VirtualBox

Ticket #19125: VBoxHardening.log

File VBoxHardening.log, 391.5 KB (added by kotenok2000, 5 years ago)
Line 
11b98.b54: Log file opened: 6.0.14r133895 g_hStartupLog=0000000000000090 g_uNtVerCombined=0xa047bb00
21b98.b54: \SystemRoot\System32\ntdll.dll:
31b98.b54: CreationTime: 2019-10-09T07:15:15.782952500Z
41b98.b54: LastWriteTime: 2019-10-09T07:15:16.191946200Z
51b98.b54: ChangeTime: 2019-11-12T21:16:16.798042000Z
61b98.b54: FileAttributes: 0x820
71b98.b54: Size: 0x1e8528
81b98.b54: NT Headers: 0xd8
91b98.b54: Timestamp: 0x99ca0526
101b98.b54: Machine: 0x8664 - amd64
111b98.b54: Timestamp: 0x99ca0526
121b98.b54: Image Version: 10.0
131b98.b54: SizeOfImage: 0x1f0000 (2031616)
141b98.b54: Resource Dir: 0x17f000 LB 0x6f310
151b98.b54: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
161b98.b54: [Raw version resource data: 0x17f0f0 LB 0x380, codepage 0x0 (reserved 0x0)]
171b98.b54: ProductName: Microsoft® Windows® Operating System
181b98.b54: ProductVersion: 10.0.18362.418
191b98.b54: FileVersion: 10.0.18362.418 (WinBuild.160101.0800)
201b98.b54: FileDescription: NT Layer DLL
211b98.b54: \SystemRoot\System32\kernel32.dll:
221b98.b54: CreationTime: 2019-09-06T08:50:11.805475900Z
231b98.b54: LastWriteTime: 2019-09-06T08:50:12.063263600Z
241b98.b54: ChangeTime: 2019-11-12T21:14:43.929620400Z
251b98.b54: FileAttributes: 0x820
261b98.b54: Size: 0xb0570
271b98.b54: NT Headers: 0xe8
281b98.b54: Timestamp: 0xd0cecc10
291b98.b54: Machine: 0x8664 - amd64
301b98.b54: Timestamp: 0xd0cecc10
311b98.b54: Image Version: 10.0
321b98.b54: SizeOfImage: 0xb2000 (729088)
331b98.b54: Resource Dir: 0xb0000 LB 0x520
341b98.b54: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
351b98.b54: [Raw version resource data: 0xb00b0 LB 0x3a4, codepage 0x0 (reserved 0x0)]
361b98.b54: ProductName: Microsoft® Windows® Operating System
371b98.b54: ProductVersion: 10.0.18362.329
381b98.b54: FileVersion: 10.0.18362.329 (WinBuild.160101.0800)
391b98.b54: FileDescription: Windows NT BASE API Client DLL
401b98.b54: \SystemRoot\System32\KernelBase.dll:
411b98.b54: CreationTime: 2019-11-12T21:02:18.696374500Z
421b98.b54: LastWriteTime: 2019-11-12T21:02:19.515375500Z
431b98.b54: ChangeTime: 2019-11-13T01:07:03.500085800Z
441b98.b54: FileAttributes: 0x20
451b98.b54: Size: 0x2a2908
461b98.b54: NT Headers: 0xf0
471b98.b54: Timestamp: 0x83c3d83a
481b98.b54: Machine: 0x8664 - amd64
491b98.b54: Timestamp: 0x83c3d83a
501b98.b54: Image Version: 10.0
511b98.b54: SizeOfImage: 0x2a3000 (2764800)
521b98.b54: Resource Dir: 0x27d000 LB 0x548
531b98.b54: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
541b98.b54: [Raw version resource data: 0x27d0b0 LB 0x3bc, codepage 0x0 (reserved 0x0)]
551b98.b54: ProductName: Microsoft® Windows® Operating System
561b98.b54: ProductVersion: 10.0.18362.476
571b98.b54: FileVersion: 10.0.18362.476 (WinBuild.160101.0800)
581b98.b54: FileDescription: Windows NT BASE API Client DLL
591b98.b54: \SystemRoot\System32\apisetschema.dll:
601b98.b54: CreationTime: 2019-03-19T04:43:54.837151500Z
611b98.b54: LastWriteTime: 2019-10-23T09:58:34.870639900Z
621b98.b54: ChangeTime: 2019-11-12T21:14:42.081621100Z
631b98.b54: FileAttributes: 0x20
641b98.b54: Size: 0x1d028
651b98.b54: NT Headers: 0xc8
661b98.b54: Timestamp: 0xd6ced080
671b98.b54: Machine: 0x8664 - amd64
681b98.b54: Timestamp: 0xd6ced080
691b98.b54: Image Version: 10.0
701b98.b54: SizeOfImage: 0x1e000 (122880)
711b98.b54: Resource Dir: 0x1d000 LB 0x408
721b98.b54: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
731b98.b54: [Raw version resource data: 0x1d060 LB 0x3a8, codepage 0x0 (reserved 0x0)]
741b98.b54: ProductName: Microsoft® Windows® Operating System
751b98.b54: ProductVersion: 10.0.18362.1
761b98.b54: FileVersion: 10.0.18362.1 (WinBuild.160101.0800)
771b98.b54: FileDescription: ApiSet Schema DLL
781b98.b54: Found driver mbamswissarmy (0x80)
791b98.b54: supR3HardenedWinFindAdversaries: 0x80
801b98.b54: \SystemRoot\System32\drivers\MBAMSwissArmy.sys:
811b98.b54: CreationTime: 2019-07-14T23:08:00.417005100Z
821b98.b54: LastWriteTime: 2019-10-23T09:14:30.733490000Z
831b98.b54: ChangeTime: 2019-10-23T09:14:30.733490000Z
841b98.b54: FileAttributes: 0x20
851b98.b54: Size: 0x43320
861b98.b54: NT Headers: 0xf8
871b98.b54: Timestamp: 0x5c9e68f9
881b98.b54: Machine: 0x8664 - amd64
891b98.b54: Timestamp: 0x5c9e68f9
901b98.b54: Image Version: 10.0
911b98.b54: SizeOfImage: 0x45000 (282624)
921b98.b54: Resource Dir: 0x43000 LB 0x3b8
931b98.b54: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
941b98.b54: [Raw version resource data: 0x43060 LB 0x358, codepage 0x0 (reserved 0x0)]
951b98.b54: ProductName: Malwarebytes SwissArmy
961b98.b54: ProductVersion: 4.3.0.170
971b98.b54: FileVersion: 4.3.0.170
981b98.b54: FileDescription: Malwarebytes SwissArmy
991b98.b54: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
1001b98.b54: Calling main()
1011b98.b54: SUPR3HardenedMain: pszProgName=VirtualBoxVM fFlags=0x2
1021b98.b54: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
1031b98.b54: SUPR3HardenedMain: Respawn #1
1041b98.b54: System32: \Device\HarddiskVolume2\Windows\System32
1051b98.b54: WinSxS: \Device\HarddiskVolume2\Windows\WinSxS
1061b98.b54: KnownDllPath: C:\WINDOWS\System32
1071b98.b54: supR3HardenedWinInit: Performing a limited self purification...
1081b98.b54: supHardNtVpScanVirtualMemory: enmKind=SELF_PURIFICATION
1091b98.b54: *0000000000000000-00000000001affff 0x0001/0x0000 0x0000000
1101b98.b54: *00000000001b0000-00000000001bffff 0x0004/0x0004 0x0040000
1111b98.b54: 00000000001c0000-00000000001cffff 0x0001/0x0000 0x0000000
1121b98.b54: *00000000001d0000-00000000001eafff 0x0002/0x0002 0x0040000
1131b98.b54: 00000000001eb000-00000000001effff 0x0001/0x0000 0x0000000
1141b98.b54: *00000000001f0000-00000000001f3fff 0x0002/0x0002 0x0040000
1151b98.b54: 00000000001f4000-00000000001fffff 0x0001/0x0000 0x0000000
1161b98.b54: *0000000000200000-0000000000373fff 0x0000/0x0004 0x0020000
1171b98.b54: 0000000000374000-0000000000376fff 0x0004/0x0004 0x0020000
1181b98.b54: 0000000000377000-00000000003fffff 0x0000/0x0004 0x0020000
1191b98.b54: *0000000000400000-00000000004b0fff 0x0000/0x0004 0x0020000
1201b98.b54: 00000000004b1000-00000000004b3fff 0x0104/0x0004 0x0020000
1211b98.b54: 00000000004b4000-00000000004fffff 0x0004/0x0004 0x0020000
1221b98.b54: *0000000000500000-0000000000501fff 0x0004/0x0004 0x0020000
1231b98.b54: 0000000000502000-000000000050ffff 0x0001/0x0000 0x0000000
1241b98.b54: *0000000000510000-00000000005d6fff 0x0002/0x0002 0x0040000
1251b98.b54: 00000000005d7000-00000000005dffff 0x0001/0x0000 0x0000000
1261b98.b54: *00000000005e0000-00000000005e1fff 0x0004/0x0004 0x0020000
1271b98.b54: 00000000005e2000-0000000000611fff 0x0000/0x0004 0x0020000
1281b98.b54: 0000000000612000-000000000062ffff 0x0001/0x0000 0x0000000
1291b98.b54: *0000000000630000-000000000063efff 0x0004/0x0004 0x0020000
1301b98.b54: 000000000063f000-000000000063ffff 0x0000/0x0004 0x0020000
1311b98.b54: 0000000000640000-000000000069ffff 0x0001/0x0000 0x0000000
1321b98.b54: *00000000006a0000-00000000006a9fff 0x0004/0x0004 0x0020000
1331b98.b54: 00000000006aa000-000000000079ffff 0x0000/0x0004 0x0020000
1341b98.b54: *00000000007a0000-00000000007a3fff 0x0000/0x0004 0x0020000
1351b98.b54: 00000000007a4000-0000000000994fff 0x0004/0x0004 0x0020000
1361b98.b54: 0000000000995000-0000000000995fff 0x0000/0x0004 0x0020000
1371b98.b54: 0000000000996000-000000000099ffff 0x0001/0x0000 0x0000000
1381b98.b54: *00000000009a0000-00000000009bcfff 0x0004/0x0004 0x0020000
1391b98.b54: 00000000009bd000-0000000000a9ffff 0x0000/0x0004 0x0020000
1401b98.b54: 0000000000aa0000-000000007ffdffff 0x0001/0x0000 0x0000000
1411b98.b54: *000000007ffe0000-000000007ffe0fff 0x0002/0x0002 0x0020000
1421b98.b54: 000000007ffe1000-00007ff4f009ffff 0x0001/0x0000 0x0000000
1431b98.b54: *00007ff4f00a0000-00007ff4f00a4fff 0x0002/0x0002 0x0040000
1441b98.b54: 00007ff4f00a5000-00007ff4f019ffff 0x0000/0x0002 0x0040000
1451b98.b54: *00007ff4f01a0000-00007ff5f01bffff 0x0000/0x0004 0x0020000
1461b98.b54: *00007ff5f01c0000-00007ff5f21bffff 0x0000/0x0004 0x0020000
1471b98.b54: 00007ff5f21c0000-00007ff5f21c0fff 0x0004/0x0004 0x0020000
1481b98.b54: 00007ff5f21c1000-00007ff5f21cffff 0x0001/0x0000 0x0000000
1491b98.b54: *00007ff5f21d0000-00007ff5f21d0fff 0x0002/0x0002 0x0040000
1501b98.b54: 00007ff5f21d1000-00007ff5f21dffff 0x0001/0x0000 0x0000000
1511b98.b54: *00007ff5f21e0000-00007ff5f2202fff 0x0002/0x0002 0x0040000
1521b98.b54: 00007ff5f2203000-00007ff74789ffff 0x0001/0x0000 0x0000000
1531b98.b54: *00007ff7478a0000-00007ff7478a0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
1541b98.b54: 00007ff7478a1000-00007ff747915fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
1551b98.b54: 00007ff747916000-00007ff747916fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
1561b98.b54: 00007ff747917000-00007ff74795efff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
1571b98.b54: 00007ff74795f000-00007ff747961fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
1581b98.b54: 00007ff747962000-00007ff747964fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
1591b98.b54: 00007ff747965000-00007ff747967fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
1601b98.b54: 00007ff747968000-00007ff747968fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
1611b98.b54: 00007ff747969000-00007ff74796afff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
1621b98.b54: 00007ff74796b000-00007ff74796bfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
1631b98.b54: 00007ff74796c000-00007ff7479b4fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
1641b98.b54: 00007ff7479b5000-00007ff933e8ffff 0x0001/0x0000 0x0000000
1651b98.b54: *00007ff933e90000-00007ff933e90fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\apphelp.dll
1661b98.b54: 00007ff933e91000-00007ff933eddfff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\apphelp.dll
1671b98.b54: 00007ff933ede000-00007ff933efffff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\apphelp.dll
1681b98.b54: 00007ff933f00000-00007ff933f02fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\apphelp.dll
1691b98.b54: 00007ff933f03000-00007ff933f1efff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\apphelp.dll
1701b98.b54: 00007ff933f1f000-00007ff9368bffff 0x0001/0x0000 0x0000000
1711b98.b54: *00007ff9368c0000-00007ff9368c0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\KernelBase.dll
1721b98.b54: 00007ff9368c1000-00007ff9369c5fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\KernelBase.dll
1731b98.b54: 00007ff9369c6000-00007ff936b27fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\KernelBase.dll
1741b98.b54: 00007ff936b28000-00007ff936b2bfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\KernelBase.dll
1751b98.b54: 00007ff936b2c000-00007ff936b2cfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\KernelBase.dll
1761b98.b54: 00007ff936b2d000-00007ff936b62fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\KernelBase.dll
1771b98.b54: 00007ff936b63000-00007ff93932ffff 0x0001/0x0000 0x0000000
1781b98.b54: *00007ff939330000-00007ff939330fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\kernel32.dll
1791b98.b54: 00007ff939331000-00007ff9393a5fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\kernel32.dll
1801b98.b54: 00007ff9393a6000-00007ff9393d7fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\kernel32.dll
1811b98.b54: 00007ff9393d8000-00007ff9393d8fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\kernel32.dll
1821b98.b54: 00007ff9393d9000-00007ff9393d9fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\kernel32.dll
1831b98.b54: 00007ff9393da000-00007ff9393e1fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\kernel32.dll
1841b98.b54: 00007ff9393e2000-00007ff93971ffff 0x0001/0x0000 0x0000000
1851b98.b54: *00007ff939720000-00007ff939720fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
1861b98.b54: 00007ff939721000-00007ff939837fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
1871b98.b54: 00007ff939838000-00007ff93987efff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
1881b98.b54: 00007ff93987f000-00007ff93987ffff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
1891b98.b54: 00007ff939880000-00007ff939881fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
1901b98.b54: 00007ff939882000-00007ff93988afff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
1911b98.b54: 00007ff93988b000-00007ff93990ffff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
1921b98.b54: 00007ff939910000-00007ffffffeffff 0x0001/0x0000 0x0000000
1931b98.b54: kernel32.dll: timestamp 0xd0cecc10 (rc=VINF_SUCCESS)
1941b98.b54: kernelbase.dll: timestamp 0x83c3d83a (rc=VINF_SUCCESS)
1951b98.b54: apphelp.dll: timestamp 0xff74693c (rc=VINF_SUCCESS)
1961b98.b54: VirtualBoxVM.exe: timestamp 0x5d9f7c37 (rc=VINF_SUCCESS)
1971b98.b54: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
1981b98.b54: '\Device\HarddiskVolume2\Windows\System32\ntdll.dll' has no imports
1991b98.b54: \Device\HarddiskVolume2\Windows\System32\apphelp.dll: Owner is not trusted installer (01 01 00 00 00 00 00 01 00 00 00 00)
2001b98.b54: \Device\HarddiskVolume2\Windows\System32\apphelp.dll: Relaxing the TrustedInstaller requirement for this DLL (it's in system32).
2011b98.b54: apphelp.dll: Differences in section #2 (.rdata) between file and memory:
2021b98.b54: 00007ff933edfe98 / 0x004fe98: 60 != e0
2031b98.b54: 00007ff933edfe99 / 0x004fe99: e1 != ed
2041b98.b54: 00007ff933edfe9a / 0x004fe9a: 93 != 34
2051b98.b54: 00007ff933edfe9b / 0x004fe9b: 36 != 39
2061b98.b54: 00007ff933edfea0 / 0x004fea0: 00 != 50
2071b98.b54: 00007ff933edfea1 / 0x004fea1: 0a != 5e
2081b98.b54: 00007ff933edfea2 / 0x004fea2: 91 != 34
2091b98.b54: 00007ff933edfea3 / 0x004fea3: 36 != 39
2101b98.b54: 00007ff933edfea8 / 0x004fea8: d0 != b0
2111b98.b54: 00007ff933edfea9 / 0x004fea9: 47 != 1d
2121b98.b54: 00007ff933edfeaa / 0x004feaa: 92 != 35
2131b98.b54: 00007ff933edfeab / 0x004feab: 36 != 39
2141b98.b54: 00007ff933edfeb0 / 0x004feb0: 20 != 50
2151b98.b54: 00007ff933edfeb1 / 0x004feb1: a7 != b7
2161b98.b54: 00007ff933edfeb2 / 0x004feb2: 92 != 34
2171b98.b54: 00007ff933edfeb3 / 0x004feb3: 36 != 39
2181b98.b54: 00007ff933edfeb8 / 0x004feb8: 90 != c0
2191b98.b54: 00007ff933edfeb9 / 0x004feb9: 22 != 1d
2201b98.b54: 00007ff933edfeba / 0x004feba: 92 != 35
2211b98.b54: 00007ff933edfebb / 0x004febb: 36 != 39
2221b98.b54: 00007ff933edfec0 / 0x004fec0: 60 != 40
2231b98.b54: 00007ff933edfec1 / 0x004fec1: bc != be
2241b98.b54: 00007ff933edfec2 / 0x004fec2: 91 != 34
2251b98.b54: 00007ff933edfec3 / 0x004fec3: 36 != 39
2261b98.b54: 00007ff933edfec8 / 0x004fec8: 80 != 60
2271b98.b54: 00007ff933edfec9 / 0x004fec9: 66 != a1
2281b98.b54: 00007ff933edfeca / 0x004feca: 92 != 34
2291b98.b54: 00007ff933edfecb / 0x004fecb: 36 != 39
2301b98.b54: 00007ff933edfed8 / 0x004fed8: c0 != a0
2311b98.b54: 00007ff933edfed9 / 0x004fed9: 72 != a1
2321b98.b54: 00007ff933edfeda / 0x004feda: 8e != 34
2331b98.b54: 00007ff933edfedb / 0x004fedb: 36 != 39
2341b98.b54: Restored 0x2000 bytes of original file content at 00007ff933ede000
2351b98.b54: supR3HardenedWinInit: SUPHARDNTVPKIND_SELF_PURIFICATION_LIMITED -> VINF_SUCCESS, cFixes=1
2361b98.b54: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
2371b98.b54: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe)
2381b98.b54: supR3HardNtEnableThreadCreationEx:
2391b98.b54: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ff9397917f0 pvNtTerminateThread=00007ff9397bcb10
2401b98.b54: supR3HardenedWinDoReSpawn(1): New child 1c54.1028 [kernel32].
2411b98.b54: supR3HardNtChildGatherData: PebBaseAddress=00000000004ba000 cbPeb=0x388
2421b98.b54: supR3HardNtPuChFindNtdll: uNtDllParentAddr=00007ff939720000 uNtDllChildAddr=00007ff939720000
2431b98.b54: supR3HardenedWinSetupChildInit: uLdrInitThunk=00007ff9397917f0
2441b98.b54: supR3HardenedWinSetupChildInit: Start child.
2451b98.b54: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 1 ms.
2461b98.b54: supR3HardNtChildPurify: Startup delay kludge #1/0: 513 ms, 57 sleeps
2471b98.b54: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
2481b98.b54: *0000000000000000-000000000023ffff 0x0001/0x0000 0x0000000
2491b98.b54: *0000000000240000-000000000025ffff 0x0004/0x0004 0x0020000
2501b98.b54: *0000000000260000-000000000027afff 0x0002/0x0002 0x0040000
2511b98.b54: 000000000027b000-000000000027ffff 0x0001/0x0000 0x0000000
2521b98.b54: *0000000000280000-000000000037afff 0x0000/0x0004 0x0020000
2531b98.b54: 000000000037b000-000000000037dfff 0x0104/0x0004 0x0020000
2541b98.b54: 000000000037e000-000000000037ffff 0x0004/0x0004 0x0020000
2551b98.b54: *0000000000380000-0000000000383fff 0x0002/0x0002 0x0040000
2561b98.b54: 0000000000384000-000000000038ffff 0x0001/0x0000 0x0000000
2571b98.b54: *0000000000390000-0000000000391fff 0x0004/0x0004 0x0020000
2581b98.b54: 0000000000392000-00000000003fffff 0x0001/0x0000 0x0000000
2591b98.b54: *0000000000400000-00000000004b9fff 0x0000/0x0004 0x0020000
2601b98.b54: 00000000004ba000-00000000004bcfff 0x0004/0x0004 0x0020000
2611b98.b54: 00000000004bd000-00000000005fffff 0x0000/0x0004 0x0020000
2621b98.b54: 0000000000600000-000000007ffdffff 0x0001/0x0000 0x0000000
2631b98.b54: *000000007ffe0000-000000007ffe0fff 0x0002/0x0002 0x0020000
2641b98.b54: 000000007ffe1000-00007ff5b60affff 0x0001/0x0000 0x0000000
2651b98.b54: *00007ff5b60b0000-00007ff5b60b0fff 0x0002/0x0002 0x0040000
2661b98.b54: 00007ff5b60b1000-00007ff5b60bffff 0x0001/0x0000 0x0000000
2671b98.b54: *00007ff5b60c0000-00007ff5b60e2fff 0x0002/0x0002 0x0040000
2681b98.b54: 00007ff5b60e3000-00007ff74789ffff 0x0001/0x0000 0x0000000
2691b98.b54: *00007ff7478a0000-00007ff7478a0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
2701b98.b54: 00007ff7478a1000-00007ff747915fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
2711b98.b54: 00007ff747916000-00007ff747916fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
2721b98.b54: 00007ff747917000-00007ff74795efff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
2731b98.b54: 00007ff74795f000-00007ff74795ffff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
2741b98.b54: 00007ff747960000-00007ff747960fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
2751b98.b54: 00007ff747961000-00007ff747965fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
2761b98.b54: 00007ff747966000-00007ff747966fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
2771b98.b54: 00007ff747967000-00007ff747967fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
2781b98.b54: 00007ff747968000-00007ff74796bfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
2791b98.b54: 00007ff74796c000-00007ff7479b4fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
2801b98.b54: 00007ff7479b5000-00007ff93971ffff 0x0001/0x0000 0x0000000
2811b98.b54: *00007ff939720000-00007ff939720fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
2821b98.b54: 00007ff939721000-00007ff939837fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
2831b98.b54: 00007ff939838000-00007ff93987efff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
2841b98.b54: 00007ff93987f000-00007ff93988afff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
2851b98.b54: 00007ff93988b000-00007ff939899fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
2861b98.b54: 00007ff93989a000-00007ff93989afff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
2871b98.b54: 00007ff93989b000-00007ff93989dfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
2881b98.b54: 00007ff93989e000-00007ff93990ffff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
2891b98.b54: 00007ff939910000-00007ffffffeffff 0x0001/0x0000 0x0000000
2901b98.b54: supR3HardNtChildPurify: Done after 667 ms and 0 fixes (loop #0).
