c64.1644: SUPR3HardenedMain: Load Runtime...
8783c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
8793c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
8803c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
8813c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rpcrt4.dll'.
8823c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ws2_32.dll'.
8833c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll) WinVerifyTrust
8843c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
8853c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
8863c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
8873c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
8883c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
8893c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'rpcrt4.dll'.
8903c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\ws2_32.dll) WinVerifyTrust
8913c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\ws2_32.dll
8923c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
8933c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
8943c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll
8953c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
8963c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
8973c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
8983c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
8993c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll
9003c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
9013c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
9023c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll) WinVerifyTrust
9033c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll
9043c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
9053c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
9063c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
9073c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
9083c64.1644: Detected WinVerifyTrust recursion: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll'.
9093c64.1644: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll)
9103c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll
9113c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
9123c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll) WinVerifyTrust
9133c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000a01:<flags> [calling]
9143c64.1644: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
9153c64.1644: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll [avoiding WinVerifyTrust]
9163c64.1644: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll
9173c64.1644: supR3HardenedDllNotificationCallback: load 000000006cd40000 LB 0x000d2000 C:\Program Files\Oracle\VirtualBox\MSVCR100.dll [fFlags=0x0]
9183c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll [avoiding WinVerifyTrust]
9193c64.1644: supR3HardenedDllNotificationCallback: load 000000006c730000 LB 0x00098000 C:\Program Files\Oracle\VirtualBox\MSVCP100.dll [fFlags=0x0]
9203c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll
9213c64.1644: supR3HardenedDllNotificationCallback: load 00007ffcb8a30000 LB 0x0006d000 C:\WINDOWS\System32\WS2_32.dll [fFlags=0x0]
9223c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ws2_32.dll
9233c64.1644: supR3HardenedDllNotificationCallback: load 00007ffc79710000 LB 0x0052d000 C:\Program Files\Oracle\VirtualBox\VBoxRT.dll [fFlags=0x0]
9243c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
9253c64.1644: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll'.
9263c64.1644: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
9273c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
9283c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
9293c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9303c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
9313c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
9323c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9333c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
9343c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
9353c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9363c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
9373c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
9383c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9393c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
9403c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
9413c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9423c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
9433c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
9443c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9453c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9463c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9473c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9483c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9493c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9503c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9513c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9523c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
9533c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
9543c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9553c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9563c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9573c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9583c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9593c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9603c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9613c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9623c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9633c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9643c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9653c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9663c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9673c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9683c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9693c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9703c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
9713c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
9723c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9733c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9743c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9753c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc79710000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
9763c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll
9773c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
9783c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7a10000 'C:\WINDOWS\system32\Wintrust.dll'
9793c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
9803c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
9813c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll
9823c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
9833c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
9843c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
9853c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\system32\crypt32.dll'
9863c64.1644: SUPR3HardenedMain: Load TrustedMain...
9873c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
9883c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'opengl32.dll'.
9893c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxglobal.dll'.
9903c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
9913c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcp100.dll'.
9923c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msvcr100.dll'.
9933c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'qt5corevbox.dll'.
9943c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'qt5guivbox.dll'.
9953c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'qt5widgetsvbox.dll'.
9963c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'qt5openglvbox.dll'.
9973c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'user32.dll'.
9983c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'ole32.dll'.
9993c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'oleaut32.dll'.
10003c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'winmm.dll'.
10013c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll) WinVerifyTrust
10023c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll
10033c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
10043c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume4\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
10053c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
10063c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
10073c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'winmmbase.dll'.
10083c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msvcrt.dll'.
10093c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\winmm.dll) WinVerifyTrust
10103c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\winmm.dll
10113c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
10123c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume4\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
10133c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
10143c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
10153c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll
10163c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmmbase.dll'...
10173c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmmbase.dll' -> '\Device\HarddiskVolume4\Windows\System32\winmmbase.dll' [rcNtRedir=0xc0150008]
10183c64.1644: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\winmmbase.dll'.
10193c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
10203c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\winmmbase.dll)
10213c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\winmmbase.dll
10223c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
10233c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
10243c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll
10253c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
10263c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll
10273c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
10283c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
10293c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
10303c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'combase.dll'.
10313c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'rpcrt4.dll'.
10323c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\oleaut32.dll) WinVerifyTrust
10333c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\oleaut32.dll
10343c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
10353c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
10363c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
10373c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
10383c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll
10393c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
10403c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume4\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
10413c64.1644: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\combase.dll'.
10423c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rpcrt4.dll'.
10433c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #46 'bcryptprimitives.dll'.
10443c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\combase.dll)
10453c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\combase.dll
10463c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
10473c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
10483c64.1644: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\msvcp_win.dll'.
10493c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\msvcp_win.dll)
10503c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\msvcp_win.dll
10513c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcryptprimitives.dll'...
10523c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcryptprimitives.dll' -> '\Device\HarddiskVolume4\Windows\System32\bcryptprimitives.dll' [rcNtRedir=0xc0150008]
10533c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\bcryptprimitives.dll
10543c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
10553c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
10563c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
10573c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
10583c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'rpcrt4.dll'.
10593c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #55 'gdi32.dll'.
10603c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #56 'user32.dll'.
10613c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #57 'combase.dll'.
10623c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\ole32.dll) WinVerifyTrust
10633c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\ole32.dll
10643c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
10653c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
10663c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
10673c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume4\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
10683c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\combase.dll [lacks WinVerifyTrust]
10693c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
10703c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
10713c64.1644: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\user32.dll'.
10723c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'win32u.dll'.
10733c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #34 'gdi32.dll'.
10743c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\user32.dll)
10753c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\user32.dll
10763c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
10773c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
10783c64.1644: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\gdi32.dll'.
10793c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\gdi32.dll)
10803c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\gdi32.dll
10813c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
10823c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
10833c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
10843c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
10853c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
10863c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
10873c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume4\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
10883c64.1644: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\win32u.dll'.
10893c64.1644: '\Device\HarddiskVolume4\Windows\System32\win32u.dll' has no imports
10903c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\win32u.dll)
10913c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\win32u.dll
10923c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
10933c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
10943c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'win32u.dll'.
10953c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #34 'gdi32.dll'.
10963c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\user32.dll) WinVerifyTrust
10973c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5openglvbox.dll'...
10983c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5openglvbox.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qt5openglvbox.dll' [rcNtRedir=0xc0150008]
10993c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
11003c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
11013c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
11023c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
11033c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume4\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
11043c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\win32u.dll [lacks WinVerifyTrust]
11053c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
11063c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'qt5widgetsvbox.dll'.
11073c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'qt5guivbox.dll'.
11083c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5corevbox.dll'.
11093c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcr100.dll'.
11103c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll) WinVerifyTrust
11113c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll
11123c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
11133c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
11143c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
11153c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
11163c64.1644: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
11173c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
11183c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
11193c64.1644: Detected WinVerifyTrust recursion: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll'.
11203c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
11213c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'shell32.dll'.
11223c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ole32.dll'.
11233c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
11243c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ws2_32.dll'.
11253c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'mpr.dll'.
11263c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'msvcp100.dll'.
11273c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'msvcr100.dll'.
11283c64.1644: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll)
11293c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
11303c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
11313c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
11323c64.1644: Detected WinVerifyTrust recursion: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll'.
11333c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ole32.dll'.
11343c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'opengl32.dll'.
11353c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
11363c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
11373c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qt5corevbox.dll'.
11383c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcp100.dll'.
11393c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msvcr100.dll'.
11403c64.1644: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll)
11413c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
11423c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
11433c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
11443c64.1644: Detected WinVerifyTrust recursion: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll'.
11453c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
11463c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
11473c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5guivbox.dll'.
11483c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qt5corevbox.dll'.
11493c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'shell32.dll'.
11503c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcp100.dll'.
11513c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msvcr100.dll'.
11523c64.1644: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll)
11533c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll
11543c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
11553c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
11563c64.1644: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
11573c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
11583c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
11593c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll
11603c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
11613c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume4\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
11623c64.1644: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\shell32.dll'.
11633c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
11643c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #75 'user32.dll'.
11653c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #77 'gdi32.dll'.
11663c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\shell32.dll)
11673c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\shell32.dll
11683c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
11693c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
11703c64.1644: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [lacks WinVerifyTrust]
11713c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
11723c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
11733c64.1644: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll [lacks WinVerifyTrust]
11743c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
11753c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
11763c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll [lacks WinVerifyTrust]
11773c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
11783c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
11793c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
11803c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
11813c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
11823c64.1644: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
11833c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
11843c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
11853c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll
11863c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
11873c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
11883c64.1644: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [lacks WinVerifyTrust]
11893c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
11903c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
11913c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll [lacks WinVerifyTrust]
11923c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
11933c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
11943c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
11953c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
11963c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume4\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
11973c64.1644: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume4\Windows\System32\opengl32.dll'.
11983c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
11993c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'advapi32.dll'.
12003c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
12013c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
12023c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'glu32.dll'.
12033c64.1644: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\System32\opengl32.dll)
12043c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\opengl32.dll
12053c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
12063c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
12073c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ole32.dll
12083c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
12093c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
12103c64.1644: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
12113c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
12123c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
12133c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll
12143c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mpr.dll'...
12153c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'mpr.dll' -> '\Device\HarddiskVolume4\Windows\System32\mpr.dll' [rcNtRedir=0xc0150008]
12163c64.1644: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\mpr.dll'.
12173c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\mpr.dll)
12183c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\mpr.dll
12193c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
12203c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
12213c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ws2_32.dll
12223c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
12233c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
12243c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\advapi32.dll
12253c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
12263c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
12273c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ole32.dll
12283c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
12293c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume4\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
12303c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\shell32.dll [lacks WinVerifyTrust]
12313c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
12323c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
12333c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll [lacks WinVerifyTrust]
12343c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'glu32.dll'...
12353c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'glu32.dll' -> '\Device\HarddiskVolume4\Windows\System32\glu32.dll' [rcNtRedir=0xc0150008]
12363c64.1644: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume4\Windows\System32\glu32.dll'.
12373c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
12383c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
12393c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'opengl32.dll'.
12403c64.1644: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\System32\glu32.dll)
12413c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\glu32.dll
12423c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
12433c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
12443c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
12453c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
12463c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
12473c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll [lacks WinVerifyTrust]
12483c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
12493c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
12503c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\advapi32.dll
12513c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
12523c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
12533c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll
12543c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
12553c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
12563c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
12573c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
12583c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
12593c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll [lacks WinVerifyTrust]
12603c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
12613c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
12623c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll
12633c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
12643c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume4\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
12653c64.1644: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\opengl32.dll [lacks WinVerifyTrust]
12663c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
12673c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
12683c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll [lacks WinVerifyTrust]
12693c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
12703c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
12713c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
12723c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
12733c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
12743c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5guivbox.dll'.
12753c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qt5corevbox.dll'.
12763c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'shell32.dll'.
12773c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcp100.dll'.
12783c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msvcr100.dll'.