2911c54.1028: Log file opened: 6.0.14r133895 g_hStartupLog=0000000000000004 g_uNtVerCombined=0xa047bb00
2921b98.b54: supR3HardNtEnableThreadCreationEx:
2931c54.1028: supR3HardenedVmProcessInit: uNtDllAddr=00007ff939720000 g_uNtVerCombined=0xa047bb00
2941c54.1028: ntdll.dll: timestamp 0x99ca0526 (rc=VINF_SUCCESS)
2951c54.1028: New simple heap: #1 0000000000700000 LB 0x400000 (for 2031616 allocation)
2961c54.1028: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
2971c54.1028: System32: \Device\HarddiskVolume2\Windows\System32
2981c54.1028: WinSxS: \Device\HarddiskVolume2\Windows\WinSxS
2991c54.1028: KnownDllPath: C:\WINDOWS\System32
3001c54.1028: supR3HardenedVmProcessInit: Opening vboxdrv stub...
3011c54.1028: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
3021c54.1028: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
3031c54.1028: Registered Dll notification callback with NTDLL.
3041c54.1028: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\kernel32.dll)
3051c54.1028: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\kernel32.dll
3061c54.1028: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\KERNEL32.DLL (Input=KERNEL32.DLL, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000004001:<flags> [calling]
3071c54.1028: supR3HardenedDllNotificationCallback: load 00007ff9368c0000 LB 0x002a3000 C:\WINDOWS\System32\KERNELBASE.dll [fFlags=0x0]
3081c54.1028: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\KernelBase.dll)
3091c54.1028: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\KernelBase.dll
3101c54.1028: supR3HardenedDllNotificationCallback: load 00007ff939330000 LB 0x000b2000 C:\WINDOWS\System32\KERNEL32.DLL [fFlags=0x0]
3111c54.1028: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
3121c54.1028: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff939330000 'C:\WINDOWS\System32\KERNEL32.DLL'
3131c54.1028: supR3HardenedDllNotificationCallback: load 00007ff7478a0000 LB 0x00115000 C:\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe [fFlags=0x0]
3141c54.1028: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
3151c54.1028: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe)
3161c54.1028: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
3171c54.1028: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ff9397917f0 pvNtTerminateThread=00007ff9397bcb10
3181b98.b54: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 202 ms.
3191c54.1028: \SystemRoot\System32\ntdll.dll:
3201c54.1028: CreationTime: 2019-10-09T07:15:15.782952500Z
3211c54.1028: LastWriteTime: 2019-10-09T07:15:16.191946200Z
3221c54.1028: ChangeTime: 2019-11-12T21:16:16.798042000Z
3231c54.1028: FileAttributes: 0x820
3241c54.1028: Size: 0x1e8528
3251c54.1028: NT Headers: 0xd8
3261c54.1028: Timestamp: 0x99ca0526
3271c54.1028: Machine: 0x8664 - amd64
3281c54.1028: Timestamp: 0x99ca0526
3291c54.1028: Image Version: 10.0
3301c54.1028: SizeOfImage: 0x1f0000 (2031616)
3311c54.1028: Resource Dir: 0x17f000 LB 0x6f310
3321c54.1028: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
3331c54.1028: [Raw version resource data: 0x17f0f0 LB 0x380, codepage 0x0 (reserved 0x0)]
3341c54.1028: ProductName: Microsoft® Windows® Operating System
3351c54.1028: ProductVersion: 10.0.18362.418
3361c54.1028: FileVersion: 10.0.18362.418 (WinBuild.160101.0800)
3371c54.1028: FileDescription: NT Layer DLL
3381c54.1028: \SystemRoot\System32\kernel32.dll:
3391c54.1028: CreationTime: 2019-09-06T08:50:11.805475900Z
3401c54.1028: LastWriteTime: 2019-09-06T08:50:12.063263600Z
3411c54.1028: ChangeTime: 2019-11-12T21:14:43.929620400Z
3421c54.1028: FileAttributes: 0x820
3431c54.1028: Size: 0xb0570
3441c54.1028: NT Headers: 0xe8
3451c54.1028: Timestamp: 0xd0cecc10
3461c54.1028: Machine: 0x8664 - amd64
3471c54.1028: Timestamp: 0xd0cecc10
3481c54.1028: Image Version: 10.0
3491c54.1028: SizeOfImage: 0xb2000 (729088)
3501c54.1028: Resource Dir: 0xb0000 LB 0x520
3511c54.1028: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
3521c54.1028: [Raw version resource data: 0xb00b0 LB 0x3a4, codepage 0x0 (reserved 0x0)]
3531c54.1028: ProductName: Microsoft® Windows® Operating System
3541c54.1028: ProductVersion: 10.0.18362.329
3551c54.1028: FileVersion: 10.0.18362.329 (WinBuild.160101.0800)
3561c54.1028: FileDescription: Windows NT BASE API Client DLL
3571c54.1028: \SystemRoot\System32\KernelBase.dll:
3581c54.1028: CreationTime: 2019-11-12T21:02:18.696374500Z
3591c54.1028: LastWriteTime: 2019-11-12T21:02:19.515375500Z
3601c54.1028: ChangeTime: 2019-11-13T01:07:03.500085800Z
3611c54.1028: FileAttributes: 0x20
3621c54.1028: Size: 0x2a2908
3631c54.1028: NT Headers: 0xf0
3641c54.1028: Timestamp: 0x83c3d83a
3651c54.1028: Machine: 0x8664 - amd64
3661c54.1028: Timestamp: 0x83c3d83a
3671c54.1028: Image Version: 10.0
3681c54.1028: SizeOfImage: 0x2a3000 (2764800)
3691c54.1028: Resource Dir: 0x27d000 LB 0x548
3701c54.1028: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
3711c54.1028: [Raw version resource data: 0x27d0b0 LB 0x3bc, codepage 0x0 (reserved 0x0)]
3721c54.1028: ProductName: Microsoft® Windows® Operating System
3731c54.1028: ProductVersion: 10.0.18362.476
3741c54.1028: FileVersion: 10.0.18362.476 (WinBuild.160101.0800)
3751c54.1028: FileDescription: Windows NT BASE API Client DLL
3761c54.1028: \SystemRoot\System32\apisetschema.dll:
3771c54.1028: CreationTime: 2019-03-19T04:43:54.837151500Z
3781c54.1028: LastWriteTime: 2019-10-23T09:58:34.870639900Z
3791c54.1028: ChangeTime: 2019-11-12T21:14:42.081621100Z
3801c54.1028: FileAttributes: 0x20
3811c54.1028: Size: 0x1d028
3821c54.1028: NT Headers: 0xc8
3831c54.1028: Timestamp: 0xd6ced080
3841c54.1028: Machine: 0x8664 - amd64
3851c54.1028: Timestamp: 0xd6ced080
3861c54.1028: Image Version: 10.0
3871c54.1028: SizeOfImage: 0x1e000 (122880)
3881c54.1028: Resource Dir: 0x1d000 LB 0x408
3891c54.1028: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
3901c54.1028: [Raw version resource data: 0x1d060 LB 0x3a8, codepage 0x0 (reserved 0x0)]
3911c54.1028: ProductName: Microsoft® Windows® Operating System
3921c54.1028: ProductVersion: 10.0.18362.1
3931c54.1028: FileVersion: 10.0.18362.1 (WinBuild.160101.0800)
3941c54.1028: FileDescription: ApiSet Schema DLL
3951c54.1028: Found driver mbamswissarmy (0x80)
3961c54.1028: supR3HardenedWinFindAdversaries: 0x80
3971c54.1028: \SystemRoot\System32\drivers\MBAMSwissArmy.sys:
3981c54.1028: CreationTime: 2019-07-14T23:08:00.417005100Z
3991c54.1028: LastWriteTime: 2019-10-23T09:14:30.733490000Z
4001c54.1028: ChangeTime: 2019-10-23T09:14:30.733490000Z
4011c54.1028: FileAttributes: 0x20
4021c54.1028: Size: 0x43320
4031c54.1028: NT Headers: 0xf8
4041c54.1028: Timestamp: 0x5c9e68f9
4051c54.1028: Machine: 0x8664 - amd64
4061c54.1028: Timestamp: 0x5c9e68f9
4071c54.1028: Image Version: 10.0
4081c54.1028: SizeOfImage: 0x45000 (282624)
4091c54.1028: Resource Dir: 0x43000 LB 0x3b8
4101c54.1028: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
4111c54.1028: [Raw version resource data: 0x43060 LB 0x358, codepage 0x0 (reserved 0x0)]
4121c54.1028: ProductName: Malwarebytes SwissArmy
4131c54.1028: ProductVersion: 4.3.0.170
4141c54.1028: FileVersion: 4.3.0.170
4151c54.1028: FileDescription: Malwarebytes SwissArmy
4161c54.1028: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
4171c54.1028: Calling main()
4181c54.1028: SUPR3HardenedMain: pszProgName=VirtualBoxVM fFlags=0x2
4191c54.1028: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
4201c54.1028: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
4211c54.1028: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe)
4221c54.1028: SUPR3HardenedMain: Respawn #2
4231c54.1028: supR3HardNtEnableThreadCreationEx:
4241c54.1028: supR3HardenedDllNotificationCallback: load 00007ff937840000 LB 0x00120000 C:\WINDOWS\System32\RPCRT4.dll [fFlags=0x0]
4251c54.1028: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll)
4261c54.1028: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
4271c54.1028: supR3HardenedDllNotificationCallback: load 00007ff9394a0000 LB 0x00097000 C:\WINDOWS\System32\sechost.dll [fFlags=0x0]
4281c54.1028: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'rpcrt4.dll'.
4291c54.1028: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\sechost.dll)
4301c54.1028: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\sechost.dll
4311c54.1028: '\Device\HarddiskVolume2\Windows\System32\ntdll.dll' has no imports
4321c54.1028: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ntdll.dll)
4331c54.1028: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ntdll.dll
4341c54.1028: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
4351c54.1028: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
4361c54.1028: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
4371c54.1028: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\ntdll.dll (Input=ntdll.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
4381c54.1028: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff939720000 'C:\WINDOWS\System32\ntdll.dll'
4391c54.1028: \Device\HarddiskVolume2\Windows\System32\apphelp.dll: Owner is not trusted installer (01 01 00 00 00 00 00 01 00 00 00 00)
4401c54.1028: \Device\HarddiskVolume2\Windows\System32\apphelp.dll: Relaxing the TrustedInstaller requirement for this DLL (it's in system32).
4411c54.1028: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\apphelp.dll)
4421c54.1028: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\apphelp.dll
4431c54.1028: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\apphelp.dll (rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
4441c54.1028: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\apphelp.dll [lacks WinVerifyTrust]
4451c54.1028: supR3HardenedDllNotificationCallback: load 00007ff933e90000 LB 0x0008f000 C:\WINDOWS\system32\apphelp.dll [fFlags=0x0]
4461c54.1028: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\apphelp.dll [lacks WinVerifyTrust]
4471c54.1028: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ntdll.dll [lacks WinVerifyTrust]
4481c54.1028: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\ntdll.dll (Input=ntdll.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
4491c54.1028: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff939720000 'C:\WINDOWS\System32\ntdll.dll'
4501c54.1028: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff933e90000 'C:\WINDOWS\system32\apphelp.dll'
4511c54.1028: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ff9397917f0 pvNtTerminateThread=00007ff9397bcb10
4521c54.1028: supR3HardenedWinDoReSpawn(2): New child 1e24.48c [kernel32].
4531c54.1028: supR3HardenedWinReSpawn: NtSetInformationThread/ThreadHideFromDebugger failed: 0xc0000022 (harmless)
4541c54.1028: supR3HardNtChildGatherData: PebBaseAddress=0000000000952000 cbPeb=0x388
4551c54.1028: supR3HardNtPuChFindNtdll: uNtDllParentAddr=00007ff939720000 uNtDllChildAddr=00007ff939720000
4561c54.1028: supR3HardenedWinSetupChildInit: uLdrInitThunk=00007ff9397917f0
4571c54.1028: supR3HardenedWinSetupChildInit: Start child.
4581c54.1028: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 1 ms.
4591c54.1028: supR3HardNtChildPurify: Startup delay kludge #1/0: 513 ms, 57 sleeps
4601c54.1028: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
4611c54.1028: *0000000000000000-000000000077ffff 0x0001/0x0000 0x0000000
4621c54.1028: *0000000000780000-000000000079ffff 0x0004/0x0004 0x0020000
4631c54.1028: *00000000007a0000-00000000007bafff 0x0002/0x0002 0x0040000
4641c54.1028: 00000000007bb000-00000000007bffff 0x0001/0x0000 0x0000000
4651c54.1028: *00000000007c0000-00000000007c3fff 0x0002/0x0002 0x0040000
4661c54.1028: 00000000007c4000-00000000007cffff 0x0001/0x0000 0x0000000
4671c54.1028: *00000000007d0000-00000000007d1fff 0x0004/0x0004 0x0020000
4681c54.1028: 00000000007d2000-00000000007fffff 0x0001/0x0000 0x0000000
4691c54.1028: *0000000000800000-0000000000951fff 0x0000/0x0004 0x0020000
4701c54.1028: 0000000000952000-0000000000954fff 0x0004/0x0004 0x0020000
4711c54.1028: 0000000000955000-00000000009fffff 0x0000/0x0004 0x0020000
4721c54.1028: *0000000000a00000-0000000000afafff 0x0000/0x0004 0x0020000
4731c54.1028: 0000000000afb000-0000000000afdfff 0x0104/0x0004 0x0020000
4741c54.1028: 0000000000afe000-0000000000afffff 0x0004/0x0004 0x0020000
4751c54.1028: 0000000000b00000-000000007ffdffff 0x0001/0x0000 0x0000000
4761c54.1028: *000000007ffe0000-000000007ffe0fff 0x0002/0x0002 0x0020000
4771c54.1028: 000000007ffe1000-00007ff5146affff 0x0001/0x0000 0x0000000
4781c54.1028: *00007ff5146b0000-00007ff5146b0fff 0x0002/0x0002 0x0040000
4791c54.1028: 00007ff5146b1000-00007ff5146bffff 0x0001/0x0000 0x0000000
4801c54.1028: *00007ff5146c0000-00007ff5146e2fff 0x0002/0x0002 0x0040000
4811c54.1028: 00007ff5146e3000-00007ff74789ffff 0x0001/0x0000 0x0000000
4821c54.1028: *00007ff7478a0000-00007ff7478a0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
4831c54.1028: 00007ff7478a1000-00007ff747915fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
4841c54.1028: 00007ff747916000-00007ff747916fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
4851c54.1028: 00007ff747917000-00007ff74795efff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
4861c54.1028: 00007ff74795f000-00007ff74795ffff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
4871c54.1028: 00007ff747960000-00007ff747960fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
4881c54.1028: 00007ff747961000-00007ff747965fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
4891c54.1028: 00007ff747966000-00007ff747966fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
4901c54.1028: 00007ff747967000-00007ff747967fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
4911c54.1028: 00007ff747968000-00007ff74796bfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
4921c54.1028: 00007ff74796c000-00007ff7479b4fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
4931c54.1028: 00007ff7479b5000-00007ff93971ffff 0x0001/0x0000 0x0000000
4941c54.1028: *00007ff939720000-00007ff939720fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
4951c54.1028: 00007ff939721000-00007ff939837fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
4961c54.1028: 00007ff939838000-00007ff93987efff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
4971c54.1028: 00007ff93987f000-00007ff93988afff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
4981c54.1028: 00007ff93988b000-00007ff939899fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
4991c54.1028: 00007ff93989a000-00007ff93989afff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
5001c54.1028: 00007ff93989b000-00007ff93989dfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
5011c54.1028: 00007ff93989e000-00007ff93990ffff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
5021c54.1028: 00007ff939910000-00007ffffffeffff 0x0001/0x0000 0x0000000
5031c54.1028: VirtualBoxVM.exe: timestamp 0x5d9f7c37 (rc=VINF_SUCCESS)
5041c54.1028: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
5051c54.1028: '\Device\HarddiskVolume2\Windows\System32\ntdll.dll' has no imports
5061c54.1028: supR3HardNtChildPurify: Done after 734 ms and 0 fixes (loop #0).
5071e24.48c: Log file opened: 6.0.14r133895 g_hStartupLog=0000000000000004 g_uNtVerCombined=0xa047bb00
5081c54.1028: supR3HardenedEarlyCompact: Removed heap 1 (0x00000000700000 LB 0x400000)
5091e24.48c: supR3HardenedVmProcessInit: uNtDllAddr=00007ff939720000 g_uNtVerCombined=0xa047bb00
5101c54.1028: supR3HardNtEnableThreadCreationEx:
5111e24.48c: ntdll.dll: timestamp 0x99ca0526 (rc=VINF_SUCCESS)
5121e24.48c: New simple heap: #1 0000000000c00000 LB 0x400000 (for 2031616 allocation)
5131e24.48c: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
5141e24.48c: System32: \Device\HarddiskVolume2\Windows\System32
5151e24.48c: WinSxS: \Device\HarddiskVolume2\Windows\WinSxS
5161e24.48c: KnownDllPath: C:\WINDOWS\System32
5171e24.48c: supR3HardenedVmProcessInit: Opening vboxdrv...
5181e24.48c: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
5191e24.48c: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
5201e24.48c: Registered Dll notification callback with NTDLL.
5211e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\kernel32.dll)
5221e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\kernel32.dll
5231e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\KERNEL32.DLL (Input=KERNEL32.DLL, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000004001:<flags> [calling]
5241e24.48c: supR3HardenedDllNotificationCallback: load 00007ff9368c0000 LB 0x002a3000 C:\WINDOWS\System32\KERNELBASE.dll [fFlags=0x0]
5251e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\KernelBase.dll)
5261e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\KernelBase.dll
5271e24.48c: supR3HardenedDllNotificationCallback: load 00007ff939330000 LB 0x000b2000 C:\WINDOWS\System32\KERNEL32.DLL [fFlags=0x0]
5281e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
5291e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff939330000 'C:\WINDOWS\System32\KERNEL32.DLL'
5301e24.48c: supR3HardenedDllNotificationCallback: load 00007ff7478a0000 LB 0x00115000 C:\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe [fFlags=0x0]
5311e24.48c: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
5321e24.48c: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe)
5331e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
5341e24.48c: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ff9397917f0 pvNtTerminateThread=00007ff9397bcb10
5351c54.1028: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 213 ms.