12793c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll) WinVerifyTrust
12803c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
12813c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
12823c64.1644: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll [redoing WinVerifyTrust]
12833c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
12843c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
12853c64.1644: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
12863c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
12873c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
12883c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll
12893c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
12903c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume4\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
12913c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\shell32.dll [lacks WinVerifyTrust]
12923c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
12933c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
12943c64.1644: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [lacks WinVerifyTrust]
12953c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
12963c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
12973c64.1644: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll [lacks WinVerifyTrust]
12983c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
12993c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
13003c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll [lacks WinVerifyTrust]
13013c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
13023c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
13033c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
13043c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
13053c64.1644: supR3HardenedScreenImage/Imports: 0 (was 24202) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll'
13063c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
13073c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
13083c64.1644: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [redoing WinVerifyTrust]
13093c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
13103c64.1644: supR3HardenedScreenImage/Imports: 0 (was 24202) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll'
13113c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
13123c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
13133c64.1644: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll [redoing WinVerifyTrust]
13143c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
13153c64.1644: supR3HardenedScreenImage/Imports: 0 (was 24202) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll'
13163c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
13173c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
13183c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll
13193c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
13203c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
13213c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxglobal.dll'...
13223c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxglobal.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxglobal.dll' [rcNtRedir=0xc0150008]
13233c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
13243c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'vboxrt.dll'.
13253c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcr100.dll'.
13263c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5corevbox.dll'.
13273c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qt5guivbox.dll'.
13283c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qt5widgetsvbox.dll'.
13293c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
13303c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'advapi32.dll'.
13313c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'ole32.dll'.
13323c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'oleaut32.dll'.
13333c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxGlobal.dll) WinVerifyTrust
13343c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxGlobal.dll
13353c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
13363c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume4\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
13373c64.1644: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\opengl32.dll [redoing WinVerifyTrust]
13383c64.1644: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000490 pwszName=\Device\HarddiskVolume4\Windows\System32\opengl32.dll
13393c64.1644: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000012655a0
13403c64.1644: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000012655a0
13413c64.1644: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=F9EA7A084F8D34EE062D8C0EF5D96EF865883D56
13423c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
13433c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume4\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
13443c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\oleaut32.dll
13453c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
13463c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
13473c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ole32.dll
13483c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
13493c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
13503c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\advapi32.dll
13513c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
13523c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
13533c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll [lacks WinVerifyTrust]
13543c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
13553c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
13563c64.1644: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll [lacks WinVerifyTrust]
13573c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
13583c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
13593c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
13603c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
13613c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
13623c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
13633c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
13643c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
13653c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
13663c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
13673c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
13683c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
13693c64.1644: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0112~31bf3856ad364e35~amd64~~10.0.17763.1.cat'; file='\Device\HarddiskVolume4\Windows\System32\opengl32.dll'
13703c64.1644: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
13713c64.1644: supR3HardenedScreenImage/Imports: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\opengl32.dll'
13723c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000a01:<flags> [calling]
13733c64.1644: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll
13743c64.1644: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\opengl32.dll
13753c64.1644: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxGlobal.dll
13763c64.1644: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
13773c64.1644: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
13783c64.1644: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll [avoiding WinVerifyTrust]
13793c64.1644: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll
13803c64.1644: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winmm.dll
13813c64.1644: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\glu32.dll [avoiding WinVerifyTrust]
13823c64.1644: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\mpr.dll [avoiding WinVerifyTrust]
13833c64.1644: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winmmbase.dll [avoiding WinVerifyTrust]
13843c64.1644: supR3HardenedDllNotificationCallback: load 00007ffcb8350000 LB 0x00020000 C:\WINDOWS\System32\win32u.dll [fFlags=0x0]
13853c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\win32u.dll [avoiding WinVerifyTrust]
13863c64.1644: supR3HardenedDllNotificationCallback: load 00007ffcb7b20000 LB 0x000a0000 C:\WINDOWS\System32\msvcp_win.dll [fFlags=0x0]
13873c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcp_win.dll [avoiding WinVerifyTrust]
13883c64.1644: supR3HardenedDllNotificationCallback: load 00007ffcb7bc0000 LB 0x0019a000 C:\WINDOWS\System32\gdi32full.dll [fFlags=0x0]
13893c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
13903c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #33 'gdi32.dll'.
13913c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #35 'user32.dll'.
13923c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #36 'win32u.dll'.
13933c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\gdi32full.dll)
13943c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\gdi32full.dll
13953c64.1644: supR3HardenedDllNotificationCallback: load 00007ffcb89f0000 LB 0x00029000 C:\WINDOWS\System32\GDI32.dll [fFlags=0x0]
13963c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gdi32.dll [avoiding WinVerifyTrust]
13973c64.1644: supR3HardenedDllNotificationCallback: load 00007ffcb8d60000 LB 0x00197000 C:\WINDOWS\System32\USER32.dll [fFlags=0x0]
13983c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll [avoiding WinVerifyTrust]
13993c64.1644: supR3HardenedDllNotificationCallback: load 00007ffc909b0000 LB 0x0002c000 C:\WINDOWS\SYSTEM32\GLU32.dll [fFlags=0x0]
14003c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\glu32.dll [avoiding WinVerifyTrust]
14013c64.1644: supR3HardenedDllNotificationCallback: load 00007ffc8e940000 LB 0x00127000 C:\WINDOWS\SYSTEM32\OPENGL32.dll [fFlags=0x0]
14023c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\opengl32.dll
14033c64.1644: supR3HardenedDllNotificationCallback: load 00007ffcb8060000 LB 0x0004a000 C:\WINDOWS\System32\cfgmgr32.dll [fFlags=0x0]
14043c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\cfgmgr32.dll)
14053c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\cfgmgr32.dll
14063c64.1644: supR3HardenedDllNotificationCallback: load 00007ffcbae10000 LB 0x0032d000 C:\WINDOWS\System32\combase.dll [fFlags=0x0]
14073c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\combase.dll [avoiding WinVerifyTrust]
14083c64.1644: supR3HardenedDllNotificationCallback: load 00007ffcb8cb0000 LB 0x000a8000 C:\WINDOWS\System32\shcore.dll [fFlags=0x0]
14093c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
14103c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #36 'rpcrt4.dll'.
14113c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #43 'combase.dll'.
14123c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\SHCore.dll)
14133c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\SHCore.dll
14143c64.1644: supR3HardenedDllNotificationCallback: load 00007ffcb7170000 LB 0x0005d000 C:\WINDOWS\System32\powrprof.dll [fFlags=0x0]
14153c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'rpcrt4.dll'.
14163c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\powrprof.dll)
14173c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\powrprof.dll
14183c64.1644: supR3HardenedDllNotificationCallback: load 00007ffcb8780000 LB 0x00052000 C:\WINDOWS\System32\shlwapi.dll [fFlags=0x0]
14193c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
14203c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #44 'gdi32.dll'.
14213c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #45 'user32.dll'.
14223c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\shlwapi.dll)
14233c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\shlwapi.dll
14243c64.1644: supR3HardenedDllNotificationCallback: load 00007ffcb71f0000 LB 0x00011000 C:\WINDOWS\System32\kernel.appcore.dll [fFlags=0x0]
14253c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'msvcrt.dll'.
14263c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'rpcrt4.dll'.
14273c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\kernel.appcore.dll)
14283c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\kernel.appcore.dll
14293c64.1644: supR3HardenedDllNotificationCallback: load 00007ffcb72c0000 LB 0x0074a000 C:\WINDOWS\System32\windows.storage.dll [fFlags=0x0]
14303c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #31 'combase.dll'.
14313c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #32 'msvcp_win.dll'.
14323c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #39 'rpcrt4.dll'.
14333c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #56 'profapi.dll'.
14343c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\windows.storage.dll)
14353c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\windows.storage.dll
14363c64.1644: supR3HardenedDllNotificationCallback: load 00007ffcb9270000 LB 0x014ef000 C:\WINDOWS\System32\SHELL32.dll [fFlags=0x0]
14373c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\shell32.dll [avoiding WinVerifyTrust]
14383c64.1644: supR3HardenedDllNotificationCallback: load 00007ffcb8f00000 LB 0x00155000 C:\WINDOWS\System32\ole32.dll [fFlags=0x0]
14393c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ole32.dll
14403c64.1644: supR3HardenedDllNotificationCallback: load 00007ffca1390000 LB 0x0001a000 C:\WINDOWS\SYSTEM32\MPR.dll [fFlags=0x0]
14413c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\mpr.dll [avoiding WinVerifyTrust]
14423c64.1644: supR3HardenedDllNotificationCallback: load 000000006bf80000 LB 0x00565000 C:\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [fFlags=0x0]
14433c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
14443c64.1644: supR3HardenedDllNotificationCallback: load 00007ffc55c70000 LB 0x005f7000 C:\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll [fFlags=0x0]
14453c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
14463c64.1644: supR3HardenedDllNotificationCallback: load 000000006ad90000 LB 0x00561000 C:\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll [fFlags=0x0]
14473c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll [avoiding WinVerifyTrust]
14483c64.1644: supR3HardenedDllNotificationCallback: load 00007ffcb8450000 LB 0x000cb000 C:\WINDOWS\System32\OLEAUT32.dll [fFlags=0x0]
14493c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\oleaut32.dll
14503c64.1644: supR3HardenedDllNotificationCallback: load 00007ffc56ff0000 LB 0x005b3000 C:\Program Files\Oracle\VirtualBox\VBoxGlobal.dll [fFlags=0x0]
14513c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxGlobal.dll
14523c64.1644: supR3HardenedDllNotificationCallback: load 000000006cc70000 LB 0x00054000 C:\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll [fFlags=0x0]
14533c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll
14543c64.1644: supR3HardenedDllNotificationCallback: load 00007ffcb46c0000 LB 0x0002d000 C:\WINDOWS\SYSTEM32\WINMMBASE.dll [fFlags=0x0]
14553c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winmmbase.dll [avoiding WinVerifyTrust]
14563c64.1644: supR3HardenedDllNotificationCallback: load 00007ffcb46f0000 LB 0x00024000 C:\WINDOWS\SYSTEM32\WINMM.dll [fFlags=0x0]
14573c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winmm.dll
14583c64.1644: supR3HardenedDllNotificationCallback: load 00007ffc4c620000 LB 0x01f3c000 C:\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll [fFlags=0x0]
14593c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll
14603c64.1644: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\windows.storage.dll'.
14613c64.1644: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\windows.storage.dll' [rescheduled]
14623c64.1644: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\kernel.appcore.dll'.
14633c64.1644: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\kernel.appcore.dll' [rescheduled]
14643c64.1644: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\shlwapi.dll'.
14653c64.1644: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\shlwapi.dll' [rescheduled]
14663c64.1644: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\powrprof.dll'.
14673c64.1644: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\powrprof.dll' [rescheduled]
14683c64.1644: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\SHCore.dll'.
14693c64.1644: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\SHCore.dll' [rescheduled]
14703c64.1644: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\cfgmgr32.dll'.
14713c64.1644: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\cfgmgr32.dll' [rescheduled]
14723c64.1644: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\gdi32full.dll'.
14733c64.1644: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\gdi32full.dll' [rescheduled]
14743c64.1644: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume4\Windows\System32\glu32.dll'.
14753c64.1644: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\glu32.dll' [rescheduled]
14763c64.1644: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\mpr.dll'.
14773c64.1644: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\mpr.dll' [rescheduled]
14783c64.1644: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\shell32.dll'.
14793c64.1644: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\shell32.dll' [rescheduled]
14803c64.1644: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll'.
14813c64.1644: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll' [rescheduled]
14823c64.1644: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\win32u.dll'.
14833c64.1644: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\win32u.dll' [rescheduled]
14843c64.1644: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\gdi32.dll'.
14853c64.1644: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rescheduled]
14863c64.1644: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\user32.dll'.
14873c64.1644: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rescheduled]
14883c64.1644: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\msvcp_win.dll'.
14893c64.1644: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\msvcp_win.dll' [rescheduled]
14903c64.1644: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\combase.dll'.
14913c64.1644: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\combase.dll' [rescheduled]
14923c64.1644: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\winmmbase.dll'.
14933c64.1644: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\winmmbase.dll' [rescheduled]
14943c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\kernel32.dll
14953c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'profapi.dll'...
14963c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'profapi.dll' -> '\Device\HarddiskVolume4\Windows\System32\profapi.dll' [rcNtRedir=0xc0150008]
14973c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\profapi.dll
14983c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
14993c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
15003c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
15013c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
15023c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcp_win.dll [redoing WinVerifyTrust]
15033c64.1644: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\msvcp_win.dll'.
15043c64.1644: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume4\Windows\System32\msvcp_win.dll
15053c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
15063c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume4\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
15073c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\combase.dll [redoing WinVerifyTrust]
15083c64.1644: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\combase.dll'.
15093c64.1644: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume4\Windows\System32\combase.dll
15103c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
15113c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
15123c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
15133c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
15143c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
15153c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
15163c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll [redoing WinVerifyTrust]
15173c64.1644: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\user32.dll'.
15183c64.1644: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume4\Windows\System32\user32.dll
15193c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
15203c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
15213c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gdi32.dll [redoing WinVerifyTrust]
15223c64.1644: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\gdi32.dll'.
15233c64.1644: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume4\Windows\System32\gdi32.dll
15243c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
15253c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
15263c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
15273c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
15283c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
15293c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume4\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
15303c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\combase.dll [redoing WinVerifyTrust]
15313c64.1644: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\combase.dll'.
15323c64.1644: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume4\Windows\System32\combase.dll
15333c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
15343c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
15353c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
15363c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
15373c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
15383c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume4\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
15393c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\win32u.dll [redoing WinVerifyTrust]
15403c64.1644: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\win32u.dll'.
15413c64.1644: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume4\Windows\System32\win32u.dll
15423c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
15433c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
15443c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll [redoing WinVerifyTrust]
15453c64.1644: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\user32.dll'.
15463c64.1644: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume4\Windows\System32\user32.dll
15473c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
15483c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
15493c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gdi32.dll [redoing WinVerifyTrust]
15503c64.1644: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\gdi32.dll'.
15513c64.1644: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume4\Windows\System32\gdi32.dll
15523c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
15533c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
15543c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcp_win.dll [redoing WinVerifyTrust]
15553c64.1644: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\msvcp_win.dll'.
15563c64.1644: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume4\Windows\System32\msvcp_win.dll
15573c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\kernel32.dll (Input=kernel32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
15583c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcba7c0000 'C:\WINDOWS\System32\kernel32.dll'
15593c64.1644: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-string-l1-1-0) -> 0x0, fPresent=1
15603c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-string-l1-1-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
15613c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb80b0000 'api-ms-win-core-string-l1-1-0'
15623c64.1644: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-datetime-l1-1-1) -> 0x0, fPresent=1
15633c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-datetime-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
15643c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb80b0000 'api-ms-win-core-datetime-l1-1-1'
15653c64.1644: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-obsolete-l1-2-0) -> 0x0, fPresent=1
15663c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-obsolete-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
15673c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb80b0000 'api-ms-win-core-localization-obsolete-l1-2-0'
15683c64.1644: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\imm32.dll'.
15693c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'user32.dll'.
15703c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'win32u.dll'.
15713c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\imm32.dll)
15723c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\imm32.dll
15733c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
15743c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume4\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
15753c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\win32u.dll [redoing WinVerifyTrust]
15763c64.1644: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\win32u.dll'.
15773c64.1644: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume4\Windows\System32\win32u.dll
15783c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
15793c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
15803c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll [redoing WinVerifyTrust]
15813c64.1644: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\user32.dll'.
15823c64.1644: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume4\Windows\System32\user32.dll
15833c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\IMM32.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
15843c64.1644: supR3HardenedDllNotificationCallback: load 00007ffcb8810000 LB 0x0002e000 C:\WINDOWS\System32\IMM32.DLL [fFlags=0x0]
15853c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\imm32.dll [avoiding WinVerifyTrust]
15863c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb8810000 'C:\WINDOWS\system32\IMM32.DLL'
15873c64.1644: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\imm32.dll'.
15883c64.1644: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\imm32.dll' [rescheduled]
15893c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\advapi32.dll
15903c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\ADVAPI32.DLL (Input=ADVAPI32.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
15913c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb8520000 'C:\WINDOWS\System32\ADVAPI32.DLL'
15923c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc4c620000 'C:\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll'
15933c64.1644: SUPR3HardenedMain: Calling TrustedMain (00007ffc4c6216c0)...
15943c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
15953c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
15963c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'ole32.dll'.
15973c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
15983c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'imm32.dll'.
15993c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'winmm.dll'.
16003c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'oleaut32.dll'.
16013c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'shell32.dll'.
16023c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'advapi32.dll'.
16033c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'qt5guivbox.dll'.
16043c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'qt5corevbox.dll'.
16053c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'msvcr100.dll'.
16063c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\platforms\qwindows.dll) WinVerifyTrust
16073c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\platforms\qwindows.dll
16083c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
16093c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
16103c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
16113c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
16123c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
16133c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
16143c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
16153c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
16163c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
16173c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
16183c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\advapi32.dll
16193c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
16203c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume4\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
16213c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\shell32.dll [redoing WinVerifyTrust]
16223c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
16233c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
16243c64.1644: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\shell32.dll'
16253c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
16263c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume4\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
16273c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\oleaut32.dll
16283c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
16293c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume4\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
16303c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winmm.dll
16313c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
16323c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume4\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
16333c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\imm32.dll [redoing WinVerifyTrust]
16343c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
16353c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
16363c64.1644: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\imm32.dll'
16373c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
16383c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
16393c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll [redoing WinVerifyTrust]
16403c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
16413c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
16423c64.1644: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\user32.dll'
16433c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
16443c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
16453c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ole32.dll
16463c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
16473c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
16483c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gdi32.dll [redoing WinVerifyTrust]
16493c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
16503c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
16513c64.1644: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\gdi32.dll'
16523c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\platforms\qwindows.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
16533c64.1644: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\platforms\qwindows.dll
16543c64.1644: supR3HardenedDllNotificationCallback: load 00007ffc7d310000 LB 0x0012e000 C:\Program Files\Oracle\VirtualBox\platforms\qwindows.dll [fFlags=0x0]
16553c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\platforms\qwindows.dll
16563c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc7d310000 'C:\Program Files\Oracle\VirtualBox\platforms\qwindows.dll'
16573c64.1644: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000620 pwszName=\Device\HarddiskVolume4\Windows\System32\uxtheme.dll
16583c64.1644: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000012655a0
16593c64.1644: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000012655a0
16603c64.1644: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=9E9C9DBAFB6FF286F236C72F471A61F524EAC54D
16613c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
16623c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
16633c64.1644: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0315~31bf3856ad364e35~amd64~~10.0.17763.1.cat'; file='\Device\HarddiskVolume4\Windows\System32\uxtheme.dll'
16643c64.1644: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
16653c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
16663c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #33 'gdi32.dll'.
16673c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #34 'user32.dll'.
16683c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\uxtheme.dll) WinVerifyTrust
16693c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\uxtheme.dll
16703c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
16713c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
16723c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
16733c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
16743c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
16753c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
16763c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
16773c64.1644: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\uxtheme.dll
16783c64.1644: supR3HardenedDllNotificationCallback: load 00007ffcb5390000 LB 0x0009c000 C:\WINDOWS\system32\uxtheme.dll [fFlags=0x0]
16793c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\uxtheme.dll
16803c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb5390000 'C:\WINDOWS\system32\uxtheme.dll'
16813c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb8d60000 'C:\WINDOWS\system32\user32.dll'
16823c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\shell32.dll
16833c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
16843c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb9270000 'C:\WINDOWS\system32\shell32.dll'
16853c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\SHCore.dll [redoing WinVerifyTrust]
16863c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
16873c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
16883c64.1644: supR3HardenedScreenImage/LdrLoadDll: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\SHCore.dll'
16893c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\SHCore.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
16903c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb8cb0000 'C:\WINDOWS\system32\SHCore.dll'
16913c64.1644: supR3HardenedMonitor_LdrLoadDll: error opening 'C:\WINDOWS\system32\wintab32.dll': 0 (NtPath=\??\C:\WINDOWS\system32\wintab32.dll; Input=C:\WINDOWS\system32\wintab32.dll; rcNtGetDll=0x0
16923c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000034 'C:\WINDOWS\system32\wintab32.dll'
16933c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll
16943c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\user32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
16953c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb8d60000 'C:\WINDOWS\system32\user32.dll'
16963c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
16973c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'crypt32.dll'.
16983c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'cryptsp.dll'.
16993c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'win32u.dll'.
17003c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #27 'user32.dll'.
17013c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #28 'gdi32.dll'.
17023c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\dwmapi.dll)
17033c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\dwmapi.dll
17043c64.1644: supR3HardenedDllNotificationCallback: load 00007ffcb5670000 LB 0x0002e000 C:\WINDOWS\system32\dwmapi.dll [fFlags=0x0]
17053c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\dwmapi.dll [avoiding WinVerifyTrust]
17063c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
17073c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
17083c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
17093c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
17103c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
17113c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume4\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
17123c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\win32u.dll [lacks WinVerifyTrust]
17133c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cryptsp.dll'...
17143c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'cryptsp.dll' -> '\Device\HarddiskVolume4\Windows\System32\cryptsp.dll' [rcNtRedir=0xc0150008]
17153c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\cryptsp.dll
17163c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
17173c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume4\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
17183c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
17193c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
17203c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
17213c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
17223c64.1644: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\dwmapi.dll'
17233c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winmm.dll
17243c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\winmm.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
17253c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb46f0000 'C:\WINDOWS\system32\winmm.dll'
17263c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winmm.dll
17273c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\winmm.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
17283c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb46f0000 'C:\WINDOWS\system32\winmm.dll'
17293c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\shell32.dll
17303c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
17313c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb9270000 'C:\WINDOWS\system32\shell32.dll'
17323c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\uxtheme.dll
17333c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
17343c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb5390000 'C:\WINDOWS\system32\uxtheme.dll'
17353c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\advapi32.dll
17363c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\advapi32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
17373c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb8520000 'C:\WINDOWS\system32\advapi32.dll'
17383c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
17393c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
17403c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'rpcrt4.dll'.
17413c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #29 'profapi.dll'.
17423c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\userenv.dll) WinVerifyTrust
17433c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\userenv.dll
17443c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'profapi.dll'...
17453c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'profapi.dll' -> '\Device\HarddiskVolume4\Windows\System32\profapi.dll' [rcNtRedir=0xc0150008]
17463c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\profapi.dll
17473c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
17483c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
17493c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\userenv.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
17503c64.1644: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\userenv.dll
17513c64.1644: supR3HardenedDllNotificationCallback: load 00007ffcb70a0000 LB 0x00028000 C:\WINDOWS\system32\userenv.dll [fFlags=0x0]
17523c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\userenv.dll
17533c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb70a0000 'C:\WINDOWS\system32\userenv.dll'
17543c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\kernel32.dll
17553c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\kernel32.dll (Input=kernel32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
17563c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcba7c0000 'C:\WINDOWS\System32\kernel32.dll'
17573c64.1644: supR3HardenedDllNotificationCallback: load 00007ffcb83a0000 LB 0x000a2000 C:\WINDOWS\System32\clbcatq.dll [fFlags=0x0]
17583c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
17593c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #28 'rpcrt4.dll'.