5361e24.48c: \SystemRoot\System32\ntdll.dll:
5371e24.48c: CreationTime: 2019-10-09T07:15:15.782952500Z
5381e24.48c: LastWriteTime: 2019-10-09T07:15:16.191946200Z
5391e24.48c: ChangeTime: 2019-11-12T21:16:16.798042000Z
5401e24.48c: FileAttributes: 0x820
5411e24.48c: Size: 0x1e8528
5421e24.48c: NT Headers: 0xd8
5431e24.48c: Timestamp: 0x99ca0526
5441e24.48c: Machine: 0x8664 - amd64
5451e24.48c: Timestamp: 0x99ca0526
5461e24.48c: Image Version: 10.0
5471e24.48c: SizeOfImage: 0x1f0000 (2031616)
5481e24.48c: Resource Dir: 0x17f000 LB 0x6f310
5491e24.48c: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
5501e24.48c: [Raw version resource data: 0x17f0f0 LB 0x380, codepage 0x0 (reserved 0x0)]
5511e24.48c: ProductName: Microsoft® Windows® Operating System
5521e24.48c: ProductVersion: 10.0.18362.418
5531e24.48c: FileVersion: 10.0.18362.418 (WinBuild.160101.0800)
5541e24.48c: FileDescription: NT Layer DLL
5551e24.48c: \SystemRoot\System32\kernel32.dll:
5561e24.48c: CreationTime: 2019-09-06T08:50:11.805475900Z
5571e24.48c: LastWriteTime: 2019-09-06T08:50:12.063263600Z
5581e24.48c: ChangeTime: 2019-11-12T21:14:43.929620400Z
5591e24.48c: FileAttributes: 0x820
5601e24.48c: Size: 0xb0570
5611e24.48c: NT Headers: 0xe8
5621e24.48c: Timestamp: 0xd0cecc10
5631e24.48c: Machine: 0x8664 - amd64
5641e24.48c: Timestamp: 0xd0cecc10
5651e24.48c: Image Version: 10.0
5661e24.48c: SizeOfImage: 0xb2000 (729088)
5671e24.48c: Resource Dir: 0xb0000 LB 0x520
5681e24.48c: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
5691e24.48c: [Raw version resource data: 0xb00b0 LB 0x3a4, codepage 0x0 (reserved 0x0)]
5701e24.48c: ProductName: Microsoft® Windows® Operating System
5711e24.48c: ProductVersion: 10.0.18362.329
5721e24.48c: FileVersion: 10.0.18362.329 (WinBuild.160101.0800)
5731e24.48c: FileDescription: Windows NT BASE API Client DLL
5741e24.48c: \SystemRoot\System32\KernelBase.dll:
5751e24.48c: CreationTime: 2019-11-12T21:02:18.696374500Z
5761e24.48c: LastWriteTime: 2019-11-12T21:02:19.515375500Z
5771e24.48c: ChangeTime: 2019-11-13T01:07:03.500085800Z
5781e24.48c: FileAttributes: 0x20
5791e24.48c: Size: 0x2a2908
5801e24.48c: NT Headers: 0xf0
5811e24.48c: Timestamp: 0x83c3d83a
5821e24.48c: Machine: 0x8664 - amd64
5831e24.48c: Timestamp: 0x83c3d83a
5841e24.48c: Image Version: 10.0
5851e24.48c: SizeOfImage: 0x2a3000 (2764800)
5861e24.48c: Resource Dir: 0x27d000 LB 0x548
5871e24.48c: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
5881e24.48c: [Raw version resource data: 0x27d0b0 LB 0x3bc, codepage 0x0 (reserved 0x0)]
5891e24.48c: ProductName: Microsoft® Windows® Operating System
5901e24.48c: ProductVersion: 10.0.18362.476
5911e24.48c: FileVersion: 10.0.18362.476 (WinBuild.160101.0800)
5921e24.48c: FileDescription: Windows NT BASE API Client DLL
5931e24.48c: \SystemRoot\System32\apisetschema.dll:
5941e24.48c: CreationTime: 2019-03-19T04:43:54.837151500Z
5951e24.48c: LastWriteTime: 2019-10-23T09:58:34.870639900Z
5961e24.48c: ChangeTime: 2019-11-12T21:14:42.081621100Z
5971e24.48c: FileAttributes: 0x20
5981e24.48c: Size: 0x1d028
5991e24.48c: NT Headers: 0xc8
6001e24.48c: Timestamp: 0xd6ced080
6011e24.48c: Machine: 0x8664 - amd64
6021e24.48c: Timestamp: 0xd6ced080
6031e24.48c: Image Version: 10.0
6041e24.48c: SizeOfImage: 0x1e000 (122880)
6051e24.48c: Resource Dir: 0x1d000 LB 0x408
6061e24.48c: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
6071e24.48c: [Raw version resource data: 0x1d060 LB 0x3a8, codepage 0x0 (reserved 0x0)]
6081e24.48c: ProductName: Microsoft® Windows® Operating System
6091e24.48c: ProductVersion: 10.0.18362.1
6101e24.48c: FileVersion: 10.0.18362.1 (WinBuild.160101.0800)
6111e24.48c: FileDescription: ApiSet Schema DLL
6121e24.48c: Found driver mbamswissarmy (0x80)
6131e24.48c: supR3HardenedWinFindAdversaries: 0x80
6141e24.48c: \SystemRoot\System32\drivers\MBAMSwissArmy.sys:
6151e24.48c: CreationTime: 2019-07-14T23:08:00.417005100Z
6161e24.48c: LastWriteTime: 2019-10-23T09:14:30.733490000Z
6171e24.48c: ChangeTime: 2019-10-23T09:14:30.733490000Z
6181e24.48c: FileAttributes: 0x20
6191e24.48c: Size: 0x43320
6201e24.48c: NT Headers: 0xf8
6211e24.48c: Timestamp: 0x5c9e68f9
6221e24.48c: Machine: 0x8664 - amd64
6231e24.48c: Timestamp: 0x5c9e68f9
6241e24.48c: Image Version: 10.0
6251e24.48c: SizeOfImage: 0x45000 (282624)
6261e24.48c: Resource Dir: 0x43000 LB 0x3b8
6271e24.48c: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
6281e24.48c: [Raw version resource data: 0x43060 LB 0x358, codepage 0x0 (reserved 0x0)]
6291e24.48c: ProductName: Malwarebytes SwissArmy
6301e24.48c: ProductVersion: 4.3.0.170
6311e24.48c: FileVersion: 4.3.0.170
6321e24.48c: FileDescription: Malwarebytes SwissArmy
6331e24.48c: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
6341e24.48c: Calling main()
6351e24.48c: SUPR3HardenedMain: pszProgName=VirtualBoxVM fFlags=0x2
6361e24.48c: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
6371e24.48c: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
6381e24.48c: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe)
6391e24.48c: SUPR3HardenedMain: Final process, opening VBoxDrv...
6401e24.48c: supR3HardenedEarlyCompact: Removed heap 1 (0x00000000c00000 LB 0x400000)
6411e24.48c: supR3HardNtEnableThreadCreationEx:
6421e24.48c: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll)
6431e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll
6441e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
6451e24.48c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
6461e24.48c: supR3HardenedDllNotificationCallback: load 00007ff933fe0000 LB 0x00005000 C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL [fFlags=0x0]
6471e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
6481e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
6491e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
6501e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff933fe0000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
6511e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
6521e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
6531e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff933fe0000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
6541e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff933fe0000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
6551e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
6561e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msasn1.dll'.
6571e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'crypt32.dll'.
6581e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #27 'rpcrt4.dll'.
6591e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\wintrust.dll)
6601e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wintrust.dll
6611e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
6621e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
6631e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll)
6641e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
6651e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
6661e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume2\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
6671e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #34 'msasn1.dll'.
6681e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\crypt32.dll)
6691e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\crypt32.dll
6701e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
6711e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume2\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
6721e24.48c: \Device\HarddiskVolume2\Windows\System32\msasn1.dll: Owner is not trusted installer (01 01 00 00 00 00 00 01 00 00 00 00)
6731e24.48c: \Device\HarddiskVolume2\Windows\System32\msasn1.dll: Relaxing the TrustedInstaller requirement for this DLL (it's in system32).
6741e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\msasn1.dll)
6751e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msasn1.dll
6761e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
6771e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
6781e24.48c: \Device\HarddiskVolume2\Windows\System32\msvcrt.dll: Owner is not trusted installer (01 01 00 00 00 00 00 01 00 00 00 00)
6791e24.48c: \Device\HarddiskVolume2\Windows\System32\msvcrt.dll: Relaxing the TrustedInstaller requirement for this DLL (it's in system32).
6801e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\msvcrt.dll)
6811e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
6821e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
6831e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume2\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
6841e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
6851e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
6861e24.48c: supR3HardenedDllNotificationCallback: load 00007ff938df0000 LB 0x0009e000 C:\WINDOWS\System32\msvcrt.dll [fFlags=0x0]
6871e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
6881e24.48c: supR3HardenedDllNotificationCallback: load 00007ff936670000 LB 0x00012000 C:\WINDOWS\System32\MSASN1.dll [fFlags=0x0]
6891e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
6901e24.48c: supR3HardenedDllNotificationCallback: load 00007ff936d70000 LB 0x000fa000 C:\WINDOWS\System32\ucrtbase.dll [fFlags=0x0]
6911e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ucrtbase.dll)
6921e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ucrtbase.dll
6931e24.48c: supR3HardenedDllNotificationCallback: load 00007ff936770000 LB 0x00149000 C:\WINDOWS\System32\CRYPT32.dll [fFlags=0x0]
6941e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
6951e24.48c: supR3HardenedDllNotificationCallback: load 00007ff937840000 LB 0x00120000 C:\WINDOWS\System32\RPCRT4.dll [fFlags=0x0]
6961e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
6971e24.48c: supR3HardenedDllNotificationCallback: load 00007ff936b70000 LB 0x0005c000 C:\WINDOWS\System32\Wintrust.dll [fFlags=0x0]
6981e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
6991e24.48c: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
7001e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
7011e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9368c0000 'api-ms-win-core-synch-l1-2-0'
7021e24.48c: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-fibers-l1-1-1) -> 0x0, fPresent=1
7031e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
7041e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9368c0000 'api-ms-win-core-fibers-l1-1-1'
7051e24.48c: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-fibers-l1-1-1) -> 0x0, fPresent=1
7061e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
7071e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9368c0000 'api-ms-win-core-fibers-l1-1-1'
7081e24.48c: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
7091e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
7101e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9368c0000 'api-ms-win-core-synch-l1-2-0'
7111e24.48c: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-l1-2-1) -> 0x0, fPresent=1
7121e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-l1-2-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
7131e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9368c0000 'api-ms-win-core-localization-l1-2-1'
7141e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936b70000 'C:\WINDOWS\system32\Wintrust.dll'
7151e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\bcrypt.dll)
7161e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\bcrypt.dll
7171e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\bcrypt.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
7181e24.48c: supR3HardenedDllNotificationCallback: load 00007ff937620000 LB 0x00026000 C:\WINDOWS\System32\bcrypt.dll [fFlags=0x0]
7191e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
7201e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff937620000 'C:\WINDOWS\system32\bcrypt.dll'
7211e24.48c: bcrypt.dll loaded at 00007ff937620000, BCryptOpenAlgorithmProvider at 00007ff937624c70, preloading providers:
7221e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll)
7231e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll
7241e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\bcryptprimitives.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
7251e24.48c: supR3HardenedDllNotificationCallback: load 00007ff937750000 LB 0x00080000 C:\WINDOWS\System32\bcryptprimitives.dll [fFlags=0x0]
7261e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
7271e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff937750000 'C:\WINDOWS\system32\bcryptprimitives.dll'
7281e24.48c: BCryptOpenAlgorithmProvider(,'MD2',0,0) -> 0x0 (hAlgo=000000000102ecd0)
7291e24.48c: BCryptOpenAlgorithmProvider(,'MD4',0,0) -> 0x0 (hAlgo=000000000102fa30)
7301e24.48c: BCryptOpenAlgorithmProvider(,'MD5',0,0) -> 0x0 (hAlgo=000000000102fd30)
7311e24.48c: BCryptOpenAlgorithmProvider(,'SHA1',0,0) -> 0x0 (hAlgo=0000000001030030)
7321e24.48c: BCryptOpenAlgorithmProvider(,'SHA256',0,0) -> 0x0 (hAlgo=0000000001030330)
7331e24.48c: BCryptOpenAlgorithmProvider(,'SHA512',0,0) -> 0x0 (hAlgo=0000000001030630)
7341e24.48c: BCryptOpenAlgorithmProvider(,'RSA',0,0) -> 0x0 (hAlgo=0000000001030930)
7351e24.48c: BCryptOpenAlgorithmProvider(,'DSA',0,0) -> 0x0 (hAlgo=0000000001030c30)
7361e24.48c: supR3HardenedDllNotificationCallback: load 00007ff936750000 LB 0x00017000 C:\WINDOWS\System32\CRYPTSP.dll [fFlags=0x0]
7371e24.48c: \Device\HarddiskVolume2\Windows\System32\cryptsp.dll: Owner is not trusted installer (01 01 00 00 00 00 00 01 00 00 00 00)
7381e24.48c: \Device\HarddiskVolume2\Windows\System32\cryptsp.dll: Relaxing the TrustedInstaller requirement for this DLL (it's in system32).
7391e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\cryptsp.dll)
7401e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cryptsp.dll
7411e24.48c: \Device\HarddiskVolume2\Windows\System32\rsaenh.dll: Owner is not trusted installer (01 01 00 00 00 00 00 01 00 00 00 00)
7421e24.48c: \Device\HarddiskVolume2\Windows\System32\rsaenh.dll: Relaxing the TrustedInstaller requirement for this DLL (it's in system32).
7431e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'bcrypt.dll'.
7441e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\rsaenh.dll)
7451e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\rsaenh.dll
7461e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
7471e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume2\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
7481e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
7491e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
7501e24.48c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
7511e24.48c: supR3HardenedDllNotificationCallback: load 00007ff9359d0000 LB 0x00033000 C:\WINDOWS\system32\rsaenh.dll [fFlags=0x0]
7521e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
7531e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
7541e24.48c: \Device\HarddiskVolume2\Windows\System32\cryptbase.dll: Owner is not trusted installer (01 01 00 00 00 00 00 01 00 00 00 00)
7551e24.48c: \Device\HarddiskVolume2\Windows\System32\cryptbase.dll: Relaxing the TrustedInstaller requirement for this DLL (it's in system32).
7561e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'bcryptprimitives.dll'.
7571e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\cryptbase.dll)
7581e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cryptbase.dll
7591e24.48c: supR3HardenedDllNotificationCallback: load 00007ff936030000 LB 0x0000c000 C:\WINDOWS\SYSTEM32\CRYPTBASE.dll [fFlags=0x0]
7601e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cryptbase.dll [lacks WinVerifyTrust]
7611e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
7621e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcryptprimitives.dll'...
7631e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcryptprimitives.dll' -> '\Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll' [rcNtRedir=0xc0150008]
7641e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
7651e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
7661e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff939330000 'C:\WINDOWS\System32\kernel32.dll'
7671e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
7681e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\WINTRUST.DLL (Input=WINTRUST.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
7691e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936b70000 'C:\WINDOWS\System32\WINTRUST.DLL'
7701e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
7711e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\CRYPT32.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
7721e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\CRYPT32.dll'
7731e24.48c: supR3HardenedDllNotificationCallback: load 00007ff938700000 LB 0x0001d000 C:\WINDOWS\System32\imagehlp.dll [fFlags=0x0]
7741e24.48c: \Device\HarddiskVolume2\Windows\System32\imagehlp.dll: Owner is not trusted installer (01 01 00 00 00 00 00 01 00 00 00 00)
7751e24.48c: \Device\HarddiskVolume2\Windows\System32\imagehlp.dll: Relaxing the TrustedInstaller requirement for this DLL (it's in system32).
7761e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #20 'rpcrt4.dll'.
7771e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\imagehlp.dll)
7781e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\imagehlp.dll
7791e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
7801e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
7811e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
7821e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
7831e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
7841e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
7851e24.48c: supR3HardenedDllNotificationCallback: load 00007ff9394a0000 LB 0x00097000 C:\WINDOWS\System32\sechost.dll [fFlags=0x0]
7861e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'rpcrt4.dll'.
7871e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\sechost.dll)
7881e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\sechost.dll
7891e24.48c: \Device\HarddiskVolume2\Windows\System32\gpapi.dll: Owner is not trusted installer (01 01 00 00 00 00 00 01 00 00 00 00)
7901e24.48c: \Device\HarddiskVolume2\Windows\System32\gpapi.dll: Relaxing the TrustedInstaller requirement for this DLL (it's in system32).
7911e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
7921e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'rpcrt4.dll'.
7931e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\gpapi.dll)
7941e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\gpapi.dll
7951e24.48c: supR3HardenedDllNotificationCallback: load 00007ff9351f0000 LB 0x00022000 C:\WINDOWS\SYSTEM32\gpapi.dll [fFlags=0x0]
7961e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gpapi.dll [lacks WinVerifyTrust]
7971e24.48c: supR3HardenedDllNotificationCallback: load 00007ff936600000 LB 0x0001f000 C:\WINDOWS\System32\profapi.dll [fFlags=0x0]
7981e24.48c: \Device\HarddiskVolume2\Windows\System32\profapi.dll: Owner is not trusted installer (01 01 00 00 00 00 00 01 00 00 00 00)
7991e24.48c: \Device\HarddiskVolume2\Windows\System32\profapi.dll: Relaxing the TrustedInstaller requirement for this DLL (it's in system32).
8001e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\profapi.dll)
8011e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\profapi.dll
8021e24.48c: \Device\HarddiskVolume2\Windows\System32\cryptnet.dll: Owner is not trusted installer (01 01 00 00 00 00 00 01 00 00 00 00)
8031e24.48c: \Device\HarddiskVolume2\Windows\System32\cryptnet.dll: Relaxing the TrustedInstaller requirement for this DLL (it's in system32).
8041e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
8051e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'crypt32.dll'.
8061e24.48c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\cryptnet.dll)
8071e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cryptnet.dll
8081e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
8091e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume2\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
8101e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
8111e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
8121e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
8131e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
8141e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
8151e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
8161e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
8171e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
8181e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
8191e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
8201e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
8211e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
8221e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
8231e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (Input=cryptnet.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
8241e24.48c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
8251e24.48c: supR3HardenedDllNotificationCallback: load 00007ff9297d0000 LB 0x0002f000 C:\WINDOWS\System32\cryptnet.dll [fFlags=0x0]
8261e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
8271e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
8281e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
8291e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9297d0000 'C:\WINDOWS\System32\cryptnet.dll'
8301e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
8311e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
8321e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9297d0000 'C:\WINDOWS\System32\cryptnet.dll'
8331e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
8341e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
8351e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9297d0000 'C:\WINDOWS\System32\cryptnet.dll'
8361e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
8371e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
8381e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9297d0000 'C:\WINDOWS\System32\cryptnet.dll'
8391e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
8401e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
8411e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9297d0000 'C:\WINDOWS\System32\cryptnet.dll'
8421e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
8431e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
8441e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9297d0000 'C:\WINDOWS\System32\cryptnet.dll'
8451e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
8461e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9297d0000 'C:\WINDOWS\System32\cryptnet.dll'
8471e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
8481e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9297d0000 'C:\WINDOWS\System32\cryptnet.dll'
8491e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
8501e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9297d0000 'C:\WINDOWS\System32\cryptnet.dll'
8511e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
8521e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9297d0000 'C:\WINDOWS\System32\cryptnet.dll'
8531e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
8541e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9297d0000 'C:\WINDOWS\System32\cryptnet.dll'
8551e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9297d0000 'C:\WINDOWS\System32\cryptnet.dll'
8561e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
8571e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9297d0000 'C:\Windows\System32\cryptnet.dll'
8581e24.48c: supR3HardenedDllNotificationCallback: load 00007ff9391d0000 LB 0x000a3000 C:\WINDOWS\System32\advapi32.dll [fFlags=0x0]
8591e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
8601e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'sechost.dll'.
8611e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #27 'rpcrt4.dll'.
8621e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\advapi32.dll)
8631e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\advapi32.dll
8641e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
8651e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
8661e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
8671e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
8681e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'sechost.dll'...
8691e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'sechost.dll' -> '\Device\HarddiskVolume2\Windows\System32\sechost.dll' [rcNtRedir=0xc0150008]
8701e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\sechost.dll [lacks WinVerifyTrust]
8711e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
8721e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
8731e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
8741e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
8751e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
8761e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
8771e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
8781e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
8791e24.48c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000000 pwszName=\SystemRoot\System32\ntdll.dll
8801e24.48c: supR3HardNtViCallWinVerifyTrustCatFile: New context 0000000001743050
8811e24.48c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000001743050
8821e24.48c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=E42142C43484BA84DDDB10D97303487D47E882DE
8831e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
8841e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\rpcrt4.dll (Input=rpcrt4.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
8851e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff937840000 'C:\WINDOWS\System32\rpcrt4.dll'
8861e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
8871e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
8881e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
8891e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
8901e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
8911e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
8921e24.48c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0416~31bf3856ad364e35~amd64~~10.0.18362.476.cat'; file='\SystemRoot\System32\ntdll.dll'
8931e24.48c: g_pfnWinVerifyTrust=00007ff936b761f0
8941e24.48c: supR3HardenedScreenImage/preload: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [redoing WinVerifyTrust]
8951e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
8961e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
8971e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
8981e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
8991e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
9001e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
9011e24.48c: supR3HardenedScreenImage/preload: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\crypt32.dll'
9021e24.48c: supR3HardenedScreenImage/preload: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [redoing WinVerifyTrust]
9031e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
9041e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
9051e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
9061e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll
9071e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
9081e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
9091e24.48c: supR3HardenedScreenImage/preload: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\wintrust.dll'
9101e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
9111e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
9121e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
9131e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
9141e24.48c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\advapi32.dll'
9151e24.48c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000003a8 pwszName=\Device\HarddiskVolume2\Windows\System32\cryptnet.dll
9161e24.48c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000001743050
9171e24.48c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000001743050
9181e24.48c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=09032EBC3D9D9BDDC0EE4A6463C043296B79FF20
9191e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
9201e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
9211e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
9221e24.48c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0416~31bf3856ad364e35~amd64~~10.0.18362.476.cat'; file='\Device\HarddiskVolume2\Windows\System32\cryptnet.dll'
9231e24.48c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
9241e24.48c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\cryptnet.dll'
9251e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
9261e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
9271e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
9281e24.48c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\profapi.dll'
9291e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
9301e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
9311e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
9321e24.48c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\gpapi.dll'
9331e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
9341e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
9351e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
9361e24.48c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\sechost.dll'
9371e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
9381e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
9391e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
9401e24.48c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\imagehlp.dll'
9411e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
9421e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
9431e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
9441e24.48c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\cryptbase.dll'
9451e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
9461e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
9471e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll
9481e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
9491e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
9501e24.48c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\rsaenh.dll'
9511e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll
9521e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
9531e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
9541e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
9551e24.48c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\cryptsp.dll'
9561e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
9571e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
9581e24.48c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll'
9591e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
9601e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
9611e24.48c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\bcrypt.dll'
9621e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
9631e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
9641e24.48c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\ucrtbase.dll'
9651e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
9661e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
9671e24.48c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll'
9681e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
9691e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
9701e24.48c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\msasn1.dll'
9711e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
9721e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
9731e24.48c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll'
9741e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
9751e24.48c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 24202) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll'
9761e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
9771e24.48c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 24202) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe'
9781e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
9791e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
9801e24.48c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\KernelBase.dll'
9811e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
9821e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
9831e24.48c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\kernel32.dll'
9841e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\system32\crypt32.dll'
9851e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0x2d281fd08c6e8eb3 CN=WZT
9861e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0xba02d0ab12c5ed00 CN=XBL Client IPsec Issuing CA
9871e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0x7275300b7705cd00 CN=shodan
9881e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0x3d98ab22bb04a300 C=IE, O=Baltimore, OU=CyberTrust, CN=Baltimore CyberTrust Root
9891e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0x5ad46780fa5df300 DC=com, DC=microsoft, CN=Microsoft Root Certificate Authority
9901e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0xea5386456178582b C=ZA, ST=Western Cape, L=Durbanville, O=Thawte, OU=Thawte Certification, CN=Thawte Timestamping CA
9911e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0x3be670c1bd02a900 OU=Copyright (c) 1997 Microsoft Corp., OU=Microsoft Corporation, CN=Microsoft Root Authority
9921e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0x79900b93675b9600 C=US, CN=The Filter
9931e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0xad4339a0b9c2ae00 C=US, ST=California, L=Irvine, O=Blizzard Entertainment, OU=Battle.net, CN=Blizzard Battle.net Local Cert
9941e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0xe991ee72b03db500 C=US, O=Symantec Corporation, CN=Symantec Enterprise Mobile Root for Microsoft
9951e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0x4d3835aa4180b200 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2011
9961e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0x646e3fe3ba08df00 C=US, O=MSFT, CN=Microsoft Authenticode(tm) Root Authority
9971e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0xa30b6913205dc200 CN=shodan
9981e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0xc14b7a9c0500a600 CN=shodan1
9991e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0xd140ebc339a98a2f CN=WZTeam
10001e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0x9546d06a8d70b800 CN=XBL Server IPsec Issuing CA
10011e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0xd4fbe673e5ccc600 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA
10021e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0xece4e4289e08b900 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010
10031e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0xf3bb4d7e894b420 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft ECC TS Root Certificate Authority 2018
10041e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0xa313393f1b21aa73 C=RU, ST=New York, L=Rochester, O=End Point, OU=Domain uploads.yandex.ru, Email=support@uploads.yandex.ru, CN=uploads.yandex.ru
10051e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0x43a9cc371ff5385a O=Microsoft Trust Network, OU=Microsoft Corporation, OU=Microsoft Time Stamping Service Root, OU=Copyright (c) 1997 Microsoft Corp.