17603c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\clbcatq.dll)
17613c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\clbcatq.dll
17623c64.13a0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
17633c64.13a0: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
17643c64.13a0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll
17653c64.13a0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
17663c64.13a0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
17673c64.13a0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
17683c64.13a0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
17693c64.13a0: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\clbcatq.dll'
17703c64.13a0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
17713c64.13a0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
17723c64.13a0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
17733c64.13a0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
17743c64.13a0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
17753c64.13a0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ole32.dll'.
17763c64.13a0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'oleaut32.dll'.
17773c64.13a0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxC.dll) WinVerifyTrust
17783c64.13a0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxC.dll
17793c64.13a0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
17803c64.13a0: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume4\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
17813c64.13a0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\oleaut32.dll
17823c64.13a0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
17833c64.13a0: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
17843c64.13a0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ole32.dll
17853c64.13a0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
17863c64.13a0: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
17873c64.13a0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\advapi32.dll
17883c64.13a0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
17893c64.13a0: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
17903c64.13a0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
17913c64.13a0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
17923c64.13a0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll
17933c64.13a0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
17943c64.13a0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
17953c64.13a0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxC.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
17963c64.13a0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxC.dll
17973c64.13a0: supR3HardenedDllNotificationCallback: load 00007ffc75ea0000 LB 0x003a1000 C:\Program Files\Oracle\VirtualBox\VBoxC.dll [fFlags=0x0]
17983c64.13a0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxC.dll
17993c64.13a0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc75ea0000 'C:\Program Files\Oracle\VirtualBox\VBoxC.dll'
18003c64.13a0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
18013c64.13a0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
18023c64.13a0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
18033c64.13a0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
18043c64.13a0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'shlwapi.dll'.
18053c64.13a0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ole32.dll'.
18063c64.13a0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'oleaut32.dll'.
18073c64.13a0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
18083c64.13a0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll) WinVerifyTrust
18093c64.13a0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll
18103c64.13a0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
18113c64.13a0: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
18123c64.13a0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
18133c64.13a0: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume4\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
18143c64.13a0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\oleaut32.dll
18153c64.13a0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
18163c64.13a0: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
18173c64.13a0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ole32.dll
18183c64.13a0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
18193c64.13a0: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume4\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
18203c64.13a0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\shlwapi.dll [redoing WinVerifyTrust]
18213c64.13a0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
18223c64.13a0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
18233c64.13a0: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\shlwapi.dll'
18243c64.13a0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
18253c64.13a0: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
18263c64.13a0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\advapi32.dll
18273c64.13a0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
18283c64.13a0: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
18293c64.13a0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
18303c64.13a0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
18313c64.13a0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
18323c64.13a0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll
18333c64.13a0: supR3HardenedDllNotificationCallback: load 00007ffc7e3c0000 LB 0x000d4000 C:\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll [fFlags=0x0]
18343c64.13a0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll
18353c64.13a0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc7e3c0000 'C:\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll'
18363c64.13a0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\oleaut32.dll
18373c64.13a0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\oleaut32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
18383c64.13a0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb8450000 'C:\Windows\System32\oleaut32.dll'
18393c64.1644: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000007b0 pwszName=\Device\HarddiskVolume4\Windows\System32\DWrite.dll
18403c64.1644: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000012655a0
18413c64.1644: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000012655a0
18423c64.1644: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=ED58C840A4C96163B90C7F051FBCA4BFD3BE7921
18433c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
18443c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
18453c64.1644: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_212_for_KB4483235~31bf3856ad364e35~amd64~~10.0.1.1.cat'; file='\Device\HarddiskVolume4\Windows\System32\DWrite.dll'
18463c64.1644: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
18473c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
18483c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'rpcrt4.dll'.
18493c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\DWrite.dll) WinVerifyTrust
18503c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\DWrite.dll
18513c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
18523c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
18533c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
18543c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
18553c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll
18563c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\dwrite.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
18573c64.1644: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\DWrite.dll
18583c64.1644: supR3HardenedDllNotificationCallback: load 00007ffc92340000 LB 0x002ff000 C:\WINDOWS\system32\dwrite.dll [fFlags=0x0]
18593c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\DWrite.dll
18603c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc92340000 'C:\WINDOWS\system32\dwrite.dll'
18613c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\shell32.dll
18623c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
18633c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb9270000 'C:\WINDOWS\system32\shell32.dll'
18643c64.1644: supR3HardenedDllNotificationCallback: load 00007ffcb8b40000 LB 0x0016a000 C:\WINDOWS\System32\MSCTF.dll [fFlags=0x0]
18653c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
18663c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'oleaut32.dll'.
18673c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #37 'user32.dll'.
18683c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #38 'gdi32.dll'.
18693c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #39 'imm32.dll'.
18703c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\msctf.dll)
18713c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\msctf.dll
18723c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
18733c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume4\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
18743c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\imm32.dll
18753c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
18763c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
18773c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
18783c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
18793c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
18803c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume4\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
18813c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\oleaut32.dll
18823c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
18833c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
18843c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
18853c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
18863c64.1644: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\msctf.dll'
18873c64.1644: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000009ec pwszName=\Device\HarddiskVolume4\Windows\System32\DataExchange.dll
18883c64.1644: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000012655a0
18893c64.1644: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000012655a0
18903c64.1644: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=59F3AE35C1BD7FF73B733C35DF45575279B981AF
18913c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
18923c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
18933c64.1644: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0310~31bf3856ad364e35~amd64~~10.0.17763.1.cat'; file='\Device\HarddiskVolume4\Windows\System32\DataExchange.dll'
18943c64.1644: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
18953c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
18963c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'shcore.dll'.
18973c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #28 'combase.dll'.
18983c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #33 'd3d11.dll'.
18993c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #34 'dcomp.dll'.
19003c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\DataExchange.dll) WinVerifyTrust
19013c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\DataExchange.dll
19023c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dcomp.dll'...
19033c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'dcomp.dll' -> '\Device\HarddiskVolume4\Windows\System32\dcomp.dll' [rcNtRedir=0xc0150008]
19043c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
19053c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
19063c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'win32u.dll'.
19073c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp_win.dll'.
19083c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #34 'oleaut32.dll'.
19093c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #35 'dxgi.dll'.
19103c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\dcomp.dll) WinVerifyTrust
19113c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\dcomp.dll
19123c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'd3d11.dll'...
19133c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'd3d11.dll' -> '\Device\HarddiskVolume4\Windows\System32\d3d11.dll' [rcNtRedir=0xc0150008]
19143c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dxgi.dll'...
19153c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'dxgi.dll' -> '\Device\HarddiskVolume4\Windows\System32\dxgi.dll' [rcNtRedir=0xc0150008]
19163c64.1644: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\dxgi.dll'.
19173c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
19183c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'win32u.dll'.
19193c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\dxgi.dll)
19203c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\dxgi.dll
19213c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
19223c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume4\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
19233c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\oleaut32.dll
19243c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
19253c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
19263c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcp_win.dll [lacks WinVerifyTrust]
19273c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
19283c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume4\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
19293c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\win32u.dll [lacks WinVerifyTrust]
19303c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
19313c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume4\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
19323c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\win32u.dll [lacks WinVerifyTrust]
19333c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
19343c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
19353c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
19363c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
19373c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
19383c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'dxgi.dll'.
19393c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #35 'win32u.dll'.
19403c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\d3d11.dll) WinVerifyTrust
19413c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\d3d11.dll
19423c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
19433c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume4\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
19443c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\combase.dll [redoing WinVerifyTrust]
19453c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
19463c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume4\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
19473c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\win32u.dll [lacks WinVerifyTrust]
19483c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dxgi.dll'...
19493c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'dxgi.dll' -> '\Device\HarddiskVolume4\Windows\System32\dxgi.dll' [rcNtRedir=0xc0150008]
19503c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\dxgi.dll [lacks WinVerifyTrust]
19513c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
19523c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
19533c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
19543c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
19553c64.1644: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\combase.dll'
19563c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shcore.dll'...
19573c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'shcore.dll' -> '\Device\HarddiskVolume4\Windows\System32\shcore.dll' [rcNtRedir=0xc0150008]
19583c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\SHCore.dll
19593c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
19603c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
19613c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\dataexchange.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
19623c64.1644: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\DataExchange.dll
19633c64.1644: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\d3d11.dll
19643c64.1644: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\dcomp.dll
19653c64.1644: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\dxgi.dll [avoiding WinVerifyTrust]
19663c64.1644: supR3HardenedDllNotificationCallback: load 00007ffcb5f90000 LB 0x000c2000 C:\WINDOWS\system32\dxgi.dll [fFlags=0x0]
19673c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\dxgi.dll [avoiding WinVerifyTrust]
19683c64.1644: supR3HardenedDllNotificationCallback: load 00007ffcb4210000 LB 0x0027e000 C:\WINDOWS\system32\d3d11.dll [fFlags=0x0]
19693c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\d3d11.dll
19703c64.1644: supR3HardenedDllNotificationCallback: load 00007ffcb4b60000 LB 0x001c3000 C:\WINDOWS\system32\dcomp.dll [fFlags=0x0]
19713c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\dcomp.dll
19723c64.1644: supR3HardenedDllNotificationCallback: load 00007ffc8e1e0000 LB 0x00056000 C:\WINDOWS\system32\dataexchange.dll [fFlags=0x0]
19733c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\DataExchange.dll
19743c64.1644: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\dxgi.dll'.
19753c64.1644: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\dxgi.dll' [rescheduled]
19763c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb89f0000 'C:\WINDOWS\System32\gdi32.dll'
19773c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc8e1e0000 'C:\WINDOWS\system32\dataexchange.dll'
19783c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rmclient.dll'.
19793c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #33 'rpcrt4.dll'.
19803c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #47 'combase.dll'.
19813c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #49 'msvcp_win.dll'.
19823c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\twinapi.appcore.dll)
19833c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\twinapi.appcore.dll
19843c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
19853c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'rpcrt4.dll'.
19863c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\rmclient.dll)
19873c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\rmclient.dll
19883c64.1644: supR3HardenedDllNotificationCallback: load 00007ffcb56a0000 LB 0x00028000 C:\WINDOWS\system32\RMCLIENT.dll [fFlags=0x0]
19893c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rmclient.dll [avoiding WinVerifyTrust]
19903c64.1644: supR3HardenedDllNotificationCallback: load 00007ffcb5450000 LB 0x0020d000 C:\WINDOWS\system32\twinapi.appcore.dll [fFlags=0x0]
19913c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\twinapi.appcore.dll [avoiding WinVerifyTrust]
19923c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll
19933c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
19943c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
19953c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
19963c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
19973c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
19983c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
19993c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcp_win.dll [lacks WinVerifyTrust]
20003c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
20013c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume4\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
20023c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\combase.dll
20033c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
20043c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
20053c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rmclient.dll'...
20063c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'rmclient.dll' -> '\Device\HarddiskVolume4\Windows\System32\rmclient.dll' [rcNtRedir=0xc0150008]
20073c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rmclient.dll [lacks WinVerifyTrust]
20083c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
20093c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
20103c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
20113c64.1644: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\rmclient.dll'
20123c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
20133c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
20143c64.1644: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\twinapi.appcore.dll'
20153c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\SHCore.dll
20163c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\Shcore.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
20173c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb8cb0000 'C:\WINDOWS\system32\Shcore.dll'
20183c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
20193c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #15 'rpcrt4.dll'.
20203c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #19 'coreuicomponents.dll'.
20213c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #20 'coremessaging.dll'.
20223c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\TextInputFramework.dll)
20233c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\TextInputFramework.dll
20243c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
20253c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #35 'coremessaging.dll'.
20263c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #48 'shcore.dll'.
20273c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\CoreUIComponents.dll)
20283c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\CoreUIComponents.dll
20293c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
20303c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #24 'rpcrt4.dll'.
20313c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\CoreMessaging.dll)
20323c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\CoreMessaging.dll
20333c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\ntmarta.dll)
20343c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\ntmarta.dll
20353c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'combase.dll'.
20363c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'rpcrt4.dll'.
20373c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #30 'bcryptprimitives.dll'.
20383c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\WinTypes.dll)
20393c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\WinTypes.dll
20403c64.1644: supR3HardenedDllNotificationCallback: load 00007ffcb6230000 LB 0x00031000 C:\WINDOWS\SYSTEM32\ntmarta.dll [fFlags=0x0]
20413c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ntmarta.dll [avoiding WinVerifyTrust]
20423c64.1644: supR3HardenedDllNotificationCallback: load 00007ffcb4e30000 LB 0x000e2000 C:\WINDOWS\System32\CoreMessaging.dll [fFlags=0x0]
20433c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\CoreMessaging.dll [avoiding WinVerifyTrust]
20443c64.1644: supR3HardenedDllNotificationCallback: load 00007ffcb1d90000 LB 0x00153000 C:\WINDOWS\SYSTEM32\wintypes.dll [fFlags=0x0]
20453c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\WinTypes.dll [avoiding WinVerifyTrust]
20463c64.1644: supR3HardenedDllNotificationCallback: load 00007ffcb1990000 LB 0x00322000 C:\WINDOWS\System32\CoreUIComponents.dll [fFlags=0x0]
20473c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\CoreUIComponents.dll [avoiding WinVerifyTrust]
20483c64.1644: supR3HardenedDllNotificationCallback: load 00007ffc9a070000 LB 0x00095000 C:\WINDOWS\System32\TextInputFramework.dll [fFlags=0x0]
20493c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\TextInputFramework.dll [avoiding WinVerifyTrust]
20503c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcryptprimitives.dll'...
20513c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcryptprimitives.dll' -> '\Device\HarddiskVolume4\Windows\System32\bcryptprimitives.dll' [rcNtRedir=0xc0150008]
20523c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\bcryptprimitives.dll
20533c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
20543c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
20553c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
20563c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume4\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
20573c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\combase.dll
20583c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
20593c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
20603c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
20613c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
20623c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shcore.dll'...
20633c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'shcore.dll' -> '\Device\HarddiskVolume4\Windows\System32\shcore.dll' [rcNtRedir=0xc0150008]
20643c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\SHCore.dll
20653c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'coremessaging.dll'...
20663c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'coremessaging.dll' -> '\Device\HarddiskVolume4\Windows\System32\coremessaging.dll' [rcNtRedir=0xc0150008]
20673c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\CoreMessaging.dll [lacks WinVerifyTrust]
20683c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
20693c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
20703c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'coremessaging.dll'...
20713c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'coremessaging.dll' -> '\Device\HarddiskVolume4\Windows\System32\coremessaging.dll' [rcNtRedir=0xc0150008]
20723c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\CoreMessaging.dll [lacks WinVerifyTrust]
20733c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'coreuicomponents.dll'...
20743c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'coreuicomponents.dll' -> '\Device\HarddiskVolume4\Windows\System32\coreuicomponents.dll' [rcNtRedir=0xc0150008]
20753c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\CoreUIComponents.dll [lacks WinVerifyTrust]
20763c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
20773c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
20783c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
20793c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
20803c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
20813c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
20823c64.1644: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\WinTypes.dll'
20833c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
20843c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
20853c64.1644: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\ntmarta.dll'
20863c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
20873c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
20883c64.1644: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\CoreMessaging.dll'
20893c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
20903c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
20913c64.1644: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\CoreUIComponents.dll'
20923c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
20933c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
20943c64.1644: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\TextInputFramework.dll'
20953c64.1644: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(ext-ms-win-rtcore-ntuser-window-ext-l1-1-0.dll) -> 0x0, fPresent=1
20963c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=ext-ms-win-rtcore-ntuser-window-ext-l1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
20973c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb8d60000 'ext-ms-win-rtcore-ntuser-window-ext-l1-1-0.dll'
20983c64.1644: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(ext-ms-win-rtcore-ntuser-integration-l1-1-0.dll) -> 0x0, fPresent=1
20993c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=ext-ms-win-rtcore-ntuser-integration-l1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
21003c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb8d60000 'ext-ms-win-rtcore-ntuser-integration-l1-1-0.dll'
21013c64.1644: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-com-l1-1-0.dll) -> 0x0, fPresent=1
21023c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-com-l1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
21033c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcbae10000 'api-ms-win-core-com-l1-1-0.dll'
21043c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msctf.dll
21053c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\MSCTF.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
21063c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb8b40000 'C:\WINDOWS\System32\MSCTF.dll'
21073c64.1644: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000a6c pwszName=\Device\HarddiskVolume4\Windows\System32\oleacc.dll
21083c64.1644: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000012655a0
21093c64.1644: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000012655a0
21103c64.1644: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=92D0420A49287CA5BE482F6435FEDE1197E38D4E
21113c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
21123c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
21133c64.1644: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package03113~31bf3856ad364e35~amd64~~10.0.17763.1.cat'; file='\Device\HarddiskVolume4\Windows\System32\oleacc.dll'
21143c64.1644: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
21153c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'rpcrt4.dll'.
21163c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #30 'user32.dll'.
21173c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\oleacc.dll) WinVerifyTrust
21183c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\oleacc.dll
21193c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
21203c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
21213c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
21223c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
21233c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\Oleacc.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
21243c64.1644: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\oleacc.dll
21253c64.1644: supR3HardenedDllNotificationCallback: load 00007ffcaa8a0000 LB 0x0006c000 C:\WINDOWS\system32\Oleacc.dll [fFlags=0x0]
21263c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\oleacc.dll
21273c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcaa8a0000 'C:\WINDOWS\system32\Oleacc.dll'
21283c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb8450000 'C:\WINDOWS\System32\OLEAUT32.DLL'
21293c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\oleacc.dll
21303c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\oleacc.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
21313c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcaa8a0000 'C:\WINDOWS\system32\oleacc.dll'
21323c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\oleacc.dll
21333c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\oleacc.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
21343c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcaa8a0000 'C:\Windows\System32\oleacc.dll'
21353c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ole32.dll
21363c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\ole32.dll (Input=ole32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
21373c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb8f00000 'C:\WINDOWS\System32\ole32.dll'
21383c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb8450000 'C:\WINDOWS\System32\OLEAUT32.dll'
21393c64.1644: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000b54 pwszName=\Device\HarddiskVolume4\Windows\System32\wbem\wbemprox.dll
21403c64.1644: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000012655a0
21413c64.1644: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000012655a0
21423c64.1644: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=61B08AF50BF6163BDE34EB0C9B6605297BA2441A
21433c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
21443c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
21453c64.1644: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package02~31bf3856ad364e35~amd64~~10.0.17763.1.cat'; file='\Device\HarddiskVolume4\Windows\System32\wbem\wbemprox.dll'
21463c64.1644: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
21473c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
21483c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ws2_32.dll'.
21493c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'wbemcomn.dll'.
21503c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\wbem\wbemprox.dll) WinVerifyTrust
21513c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\wbem\wbemprox.dll
21523c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wbemcomn.dll'...
21533c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'wbemcomn.dll' -> '\Device\HarddiskVolume4\Windows\System32\wbemcomn.dll' [rcNtRedir=0xc0150008]
21543c64.1644: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000b60 pwszName=\Device\HarddiskVolume4\Windows\System32\wbemcomn.dll
21553c64.1644: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000012655a0
21563c64.1644: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000012655a0
21573c64.1644: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=585E55607969886FF9DCECA6C86E3FD6D59F65D2
21583c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
21593c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
21603c64.1644: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package02~31bf3856ad364e35~amd64~~10.0.17763.1.cat'; file='\Device\HarddiskVolume4\Windows\System32\wbemcomn.dll'
21613c64.1644: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
21623c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
21633c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'bcrypt.dll'.
21643c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'ws2_32.dll'.
21653c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\wbemcomn.dll) WinVerifyTrust
21663c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\wbemcomn.dll
21673c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
21683c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
21693c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ws2_32.dll
21703c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
21713c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
21723c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
21733c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
21743c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ws2_32.dll
21753c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
21763c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume4\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
21773c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\bcrypt.dll
21783c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
21793c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
21803c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\wbem\wbemprox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
21813c64.1644: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wbem\wbemprox.dll
21823c64.1644: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wbemcomn.dll
21833c64.1644: supR3HardenedDllNotificationCallback: load 00007ffca25d0000 LB 0x00085000 C:\WINDOWS\SYSTEM32\wbemcomn.dll [fFlags=0x0]
21843c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wbemcomn.dll
21853c64.1644: supR3HardenedDllNotificationCallback: load 00007ffc9ee90000 LB 0x00011000 C:\WINDOWS\system32\wbem\wbemprox.dll [fFlags=0x0]
21863c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wbem\wbemprox.dll
21873c64.1644: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(API-MS-Win-Core-LocalRegistry-L1-1-0.dll) -> 0x0, fPresent=1
21883c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Core-LocalRegistry-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
21893c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb80b0000 'API-MS-Win-Core-LocalRegistry-L1-1-0.dll'
21903c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc9ee90000 'C:\WINDOWS\system32\wbem\wbemprox.dll'
21913c64.1644: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000bb0 pwszName=\Device\HarddiskVolume4\Windows\System32\wbem\wbemsvc.dll
21923c64.1644: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000012655a0
21933c64.1644: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000012655a0
21943c64.1644: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2479751D59078C3499423233D67A94D93457E663
21953c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
21963c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
21973c64.1644: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package02~31bf3856ad364e35~amd64~~10.0.17763.1.cat'; file='\Device\HarddiskVolume4\Windows\System32\wbem\wbemsvc.dll'
21983c64.1644: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
21993c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
22003c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'rpcrt4.dll'.
22013c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\wbem\wbemsvc.dll) WinVerifyTrust
22023c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\wbem\wbemsvc.dll
22033c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
22043c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
22053c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
22063c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
22073c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\wbem\wbemsvc.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
22083c64.1644: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wbem\wbemsvc.dll
22093c64.1644: supR3HardenedDllNotificationCallback: load 00007ffc9e170000 LB 0x00014000 C:\WINDOWS\system32\wbem\wbemsvc.dll [fFlags=0x0]
22103c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wbem\wbemsvc.dll
22113c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc9e170000 'C:\WINDOWS\system32\wbem\wbemsvc.dll'
22123c64.1644: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-l1-2-0.dll) -> 0x0, fPresent=1
22133c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-l1-2-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
22143c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb80b0000 'api-ms-win-core-localization-l1-2-0.dll'
22153c64.1644: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-obsolete-l1-1-0.dll) -> 0x0, fPresent=1
22163c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-obsolete-l1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
22173c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb80b0000 'api-ms-win-core-localization-obsolete-l1-1-0.dll'
22183c64.1644: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000b64 pwszName=\Device\HarddiskVolume4\Windows\System32\wbem\fastprox.dll
22193c64.1644: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000012655a0
22203c64.1644: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000012655a0
22213c64.1644: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=5D738E4890595C8890290239456518F354997BFD
22223c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
22233c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll
22243c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
22253c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
22263c64.1644: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package02~31bf3856ad364e35~amd64~~10.0.17763.1.cat'; file='\Device\HarddiskVolume4\Windows\System32\wbem\fastprox.dll'
22273c64.1644: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
22283c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
22293c64.1644: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #19 'wbemcomn.dll'.