10061e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0x2e2d2c7c68f0202e O=VeriSign Trust Network, OU=VeriSign, Inc., OU=VeriSign Time Stamping Service Root, OU=NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.
10071e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0xcec3d46562b9be8e C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft ECC Product Root Certificate Authority 2018
10081e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0xca58a05dd401ae00 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Time Stamp Root Certificate Authority 2014
10091e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0xa12b07674f1bf600 C=US, O=AffirmTrust, CN=AffirmTrust Commercial
10101e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0x2ca429a5c4c6a700 C=IT, L=Milan, O=Actalis S.p.A./03358520967, CN=Actalis Authentication Root CA
10111e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0xd8dbfb2c27bfb200 C=US, O=thawte, Inc., OU=Certification Services Division, OU=(c) 2008 thawte, Inc. - For authorized use only, CN=thawte Primary Root CA - G3
10121e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0x6e864c7a8071ba00 C=ES, O=FNMT-RCM, OU=AC RAIZ FNMT-RCM
10131e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0x61a3a33f81aace00 C=US, ST=UT, L=Salt Lake City, O=The USERTRUST Network, OU=http://www.usertrust.com, CN=UTN-USERFirst-Object
10141e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0x6b7bdc34cd37bb00 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root G2
10151e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0xf4fd306318ccda00 C=US, O=GeoTrust Inc., CN=GeoTrust Global CA
10161e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0x83085097e9afdf00 O=Digital Signature Trust Co., CN=DST Root CA X3
10171e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0x780679907625cc00 OU=GlobalSign Root CA - R3, O=GlobalSign, CN=GlobalSign
10181e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0x3d98ab22bb04a300 C=IE, O=Baltimore, OU=CyberTrust, CN=Baltimore CyberTrust Root
10191e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0xa0ee62086758b15d C=US, O=Equifax, OU=Equifax Secure Certificate Authority
10201e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0x9403a4b8727eb000 C=TW, O=TAIWAN-CA, OU=Root CA, CN=TWCA Root Certification Authority
10211e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0xd944bca189a00 C=BM, O=QuoVadis Limited, CN=QuoVadis Root CA 2
10221e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0x1591b8ac8dcabd00 C=CN, O=WoSign CA Limited, CN=Certification Authority of WoSign
10231e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0x8ff6fc03c1edbd00 C=US, ST=Arizona, L=Scottsdale, O=Starfield Technologies, Inc., CN=Starfield Root Certificate Authority - G2
10241e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0xc6fa4243b695b600 C=US, O=Entrust, Inc., OU=www.entrust.net/CPS is incorporated by reference, OU=(c) 2006 Entrust, Inc., CN=Entrust Root Certification Authority
10251e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0xa3ce8d99e60eda00 C=BE, O=GlobalSign nv-sa, OU=Root CA, CN=GlobalSign Root CA
10261e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0x560ad29254e89100 C=GB, ST=Greater Manchester, L=Salford, O=COMODO CA Limited, CN=COMODO RSA Certification Authority
10271e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0xa671e9fec832b700 C=US, O=Starfield Technologies, Inc., OU=Starfield Class 2 Certification Authority
10281e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0xa8de7211e13be200 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root CA
10291e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0xd41691e475fb8515 C=GB, ST=Greater Manchester, L=Salford, O=COMODO CA Limited, CN=COMODO ECC Certification Authority
10301e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0x3178d37f87f1c400 C=CH, O=SwissSign AG, CN=SwissSign Silver CA - G2
10311e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0xd45980fbf0a0ac00 C=US, O=thawte, Inc., OU=Certification Services Division, OU=(c) 2006 thawte, Inc. - For authorized use only, CN=thawte Primary Root CA
10321e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0xc9edb72b684ba00 C=US, O=Entrust, Inc., OU=See www.entrust.net/legal-terms, OU=(c) 2009 Entrust, Inc. - for authorized use only, CN=Entrust Root Certification Authority - G2
10331e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0xf5cd95e581a4ab00 C=US, O=SecureTrust Corporation, CN=SecureTrust CA
10341e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0x298be035a30bab00 C=DE, O=Deutsche Telekom AG, OU=T-TeleSec Trust Center, CN=Deutsche Telekom Root CA 2
10351e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0xabd0695c5d11d15e C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority - G2, OU=(c) 1998 VeriSign, Inc. - For authorized use only, OU=VeriSign Trust Network
10361e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0xbebef0d2217f0bfb C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root G3
10371e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0x802b3770cb00af00 C=EU, L=Madrid (see current address at www.camerfirma.com/address), SRN=A82743287, O=AC Camerfirma S.A., CN=Chambers of Commerce Root - 2008
10381e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0x6f2ebe0e24cfa600 OU=GlobalSign Root CA - R2, O=GlobalSign, CN=GlobalSign
10391e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0x14018a1bf29e595c C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority
10401e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0x9e5bc2d78b6a3636 C=ZA, ST=Western Cape, L=Cape Town, O=Thawte Consulting cc, OU=Certification Services Division, CN=Thawte Premium Server CA, Email=premium-server@thawte.com
10411e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0x7c4fd32ec1b1ce00 C=PL, O=Unizeto Sp. z o.o., CN=Certum CA
10421e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0xd4fbe673e5ccc600 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA
10431e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0xb352b1523915d000 C=JP, O=SECOM Trust Systems CO.,LTD., OU=Security Communication RootCA2
10441e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0x16e64d2a56ccf200 C=US, ST=Arizona, L=Scottsdale, O=Starfield Technologies, Inc., OU=http://certificates.starfieldtech.com/repository/, CN=Starfield Services Root Certificate Authority
10451e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0x73e85f1bda5faa00 C=DE, O=T-Systems Enterprise Services GmbH, OU=T-Systems Trust Center, CN=T-TeleSec GlobalRoot Class 2
10461e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0xef477acf4ab2d300 C=DE, O=D-Trust GmbH, CN=D-TRUST Root Class 3 CA 2 2009
10471e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0x1b8578514b74ac00 C=US, O=WFA Hotspot 2.0, CN=Hotspot 2.0 Trust Root CA - 03
10481e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0xb28612a94b4dad00 O=Entrust.net, OU=www.entrust.net/CPS_2048 incorp. by ref. (limits liab.), OU=(c) 1999 Entrust.net Limited, CN=Entrust.net Certification Authority (2048)
10491e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0x357a29080824af00 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2006 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G5
10501e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0x59faf1086271bf00 C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com, Inc., CN=Go Daddy Root Certificate Authority - G2
10511e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0x466cbc09db88c100 C=IL, O=StartCom Ltd., OU=Secure Digital Certificate Signing, CN=StartCom Certification Authority
10521e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0xb16dd37ffeb3b300 C=JP, O=SECOM Trust.net, OU=Security Communication RootCA1
10531e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0x3401b15e3761c700 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2008 VeriSign, Inc. - For authorized use only, CN=VeriSign Universal Root Certification Authority
10541e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0x7cd4ff7b15b8be00 C=US, O=GeoTrust Inc., CN=GeoTrust Primary Certification Authority
10551e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0xac1e0fca7ad3c900 C=ES, O=IZENPE S.A., CN=Izenpe.com
10561e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0xc30e361765128000 C=US, ST=New Jersey, L=Jersey City, O=The USERTRUST Network, CN=USERTrust RSA Certification Authority
10571e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0x491857ead79dde00 C=US, O=The Go Daddy Group, Inc., OU=Go Daddy Class 2 Certification Authority
10581e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0xab549401526569d3 L=Internet, O=VeriSign, Inc., OU=VeriSign Commercial Software Publishers CA
10591e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0xb9ff821d139e9bf OU=GlobalSign ECC Root CA - R5, O=GlobalSign, CN=GlobalSign
10601e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0xdc1801b225aea100 C=BM, O=QuoVadis Limited, CN=QuoVadis Root CA 2 G3
10611e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0xc2ba72a37dfbe300 C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Trusted Network CA
10621e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0x8043e4ce150ead00 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID Root CA
10631e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0xa8b43f38c3f7b100 C=US, ST=UT, L=Salt Lake City, O=The USERTRUST Network, OU=http://www.usertrust.com, CN=UTN-USERFirst-Hardware
10641e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0x331d58625ee2dc00 C=US, O=GeoTrust Inc., OU=(c) 2008 GeoTrust Inc. - For authorized use only, CN=GeoTrust Primary Certification Authority - G3
10651e24.48c: supR3HardenedWinIsDesiredRootCA: Adding 0xf2e6331af7b700 C=SE, O=AddTrust AB, OU=AddTrust External TTP Network, CN=AddTrust External CA Root
10661e24.48c: supR3HardenedWinRetrieveTrustedRootCAs: cAdded=81
10671e24.48c: SUPR3HardenedMain: Load Runtime...
10681e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
10691e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
10701e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
10711e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rpcrt4.dll'.
10721e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ws2_32.dll'.
10731e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll) WinVerifyTrust
10741e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
10751e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
10761e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
10771e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
10781e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
10791e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'rpcrt4.dll'.
10801e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ws2_32.dll) WinVerifyTrust
10811e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
10821e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
10831e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
10841e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
10851e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
10861e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
10871e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
10881e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
10891e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
10901e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
10911e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
10921e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll) WinVerifyTrust
10931e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
10941e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
10951e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
10961e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
10971e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
10981e24.48c: Detected WinVerifyTrust recursion: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll'.
10991e24.48c: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll)
11001e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
11011e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
11021e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll) WinVerifyTrust
11031e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000a01:<flags> [calling]
11041e24.48c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
11051e24.48c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll [avoiding WinVerifyTrust]
11061e24.48c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
11071e24.48c: supR3HardenedDllNotificationCallback: load 00000000741a0000 LB 0x000d2000 C:\Program Files\Oracle\VirtualBox\MSVCR100.dll [fFlags=0x0]
11081e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll [avoiding WinVerifyTrust]
11091e24.48c: supR3HardenedDllNotificationCallback: load 0000000074100000 LB 0x00098000 C:\Program Files\Oracle\VirtualBox\MSVCP100.dll [fFlags=0x0]
11101e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
11111e24.48c: supR3HardenedDllNotificationCallback: load 00007ff939430000 LB 0x0006f000 C:\WINDOWS\System32\WS2_32.dll [fFlags=0x0]
11121e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
11131e24.48c: supR3HardenedDllNotificationCallback: load 00007ff90b920000 LB 0x005e2000 C:\Program Files\Oracle\VirtualBox\VBoxRT.dll [fFlags=0x0]
11141e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
11151e24.48c: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll'.
11161e24.48c: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
11171e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
11181e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
11191e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff90b920000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11201e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
11211e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
11221e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff90b920000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11231e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
11241e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
11251e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff90b920000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11261e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
11271e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
11281e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff90b920000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11291e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
11301e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
11311e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff90b920000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11321e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
11331e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
11341e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff90b920000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11351e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff90b920000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11361e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff90b920000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11371e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff90b920000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11381e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff90b920000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11391e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff90b920000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11401e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff90b920000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11411e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff90b920000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11421e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
11431e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
11441e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff90b920000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11451e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff90b920000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11461e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff90b920000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11471e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff90b920000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11481e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff90b920000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11491e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff90b920000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11501e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff90b920000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11511e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff90b920000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11521e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff90b920000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11531e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff90b920000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11541e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff90b920000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11551e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff90b920000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11561e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff90b920000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11571e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff90b920000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11581e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff90b920000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11591e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff90b920000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11601e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
11611e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
11621e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff90b920000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11631e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff90b920000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11641e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff90b920000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11651e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff90b920000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11661e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll
11671e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
11681e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936b70000 'C:\WINDOWS\system32\Wintrust.dll'
11691e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
11701e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
11711e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll
11721e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
11731e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
11741e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
11751e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\system32\crypt32.dll'
11761e24.48c: SUPR3HardenedMain: Load TrustedMain...
11771e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
11781e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'opengl32.dll'.
11791e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxglobal.dll'.
11801e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
11811e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcp100.dll'.
11821e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msvcr100.dll'.
11831e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'qt5corevbox.dll'.
11841e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'qt5guivbox.dll'.
11851e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'qt5widgetsvbox.dll'.
11861e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'qt5openglvbox.dll'.
11871e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'user32.dll'.
11881e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'ole32.dll'.
11891e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'oleaut32.dll'.
11901e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'winmm.dll'.
11911e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll) WinVerifyTrust
11921e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll
11931e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
11941e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
11951e24.48c: \Device\HarddiskVolume2\Windows\System32\winmm.dll: Owner is not trusted installer (01 01 00 00 00 00 00 01 00 00 00 00)
11961e24.48c: \Device\HarddiskVolume2\Windows\System32\winmm.dll: Relaxing the TrustedInstaller requirement for this DLL (it's in system32).
11971e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
11981e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
11991e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'winmmbase.dll'.
12001e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msvcrt.dll'.
12011e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\winmm.dll) WinVerifyTrust
12021e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\winmm.dll
12031e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
12041e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
12051e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
12061e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
12071e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
12081e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmmbase.dll'...
12091e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmmbase.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmmbase.dll' [rcNtRedir=0xc0150008]
12101e24.48c: \Device\HarddiskVolume2\Windows\System32\winmmbase.dll: Owner is not trusted installer (01 01 00 00 00 00 00 01 00 00 00 00)
12111e24.48c: \Device\HarddiskVolume2\Windows\System32\winmmbase.dll: Relaxing the TrustedInstaller requirement for this DLL (it's in system32).
12121e24.48c: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\winmmbase.dll'.
12131e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
12141e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\winmmbase.dll)
12151e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\winmmbase.dll
12161e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
12171e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
12181e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
12191e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
12201e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll
12211e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
12221e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
12231e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
12241e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'combase.dll'.
12251e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'rpcrt4.dll'.
12261e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\oleaut32.dll) WinVerifyTrust
12271e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
12281e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
12291e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
12301e24.48c: \Device\HarddiskVolume2\Windows\System32\ole32.dll: Owner is not trusted installer (01 01 00 00 00 00 00 01 00 00 00 00)
12311e24.48c: \Device\HarddiskVolume2\Windows\System32\ole32.dll: Relaxing the TrustedInstaller requirement for this DLL (it's in system32).
12321e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
12331e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
12341e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
12351e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume2\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
12361e24.48c: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\combase.dll'.
12371e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rpcrt4.dll'.
12381e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #46 'bcryptprimitives.dll'.
12391e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\combase.dll)
12401e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\combase.dll
12411e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
12421e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
12431e24.48c: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\msvcp_win.dll'.
12441e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\msvcp_win.dll)
12451e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msvcp_win.dll
12461e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcryptprimitives.dll'...
12471e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcryptprimitives.dll' -> '\Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll' [rcNtRedir=0xc0150008]
12481e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll
12491e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
12501e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
12511e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
12521e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
12531e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #22 'rpcrt4.dll'.
12541e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #56 'gdi32.dll'.
12551e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #57 'user32.dll'.
12561e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #58 'combase.dll'.
12571e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ole32.dll) WinVerifyTrust
12581e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ole32.dll
12591e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
12601e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
12611e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
12621e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume2\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
12631e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\combase.dll [lacks WinVerifyTrust]
12641e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
12651e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
12661e24.48c: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\user32.dll'.
12671e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'win32u.dll'.
12681e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #34 'gdi32.dll'.
12691e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\user32.dll)
12701e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\user32.dll
12711e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
12721e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
12731e24.48c: \Device\HarddiskVolume2\Windows\System32\gdi32.dll: Owner is not trusted installer (01 01 00 00 00 00 00 01 00 00 00 00)
12741e24.48c: \Device\HarddiskVolume2\Windows\System32\gdi32.dll: Relaxing the TrustedInstaller requirement for this DLL (it's in system32).
12751e24.48c: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\gdi32.dll'.
12761e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'win32u.dll'.
12771e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\gdi32.dll)
12781e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\gdi32.dll
12791e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
12801e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
12811e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
12821e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume2\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
12831e24.48c: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\win32u.dll'.
12841e24.48c: '\Device\HarddiskVolume2\Windows\System32\win32u.dll' has no imports
12851e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\win32u.dll)
12861e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\win32u.dll
12871e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
12881e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
12891e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
12901e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
12911e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume2\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
12921e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\win32u.dll [lacks WinVerifyTrust]
12931e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
12941e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
12951e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'win32u.dll'.
12961e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #34 'gdi32.dll'.
12971e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\user32.dll) WinVerifyTrust
12981e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5openglvbox.dll'...
12991e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5openglvbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5openglvbox.dll' [rcNtRedir=0xc0150008]
13001e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
13011e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
13021e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
13031e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
13041e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume2\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
13051e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\win32u.dll [lacks WinVerifyTrust]
13061e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
13071e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'qt5widgetsvbox.dll'.
13081e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'qt5guivbox.dll'.
13091e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5corevbox.dll'.
13101e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcr100.dll'.
13111e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll) WinVerifyTrust
13121e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll
13131e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
13141e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
13151e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
13161e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
13171e24.48c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
13181e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
13191e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
13201e24.48c: Detected WinVerifyTrust recursion: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll'.
13211e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
13221e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'shell32.dll'.
13231e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ole32.dll'.
13241e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
13251e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ws2_32.dll'.
13261e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'mpr.dll'.
13271e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'msvcp100.dll'.
13281e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'msvcr100.dll'.
13291e24.48c: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll)
13301e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
13311e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
13321e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
13331e24.48c: Detected WinVerifyTrust recursion: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll'.
13341e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ole32.dll'.
13351e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'opengl32.dll'.
13361e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
13371e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
13381e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qt5corevbox.dll'.
13391e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcp100.dll'.
13401e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msvcr100.dll'.
13411e24.48c: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll)
13421e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
13431e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
13441e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
13451e24.48c: Detected WinVerifyTrust recursion: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll'.
13461e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
13471e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
13481e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5guivbox.dll'.
13491e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qt5corevbox.dll'.
13501e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'shell32.dll'.
13511e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcp100.dll'.
13521e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msvcr100.dll'.
13531e24.48c: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll)
13541e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll
13551e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
13561e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
13571e24.48c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
13581e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
13591e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
13601e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
13611e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
13621e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
13631e24.48c: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\shell32.dll'.
13641e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #77 'user32.dll'.
13651e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #79 'gdi32.dll'.
13661e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\shell32.dll)
13671e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\shell32.dll
13681e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
13691e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
13701e24.48c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [lacks WinVerifyTrust]
13711e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
13721e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
13731e24.48c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll [lacks WinVerifyTrust]
13741e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
13751e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
13761e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
13771e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
13781e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
13791e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
13801e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
13811e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
13821e24.48c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
13831e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
13841e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
13851e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
13861e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
13871e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
13881e24.48c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [lacks WinVerifyTrust]
13891e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
13901e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
13911e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
13921e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
13931e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
13941e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
13951e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
13961e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
13971e24.48c: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume2\Windows\System32\opengl32.dll'.
13981e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
13991e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'advapi32.dll'.
14001e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
14011e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
14021e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'glu32.dll'.
14031e24.48c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\opengl32.dll)
14041e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\opengl32.dll
14051e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
14061e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
14071e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
14081e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
14091e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
14101e24.48c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
14111e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
14121e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
14131e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
14141e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mpr.dll'...
14151e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'mpr.dll' -> '\Device\HarddiskVolume2\Windows\System32\mpr.dll' [rcNtRedir=0xc0150008]
14161e24.48c: \Device\HarddiskVolume2\Windows\System32\mpr.dll: Owner is not trusted installer (01 01 00 00 00 00 00 01 00 00 00 00)
14171e24.48c: \Device\HarddiskVolume2\Windows\System32\mpr.dll: Relaxing the TrustedInstaller requirement for this DLL (it's in system32).