22303c64.1644: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\wbem\fastprox.dll) WinVerifyTrust
22313c64.1644: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\wbem\fastprox.dll
22323c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wbemcomn.dll'...
22333c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'wbemcomn.dll' -> '\Device\HarddiskVolume4\Windows\System32\wbemcomn.dll' [rcNtRedir=0xc0150008]
22343c64.1644: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wbemcomn.dll
22353c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
22363c64.1644: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
22373c64.1644: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\wbem\fastprox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
22383c64.1644: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wbem\fastprox.dll
22393c64.1644: supR3HardenedDllNotificationCallback: load 00007ffc9e2d0000 LB 0x000f1000 C:\WINDOWS\system32\wbem\fastprox.dll [fFlags=0x0]
22403c64.1644: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wbem\fastprox.dll
22413c64.1644: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc9e2d0000 'C:\WINDOWS\system32\wbem\fastprox.dll'
22423c64.52cc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
22433c64.52cc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
22443c64.52cc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrem.dll'.
22453c64.52cc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
22463c64.52cc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxVMM.dll) WinVerifyTrust
22473c64.52cc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxVMM.dll
22483c64.52cc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
22493c64.52cc: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
22503c64.52cc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrem.dll'...
22513c64.52cc: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrem.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrem.dll' [rcNtRedir=0xc0150008]
22523c64.52cc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
22533c64.52cc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'vboxrt.dll'.
22543c64.52cc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
22553c64.52cc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcrt.dll'.
22563c64.52cc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxREM.dll) WinVerifyTrust
22573c64.52cc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxREM.dll
22583c64.52cc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
22593c64.52cc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
22603c64.52cc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
22613c64.52cc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
22623c64.52cc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
22633c64.52cc: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
22643c64.52cc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxVMM.dll
22653c64.52cc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
22663c64.52cc: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
22673c64.52cc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
22683c64.52cc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxVMM.dll
22693c64.52cc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxREM.dll
22703c64.52cc: supR3HardenedDllNotificationCallback: load 000000006cb60000 LB 0x0010b000 C:\Program Files\Oracle\VirtualBox\VBoxREM.dll [fFlags=0x0]
22713c64.52cc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxREM.dll
22723c64.52cc: supR3HardenedDllNotificationCallback: load 00007ffc55940000 LB 0x00330000 C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL [fFlags=0x0]
22733c64.52cc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxVMM.dll
22743c64.52cc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc55940000 'C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL'
22753c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
22763c64.1ddc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
22773c64.1ddc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
22783c64.1ddc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
22793c64.1ddc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
22803c64.1ddc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
22813c64.1ddc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll) WinVerifyTrust
22823c64.1ddc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll
22833c64.1ddc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
22843c64.1ddc: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
22853c64.1ddc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
22863c64.1ddc: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
22873c64.1ddc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
22883c64.1ddc: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
22893c64.1ddc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxVMM.dll
22903c64.1ddc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
22913c64.1ddc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
22923c64.1ddc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
22933c64.1ddc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll
22943c64.1ddc: supR3HardenedDllNotificationCallback: load 00007ffcb2960000 LB 0x0000b000 C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL [fFlags=0x0]
22953c64.1ddc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll
22963c64.1ddc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb2960000 'C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL'
22973c64.1ddc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb8d60000 'C:\WINDOWS\system32\User32.dll'
22983c64.3ce4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
22993c64.3ce4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
23003c64.3ce4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
23013c64.3ce4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
23023c64.3ce4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll) WinVerifyTrust
23033c64.3ce4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll
23043c64.3ce4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
23053c64.3ce4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
23063c64.3ce4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
23073c64.3ce4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
23083c64.3ce4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
23093c64.3ce4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
23103c64.3ce4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
23113c64.3ce4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll
23123c64.3ce4: supR3HardenedDllNotificationCallback: load 00007ffcb0570000 LB 0x0000d000 C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL [fFlags=0x0]
23133c64.3ce4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll
23143c64.3ce4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb0570000 'C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL'
23153c64.54d8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\shell32.dll
23163c64.54d8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\Shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
23173c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb9270000 'C:\WINDOWS\system32\Shell32.dll'
23183c64.54d8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000d34 pwszName=\Device\HarddiskVolume4\Windows\System32\WinHvPlatform.dll
23193c64.54d8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000012655a0
23203c64.54d8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000012655a0
23213c64.54d8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=9143E96BE13DAE364B45A7FAC5B6C12AFE680873
23223c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
23233c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
23243c64.54d8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package01~31bf3856ad364e35~amd64~~10.0.17763.1.cat'; file='\Device\HarddiskVolume4\Windows\System32\WinHvPlatform.dll'
23253c64.54d8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
23263c64.54d8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'vid.dll'.
23273c64.54d8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\WinHvPlatform.dll) WinVerifyTrust
23283c64.54d8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\WinHvPlatform.dll
23293c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vid.dll'...
23303c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vid.dll' -> '\Device\HarddiskVolume4\Windows\System32\vid.dll' [rcNtRedir=0xc0150008]
23313c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
23323c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
23333c64.54d8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\vid.dll) WinVerifyTrust
23343c64.54d8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\vid.dll
23353c64.54d8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\WinHvPlatform.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
23363c64.54d8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\WinHvPlatform.dll
23373c64.54d8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\vid.dll
23383c64.54d8: supR3HardenedDllNotificationCallback: load 00007ffca1bd0000 LB 0x00017000 C:\WINDOWS\SYSTEM32\vid.dll [fFlags=0x0]
23393c64.54d8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\vid.dll
23403c64.54d8: supR3HardenedDllNotificationCallback: load 00007ffcaab20000 LB 0x0001f000 C:\WINDOWS\system32\WinHvPlatform.dll [fFlags=0x0]
23413c64.54d8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\WinHvPlatform.dll
23423c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcaab20000 'C:\WINDOWS\system32\WinHvPlatform.dll'
23433c64.54d8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\vid.dll
23443c64.54d8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\vid.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
23453c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffca1bd0000 'C:\WINDOWS\system32\vid.dll'
23463c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
23473c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
23483c64.54d8: '\Device\HarddiskVolume4\Windows\System32\ntdll.dll' has no imports
23493c64.54d8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\ntdll.dll) WinVerifyTrust
23503c64.54d8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\ntdll.dll
23513c64.54d8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\NTDLL.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
23523c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcbb170000 'C:\WINDOWS\system32\NTDLL.DLL'
23533c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
23543c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
23553c64.54d8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
23563c64.54d8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
23573c64.54d8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
23583c64.54d8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vboxddu.dll'.
23593c64.54d8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'vboxdd2.dll'.
23603c64.54d8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
23613c64.54d8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'setupapi.dll'.
23623c64.54d8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'ws2_32.dll'.
23633c64.54d8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'ole32.dll'.
23643c64.54d8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'iphlpapi.dll'.
23653c64.54d8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDD.dll) WinVerifyTrust
23663c64.54d8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDD.dll
23673c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'iphlpapi.dll'...
23683c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: 'iphlpapi.dll' -> '\Device\HarddiskVolume4\Windows\System32\iphlpapi.dll' [rcNtRedir=0xc0150008]
23693c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
23703c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
23713c64.54d8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #21 'rpcrt4.dll'.
23723c64.54d8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\IPHLPAPI.DLL) WinVerifyTrust
23733c64.54d8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\IPHLPAPI.DLL
23743c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
23753c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
23763c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
23773c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
23783c64.54d8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ws2_32.dll
23793c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
23803c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume4\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
23813c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
23823c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
23833c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
23843c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
23853c64.54d8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
23863c64.54d8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #29 'rpcrt4.dll'.
23873c64.54d8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #37 'cfgmgr32.dll'.
23883c64.54d8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #41 'bcrypt.dll'.
23893c64.54d8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\setupapi.dll) WinVerifyTrust
23903c64.54d8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\setupapi.dll
23913c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
23923c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
23933c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxdd2.dll'...
23943c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxdd2.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxdd2.dll' [rcNtRedir=0xc0150008]
23953c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
23963c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume4\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
23973c64.54d8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\bcrypt.dll
23983c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
23993c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume4\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
24003c64.54d8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\cfgmgr32.dll [lacks WinVerifyTrust]
24013c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
24023c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
24033c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
24043c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
24053c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
24063c64.54d8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
24073c64.54d8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
24083c64.54d8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDD2.dll) WinVerifyTrust
24093c64.54d8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDD2.dll
24103c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxddu.dll'...
24113c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxddu.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxddu.dll' [rcNtRedir=0xc0150008]
24123c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
24133c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
24143c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
24153c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
24163c64.54d8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll
24173c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
24183c64.54d8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
24193c64.54d8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
24203c64.54d8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
24213c64.54d8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'setupapi.dll'.
24223c64.54d8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'advapi32.dll'.
24233c64.54d8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDDU.dll) WinVerifyTrust
24243c64.54d8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDDU.dll
24253c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
24263c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
24273c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
24283c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
24293c64.54d8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxVMM.dll
24303c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
24313c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
24323c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
24333c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
24343c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
24353c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume4\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
24363c64.54d8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\setupapi.dll
24373c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
24383c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
24393c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
24403c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
24413c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
24423c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
24433c64.54d8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxDD.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
24443c64.54d8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDD.dll
24453c64.54d8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDDU.dll
24463c64.54d8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDD2.dll
24473c64.54d8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\IPHLPAPI.DLL
24483c64.54d8: supR3HardenedDllNotificationCallback: load 00007ffcba890000 LB 0x00475000 C:\WINDOWS\System32\SETUPAPI.dll [fFlags=0x0]
24493c64.54d8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\setupapi.dll
24503c64.54d8: supR3HardenedDllNotificationCallback: load 00007ffc7f3b0000 LB 0x00063000 C:\Program Files\Oracle\VirtualBox\VBoxDDU.dll [fFlags=0x0]
24513c64.54d8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDDU.dll
24523c64.54d8: supR3HardenedDllNotificationCallback: load 00007ffc7df90000 LB 0x0005c000 C:\Program Files\Oracle\VirtualBox\VBoxDD2.dll [fFlags=0x0]
24533c64.54d8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDD2.dll
24543c64.54d8: supR3HardenedDllNotificationCallback: load 00007ffcb66c0000 LB 0x0003d000 C:\WINDOWS\SYSTEM32\IPHLPAPI.DLL [fFlags=0x0]
24553c64.54d8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\IPHLPAPI.DLL
24563c64.54d8: supR3HardenedDllNotificationCallback: load 00007ffc54f60000 LB 0x009d7000 C:\Program Files\Oracle\VirtualBox\VBoxDD.DLL [fFlags=0x0]
24573c64.54d8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDD.dll
24583c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc54f60000 'C:\Program Files\Oracle\VirtualBox\VBoxDD.DLL'
24593c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
24603c64.54d8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxC.dll
24613c64.54d8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxC.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
24623c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc75ea0000 'C:\Program Files\Oracle\VirtualBox\VBoxC.DLL'
24633c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
24643c64.54d8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxDD2.dll
24653c64.54d8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxDD2.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
24663c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc7df90000 'C:\Program Files\Oracle\VirtualBox\VBoxDD2.DLL'
24673c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
24683c64.5980: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
24693c64.5980: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
24703c64.5980: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
24713c64.5980: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
24723c64.5980: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll) WinVerifyTrust
24733c64.5980: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll
24743c64.5980: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
24753c64.5980: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
24763c64.5980: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
24773c64.5980: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
24783c64.5980: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxVMM.dll
24793c64.5980: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
24803c64.5980: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
24813c64.5980: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
24823c64.5980: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll
24833c64.5980: supR3HardenedDllNotificationCallback: load 00007ffcaab00000 LB 0x00012000 C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL [fFlags=0x0]
24843c64.5980: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll
24853c64.5980: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcaab00000 'C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL'
24863c64.694: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
24873c64.694: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
24883c64.694: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
24893c64.694: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxvmm.dll'.
24903c64.694: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vboxrt.dll'.
24913c64.694: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll) WinVerifyTrust
24923c64.694: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll
24933c64.694: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
24943c64.694: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
24953c64.694: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
24963c64.694: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
24973c64.694: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxVMM.dll
24983c64.694: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
24993c64.694: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
25003c64.694: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
25013c64.694: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
25023c64.694: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
25033c64.694: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll
25043c64.694: supR3HardenedDllNotificationCallback: load 00007ffcb0560000 LB 0x0000c000 C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL [fFlags=0x0]
25053c64.694: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll
25063c64.694: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb0560000 'C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL'
25073c64.1b50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
25083c64.1b50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
25093c64.1b50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
25103c64.1b50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
25113c64.1b50: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll) WinVerifyTrust
25123c64.1b50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll
25133c64.1b50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
25143c64.1b50: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
25153c64.1b50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
25163c64.1b50: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
25173c64.1b50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
25183c64.1b50: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
25193c64.1b50: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
25203c64.1b50: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll
25213c64.1b50: supR3HardenedDllNotificationCallback: load 00007ffcaac20000 LB 0x0000d000 C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL [fFlags=0x0]
25223c64.1b50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll
25233c64.1b50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcaac20000 'C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL'
25243c64.54d8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\IPHLPAPI.DLL
25253c64.54d8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\Iphlpapi.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
25263c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb66c0000 'C:\WINDOWS\system32\Iphlpapi.dll'
25273c64.54d8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rpcrt4.dll'.
25283c64.54d8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'nsi.dll'.
25293c64.54d8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\winnsi.dll)
25303c64.54d8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\winnsi.dll
25313c64.54d8: supR3HardenedDllNotificationCallback: load 00007ffcba880000 LB 0x00008000 C:\WINDOWS\System32\NSI.dll [fFlags=0x0]
25323c64.54d8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\nsi.dll)
25333c64.54d8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\nsi.dll
25343c64.54d8: supR3HardenedDllNotificationCallback: load 00007ffcb0820000 LB 0x0000b000 C:\WINDOWS\SYSTEM32\WINNSI.DLL [fFlags=0x0]
25353c64.54d8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winnsi.dll [avoiding WinVerifyTrust]
25363c64.54d8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rpcrt4.dll'.
25373c64.54d8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\System32\dhcpcsvc6.dll)
25383c64.54d8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\dhcpcsvc6.dll
25393c64.54d8: supR3HardenedDllNotificationCallback: load 00007ffcaf8a0000 LB 0x00016000 C:\WINDOWS\SYSTEM32\dhcpcsvc6.DLL [fFlags=0x0]
25403c64.54d8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\dhcpcsvc6.dll [avoiding WinVerifyTrust]
25413c64.54d8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rpcrt4.dll'.
25423c64.54d8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ws2_32.dll'.
25433c64.54d8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'nsi.dll'.
25443c64.54d8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\System32\dhcpcsvc.dll)
25453c64.54d8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\dhcpcsvc.dll
25463c64.54d8: supR3HardenedDllNotificationCallback: load 00007ffcaf810000 LB 0x0001c000 C:\WINDOWS\SYSTEM32\dhcpcsvc.DLL [fFlags=0x0]
25473c64.54d8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\dhcpcsvc.dll [avoiding WinVerifyTrust]
25483c64.54d8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #21 'ws2_32.dll'.
25493c64.54d8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'nsi.dll'.
25503c64.54d8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\dnsapi.dll)
25513c64.54d8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\dnsapi.dll
25523c64.54d8: supR3HardenedDllNotificationCallback: load 00007ffcb6700000 LB 0x000c6000 C:\WINDOWS\SYSTEM32\DNSAPI.dll [fFlags=0x0]
25533c64.54d8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\dnsapi.dll [avoiding WinVerifyTrust]
25543c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
25553c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume4\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
25563c64.54d8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\nsi.dll [lacks WinVerifyTrust]
25573c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
25583c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
25593c64.54d8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ws2_32.dll
25603c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
25613c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume4\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
25623c64.54d8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\nsi.dll [lacks WinVerifyTrust]
25633c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
25643c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
25653c64.54d8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ws2_32.dll
25663c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
25673c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
25683c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
25693c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
25703c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
25713c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume4\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
25723c64.54d8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\nsi.dll [lacks WinVerifyTrust]
25733c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
25743c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
25753c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
25763c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
25773c64.54d8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\dnsapi.dll'
25783c64.54d8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000f90 pwszName=\Device\HarddiskVolume4\Windows\System32\dhcpcsvc.dll
25793c64.54d8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000012655a0
25803c64.54d8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000012655a0
25813c64.54d8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=023C8DA2B39F9AA3A5B23F6B14BA6DD8E8288590
25823c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
25833c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
25843c64.54d8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0316~31bf3856ad364e35~amd64~~10.0.17763.1.cat'; file='\Device\HarddiskVolume4\Windows\System32\dhcpcsvc.dll'
25853c64.54d8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
25863c64.54d8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\dhcpcsvc.dll'
25873c64.54d8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000e0c pwszName=\Device\HarddiskVolume4\Windows\System32\dhcpcsvc6.dll
25883c64.54d8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000012655a0
25893c64.54d8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000012655a0
25903c64.54d8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=E0A1EEF9F9131F768A30314D53D98D8EC54A521D
25913c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
25923c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
25933c64.54d8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0316~31bf3856ad364e35~amd64~~10.0.17763.1.cat'; file='\Device\HarddiskVolume4\Windows\System32\dhcpcsvc6.dll'
25943c64.54d8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
25953c64.54d8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\dhcpcsvc6.dll'
25963c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
25973c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
25983c64.54d8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\nsi.dll'
25993c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
26003c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
26013c64.54d8: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\winnsi.dll'
26023c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
26033c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
26043c64.54d8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'rpcrt4.dll'.
26053c64.54d8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'devobj.dll'.
26063c64.54d8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #37 'propsys.dll'.
26073c64.54d8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\MMDevAPI.dll) WinVerifyTrust
26083c64.54d8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\MMDevAPI.dll
26093c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'propsys.dll'...
26103c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: 'propsys.dll' -> '\Device\HarddiskVolume4\Windows\System32\propsys.dll' [rcNtRedir=0xc0150008]
26113c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
26123c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
26133c64.54d8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
26143c64.54d8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #15 'oleaut32.dll'.
26153c64.54d8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #31 'rpcrt4.dll'.
26163c64.54d8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\propsys.dll) WinVerifyTrust
26173c64.54d8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\propsys.dll
26183c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'devobj.dll'...
26193c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: 'devobj.dll' -> '\Device\HarddiskVolume4\Windows\System32\devobj.dll' [rcNtRedir=0xc0150008]
26203c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
26213c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
26223c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
26233c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume4\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
26243c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
26253c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
26263c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
26273c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
26283c64.54d8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'cfgmgr32.dll'.
26293c64.54d8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\devobj.dll) WinVerifyTrust
26303c64.54d8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\devobj.dll
26313c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
26323c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
26333c64.54d8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll
26343c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
26353c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume4\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
26363c64.54d8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\cfgmgr32.dll [redoing WinVerifyTrust]
26373c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
26383c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
26393c64.54d8: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\cfgmgr32.dll'
26403c64.54d8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\MMDevApi.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
26413c64.54d8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\MMDevAPI.dll
26423c64.54d8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\devobj.dll
26433c64.54d8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\propsys.dll
26443c64.54d8: supR3HardenedDllNotificationCallback: load 00007ffcb6f20000 LB 0x00029000 C:\WINDOWS\System32\DEVOBJ.dll [fFlags=0x0]
26453c64.54d8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\devobj.dll
26463c64.54d8: supR3HardenedDllNotificationCallback: load 00007ffcb3f70000 LB 0x001a8000 C:\WINDOWS\System32\PROPSYS.dll [fFlags=0x0]
26473c64.54d8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\propsys.dll
26483c64.54d8: supR3HardenedDllNotificationCallback: load 00007ffcaf830000 LB 0x00070000 C:\WINDOWS\System32\MMDevApi.dll [fFlags=0x0]
26493c64.54d8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\MMDevAPI.dll
26503c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcaf830000 'C:\WINDOWS\System32\MMDevApi.dll'
26513c64.54d8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000e20 pwszName=\Device\HarddiskVolume4\Windows\System32\dsound.dll
26523c64.54d8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000012655a0
26533c64.54d8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000012655a0
26543c64.54d8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B973A852091636F8493626192E69AE7AC7CBBB7F
26553c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
26563c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
26573c64.54d8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package~31bf3856ad364e35~amd64~~10.0.17763.1.cat'; file='\Device\HarddiskVolume4\Windows\System32\dsound.dll'
26583c64.54d8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
26593c64.54d8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
26603c64.54d8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #32 'winmm.dll'.
26613c64.54d8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\dsound.dll) WinVerifyTrust
26623c64.54d8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\dsound.dll
26633c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
26643c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume4\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
26653c64.54d8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winmm.dll
26663c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
26673c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
26683c64.54d8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll
26693c64.54d8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
26703c64.54d8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\dsound.dll
26713c64.54d8: supR3HardenedDllNotificationCallback: load 00007ffc91be0000 LB 0x00096000 C:\WINDOWS\System32\dsound.dll [fFlags=0x0]
26723c64.54d8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\dsound.dll
26733c64.54d8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\dsound.dll
26743c64.54d8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
26753c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc91be0000 'C:\WINDOWS\System32\dsound.dll'
26763c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc91be0000 'C:\WINDOWS\System32\dsound.dll'
26773c64.54d8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\dsound.dll
26783c64.54d8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
26793c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc91be0000 'C:\WINDOWS\system32\dsound.dll'
26803c64.54d8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\MMDevAPI.dll
26813c64.54d8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\MMDEVAPI.DLL (Input=MMDEVAPI.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
26823c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcaf830000 'C:\WINDOWS\System32\MMDEVAPI.DLL'
26833c64.54d8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winmm.dll
26843c64.54d8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\winmm.dll (Input=winmm.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
26853c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb46f0000 'C:\WINDOWS\System32\winmm.dll'
26863c64.54d8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000105c pwszName=\Device\HarddiskVolume4\Windows\System32\wdmaud.drv
26873c64.54d8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000012655a0
26883c64.54d8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000012655a0
26893c64.54d8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=22E5B934FBB9B8EED168F5BD0121AD902CCB797A
26903c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
26913c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
26923c64.54d8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package~31bf3856ad364e35~amd64~~10.0.17763.1.cat'; file='\Device\HarddiskVolume4\Windows\System32\wdmaud.drv'
26933c64.54d8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
26943c64.54d8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
26953c64.54d8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'mmdevapi.dll'.