14181e24.48c: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\mpr.dll'.
14191e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\mpr.dll)
14201e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\mpr.dll
14211e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
14221e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
14231e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
14241e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
14251e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
14261e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
14271e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
14281e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
14291e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
14301e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
14311e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
14321e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll [lacks WinVerifyTrust]
14331e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
14341e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
14351e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
14361e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'glu32.dll'...
14371e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'glu32.dll' -> '\Device\HarddiskVolume2\Windows\System32\glu32.dll' [rcNtRedir=0xc0150008]
14381e24.48c: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume2\Windows\System32\glu32.dll'.
14391e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
14401e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
14411e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'opengl32.dll'.
14421e24.48c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\glu32.dll)
14431e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\glu32.dll
14441e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
14451e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
14461e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
14471e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
14481e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
14491e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
14501e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
14511e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
14521e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
14531e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
14541e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
14551e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
14561e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
14571e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
14581e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
14591e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
14601e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
14611e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
14621e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
14631e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
14641e24.48c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll [lacks WinVerifyTrust]
14651e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
14661e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
14671e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
14681e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
14691e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
14701e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
14711e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
14721e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
14731e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
14741e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5guivbox.dll'.
14751e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qt5corevbox.dll'.
14761e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'shell32.dll'.
14771e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcp100.dll'.
14781e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msvcr100.dll'.
14791e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll) WinVerifyTrust
14801e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
14811e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
14821e24.48c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll [redoing WinVerifyTrust]
14831e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
14841e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
14851e24.48c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
14861e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
14871e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
14881e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
14891e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
14901e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
14911e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll [lacks WinVerifyTrust]
14921e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
14931e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
14941e24.48c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [lacks WinVerifyTrust]
14951e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
14961e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
14971e24.48c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll [lacks WinVerifyTrust]
14981e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
14991e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
15001e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
15011e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
15021e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
15031e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
15041e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
15051e24.48c: supR3HardenedScreenImage/Imports: 0 (was 24202) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll'
15061e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
15071e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
15081e24.48c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [redoing WinVerifyTrust]
15091e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
15101e24.48c: supR3HardenedScreenImage/Imports: 0 (was 24202) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll'
15111e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
15121e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
15131e24.48c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll [redoing WinVerifyTrust]
15141e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
15151e24.48c: supR3HardenedScreenImage/Imports: 0 (was 24202) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll'
15161e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
15171e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
15181e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
15191e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
15201e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
15211e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxglobal.dll'...
15221e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxglobal.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxglobal.dll' [rcNtRedir=0xc0150008]
15231e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
15241e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'vboxrt.dll'.
15251e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcr100.dll'.
15261e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5corevbox.dll'.
15271e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qt5guivbox.dll'.
15281e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qt5widgetsvbox.dll'.
15291e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
15301e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'advapi32.dll'.
15311e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'ole32.dll'.
15321e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'oleaut32.dll'.
15331e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'rpcrt4.dll'.
15341e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxGlobal.dll) WinVerifyTrust
15351e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxGlobal.dll
15361e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
15371e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
15381e24.48c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll [redoing WinVerifyTrust]
15391e24.48c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004dc pwszName=\Device\HarddiskVolume2\Windows\System32\opengl32.dll
15401e24.48c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000001743050
15411e24.48c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000001743050
15421e24.48c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=0837440FAE05EB650168FFA2D15E73182F6A3A26
15431e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
15441e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
15451e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
15461e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
15471e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
15481e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
15491e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
15501e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
15511e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
15521e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
15531e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
15541e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
15551e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
15561e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
15571e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
15581e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
15591e24.48c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll [lacks WinVerifyTrust]
15601e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
15611e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
15621e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
15631e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
15641e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
15651e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
15661e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
15671e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
15681e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
15691e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
15701e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
15711e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
15721e24.48c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0212~31bf3856ad364e35~amd64~~10.0.18362.449.cat'; file='\Device\HarddiskVolume2\Windows\System32\opengl32.dll'
15731e24.48c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
15741e24.48c: supR3HardenedScreenImage/Imports: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\opengl32.dll'
15751e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000a01:<flags> [calling]
15761e24.48c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll
15771e24.48c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
15781e24.48c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxGlobal.dll
15791e24.48c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
15801e24.48c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
15811e24.48c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll [avoiding WinVerifyTrust]
15821e24.48c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll
15831e24.48c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
15841e24.48c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\glu32.dll [avoiding WinVerifyTrust]
15851e24.48c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\mpr.dll [avoiding WinVerifyTrust]
15861e24.48c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmmbase.dll [avoiding WinVerifyTrust]
15871e24.48c: \Device\HarddiskVolume2\Windows\System32\DXCore.dll: Owner is not trusted installer (01 01 00 00 00 00 00 01 00 00 00 00)
15881e24.48c: \Device\HarddiskVolume2\Windows\System32\DXCore.dll: Relaxing the TrustedInstaller requirement for this DLL (it's in system32).
15891e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
15901e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #22 'win32u.dll'.
15911e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\DXCore.dll)
15921e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\DXCore.dll
15931e24.48c: supR3HardenedDllNotificationCallback: load 00007ff9375f0000 LB 0x00021000 C:\WINDOWS\System32\win32u.dll [fFlags=0x0]
15941e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\win32u.dll [avoiding WinVerifyTrust]
15951e24.48c: supR3HardenedDllNotificationCallback: load 00007ff9366b0000 LB 0x0009e000 C:\WINDOWS\System32\msvcp_win.dll [fFlags=0x0]
15961e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcp_win.dll [avoiding WinVerifyTrust]
15971e24.48c: supR3HardenedDllNotificationCallback: load 00007ff936bd0000 LB 0x00194000 C:\WINDOWS\System32\gdi32full.dll [fFlags=0x0]
15981e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
15991e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #33 'gdi32.dll'.
16001e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #35 'user32.dll'.
16011e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #36 'win32u.dll'.
16021e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\gdi32full.dll)
16031e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\gdi32full.dll
16041e24.48c: supR3HardenedDllNotificationCallback: load 00007ff9393f0000 LB 0x00026000 C:\WINDOWS\System32\GDI32.dll [fFlags=0x0]
16051e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [avoiding WinVerifyTrust]
16061e24.48c: supR3HardenedDllNotificationCallback: load 00007ff939540000 LB 0x00194000 C:\WINDOWS\System32\USER32.dll [fFlags=0x0]
16071e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll [avoiding WinVerifyTrust]
16081e24.48c: supR3HardenedDllNotificationCallback: load 00007ff938e90000 LB 0x00336000 C:\WINDOWS\System32\combase.dll [fFlags=0x0]
16091e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\combase.dll [avoiding WinVerifyTrust]
16101e24.48c: supR3HardenedDllNotificationCallback: load 00007ff937650000 LB 0x0004a000 C:\WINDOWS\System32\cfgmgr32.dll [fFlags=0x0]
16111e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll)
16121e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll
16131e24.48c: supR3HardenedDllNotificationCallback: load 00007ff935240000 LB 0x00020000 C:\WINDOWS\SYSTEM32\dxcore.dll [fFlags=0x0]
16141e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\DXCore.dll [avoiding WinVerifyTrust]
16151e24.48c: supR3HardenedDllNotificationCallback: load 00007ff92eb20000 LB 0x0002c000 C:\WINDOWS\SYSTEM32\GLU32.dll [fFlags=0x0]
16161e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\glu32.dll [avoiding WinVerifyTrust]
16171e24.48c: supR3HardenedDllNotificationCallback: load 00007ff90e4f0000 LB 0x00156000 C:\WINDOWS\SYSTEM32\OPENGL32.dll [fFlags=0x0]
16181e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
16191e24.48c: supR3HardenedDllNotificationCallback: load 00007ff939280000 LB 0x000a9000 C:\WINDOWS\System32\shcore.dll [fFlags=0x0]
16201e24.48c: \Device\HarddiskVolume2\Windows\System32\SHCore.dll: Owner is not trusted installer (01 01 00 00 00 00 00 01 00 00 00 00)
16211e24.48c: \Device\HarddiskVolume2\Windows\System32\SHCore.dll: Relaxing the TrustedInstaller requirement for this DLL (it's in system32).
16221e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
16231e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #36 'rpcrt4.dll'.
16241e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #43 'combase.dll'.
16251e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\SHCore.dll)
16261e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\SHCore.dll
16271e24.48c: supR3HardenedDllNotificationCallback: load 00007ff9365f0000 LB 0x00010000 C:\WINDOWS\System32\UMPDC.dll [fFlags=0x0]
16281e24.48c: \Device\HarddiskVolume2\Windows\System32\umpdc.dll: Owner is not trusted installer (01 01 00 00 00 00 00 01 00 00 00 00)
16291e24.48c: \Device\HarddiskVolume2\Windows\System32\umpdc.dll: Relaxing the TrustedInstaller requirement for this DLL (it's in system32).
16301e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\umpdc.dll)
16311e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\umpdc.dll
16321e24.48c: supR3HardenedDllNotificationCallback: load 00007ff936620000 LB 0x0004a000 C:\WINDOWS\System32\powrprof.dll [fFlags=0x0]
16331e24.48c: \Device\HarddiskVolume2\Windows\System32\powrprof.dll: Owner is not trusted installer (01 01 00 00 00 00 00 01 00 00 00 00)
16341e24.48c: \Device\HarddiskVolume2\Windows\System32\powrprof.dll: Relaxing the TrustedInstaller requirement for this DLL (it's in system32).
16351e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'rpcrt4.dll'.
16361e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #19 'umpdc.dll'.
16371e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\powrprof.dll)
16381e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\powrprof.dll
16391e24.48c: supR3HardenedDllNotificationCallback: load 00007ff938430000 LB 0x00052000 C:\WINDOWS\System32\shlwapi.dll [fFlags=0x0]
16401e24.48c: \Device\HarddiskVolume2\Windows\System32\shlwapi.dll: Owner is not trusted installer (01 01 00 00 00 00 00 01 00 00 00 00)
16411e24.48c: \Device\HarddiskVolume2\Windows\System32\shlwapi.dll: Relaxing the TrustedInstaller requirement for this DLL (it's in system32).
16421e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
16431e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #44 'gdi32.dll'.
16441e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #45 'user32.dll'.
16451e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\shlwapi.dll)
16461e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\shlwapi.dll
16471e24.48c: supR3HardenedDllNotificationCallback: load 00007ff936690000 LB 0x00011000 C:\WINDOWS\System32\kernel.appcore.dll [fFlags=0x0]
16481e24.48c: \Device\HarddiskVolume2\Windows\System32\kernel.appcore.dll: Owner is not trusted installer (01 01 00 00 00 00 00 01 00 00 00 00)
16491e24.48c: \Device\HarddiskVolume2\Windows\System32\kernel.appcore.dll: Relaxing the TrustedInstaller requirement for this DLL (it's in system32).
16501e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'msvcrt.dll'.
16511e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'rpcrt4.dll'.
16521e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\kernel.appcore.dll)
16531e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\kernel.appcore.dll
16541e24.48c: supR3HardenedDllNotificationCallback: load 00007ff936e70000 LB 0x0077e000 C:\WINDOWS\System32\windows.storage.dll [fFlags=0x0]
16551e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #31 'combase.dll'.
16561e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #32 'msvcp_win.dll'.
16571e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #39 'rpcrt4.dll'.
16581e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #56 'profapi.dll'.
16591e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\windows.storage.dll)
16601e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\windows.storage.dll
16611e24.48c: supR3HardenedDllNotificationCallback: load 00007ff937c00000 LB 0x006e5000 C:\WINDOWS\System32\SHELL32.dll [fFlags=0x0]
16621e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll [avoiding WinVerifyTrust]
16631e24.48c: supR3HardenedDllNotificationCallback: load 00007ff938490000 LB 0x00156000 C:\WINDOWS\System32\ole32.dll [fFlags=0x0]
16641e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
16651e24.48c: supR3HardenedDllNotificationCallback: load 00007ff92a250000 LB 0x0001b000 C:\WINDOWS\SYSTEM32\MPR.dll [fFlags=0x0]
16661e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\mpr.dll [avoiding WinVerifyTrust]
16671e24.48c: supR3HardenedDllNotificationCallback: load 0000000072aa0000 LB 0x00565000 C:\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [fFlags=0x0]
16681e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
16691e24.48c: supR3HardenedDllNotificationCallback: load 00007ff90b320000 LB 0x005f7000 C:\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll [fFlags=0x0]
16701e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
16711e24.48c: supR3HardenedDllNotificationCallback: load 0000000072530000 LB 0x00561000 C:\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll [fFlags=0x0]
16721e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll [avoiding WinVerifyTrust]
16731e24.48c: supR3HardenedDllNotificationCallback: load 00007ff937970000 LB 0x000c4000 C:\WINDOWS\System32\OLEAUT32.dll [fFlags=0x0]
16741e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
16751e24.48c: supR3HardenedDllNotificationCallback: load 00007ff8fe660000 LB 0x02387000 C:\Program Files\Oracle\VirtualBox\VBoxGlobal.dll [fFlags=0x0]
16761e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxGlobal.dll
16771e24.48c: supR3HardenedDllNotificationCallback: load 0000000074060000 LB 0x00054000 C:\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll [fFlags=0x0]
16781e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll
16791e24.48c: supR3HardenedDllNotificationCallback: load 00007ff92b380000 LB 0x0002d000 C:\WINDOWS\SYSTEM32\WINMMBASE.dll [fFlags=0x0]
16801e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmmbase.dll [avoiding WinVerifyTrust]
16811e24.48c: supR3HardenedDllNotificationCallback: load 00007ff92b3b0000 LB 0x00024000 C:\WINDOWS\SYSTEM32\WINMM.dll [fFlags=0x0]
16821e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
16831e24.48c: supR3HardenedDllNotificationCallback: load 00007ff90c610000 LB 0x00188000 C:\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll [fFlags=0x0]
16841e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll
16851e24.48c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\windows.storage.dll'.
16861e24.48c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\windows.storage.dll' [rescheduled]
16871e24.48c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\kernel.appcore.dll'.
16881e24.48c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\kernel.appcore.dll' [rescheduled]
16891e24.48c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll'.
16901e24.48c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll' [rescheduled]
16911e24.48c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\powrprof.dll'.
16921e24.48c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\powrprof.dll' [rescheduled]
16931e24.48c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\umpdc.dll'.
16941e24.48c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\umpdc.dll' [rescheduled]
16951e24.48c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\SHCore.dll'.
16961e24.48c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\SHCore.dll' [rescheduled]
16971e24.48c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll'.
16981e24.48c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll' [rescheduled]
16991e24.48c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\gdi32full.dll'.
17001e24.48c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\gdi32full.dll' [rescheduled]
17011e24.48c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\DXCore.dll'.
17021e24.48c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\DXCore.dll' [rescheduled]
17031e24.48c: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume2\Windows\System32\glu32.dll'.
17041e24.48c: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\glu32.dll' [rescheduled]
17051e24.48c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\mpr.dll'.
17061e24.48c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\mpr.dll' [rescheduled]
17071e24.48c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\shell32.dll'.
17081e24.48c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rescheduled]
17091e24.48c: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll'.
17101e24.48c: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll' [rescheduled]
17111e24.48c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\win32u.dll'.
17121e24.48c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\win32u.dll' [rescheduled]
17131e24.48c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\gdi32.dll'.
17141e24.48c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rescheduled]
17151e24.48c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\user32.dll'.
17161e24.48c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rescheduled]
17171e24.48c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\msvcp_win.dll'.
17181e24.48c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\msvcp_win.dll' [rescheduled]
17191e24.48c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\combase.dll'.
17201e24.48c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\combase.dll' [rescheduled]
17211e24.48c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\winmmbase.dll'.
17221e24.48c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\winmmbase.dll' [rescheduled]
17231e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll
17241e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'profapi.dll'...
17251e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'profapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\profapi.dll' [rcNtRedir=0xc0150008]
17261e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\profapi.dll
17271e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
17281e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
17291e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
17301e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
17311e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcp_win.dll [redoing WinVerifyTrust]
17321e24.48c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\msvcp_win.dll'.
17331e24.48c: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume2\Windows\System32\msvcp_win.dll
17341e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
17351e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume2\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
17361e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\combase.dll [redoing WinVerifyTrust]
17371e24.48c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\combase.dll'.
17381e24.48c: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume2\Windows\System32\combase.dll
17391e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
17401e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
17411e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
17421e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
17431e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
17441e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
17451e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll [redoing WinVerifyTrust]
17461e24.48c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\user32.dll'.
17471e24.48c: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume2\Windows\System32\user32.dll
17481e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
17491e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
17501e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [redoing WinVerifyTrust]
17511e24.48c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\gdi32.dll'.
17521e24.48c: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume2\Windows\System32\gdi32.dll
17531e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
17541e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
17551e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'umpdc.dll'...
17561e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'umpdc.dll' -> '\Device\HarddiskVolume2\Windows\System32\umpdc.dll' [rcNtRedir=0xc0150008]
17571e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\umpdc.dll [redoing WinVerifyTrust]
17581e24.48c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\umpdc.dll'.
17591e24.48c: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume2\Windows\System32\umpdc.dll
17601e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
17611e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
17621e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
17631e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume2\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
17641e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\combase.dll [redoing WinVerifyTrust]
17651e24.48c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\combase.dll'.
17661e24.48c: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume2\Windows\System32\combase.dll
17671e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
17681e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
17691e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
17701e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
17711e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
17721e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
17731e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume2\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
17741e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\win32u.dll [redoing WinVerifyTrust]
17751e24.48c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\win32u.dll'.
17761e24.48c: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume2\Windows\System32\win32u.dll
17771e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
17781e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
17791e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll [redoing WinVerifyTrust]
17801e24.48c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\user32.dll'.
17811e24.48c: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume2\Windows\System32\user32.dll
17821e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
17831e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
17841e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [redoing WinVerifyTrust]
17851e24.48c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\gdi32.dll'.
17861e24.48c: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume2\Windows\System32\gdi32.dll
17871e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
17881e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
17891e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcp_win.dll [redoing WinVerifyTrust]
17901e24.48c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\msvcp_win.dll'.
17911e24.48c: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume2\Windows\System32\msvcp_win.dll
17921e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
17931e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume2\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
17941e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\win32u.dll [redoing WinVerifyTrust]
17951e24.48c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\win32u.dll'.
17961e24.48c: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume2\Windows\System32\win32u.dll
17971e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
17981e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
17991e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcp_win.dll [redoing WinVerifyTrust]
18001e24.48c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\msvcp_win.dll'.
18011e24.48c: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume2\Windows\System32\msvcp_win.dll
18021e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\kernel32.dll (Input=kernel32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
18031e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff939330000 'C:\WINDOWS\System32\kernel32.dll'
18041e24.48c: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-string-l1-1-0) -> 0x0, fPresent=1
18051e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-string-l1-1-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
18061e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9368c0000 'api-ms-win-core-string-l1-1-0'
18071e24.48c: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-datetime-l1-1-1) -> 0x0, fPresent=1
18081e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-datetime-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
18091e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9368c0000 'api-ms-win-core-datetime-l1-1-1'
18101e24.48c: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-obsolete-l1-2-0) -> 0x0, fPresent=1
18111e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-obsolete-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
18121e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9368c0000 'api-ms-win-core-localization-obsolete-l1-2-0'
18131e24.48c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\imm32.dll'.
18141e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'user32.dll'.
18151e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'win32u.dll'.
18161e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\imm32.dll)
18171e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\imm32.dll
18181e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
18191e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume2\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
18201e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\win32u.dll [redoing WinVerifyTrust]
18211e24.48c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\win32u.dll'.
18221e24.48c: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume2\Windows\System32\win32u.dll
18231e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
18241e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
18251e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll [redoing WinVerifyTrust]
18261e24.48c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\user32.dll'.
18271e24.48c: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume2\Windows\System32\user32.dll
18281e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\IMM32.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
18291e24.48c: supR3HardenedDllNotificationCallback: load 00007ff938d60000 LB 0x0002e000 C:\WINDOWS\System32\IMM32.DLL [fFlags=0x0]
18301e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\imm32.dll [avoiding WinVerifyTrust]
18311e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff938d60000 'C:\WINDOWS\system32\IMM32.DLL'
18321e24.48c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\imm32.dll'.
18331e24.48c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\imm32.dll' [rescheduled]
18341e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
18351e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\ADVAPI32.DLL (Input=ADVAPI32.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
18361e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9391d0000 'C:\WINDOWS\System32\ADVAPI32.DLL'
18371e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff90c610000 'C:\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll'
18381e24.48c: SUPR3HardenedMain: Calling TrustedMain (00007ff90c6116c0)...
18391e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
18401e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
18411e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'ole32.dll'.
18421e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
18431e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'imm32.dll'.
18441e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'winmm.dll'.
18451e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'oleaut32.dll'.
18461e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'shell32.dll'.
18471e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'advapi32.dll'.
18481e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'qt5guivbox.dll'.
18491e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'qt5corevbox.dll'.
18501e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'msvcr100.dll'.