26963c64.54d8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #27 'ksuser.dll'.
26973c64.54d8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #28 'avrt.dll'.
26983c64.54d8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\wdmaud.drv) WinVerifyTrust
26993c64.54d8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\wdmaud.drv
27003c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'avrt.dll'...
27013c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: 'avrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\avrt.dll' [rcNtRedir=0xc0150008]
27023c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
27033c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
27043c64.54d8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\avrt.dll) WinVerifyTrust
27053c64.54d8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\avrt.dll
27063c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ksuser.dll'...
27073c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ksuser.dll' -> '\Device\HarddiskVolume4\Windows\System32\ksuser.dll' [rcNtRedir=0xc0150008]
27083c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
27093c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
27103c64.54d8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
27113c64.54d8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\ksuser.dll) WinVerifyTrust
27123c64.54d8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\ksuser.dll
27133c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mmdevapi.dll'...
27143c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: 'mmdevapi.dll' -> '\Device\HarddiskVolume4\Windows\System32\mmdevapi.dll' [rcNtRedir=0xc0150008]
27153c64.54d8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\MMDevAPI.dll
27163c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
27173c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
27183c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
27193c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
27203c64.54d8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
27213c64.54d8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wdmaud.drv
27223c64.54d8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ksuser.dll
27233c64.54d8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\avrt.dll
27243c64.54d8: supR3HardenedDllNotificationCallback: load 00007ffc953d0000 LB 0x00009000 C:\WINDOWS\SYSTEM32\ksuser.dll [fFlags=0x0]
27253c64.54d8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ksuser.dll
27263c64.54d8: supR3HardenedDllNotificationCallback: load 00007ffcb2c80000 LB 0x0000a000 C:\WINDOWS\SYSTEM32\AVRT.dll [fFlags=0x0]
27273c64.54d8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\avrt.dll
27283c64.54d8: supR3HardenedDllNotificationCallback: load 00007ffcb37f0000 LB 0x00044000 C:\WINDOWS\System32\wdmaud.drv [fFlags=0x0]
27293c64.54d8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wdmaud.drv
27303c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb37f0000 'C:\WINDOWS\System32\wdmaud.drv'
27313c64.54d8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wdmaud.drv
27323c64.54d8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
27333c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb37f0000 'C:\WINDOWS\System32\wdmaud.drv'
27343c64.54d8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wdmaud.drv
27353c64.54d8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
27363c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb37f0000 'C:\WINDOWS\System32\wdmaud.drv'
27373c64.54d8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wdmaud.drv
27383c64.54d8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
27393c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb37f0000 'C:\WINDOWS\System32\wdmaud.drv'
27403c64.54d8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wdmaud.drv
27413c64.54d8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
27423c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb37f0000 'C:\WINDOWS\System32\wdmaud.drv'
27433c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
27443c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
27453c64.54d8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
27463c64.54d8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'rpcrt4.dll'.
27473c64.54d8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'oleaut32.dll'.
27483c64.54d8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #57 'mmdevapi.dll'.
27493c64.54d8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #58 'avrt.dll'.
27503c64.54d8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\AudioSes.dll) WinVerifyTrust
27513c64.54d8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\AudioSes.dll
27523c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'avrt.dll'...
27533c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: 'avrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\avrt.dll' [rcNtRedir=0xc0150008]
27543c64.54d8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\avrt.dll
27553c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mmdevapi.dll'...
27563c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: 'mmdevapi.dll' -> '\Device\HarddiskVolume4\Windows\System32\mmdevapi.dll' [rcNtRedir=0xc0150008]
27573c64.54d8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\MMDevAPI.dll
27583c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
27593c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume4\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
27603c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
27613c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
27623c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
27633c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
27643c64.54d8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcp_win.dll [redoing WinVerifyTrust]
27653c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
27663c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
27673c64.54d8: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\msvcp_win.dll'
27683c64.54d8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\AUDIOSES.DLL (Input=AUDIOSES.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
27693c64.54d8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\AudioSes.dll
27703c64.54d8: supR3HardenedDllNotificationCallback: load 00007ffcaf8c0000 LB 0x00148000 C:\WINDOWS\System32\AUDIOSES.DLL [fFlags=0x0]
27713c64.54d8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\AudioSes.dll
27723c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcaf8c0000 'C:\WINDOWS\System32\AUDIOSES.DLL'
27733c64.54d8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wdmaud.drv
27743c64.54d8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
27753c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb37f0000 'C:\WINDOWS\System32\wdmaud.drv'
27763c64.54d8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wdmaud.drv
27773c64.54d8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
27783c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb37f0000 'C:\WINDOWS\System32\wdmaud.drv'
27793c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb37f0000 'C:\WINDOWS\System32\wdmaud.drv'
27803c64.54d8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000f94 pwszName=\Device\HarddiskVolume4\Windows\System32\msacm32.drv
27813c64.54d8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000012655a0
27823c64.54d8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000012655a0
27833c64.54d8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=DF9222E8F115E50DE05D7AD2D27BDC071ADD62AF
27843c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
27853c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
27863c64.54d8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package~31bf3856ad364e35~amd64~~10.0.17763.1.cat'; file='\Device\HarddiskVolume4\Windows\System32\msacm32.drv'
27873c64.54d8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
27883c64.54d8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
27893c64.54d8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'mmdevapi.dll'.
27903c64.54d8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'msacm32.dll'.
27913c64.54d8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'winmmbase.dll'.
27923c64.54d8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\msacm32.drv) WinVerifyTrust
27933c64.54d8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\msacm32.drv
27943c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmmbase.dll'...
27953c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmmbase.dll' -> '\Device\HarddiskVolume4\Windows\System32\winmmbase.dll' [rcNtRedir=0xc0150008]
27963c64.54d8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winmmbase.dll [redoing WinVerifyTrust]
27973c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
27983c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
27993c64.54d8: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\winmmbase.dll'
28003c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msacm32.dll'...
28013c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msacm32.dll' -> '\Device\HarddiskVolume4\Windows\System32\msacm32.dll' [rcNtRedir=0xc0150008]
28023c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
28033c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
28043c64.54d8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
28053c64.54d8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\msacm32.dll) WinVerifyTrust
28063c64.54d8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\msacm32.dll
28073c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mmdevapi.dll'...
28083c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: 'mmdevapi.dll' -> '\Device\HarddiskVolume4\Windows\System32\mmdevapi.dll' [rcNtRedir=0xc0150008]
28093c64.54d8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\MMDevAPI.dll
28103c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
28113c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
28123c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
28133c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
28143c64.54d8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
28153c64.54d8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msacm32.drv
28163c64.54d8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msacm32.dll
28173c64.54d8: supR3HardenedDllNotificationCallback: load 00007ffcb37c0000 LB 0x0001c000 C:\WINDOWS\SYSTEM32\MSACM32.dll [fFlags=0x0]
28183c64.54d8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msacm32.dll
28193c64.54d8: supR3HardenedDllNotificationCallback: load 00007ffcb37e0000 LB 0x0000d000 C:\WINDOWS\System32\msacm32.drv [fFlags=0x0]
28203c64.54d8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msacm32.drv
28213c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb37e0000 'C:\WINDOWS\System32\msacm32.drv'
28223c64.54d8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msacm32.drv
28233c64.54d8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
28243c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb37e0000 'C:\WINDOWS\System32\msacm32.drv'
28253c64.54d8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msacm32.drv
28263c64.54d8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
28273c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb37e0000 'C:\WINDOWS\System32\msacm32.drv'
28283c64.54d8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msacm32.drv
28293c64.54d8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
28303c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb37e0000 'C:\WINDOWS\System32\msacm32.drv'
28313c64.54d8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msacm32.drv
28323c64.54d8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
28333c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb37e0000 'C:\WINDOWS\System32\msacm32.drv'
28343c64.54d8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msacm32.drv
28353c64.54d8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
28363c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb37e0000 'C:\WINDOWS\System32\msacm32.drv'
28373c64.54d8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msacm32.drv
28383c64.54d8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
28393c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb37e0000 'C:\WINDOWS\System32\msacm32.drv'
28403c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb37e0000 'C:\WINDOWS\System32\msacm32.drv'
28413c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb37e0000 'C:\WINDOWS\System32\msacm32.drv'
28423c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb37e0000 'C:\WINDOWS\System32\msacm32.drv'
28433c64.54d8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000010b0 pwszName=\Device\HarddiskVolume4\Windows\System32\midimap.dll
28443c64.54d8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000012655a0
28453c64.54d8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000012655a0
28463c64.54d8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=FE1B51D5EFA4634DA5F3478BB920BDCB24116539
28473c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb6520000 'C:\WINDOWS\system32\rsaenh.dll'
28483c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb7e80000 'C:\WINDOWS\System32\crypt32.dll'
28493c64.54d8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package~31bf3856ad364e35~amd64~~10.0.17763.1.cat'; file='\Device\HarddiskVolume4\Windows\System32\midimap.dll'
28503c64.54d8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
28513c64.54d8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
28523c64.54d8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'winmm.dll'.
28533c64.54d8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\midimap.dll) WinVerifyTrust
28543c64.54d8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\midimap.dll
28553c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
28563c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume4\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
28573c64.54d8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winmm.dll
28583c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
28593c64.54d8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
28603c64.54d8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
28613c64.54d8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\midimap.dll
28623c64.54d8: supR3HardenedDllNotificationCallback: load 00007ffcb37b0000 LB 0x0000a000 C:\WINDOWS\System32\midimap.dll [fFlags=0x0]
28633c64.54d8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\midimap.dll
28643c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb37b0000 'C:\WINDOWS\System32\midimap.dll'
28653c64.54d8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\midimap.dll
28663c64.54d8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
28673c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb37b0000 'C:\WINDOWS\System32\midimap.dll'
28683c64.54d8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\midimap.dll
28693c64.54d8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
28703c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb37b0000 'C:\WINDOWS\System32\midimap.dll'
28713c64.54d8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\midimap.dll
28723c64.54d8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
28733c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb37b0000 'C:\WINDOWS\System32\midimap.dll'
28743c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb46f0000 'C:\WINDOWS\System32\winmm.dll'
28753c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb46f0000 'C:\WINDOWS\System32\winmm.dll'
28763c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb46f0000 'C:\WINDOWS\System32\winmm.dll'
28773c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb46f0000 'C:\WINDOWS\System32\winmm.dll'
28783c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb46f0000 'C:\WINDOWS\System32\winmm.dll'
28793c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb46f0000 'C:\WINDOWS\System32\winmm.dll'
28803c64.54d8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\dsound.dll
28813c64.54d8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
28823c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc91be0000 'C:\WINDOWS\system32\dsound.dll'
28833c64.54d8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffcb46f0000 'C:\WINDOWS\System32\winmm.dll'
2884410c.4b50: supR3HardNtChildWaitFor[2]: Quitting: ExitCode=0xcfffffff (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 124927 ms, the end);
28855c38.ba4: supR3HardNtChildWaitFor[1]: Quitting: ExitCode=0xcfffffff (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 125685 ms, the end);

© 2024 Oracle Support Privacy / Do Not Sell My Info Terms of Use Trademark Policy Automated Access Etiquette