18511e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\platforms\qwindows.dll) WinVerifyTrust
18521e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\platforms\qwindows.dll
18531e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
18541e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
18551e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
18561e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
18571e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
18581e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
18591e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
18601e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
18611e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
18621e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
18631e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
18641e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
18651e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
18661e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll [redoing WinVerifyTrust]
18671e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
18681e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
18691e24.48c: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\shell32.dll'
18701e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
18711e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
18721e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
18731e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
18741e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
18751e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
18761e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
18771e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume2\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
18781e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\imm32.dll [redoing WinVerifyTrust]
18791e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
18801e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
18811e24.48c: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\imm32.dll'
18821e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
18831e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
18841e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll [redoing WinVerifyTrust]
18851e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
18861e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
18871e24.48c: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\user32.dll'
18881e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
18891e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
18901e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
18911e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
18921e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
18931e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [redoing WinVerifyTrust]
18941e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
18951e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
18961e24.48c: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\gdi32.dll'
18971e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\platforms\qwindows.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
18981e24.48c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\platforms\qwindows.dll
18991e24.48c: supR3HardenedDllNotificationCallback: load 00007ff90ca90000 LB 0x0012e000 C:\Program Files\Oracle\VirtualBox\platforms\qwindows.dll [fFlags=0x0]
19001e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\platforms\qwindows.dll
19011e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff90ca90000 'C:\Program Files\Oracle\VirtualBox\platforms\qwindows.dll'
19021e24.48c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000568 pwszName=\Device\HarddiskVolume2\Windows\System32\uxtheme.dll
19031e24.48c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000001743050
19041e24.48c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000001743050
19051e24.48c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=286AD1CEC16EFDCA5718925D19E68A486A5851A0
19061e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
19071e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
19081e24.48c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0415~31bf3856ad364e35~amd64~~10.0.18362.476.cat'; file='\Device\HarddiskVolume2\Windows\System32\uxtheme.dll'
19091e24.48c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
19101e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
19111e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #33 'gdi32.dll'.
19121e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #34 'user32.dll'.
19131e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\uxtheme.dll) WinVerifyTrust
19141e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
19151e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
19161e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
19171e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
19181e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
19191e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
19201e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
19211e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
19221e24.48c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
19231e24.48c: supR3HardenedDllNotificationCallback: load 00007ff934860000 LB 0x00099000 C:\WINDOWS\system32\uxtheme.dll [fFlags=0x0]
19241e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
19251e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff934860000 'C:\WINDOWS\system32\uxtheme.dll'
19261e24.48c: \Device\HarddiskVolume2\Program Files (x86)\RivaTuner Statistics Server\RTSSHooks64.dll: Owner is administrators group.
19271e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
19281e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'shlwapi.dll'.
19291e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'winmm.dll'.
19301e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
19311e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'gdi32.dll'.
19321e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files (x86)\RivaTuner Statistics Server\RTSSHooks64.dll) WinVerifyTrust
19331e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files (x86)\RivaTuner Statistics Server\RTSSHooks64.dll
19341e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
19351e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
19361e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
19371e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
19381e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
19391e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
19401e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
19411e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
19421e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
19431e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll [redoing WinVerifyTrust]
19441e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
19451e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
19461e24.48c: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll'
19471e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files (x86)\RivaTuner Statistics Server\RTSSHooks64.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
19481e24.48c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files (x86)\RivaTuner Statistics Server\RTSSHooks64.dll
19491e24.48c: supR3HardenedDllNotificationCallback: load 0000000180000000 LB 0x00272000 C:\Program Files (x86)\RivaTuner Statistics Server\RTSSHooks64.dll [fFlags=0x0]
19501e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files (x86)\RivaTuner Statistics Server\RTSSHooks64.dll
19511e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000180000000 'C:\Program Files (x86)\RivaTuner Statistics Server\RTSSHooks64.dll'
19521e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll
19531e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\user32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
19541e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff939540000 'C:\WINDOWS\system32\user32.dll'
19551e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
19561e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
19571e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff937c00000 'C:\WINDOWS\system32\shell32.dll'
19581e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\SHCore.dll [redoing WinVerifyTrust]
19591e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
19601e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
19611e24.48c: supR3HardenedScreenImage/LdrLoadDll: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\SHCore.dll'
19621e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\SHCore.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
19631e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff939280000 'C:\WINDOWS\system32\SHCore.dll'
19641e24.48c: supR3HardenedMonitor_LdrLoadDll: error opening 'C:\WINDOWS\system32\wintab32.dll': 0 (NtPath=\??\C:\WINDOWS\system32\wintab32.dll; Input=C:\WINDOWS\system32\wintab32.dll; rcNtGetDll=0x0
19651e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000034 'C:\WINDOWS\system32\wintab32.dll'
19661e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
19671e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\winmm.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
19681e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff92b3b0000 'C:\WINDOWS\system32\winmm.dll'
19691e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
19701e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\winmm.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
19711e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff92b3b0000 'C:\WINDOWS\system32\winmm.dll'
19721e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
19731e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
19741e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff937c00000 'C:\WINDOWS\system32\shell32.dll'
19751e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
19761e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
19771e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff934860000 'C:\WINDOWS\system32\uxtheme.dll'
19781e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
19791e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\advapi32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
19801e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9391d0000 'C:\WINDOWS\system32\advapi32.dll'
19811e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
19821e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
19831e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'rpcrt4.dll'.
19841e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #30 'profapi.dll'.
19851e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\userenv.dll) WinVerifyTrust
19861e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\userenv.dll
19871e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'profapi.dll'...
19881e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'profapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\profapi.dll' [rcNtRedir=0xc0150008]
19891e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\profapi.dll
19901e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
19911e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
19921e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\userenv.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
19931e24.48c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\userenv.dll
19941e24.48c: supR3HardenedDllNotificationCallback: load 00007ff936510000 LB 0x00025000 C:\WINDOWS\system32\userenv.dll [fFlags=0x0]
19951e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\userenv.dll
19961e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936510000 'C:\WINDOWS\system32\userenv.dll'
19971e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll
19981e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\kernel32.dll (Input=kernel32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
19991e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff939330000 'C:\WINDOWS\System32\kernel32.dll'
20001e24.48c: supR3HardenedDllNotificationCallback: load 00007ff9385f0000 LB 0x000a2000 C:\WINDOWS\System32\clbcatq.dll [fFlags=0x0]
20011e24.48c: \Device\HarddiskVolume2\Windows\System32\clbcatq.dll: Owner is not trusted installer (01 01 00 00 00 00 00 01 00 00 00 00)
20021e24.48c: \Device\HarddiskVolume2\Windows\System32\clbcatq.dll: Relaxing the TrustedInstaller requirement for this DLL (it's in system32).
20031e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
20041e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #30 'rpcrt4.dll'.
20051e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\clbcatq.dll)
20061e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\clbcatq.dll
20071e24.2b60: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
20081e24.2b60: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
20091e24.2b60: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
20101e24.2b60: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
20111e24.2b60: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
20121e24.2b60: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
20131e24.2b60: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\clbcatq.dll'
20141e24.2b60: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
20151e24.2b60: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
20161e24.2b60: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
20171e24.2b60: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
20181e24.2b60: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
20191e24.2b60: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ole32.dll'.
20201e24.2b60: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'oleaut32.dll'.
20211e24.2b60: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxC.dll) WinVerifyTrust
20221e24.2b60: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxC.dll
20231e24.2b60: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
20241e24.2b60: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
20251e24.2b60: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
20261e24.2b60: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
20271e24.2b60: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
20281e24.2b60: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
20291e24.2b60: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
20301e24.2b60: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
20311e24.2b60: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
20321e24.2b60: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
20331e24.2b60: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
20341e24.2b60: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
20351e24.2b60: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
20361e24.2b60: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
20371e24.2b60: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
20381e24.2b60: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
20391e24.2b60: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxC.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
20401e24.2b60: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxC.dll
20411e24.2b60: supR3HardenedDllNotificationCallback: load 00007ff9049d0000 LB 0x003a4000 C:\Program Files\Oracle\VirtualBox\VBoxC.dll [fFlags=0x0]
20421e24.2b60: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxC.dll
20431e24.2b60: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9049d0000 'C:\Program Files\Oracle\VirtualBox\VBoxC.dll'
20441e24.2b60: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
20451e24.2b60: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
20461e24.2b60: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
20471e24.2b60: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
20481e24.2b60: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'shlwapi.dll'.
20491e24.2b60: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ole32.dll'.
20501e24.2b60: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'oleaut32.dll'.
20511e24.2b60: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
20521e24.2b60: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll) WinVerifyTrust
20531e24.2b60: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll
20541e24.2b60: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
20551e24.2b60: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
20561e24.2b60: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
20571e24.2b60: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
20581e24.2b60: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
20591e24.2b60: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
20601e24.2b60: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
20611e24.2b60: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
20621e24.2b60: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
20631e24.2b60: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
20641e24.2b60: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll
20651e24.2b60: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
20661e24.2b60: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
20671e24.2b60: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
20681e24.2b60: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
20691e24.2b60: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
20701e24.2b60: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
20711e24.2b60: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
20721e24.2b60: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
20731e24.2b60: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll
20741e24.2b60: supR3HardenedDllNotificationCallback: load 00007ff90c9b0000 LB 0x000d5000 C:\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll [fFlags=0x0]
20751e24.2b60: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll
20761e24.2b60: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff90c9b0000 'C:\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll'
20771e24.2b60: \Device\HarddiskVolume2\Windows\System32\msiltcfg.dll: Owner is not trusted installer (01 01 00 00 00 00 00 01 00 00 00 00)
20781e24.2b60: \Device\HarddiskVolume2\Windows\System32\msiltcfg.dll: Relaxing the TrustedInstaller requirement for this DLL (it's in system32).
20791e24.2b60: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000734 pwszName=\Device\HarddiskVolume2\Windows\System32\msiltcfg.dll
20801e24.2b60: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000001743050
20811e24.2b60: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000001743050
20821e24.2b60: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=18F5337EE7F9E69042ABA03B5E3E62E237D3C5A9
20831e24.2b60: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
20841e24.2b60: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
20851e24.2b60: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0211~31bf3856ad364e35~amd64~~10.0.18362.476.cat'; file='\Device\HarddiskVolume2\Windows\System32\msiltcfg.dll'
20861e24.2b60: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
20871e24.2b60: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
20881e24.2b60: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'advapi32.dll'.
20891e24.2b60: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'version.dll'.
20901e24.2b60: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\msiltcfg.dll) WinVerifyTrust
20911e24.2b60: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msiltcfg.dll
20921e24.2b60: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'version.dll'...
20931e24.2b60: supR3HardenedWinVerifyCacheProcessImportTodos: 'version.dll' -> '\Device\HarddiskVolume2\Windows\System32\version.dll' [rcNtRedir=0xc0150008]
20941e24.2b60: \Device\HarddiskVolume2\Windows\System32\version.dll: Owner is not trusted installer (01 01 00 00 00 00 00 01 00 00 00 00)
20951e24.2b60: \Device\HarddiskVolume2\Windows\System32\version.dll: Relaxing the TrustedInstaller requirement for this DLL (it's in system32).
20961e24.2b60: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
20971e24.2b60: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
20981e24.2b60: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
20991e24.2b60: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\version.dll) WinVerifyTrust
21001e24.2b60: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\version.dll
21011e24.2b60: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
21021e24.2b60: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
21031e24.2b60: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
21041e24.2b60: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
21051e24.2b60: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
21061e24.2b60: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
21071e24.2b60: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\msiltcfg.dll (Input=msiltcfg.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
21081e24.2b60: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msiltcfg.dll
21091e24.2b60: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\version.dll
21101e24.2b60: supR3HardenedDllNotificationCallback: load 00007ff92e8b0000 LB 0x0000a000 C:\WINDOWS\SYSTEM32\VERSION.dll [fFlags=0x0]
21111e24.2b60: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\version.dll
21121e24.2b60: supR3HardenedDllNotificationCallback: load 00007ff92a470000 LB 0x0000a000 C:\WINDOWS\System32\msiltcfg.dll [fFlags=0x0]
21131e24.2b60: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msiltcfg.dll
21141e24.2b60: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff92a470000 'C:\WINDOWS\System32\msiltcfg.dll'
21151e24.2b60: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff939540000 'C:\WINDOWS\System32\user32.dll'
21161e24.2b60: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000006e0 pwszName=\Device\HarddiskVolume2\Windows\System32\msi.dll
21171e24.2b60: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000001743050
21181e24.2b60: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000001743050
21191e24.2b60: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=E07235823200E1F512A3AB1B2628DC18E25FBC0B
21201e24.2b60: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
21211e24.2b60: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
21221e24.2b60: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0211~31bf3856ad364e35~amd64~~10.0.18362.476.cat'; file='\Device\HarddiskVolume2\Windows\System32\msi.dll'
21231e24.2b60: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
21241e24.2b60: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
21251e24.2b60: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'advapi32.dll'.
21261e24.2b60: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
21271e24.2b60: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'shell32.dll'.
21281e24.2b60: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'gdi32.dll'.
21291e24.2b60: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
21301e24.2b60: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'ole32.dll'.
21311e24.2b60: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'bcrypt.dll'.
21321e24.2b60: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\msi.dll) WinVerifyTrust
21331e24.2b60: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msi.dll
21341e24.2b60: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
21351e24.2b60: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume2\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
21361e24.2b60: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll
21371e24.2b60: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
21381e24.2b60: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
21391e24.2b60: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
21401e24.2b60: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
21411e24.2b60: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
21421e24.2b60: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
21431e24.2b60: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
21441e24.2b60: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
21451e24.2b60: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
21461e24.2b60: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
21471e24.2b60: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
21481e24.2b60: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
21491e24.2b60: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
21501e24.2b60: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
21511e24.2b60: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
21521e24.2b60: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
21531e24.2b60: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
21541e24.2b60: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\msi.dll (Input=msi.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
21551e24.2b60: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msi.dll
21561e24.2b60: supR3HardenedDllNotificationCallback: load 00007ff91eb30000 LB 0x00466000 C:\WINDOWS\System32\msi.dll [fFlags=0x0]
21571e24.2b60: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msi.dll
21581e24.2b60: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff91eb30000 'C:\WINDOWS\System32\msi.dll'
21591e24.2b60: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msiltcfg.dll
21601e24.2b60: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\msiltcfg.dll (Input=msiltcfg.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
21611e24.2b60: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff92a470000 'C:\WINDOWS\System32\msiltcfg.dll'
21621e24.2b60: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
21631e24.2b60: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\oleaut32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
21641e24.2b60: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff937970000 'C:\WINDOWS\system32\oleaut32.dll'
21651e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9393f0000 'C:\WINDOWS\system32\gdi32.dll'
21661e24.a1c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
21671e24.a1c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
21681e24.a1c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
21691e24.a1c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
21701e24.a1c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
21711e24.a1c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMainVM.dll) WinVerifyTrust
21721e24.a1c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMainVM.dll
21731e24.a1c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
21741e24.a1c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
21751e24.a1c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
21761e24.a1c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
21771e24.a1c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMainVM.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
21781e24.a1c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMainVM.dll
21791e24.a1c: supR3HardenedDllNotificationCallback: load 00007ff9319f0000 LB 0x0000e000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMainVM.DLL [fFlags=0x0]
21801e24.a1c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMainVM.dll
21811e24.a1c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9319f0000 'C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMainVM.DLL'
21821e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
21831e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\oleaut32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
21841e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff937970000 'C:\Windows\System32\oleaut32.dll'
21851e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
21861e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
21871e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff937c00000 'C:\WINDOWS\system32\shell32.dll'
21881e24.48c: supR3HardenedDllNotificationCallback: load 00007ff9382f0000 LB 0x00136000 C:\WINDOWS\System32\MSCTF.dll [fFlags=0x0]
21891e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
21901e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'oleaut32.dll'.
21911e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #38 'user32.dll'.
21921e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #39 'gdi32.dll'.
21931e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #40 'imm32.dll'.
21941e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #41 'advapi32.dll'.
21951e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\msctf.dll)
21961e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msctf.dll
21971e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll
21981e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
21991e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
22001e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
22011e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume2\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
22021e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\imm32.dll
22031e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
22041e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
22051e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll
22061e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
22071e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
22081e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
22091e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
22101e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
22111e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
22121e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
22131e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
22141e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
22151e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
22161e24.48c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\msctf.dll'
22171e24.48c: \Device\HarddiskVolume2\Windows\System32\DataExchange.dll: Owner is not trusted installer (01 01 00 00 00 00 00 01 00 00 00 00)
22181e24.48c: \Device\HarddiskVolume2\Windows\System32\DataExchange.dll: Relaxing the TrustedInstaller requirement for this DLL (it's in system32).
22191e24.48c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000aac pwszName=\Device\HarddiskVolume2\Windows\System32\DataExchange.dll
22201e24.48c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000001743050
22211e24.48c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000001743050
22221e24.48c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=3632E0380EF7C400BBC7C4B0B9ED8D9F9860503B
22231e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
22241e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
22251e24.48c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0410~31bf3856ad364e35~amd64~~10.0.18362.476.cat'; file='\Device\HarddiskVolume2\Windows\System32\DataExchange.dll'
22261e24.48c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
22271e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
22281e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'shcore.dll'.
22291e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #29 'combase.dll'.
22301e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #34 'd3d11.dll'.
22311e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #35 'dcomp.dll'.
22321e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\DataExchange.dll) WinVerifyTrust
22331e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\DataExchange.dll
22341e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dcomp.dll'...
22351e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'dcomp.dll' -> '\Device\HarddiskVolume2\Windows\System32\dcomp.dll' [rcNtRedir=0xc0150008]
22361e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
22371e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
22381e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'win32u.dll'.
22391e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp_win.dll'.
22401e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\dcomp.dll) WinVerifyTrust
22411e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\dcomp.dll
22421e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'd3d11.dll'...
22431e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'd3d11.dll' -> '\Device\HarddiskVolume2\Windows\System32\d3d11.dll' [rcNtRedir=0xc0150008]
22441e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
22451e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
22461e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcp_win.dll [lacks WinVerifyTrust]
22471e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
22481e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume2\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
22491e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\win32u.dll [lacks WinVerifyTrust]
22501e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
22511e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
22521e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
22531e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #24 'dxgi.dll'.
22541e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #27 'win32u.dll'.
22551e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\d3d11.dll) WinVerifyTrust
22561e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\d3d11.dll
22571e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
22581e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume2\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
22591e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\combase.dll [redoing WinVerifyTrust]
22601e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
22611e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume2\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
22621e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\win32u.dll [lacks WinVerifyTrust]
22631e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dxgi.dll'...
22641e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'dxgi.dll' -> '\Device\HarddiskVolume2\Windows\System32\dxgi.dll' [rcNtRedir=0xc0150008]
22651e24.48c: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\dxgi.dll'.
22661e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
22671e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'win32u.dll'.
22681e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\dxgi.dll)
22691e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\dxgi.dll
22701e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
22711e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
22721e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
22731e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume2\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
22741e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\win32u.dll [lacks WinVerifyTrust]
22751e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
22761e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
22771e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
22781e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
22791e24.48c: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\combase.dll'
22801e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shcore.dll'...
22811e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'shcore.dll' -> '\Device\HarddiskVolume2\Windows\System32\shcore.dll' [rcNtRedir=0xc0150008]
22821e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\SHCore.dll
22831e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
22841e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
22851e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\dataexchange.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
22861e24.48c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\DataExchange.dll
22871e24.48c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\d3d11.dll
22881e24.48c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dcomp.dll
22891e24.48c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dxgi.dll [avoiding WinVerifyTrust]
22901e24.48c: supR3HardenedDllNotificationCallback: load 00007ff9352d0000 LB 0x000eb000 C:\WINDOWS\system32\dxgi.dll [fFlags=0x0]
22911e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dxgi.dll [avoiding WinVerifyTrust]
22921e24.48c: supR3HardenedDllNotificationCallback: load 00007ff933270000 LB 0x0025b000 C:\WINDOWS\system32\d3d11.dll [fFlags=0x0]
22931e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\d3d11.dll
22941e24.48c: supR3HardenedDllNotificationCallback: load 00007ff9334d0000 LB 0x001db000 C:\WINDOWS\system32\dcomp.dll [fFlags=0x0]
22951e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dcomp.dll
22961e24.48c: supR3HardenedDllNotificationCallback: load 00007ff9314d0000 LB 0x0003a000 C:\WINDOWS\system32\dataexchange.dll [fFlags=0x0]
22971e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\DataExchange.dll
22981e24.48c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\dxgi.dll'.
22991e24.48c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\System32\dxgi.dll' [rescheduled]
23001e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9393f0000 'C:\WINDOWS\System32\gdi32.dll'
23011e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9314d0000 'C:\WINDOWS\system32\dataexchange.dll'
23021e24.48c: \Device\HarddiskVolume2\Windows\System32\twinapi.appcore.dll: Owner is not trusted installer (01 01 00 00 00 00 00 01 00 00 00 00)
23031e24.48c: \Device\HarddiskVolume2\Windows\System32\twinapi.appcore.dll: Relaxing the TrustedInstaller requirement for this DLL (it's in system32).
23041e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rmclient.dll'.
23051e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #31 'rpcrt4.dll'.
23061e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #47 'combase.dll'.
23071e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #50 'msvcp_win.dll'.
23081e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\twinapi.appcore.dll)
23091e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\twinapi.appcore.dll
23101e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
23111e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'rpcrt4.dll'.
23121e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\rmclient.dll)
23131e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\rmclient.dll
23141e24.48c: supR3HardenedDllNotificationCallback: load 00007ff934e50000 LB 0x00029000 C:\WINDOWS\system32\RMCLIENT.dll [fFlags=0x0]
23151e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rmclient.dll [avoiding WinVerifyTrust]
23161e24.48c: supR3HardenedDllNotificationCallback: load 00007ff934a20000 LB 0x0025a000 C:\WINDOWS\system32\twinapi.appcore.dll [fFlags=0x0]
23171e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\twinapi.appcore.dll [avoiding WinVerifyTrust]
23181e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
23191e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
23201e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
23211e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
23221e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
23231e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
23241e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcp_win.dll [lacks WinVerifyTrust]
23251e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
23261e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume2\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
23271e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\combase.dll
23281e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
23291e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
23301e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rmclient.dll'...
23311e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rmclient.dll' -> '\Device\HarddiskVolume2\Windows\System32\rmclient.dll' [rcNtRedir=0xc0150008]
23321e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rmclient.dll [lacks WinVerifyTrust]
23331e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
23341e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
23351e24.48c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\rmclient.dll'
23361e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
23371e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
23381e24.48c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\twinapi.appcore.dll'
23391e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\SHCore.dll
23401e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\Shcore.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
23411e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff939280000 'C:\WINDOWS\system32\Shcore.dll'
23421e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff937c00000 'C:\WINDOWS\system32\shell32.dll'
23431e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff937c00000 'C:\WINDOWS\system32\shell32.dll'
23441e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff937c00000 'C:\WINDOWS\system32\shell32.dll'
23451e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff937c00000 'C:\WINDOWS\system32\shell32.dll'
23461e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff937c00000 'C:\WINDOWS\system32\shell32.dll'
23471e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff937c00000 'C:\WINDOWS\system32\shell32.dll'
23481e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff937c00000 'C:\WINDOWS\system32\shell32.dll'
23491e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff938490000 'C:\WINDOWS\System32\ole32.dll'
23501e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff937970000 'C:\WINDOWS\System32\OLEAUT32.dll'
23511e24.48c: \Device\HarddiskVolume2\Windows\System32\wbem\wbemprox.dll: Owner is not trusted installer (01 01 00 00 00 00 00 01 00 00 00 00)
23521e24.48c: \Device\HarddiskVolume2\Windows\System32\wbem\wbemprox.dll: Relaxing the TrustedInstaller requirement for this DLL (it's in system32).
23531e24.48c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000b90 pwszName=\Device\HarddiskVolume2\Windows\System32\wbem\wbemprox.dll
23541e24.48c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000001743050
23551e24.48c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000001743050
23561e24.48c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=DB1AA7E2E4704C908EC9382E1F9E64808B9E5E1D
23571e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
23581e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
23591e24.48c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package03~31bf3856ad364e35~amd64~~10.0.18362.476.cat'; file='\Device\HarddiskVolume2\Windows\System32\wbem\wbemprox.dll'
23601e24.48c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
23611e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
23621e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ws2_32.dll'.
23631e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'wbemcomn.dll'.
23641e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\wbem\wbemprox.dll) WinVerifyTrust
23651e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wbem\wbemprox.dll
23661e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wbemcomn.dll'...
23671e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'wbemcomn.dll' -> '\Device\HarddiskVolume2\Windows\System32\wbemcomn.dll' [rcNtRedir=0xc0150008]
23681e24.48c: \Device\HarddiskVolume2\Windows\System32\wbemcomn.dll: Owner is not trusted installer (01 01 00 00 00 00 00 01 00 00 00 00)
23691e24.48c: \Device\HarddiskVolume2\Windows\System32\wbemcomn.dll: Relaxing the TrustedInstaller requirement for this DLL (it's in system32).
23701e24.48c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000b60 pwszName=\Device\HarddiskVolume2\Windows\System32\wbemcomn.dll
23711e24.48c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000001743050
23721e24.48c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000001743050
23731e24.48c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=22EAF38FA276D7A374D3945ACD556FA0953D3440
23741e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
23751e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
23761e24.48c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package03~31bf3856ad364e35~amd64~~10.0.18362.476.cat'; file='\Device\HarddiskVolume2\Windows\System32\wbemcomn.dll'
23771e24.48c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
23781e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
23791e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'bcrypt.dll'.
23801e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'ws2_32.dll'.
23811e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\wbemcomn.dll) WinVerifyTrust
23821e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wbemcomn.dll
23831e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
23841e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
23851e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
23861e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
23871e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
23881e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
23891e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
23901e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
23911e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
23921e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume2\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
23931e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll
23941e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
23951e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
23961e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\wbem\wbemprox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
23971e24.48c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbem\wbemprox.dll
23981e24.48c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbemcomn.dll
23991e24.48c: supR3HardenedDllNotificationCallback: load 00007ff92fc60000 LB 0x00084000 C:\WINDOWS\SYSTEM32\wbemcomn.dll [fFlags=0x0]
24001e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbemcomn.dll
24011e24.48c: supR3HardenedDllNotificationCallback: load 00007ff92ffd0000 LB 0x00011000 C:\WINDOWS\system32\wbem\wbemprox.dll [fFlags=0x0]
24021e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbem\wbemprox.dll
24031e24.48c: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(API-MS-Win-Core-LocalRegistry-L1-1-0.dll) -> 0x0, fPresent=1
24041e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Core-LocalRegistry-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
24051e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9368c0000 'API-MS-Win-Core-LocalRegistry-L1-1-0.dll'
24061e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff92ffd0000 'C:\WINDOWS\system32\wbem\wbemprox.dll'
24071e24.48c: \Device\HarddiskVolume2\Windows\System32\wbem\wbemsvc.dll: Owner is not trusted installer (01 01 00 00 00 00 00 01 00 00 00 00)
24081e24.48c: \Device\HarddiskVolume2\Windows\System32\wbem\wbemsvc.dll: Relaxing the TrustedInstaller requirement for this DLL (it's in system32).
24091e24.48c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000ab4 pwszName=\Device\HarddiskVolume2\Windows\System32\wbem\wbemsvc.dll
24101e24.48c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000001743050
24111e24.48c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000001743050
24121e24.48c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=00C864D7F76A7AD25E7D0DA164B0B66188F5B7FF
24131e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
24141e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
24151e24.48c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package03~31bf3856ad364e35~amd64~~10.0.18362.476.cat'; file='\Device\HarddiskVolume2\Windows\System32\wbem\wbemsvc.dll'
24161e24.48c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
24171e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
24181e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'rpcrt4.dll'.
24191e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\wbem\wbemsvc.dll) WinVerifyTrust
24201e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wbem\wbemsvc.dll
24211e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
24221e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
24231e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
24241e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
24251e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\wbem\wbemsvc.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
24261e24.48c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbem\wbemsvc.dll
24271e24.48c: supR3HardenedDllNotificationCallback: load 00007ff9310b0000 LB 0x00014000 C:\WINDOWS\system32\wbem\wbemsvc.dll [fFlags=0x0]
24281e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbem\wbemsvc.dll
24291e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9310b0000 'C:\WINDOWS\system32\wbem\wbemsvc.dll'
24301e24.48c: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-l1-2-0.dll) -> 0x0, fPresent=1
24311e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-l1-2-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
24321e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9368c0000 'api-ms-win-core-localization-l1-2-0.dll'
24331e24.48c: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-obsolete-l1-1-0.dll) -> 0x0, fPresent=1
24341e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-obsolete-l1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
24351e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9368c0000 'api-ms-win-core-localization-obsolete-l1-1-0.dll'
24361e24.48c: \Device\HarddiskVolume2\Windows\System32\wbem\fastprox.dll: Owner is not trusted installer (01 01 00 00 00 00 00 01 00 00 00 00)
24371e24.48c: \Device\HarddiskVolume2\Windows\System32\wbem\fastprox.dll: Relaxing the TrustedInstaller requirement for this DLL (it's in system32).
24381e24.48c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000bcc pwszName=\Device\HarddiskVolume2\Windows\System32\wbem\fastprox.dll
24391e24.48c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000001743050
24401e24.48c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000001743050
24411e24.48c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=0708A64F48237CD4D5092546CE9C373F20B30CA1
24421e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
24431e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
24441e24.48c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package03~31bf3856ad364e35~amd64~~10.0.18362.476.cat'; file='\Device\HarddiskVolume2\Windows\System32\wbem\fastprox.dll'
24451e24.48c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
24461e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
24471e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #20 'wbemcomn.dll'.
24481e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\wbem\fastprox.dll) WinVerifyTrust
24491e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wbem\fastprox.dll
24501e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wbemcomn.dll'...
24511e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'wbemcomn.dll' -> '\Device\HarddiskVolume2\Windows\System32\wbemcomn.dll' [rcNtRedir=0xc0150008]
24521e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbemcomn.dll
24531e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
24541e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
24551e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\wbem\fastprox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
24561e24.48c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbem\fastprox.dll
24571e24.48c: supR3HardenedDllNotificationCallback: load 00007ff92fab0000 LB 0x00101000 C:\WINDOWS\system32\wbem\fastprox.dll [fFlags=0x0]
24581e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbem\fastprox.dll
24591e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff92fab0000 'C:\WINDOWS\system32\wbem\fastprox.dll'
24601e24.48c: \Device\HarddiskVolume2\Windows\System32\amsi.dll: Owner is not trusted installer (01 01 00 00 00 00 00 01 00 00 00 00)
24611e24.48c: \Device\HarddiskVolume2\Windows\System32\amsi.dll: Relaxing the TrustedInstaller requirement for this DLL (it's in system32).
24621e24.48c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000ba4 pwszName=\Device\HarddiskVolume2\Windows\System32\amsi.dll
24631e24.48c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000001743050
24641e24.48c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000001743050
24651e24.48c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B5D4D58A583ACAD5AA76D7DD0F2DB8ADE903942B
24661e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
24671e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
24681e24.48c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package04~31bf3856ad364e35~amd64~~10.0.18362.476.cat'; file='\Device\HarddiskVolume2\Windows\System32\amsi.dll'
24691e24.48c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
24701e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
24711e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'rpcrt4.dll'.
24721e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'userenv.dll'.
24731e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\amsi.dll) WinVerifyTrust
24741e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\amsi.dll
24751e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'userenv.dll'...
24761e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'userenv.dll' -> '\Device\HarddiskVolume2\Windows\System32\userenv.dll' [rcNtRedir=0xc0150008]
24771e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\userenv.dll
24781e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
24791e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
24801e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
24811e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
24821e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\amsi.dll (Input=amsi.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
24831e24.48c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\amsi.dll
24841e24.48c: supR3HardenedDllNotificationCallback: load 00007ff92cad0000 LB 0x00015000 C:\WINDOWS\System32\amsi.dll [fFlags=0x0]
24851e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\amsi.dll
24861e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff92cad0000 'C:\WINDOWS\System32\amsi.dll'
24871e24.48c: supR3HardenedMonitor_LdrLoadDll: error opening 'C:\Program Files (x86)\CheckPoint\Endpoint Security\EFR\CP_AmsiProvider64.dll': 0 (NtPath=\??\C:\Program Files (x86)\CheckPoint\Endpoint Security\EFR\CP_AmsiProvider64.dll; Input=C:\Program Files (x86)\CheckPoint\Endpoint Security\EFR\CP_AmsiProvider64.dll; rcNtGetDll=0x0
24881e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc000003a 'C:\Program Files (x86)\CheckPoint\Endpoint Security\EFR\CP_AmsiProvider64.dll'
24891e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msctf.dll
24901e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\MSCTF.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
24911e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9382f0000 'C:\WINDOWS\System32\MSCTF.dll'
24921e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
24931e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #15 'rpcrt4.dll'.
24941e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #19 'coreuicomponents.dll'.
24951e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #20 'coremessaging.dll'.
24961e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\TextInputFramework.dll)
24971e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\TextInputFramework.dll
24981e24.48c: \Device\HarddiskVolume2\Windows\System32\CoreUIComponents.dll: Owner is not trusted installer (01 01 00 00 00 00 00 01 00 00 00 00)
24991e24.48c: \Device\HarddiskVolume2\Windows\System32\CoreUIComponents.dll: Relaxing the TrustedInstaller requirement for this DLL (it's in system32).
25001e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
25011e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #35 'coremessaging.dll'.
25021e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #47 'shcore.dll'.
25031e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\CoreUIComponents.dll)
25041e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\CoreUIComponents.dll
25051e24.48c: \Device\HarddiskVolume2\Windows\System32\CoreMessaging.dll: Owner is not trusted installer (01 01 00 00 00 00 00 01 00 00 00 00)
25061e24.48c: \Device\HarddiskVolume2\Windows\System32\CoreMessaging.dll: Relaxing the TrustedInstaller requirement for this DLL (it's in system32).
25071e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
25081e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\CoreMessaging.dll)
25091e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\CoreMessaging.dll
25101e24.48c: \Device\HarddiskVolume2\Windows\System32\ntmarta.dll: Owner is not trusted installer (01 01 00 00 00 00 00 01 00 00 00 00)
25111e24.48c: \Device\HarddiskVolume2\Windows\System32\ntmarta.dll: Relaxing the TrustedInstaller requirement for this DLL (it's in system32).
25121e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ntmarta.dll)
25131e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ntmarta.dll
25141e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'combase.dll'.
25151e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #24 'rpcrt4.dll'.
25161e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #32 'bcryptprimitives.dll'.
25171e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\WinTypes.dll)
25181e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\WinTypes.dll
25191e24.48c: supR3HardenedDllNotificationCallback: load 00007ff935740000 LB 0x00031000 C:\WINDOWS\SYSTEM32\ntmarta.dll [fFlags=0x0]
25201e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ntmarta.dll [avoiding WinVerifyTrust]
25211e24.48c: supR3HardenedDllNotificationCallback: load 00007ff933a20000 LB 0x000d4000 C:\WINDOWS\System32\CoreMessaging.dll [fFlags=0x0]
25221e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\CoreMessaging.dll [avoiding WinVerifyTrust]
25231e24.48c: supR3HardenedDllNotificationCallback: load 00007ff9316e0000 LB 0x00153000 C:\WINDOWS\SYSTEM32\wintypes.dll [fFlags=0x0]
25241e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\WinTypes.dll [avoiding WinVerifyTrust]
25251e24.48c: supR3HardenedDllNotificationCallback: load 00007ff927ad0000 LB 0x0032a000 C:\WINDOWS\System32\CoreUIComponents.dll [fFlags=0x0]
25261e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\CoreUIComponents.dll [avoiding WinVerifyTrust]
25271e24.48c: supR3HardenedDllNotificationCallback: load 00007ff927e00000 LB 0x0009e000 C:\WINDOWS\System32\TextInputFramework.dll [fFlags=0x0]
25281e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\TextInputFramework.dll [avoiding WinVerifyTrust]
25291e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcryptprimitives.dll'...
25301e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcryptprimitives.dll' -> '\Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll' [rcNtRedir=0xc0150008]
25311e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll
25321e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
25331e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
25341e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
25351e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume2\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
25361e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\combase.dll
25371e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
25381e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
25391e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shcore.dll'...
25401e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'shcore.dll' -> '\Device\HarddiskVolume2\Windows\System32\shcore.dll' [rcNtRedir=0xc0150008]
25411e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\SHCore.dll
25421e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'coremessaging.dll'...
25431e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'coremessaging.dll' -> '\Device\HarddiskVolume2\Windows\System32\coremessaging.dll' [rcNtRedir=0xc0150008]
25441e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\CoreMessaging.dll [lacks WinVerifyTrust]
25451e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
25461e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
25471e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'coremessaging.dll'...
25481e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'coremessaging.dll' -> '\Device\HarddiskVolume2\Windows\System32\coremessaging.dll' [rcNtRedir=0xc0150008]
25491e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\CoreMessaging.dll [lacks WinVerifyTrust]
25501e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'coreuicomponents.dll'...
25511e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'coreuicomponents.dll' -> '\Device\HarddiskVolume2\Windows\System32\coreuicomponents.dll' [rcNtRedir=0xc0150008]
25521e24.48c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\CoreUIComponents.dll [lacks WinVerifyTrust]
25531e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
25541e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
25551e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
25561e24.48c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
25571e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
25581e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
25591e24.48c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\WinTypes.dll'
25601e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
25611e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
25621e24.48c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\ntmarta.dll'
25631e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
25641e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
25651e24.48c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\CoreMessaging.dll'
25661e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
25671e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
25681e24.48c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\CoreUIComponents.dll'
25691e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
25701e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll
25711e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
25721e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
25731e24.48c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\TextInputFramework.dll'
25741e24.48c: supR3HardenedMonitor_LdrLoadDll: error opening 'C:\Program Files (x86)\CheckPoint\Endpoint Security\EFR\CP_AmsiProvider64.dll': 0 (NtPath=\??\C:\Program Files (x86)\CheckPoint\Endpoint Security\EFR\CP_AmsiProvider64.dll; Input=C:\Program Files (x86)\CheckPoint\Endpoint Security\EFR\CP_AmsiProvider64.dll; rcNtGetDll=0x0
25751e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc000003a 'C:\Program Files (x86)\CheckPoint\Endpoint Security\EFR\CP_AmsiProvider64.dll'
25761e24.48c: supR3HardenedMonitor_LdrLoadDll: error opening 'C:\Program Files (x86)\CheckPoint\Endpoint Security\EFR\CP_AmsiProvider64.dll': 0 (NtPath=\??\C:\Program Files (x86)\CheckPoint\Endpoint Security\EFR\CP_AmsiProvider64.dll; Input=C:\Program Files (x86)\CheckPoint\Endpoint Security\EFR\CP_AmsiProvider64.dll; rcNtGetDll=0x0
25771e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc000003a 'C:\Program Files (x86)\CheckPoint\Endpoint Security\EFR\CP_AmsiProvider64.dll'
25781e24.48c: supR3HardenedMonitor_LdrLoadDll: error opening 'C:\Program Files (x86)\CheckPoint\Endpoint Security\EFR\CP_AmsiProvider64.dll': 0 (NtPath=\??\C:\Program Files (x86)\CheckPoint\Endpoint Security\EFR\CP_AmsiProvider64.dll; Input=C:\Program Files (x86)\CheckPoint\Endpoint Security\EFR\CP_AmsiProvider64.dll; rcNtGetDll=0x0
25791e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc000003a 'C:\Program Files (x86)\CheckPoint\Endpoint Security\EFR\CP_AmsiProvider64.dll'
25801e24.48c: supR3HardenedMonitor_LdrLoadDll: error opening 'C:\Program Files (x86)\CheckPoint\Endpoint Security\EFR\CP_AmsiProvider64.dll': 0 (NtPath=\??\C:\Program Files (x86)\CheckPoint\Endpoint Security\EFR\CP_AmsiProvider64.dll; Input=C:\Program Files (x86)\CheckPoint\Endpoint Security\EFR\CP_AmsiProvider64.dll; rcNtGetDll=0x0
25811e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc000003a 'C:\Program Files (x86)\CheckPoint\Endpoint Security\EFR\CP_AmsiProvider64.dll'
25821e24.48c: supR3HardenedMonitor_LdrLoadDll: error opening 'C:\Program Files (x86)\CheckPoint\Endpoint Security\EFR\CP_AmsiProvider64.dll': 0 (NtPath=\??\C:\Program Files (x86)\CheckPoint\Endpoint Security\EFR\CP_AmsiProvider64.dll; Input=C:\Program Files (x86)\CheckPoint\Endpoint Security\EFR\CP_AmsiProvider64.dll; rcNtGetDll=0x0
25831e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc000003a 'C:\Program Files (x86)\CheckPoint\Endpoint Security\EFR\CP_AmsiProvider64.dll'
25841e24.292c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
25851e24.292c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
25861e24.292c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrem.dll'.
25871e24.292c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
25881e24.292c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll) WinVerifyTrust
25891e24.292c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
25901e24.292c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
25911e24.292c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
25921e24.292c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrem.dll'...
25931e24.292c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrem.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrem.dll' [rcNtRedir=0xc0150008]
25941e24.292c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
25951e24.292c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'vboxrt.dll'.
25961e24.292c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
25971e24.292c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcrt.dll'.
25981e24.292c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxREM.dll) WinVerifyTrust
25991e24.292c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxREM.dll
26001e24.292c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
26011e24.292c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
26021e24.292c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
26031e24.292c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
26041e24.292c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
26051e24.292c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
26061e24.292c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
26071e24.292c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
26081e24.292c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
26091e24.292c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
26101e24.292c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
26111e24.292c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxREM.dll
26121e24.292c: supR3HardenedDllNotificationCallback: load 0000000073f50000 LB 0x0010b000 C:\Program Files\Oracle\VirtualBox\VBoxREM.dll [fFlags=0x0]
26131e24.292c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxREM.dll
26141e24.292c: supR3HardenedDllNotificationCallback: load 00007ff901c60000 LB 0x00331000 C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL [fFlags=0x0]
26151e24.292c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
26161e24.292c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff901c60000 'C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL'
26171e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
26181e24.60c: \Device\HarddiskVolume2\Windows\System32\NetSetupShim.dll: Owner is not trusted installer (01 01 00 00 00 00 00 01 00 00 00 00)
26191e24.60c: \Device\HarddiskVolume2\Windows\System32\NetSetupShim.dll: Relaxing the TrustedInstaller requirement for this DLL (it's in system32).
26201e24.60c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000c8c pwszName=\Device\HarddiskVolume2\Windows\System32\NetSetupShim.dll
26211e24.60c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000001743050
26221e24.60c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000001743050
26231e24.60c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=7F5B666FF2CFCD1394E450AF7141F0F82A5730F3
26241e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
26251e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
26261e24.60c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package04113~31bf3856ad364e35~amd64~~10.0.18362.476.cat'; file='\Device\HarddiskVolume2\Windows\System32\NetSetupShim.dll'
26271e24.60c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
26281e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
26291e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #31 'rpcrt4.dll'.
26301e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #32 'oleaut32.dll'.
26311e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #34 'ws2_32.dll'.
26321e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #35 'netsetupapi.dll'.
26331e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #36 'setupapi.dll'.
26341e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #37 'devrtl.dll'.
26351e24.60c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\NetSetupShim.dll) WinVerifyTrust
26361e24.60c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\NetSetupShim.dll
26371e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'devrtl.dll'...
26381e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'devrtl.dll' -> '\Device\HarddiskVolume2\Windows\System32\devrtl.dll' [rcNtRedir=0xc0150008]
26391e24.60c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000bac pwszName=\Device\HarddiskVolume2\Windows\System32\devrtl.dll
26401e24.60c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000001743050
26411e24.60c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000001743050
26421e24.60c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=D2E5A6C3AFA14B1D9C532760FD646C3AC357C7AB
26431e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
26441e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
26451e24.60c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0416~31bf3856ad364e35~amd64~~10.0.18362.476.cat'; file='\Device\HarddiskVolume2\Windows\System32\devrtl.dll'
26461e24.60c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
26471e24.60c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\devrtl.dll) WinVerifyTrust
26481e24.60c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\devrtl.dll
26491e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
26501e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
26511e24.60c: \Device\HarddiskVolume2\Windows\System32\setupapi.dll: Owner is not trusted installer (01 01 00 00 00 00 00 01 00 00 00 00)
26521e24.60c: \Device\HarddiskVolume2\Windows\System32\setupapi.dll: Relaxing the TrustedInstaller requirement for this DLL (it's in system32).
26531e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
26541e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
26551e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
26561e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #29 'rpcrt4.dll'.
26571e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #36 'cfgmgr32.dll'.
26581e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #41 'bcrypt.dll'.
26591e24.60c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\setupapi.dll) WinVerifyTrust
26601e24.60c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\setupapi.dll
26611e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'netsetupapi.dll'...
26621e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'netsetupapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\netsetupapi.dll' [rcNtRedir=0xc0150008]
26631e24.60c: \Device\HarddiskVolume2\Windows\System32\NetSetupApi.dll: Owner is not trusted installer (01 01 00 00 00 00 00 01 00 00 00 00)
26641e24.60c: \Device\HarddiskVolume2\Windows\System32\NetSetupApi.dll: Relaxing the TrustedInstaller requirement for this DLL (it's in system32).
26651e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
26661e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume2\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
26671e24.60c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll
26681e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
26691e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
26701e24.60c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll [lacks WinVerifyTrust]
26711e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
26721e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
26731e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
26741e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
26751e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
26761e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
26771e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
26781e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'rpcrt4.dll'.
26791e24.60c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\NetSetupApi.dll) WinVerifyTrust
26801e24.60c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\NetSetupApi.dll
26811e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
26821e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
26831e24.60c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
26841e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
26851e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
26861e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
26871e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
26881e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
26891e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
26901e24.60c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcp_win.dll [redoing WinVerifyTrust]
26911e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
26921e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
26931e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
26941e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
26951e24.60c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
26961e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
26971e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
26981e24.60c: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\msvcp_win.dll'
26991e24.60c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\NetSetupShim.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
27001e24.60c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\NetSetupShim.dll
27011e24.60c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\NetSetupApi.dll
27021e24.60c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\devrtl.dll
27031e24.60c: supR3HardenedDllNotificationCallback: load 00007ff92d700000 LB 0x00025000 C:\Windows\System32\NetSetupApi.dll [fFlags=0x0]
27041e24.60c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\NetSetupApi.dll
27051e24.60c: supR3HardenedDllNotificationCallback: load 00007ff9388f0000 LB 0x00470000 C:\WINDOWS\System32\setupapi.dll [fFlags=0x0]
27061e24.60c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\setupapi.dll
27071e24.60c: supR3HardenedDllNotificationCallback: load 00007ff924800000 LB 0x00013000 C:\Windows\System32\DEVRTL.dll [fFlags=0x0]
27081e24.60c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\devrtl.dll
27091e24.60c: supR3HardenedDllNotificationCallback: load 00007ff924820000 LB 0x00081000 C:\Windows\System32\NetSetupShim.dll [fFlags=0x0]
27101e24.60c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\NetSetupShim.dll
27111e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff924820000 'C:\Windows\System32\NetSetupShim.dll'
27121e24.60c: \Device\HarddiskVolume2\Windows\System32\NetSetupEngine.dll: Owner is not trusted installer (01 01 00 00 00 00 00 01 00 00 00 00)
27131e24.60c: \Device\HarddiskVolume2\Windows\System32\NetSetupEngine.dll: Relaxing the TrustedInstaller requirement for this DLL (it's in system32).
27141e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
27151e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
27161e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
27171e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'rpcrt4.dll'.
27181e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #24 'nsi.dll'.
27191e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'winnsi.dll'.
27201e24.60c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\NetSetupEngine.dll) WinVerifyTrust
27211e24.60c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\NetSetupEngine.dll
27221e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winnsi.dll'...
27231e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'winnsi.dll' -> '\Device\HarddiskVolume2\Windows\System32\winnsi.dll' [rcNtRedir=0xc0150008]
27241e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
27251e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
27261e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rpcrt4.dll'.
27271e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'nsi.dll'.
27281e24.60c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\winnsi.dll) WinVerifyTrust
27291e24.60c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\winnsi.dll
27301e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
27311e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume2\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
27321e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
27331e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume2\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
27341e24.60c: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\nsi.dll'.
27351e24.60c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\nsi.dll)
27361e24.60c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\nsi.dll
27371e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
27381e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
27391e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
27401e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
27411e24.60c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\nsi.dll) WinVerifyTrust
27421e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
27431e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
27441e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
27451e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
27461e24.60c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\NetSetupEngine.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
27471e24.60c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\NetSetupEngine.dll
27481e24.60c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winnsi.dll
27491e24.60c: supR3HardenedDllNotificationCallback: load 00007ff937960000 LB 0x00008000 C:\WINDOWS\System32\NSI.dll [fFlags=0x0]
27501e24.60c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\nsi.dll [avoiding WinVerifyTrust]
27511e24.60c: supR3HardenedDllNotificationCallback: load 00007ff933c30000 LB 0x0000b000 C:\WINDOWS\SYSTEM32\WINNSI.DLL [fFlags=0x0]
27521e24.60c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winnsi.dll
27531e24.60c: supR3HardenedDllNotificationCallback: load 00007ff90c8e0000 LB 0x000ce000 C:\Windows\System32\NetSetupEngine.dll [fFlags=0x0]
27541e24.60c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\NetSetupEngine.dll
27551e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff90c8e0000 'C:\Windows\System32\NetSetupEngine.dll'
27561e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
27571e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
27581e24.60c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\nsi.dll'
27591e24.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
27601e24.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
27611e24.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
27621e24.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
27631e24.d9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
27641e24.d9c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll) WinVerifyTrust
27651e24.d9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll
27661e24.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
27671e24.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
27681e24.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
27691e24.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
27701e24.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
27711e24.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
27721e24.d9c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
27731e24.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
27741e24.d9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
27751e24.d9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
27761e24.d9c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll
27771e24.d9c: supR3HardenedDllNotificationCallback: load 00007ff930190000 LB 0x0000b000 C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL [fFlags=0x0]
27781e24.d9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll
27791e24.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff930190000 'C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL'
27801e24.d9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff939540000 'C:\WINDOWS\system32\User32.dll'
27811e24.99c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
27821e24.99c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
27831e24.99c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
27841e24.99c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
27851e24.99c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll) WinVerifyTrust
27861e24.99c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll
27871e24.99c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
27881e24.99c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
27891e24.99c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
27901e24.99c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
27911e24.99c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
27921e24.99c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
27931e24.99c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
27941e24.99c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
27951e24.99c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll
27961e24.99c: supR3HardenedDllNotificationCallback: load 00007ff92c5a0000 LB 0x0000d000 C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL [fFlags=0x0]
27971e24.99c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll
27981e24.99c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff92c5a0000 'C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL'
27991e24.60c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
28001e24.60c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\Shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
28011e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff937c00000 'C:\WINDOWS\system32\Shell32.dll'
28021e24.60c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
28031e24.60c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
28041e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff901c60000 'C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL'
28051e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
28061e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
28071e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
28081e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
28091e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ole32.dll'.
28101e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'oleaut32.dll'.
28111e24.60c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll) WinVerifyTrust
28121e24.60c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
28131e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
28141e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
28151e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
28161e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
28171e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
28181e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
28191e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
28201e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
28211e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
28221e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
28231e24.60c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
28241e24.60c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
28251e24.60c: supR3HardenedDllNotificationCallback: load 00007ff920a20000 LB 0x00041000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL [fFlags=0x0]
28261e24.60c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
28271e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff920a20000 'C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL'
28281e24.60c: supR3HardenedDllNotificationCallback: Unload 00007ff920a20000 LB 0x00041000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL [flags=0x0]
28291e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
28301e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
28311e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
28321e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
28331e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
28341e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vboxddu.dll'.
28351e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'vboxdd2.dll'.
28361e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
28371e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'setupapi.dll'.
28381e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'ws2_32.dll'.
28391e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'ole32.dll'.
28401e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'iphlpapi.dll'.
28411e24.60c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD.dll) WinVerifyTrust
28421e24.60c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD.dll
28431e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'iphlpapi.dll'...
28441e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'iphlpapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\iphlpapi.dll' [rcNtRedir=0xc0150008]
28451e24.60c: \Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL: Owner is not trusted installer (01 01 00 00 00 00 00 01 00 00 00 00)
28461e24.60c: \Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL: Relaxing the TrustedInstaller requirement for this DLL (it's in system32).
28471e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
28481e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
28491e24.60c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL) WinVerifyTrust
28501e24.60c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL
28511e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
28521e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
28531e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
28541e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
28551e24.60c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
28561e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
28571e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
28581e24.60c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\setupapi.dll
28591e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
28601e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
28611e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxdd2.dll'...
28621e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxdd2.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxdd2.dll' [rcNtRedir=0xc0150008]
28631e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
28641e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
28651e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
28661e24.60c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD2.dll) WinVerifyTrust
28671e24.60c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD2.dll
28681e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxddu.dll'...
28691e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxddu.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxddu.dll' [rcNtRedir=0xc0150008]
28701e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
28711e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
28721e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
28731e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
28741e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
28751e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
28761e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
28771e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
28781e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'setupapi.dll'.
28791e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'advapi32.dll'.
28801e24.60c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDDU.dll) WinVerifyTrust
28811e24.60c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDDU.dll
28821e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
28831e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
28841e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
28851e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
28861e24.60c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
28871e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
28881e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
28891e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
28901e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
28911e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
28921e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
28931e24.60c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\setupapi.dll
28941e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
28951e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
28961e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
28971e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
28981e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
28991e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
29001e24.60c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxDD.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
29011e24.60c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD.dll
29021e24.60c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDDU.dll
29031e24.60c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD2.dll
29041e24.60c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL
29051e24.60c: supR3HardenedDllNotificationCallback: load 00007ff911c50000 LB 0x00064000 C:\Program Files\Oracle\VirtualBox\VBoxDDU.dll [fFlags=0x0]
29061e24.60c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDDU.dll
29071e24.60c: supR3HardenedDllNotificationCallback: load 00007ff920a10000 LB 0x0005c000 C:\Program Files\Oracle\VirtualBox\VBoxDD2.dll [fFlags=0x0]
29081e24.60c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD2.dll
29091e24.60c: supR3HardenedDllNotificationCallback: load 00007ff935b70000 LB 0x0003a000 C:\WINDOWS\SYSTEM32\IPHLPAPI.DLL [fFlags=0x0]
29101e24.60c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL
29111e24.60c: supR3HardenedDllNotificationCallback: load 00007ff901280000 LB 0x009da000 C:\Program Files\Oracle\VirtualBox\VBoxDD.DLL [fFlags=0x0]
29121e24.60c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD.dll
29131e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff901280000 'C:\Program Files\Oracle\VirtualBox\VBoxDD.DLL'
29141e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
29151e24.60c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
29161e24.60c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
29171e24.60c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
29181e24.60c: supR3HardenedDllNotificationCallback: load 00007ff91a630000 LB 0x00041000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL [fFlags=0x0]
29191e24.60c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
29201e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff91a630000 'C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL'
29211e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
29221e24.60c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxC.dll
29231e24.60c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxC.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
29241e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9049d0000 'C:\Program Files\Oracle\VirtualBox\VBoxC.DLL'
29251e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
29261e24.60c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxDD2.dll
29271e24.60c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxDD2.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
29281e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff920a10000 'C:\Program Files\Oracle\VirtualBox\VBoxDD2.DLL'
29291e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
29301e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
29311e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
29321e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
29331e24.60c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.dll) WinVerifyTrust
29341e24.60c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.dll
29351e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
29361e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
29371e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
29381e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
29391e24.60c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
29401e24.60c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.dll
29411e24.60c: supR3HardenedDllNotificationCallback: load 00007ff92a040000 LB 0x0001e000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.DLL [fFlags=0x0]
29421e24.60c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.dll
29431e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff92a040000 'C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.DLL'
29441e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
29451e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
29461e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
29471e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
29481e24.60c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.dll) WinVerifyTrust
29491e24.60c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.dll
29501e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
29511e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
29521e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
29531e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
29541e24.60c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
29551e24.60c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.dll
29561e24.60c: supR3HardenedDllNotificationCallback: load 00007ff928a00000 LB 0x00018000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.DLL [fFlags=0x0]
29571e24.60c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.dll
29581e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff928a00000 'C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.DLL'
29591e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
29601e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
29611e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
29621e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
29631e24.60c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.dll) WinVerifyTrust
29641e24.60c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.dll
29651e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
29661e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
29671e24.48c: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(ext-ms-win-rtcore-ntuser-window-ext-l1-1-0.dll) -> 0x0, fPresent=1
29681e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
29691e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=ext-ms-win-rtcore-ntuser-window-ext-l1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
29701e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
29711e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff939540000 'ext-ms-win-rtcore-ntuser-window-ext-l1-1-0.dll'
29721e24.60c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
29731e24.60c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.dll
29741e24.48c: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(ext-ms-win-rtcore-ntuser-integration-l1-1-0.dll) -> 0x0, fPresent=1
29751e24.60c: supR3HardenedDllNotificationCallback: load 00007ff9289e0000 LB 0x00018000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.DLL [fFlags=0x0]
29761e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=ext-ms-win-rtcore-ntuser-integration-l1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
29771e24.60c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.dll
29781e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff939540000 'ext-ms-win-rtcore-ntuser-integration-l1-1-0.dll'
29791e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9289e0000 'C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.DLL'
29801e24.48c: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-com-l1-1-0.dll) -> 0x0, fPresent=1
29811e24.48c: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-com-l1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
29821e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff938e90000 'api-ms-win-core-com-l1-1-0.dll'
29831e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
29841e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
29851e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
29861e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
29871e24.60c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.dll) WinVerifyTrust
29881e24.60c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.dll
29891e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
29901e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
29911e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
29921e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
29931e24.60c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
29941e24.48c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
29951e24.48c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\iertutil.dll)
29961e24.48c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\iertutil.dll
29971e24.48c: supR3HardenedDllNotificationCallback: load 00007ff92e190000 LB 0x002a6000 C:\WINDOWS\System32\iertutil.dll [fFlags=0x0]
29981e24.48c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\iertutil.dll [avoiding WinVerifyTrust]
29991e24.60c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.dll
30001e24.60c: supR3HardenedDllNotificationCallback: load 00007ff91dc50000 LB 0x00019000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.DLL [fFlags=0x0]
30011e24.60c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.dll
30021e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff91dc50000 'C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.DLL'
30031e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
30041e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
30051e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
30061e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
30071e24.60c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\iertutil.dll'
30081e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
30091e24.105c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
30101e24.105c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
30111e24.105c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
30121e24.105c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
30131e24.105c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll) WinVerifyTrust
30141e24.105c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll
30151e24.105c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
30161e24.105c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
30171e24.105c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
30181e24.105c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
30191e24.105c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
30201e24.105c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
30211e24.105c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
30221e24.105c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
30231e24.105c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll
30241e24.105c: supR3HardenedDllNotificationCallback: load 00007ff91dc30000 LB 0x00014000 C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL [fFlags=0x0]
30251e24.105c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll
30261e24.105c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff91dc30000 'C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL'
30271e24.e38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
30281e24.e38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
30291e24.e38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
30301e24.e38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxvmm.dll'.
30311e24.e38: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vboxrt.dll'.
30321e24.e38: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll) WinVerifyTrust
30331e24.e38: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll
30341e24.e38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
30351e24.e38: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
30361e24.e38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
30371e24.e38: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
30381e24.e38: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxVMM.dll
30391e24.e38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
30401e24.e38: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
30411e24.e38: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
30421e24.e38: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
30431e24.e38: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
30441e24.e38: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll
30451e24.e38: supR3HardenedDllNotificationCallback: load 00007ff92c570000 LB 0x0000c000 C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL [fFlags=0x0]
30461e24.e38: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll
30471e24.e38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff92c570000 'C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL'
30481e24.1c9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
30491e24.1c9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
30501e24.1c9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
30511e24.1c9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
30521e24.1c9c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll) WinVerifyTrust
30531e24.1c9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll
30541e24.1c9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
30551e24.1c9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
30561e24.1c9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
30571e24.1c9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
30581e24.1c9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
30591e24.1c9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
30601e24.1c9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
30611e24.1c9c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll
30621e24.1c9c: supR3HardenedDllNotificationCallback: load 00007ff92be80000 LB 0x0000d000 C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL [fFlags=0x0]
30631e24.1c9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll
30641e24.1c9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff92be80000 'C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL'
30651e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
30661e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
30671e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
30681e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
30691e24.60c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.dll) WinVerifyTrust
30701e24.60c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.dll
30711e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
30721e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
30731e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
30741e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
30751e24.60c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
30761e24.60c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.dll
30771e24.60c: supR3HardenedDllNotificationCallback: load 00007ff933ff0000 LB 0x0000a000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.DLL [fFlags=0x0]
30781e24.60c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.dll
30791e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff933ff0000 'C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.DLL'
30801e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
30811e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
30821e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
30831e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'rpcrt4.dll'.
30841e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #28 'devobj.dll'.
30851e24.60c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll) WinVerifyTrust
30861e24.60c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
30871e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'devobj.dll'...
30881e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'devobj.dll' -> '\Device\HarddiskVolume2\Windows\System32\devobj.dll' [rcNtRedir=0xc0150008]
30891e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
30901e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
30911e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'cfgmgr32.dll'.
30921e24.60c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\devobj.dll) WinVerifyTrust
30931e24.60c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\devobj.dll
30941e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
30951e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
30961e24.60c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
30971e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
30981e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
30991e24.60c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcp_win.dll
31001e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
31011e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
31021e24.60c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll [redoing WinVerifyTrust]
31031e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
31041e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
31051e24.60c: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll'
31061e24.60c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\MMDevApi.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
31071e24.60c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
31081e24.60c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\devobj.dll
31091e24.60c: supR3HardenedDllNotificationCallback: load 00007ff9363f0000 LB 0x0002a000 C:\WINDOWS\System32\DEVOBJ.dll [fFlags=0x0]
31101e24.60c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\devobj.dll
31111e24.60c: supR3HardenedDllNotificationCallback: load 00007ff931410000 LB 0x00072000 C:\WINDOWS\System32\MMDevApi.dll [fFlags=0x0]
31121e24.60c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
31131e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff931410000 'C:\WINDOWS\System32\MMDevApi.dll'
31141e24.60c: \Device\HarddiskVolume2\Windows\System32\dsound.dll: Owner is not trusted installer (01 01 00 00 00 00 00 01 00 00 00 00)
31151e24.60c: \Device\HarddiskVolume2\Windows\System32\dsound.dll: Relaxing the TrustedInstaller requirement for this DLL (it's in system32).
31161e24.60c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000010bc pwszName=\Device\HarddiskVolume2\Windows\System32\dsound.dll
31171e24.60c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000001743050
31181e24.60c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000001743050
31191e24.60c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=8184043CF3F3DF1E3CF96E74DBBF7D0836417373
31201e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
31211e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
31221e24.60c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package~31bf3856ad364e35~amd64~~10.0.18362.476.cat'; file='\Device\HarddiskVolume2\Windows\System32\dsound.dll'
31231e24.60c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
31241e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
31251e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #32 'winmm.dll'.
31261e24.60c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\dsound.dll) WinVerifyTrust
31271e24.60c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\dsound.dll
31281e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
31291e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
31301e24.60c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
31311e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
31321e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
31331e24.60c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
31341e24.60c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dsound.dll
31351e24.60c: supR3HardenedDllNotificationCallback: load 00007ff90c840000 LB 0x00099000 C:\WINDOWS\System32\dsound.dll [fFlags=0x0]
31361e24.60c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dsound.dll
31371e24.60c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dsound.dll
31381e24.60c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
31391e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff90c840000 'C:\WINDOWS\System32\dsound.dll'
31401e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff90c840000 'C:\WINDOWS\System32\dsound.dll'
31411e24.60c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dsound.dll
31421e24.60c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
31431e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff90c840000 'C:\WINDOWS\system32\dsound.dll'
31441e24.60c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
31451e24.60c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\MMDEVAPI.DLL (Input=MMDEVAPI.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
31461e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff931410000 'C:\WINDOWS\System32\MMDEVAPI.DLL'
31471e24.1910: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
31481e24.1910: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
31491e24.1910: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
31501e24.1910: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'rpcrt4.dll'.
31511e24.1910: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'oleaut32.dll'.
31521e24.1910: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #29 'mmdevapi.dll'.
31531e24.1910: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\AudioSes.dll) WinVerifyTrust
31541e24.1910: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\AudioSes.dll
31551e24.1910: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mmdevapi.dll'...
31561e24.1910: supR3HardenedWinVerifyCacheProcessImportTodos: 'mmdevapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\mmdevapi.dll' [rcNtRedir=0xc0150008]
31571e24.1910: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
31581e24.1910: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
31591e24.1910: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
31601e24.1910: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
31611e24.1910: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
31621e24.1910: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
31631e24.1910: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
31641e24.1910: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\AUDIOSES.DLL (Input=AUDIOSES.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
31651e24.1910: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\AudioSes.dll
31661e24.1910: supR3HardenedDllNotificationCallback: load 00007ff921480000 LB 0x0015d000 C:\WINDOWS\System32\AUDIOSES.DLL [fFlags=0x0]
31671e24.1910: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\AudioSes.dll
31681e24.1910: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff921480000 'C:\WINDOWS\System32\AUDIOSES.DLL'
31691e24.1910: \Device\HarddiskVolume2\Windows\System32\ResourcePolicyClient.dll: Owner is not trusted installer (01 01 00 00 00 00 00 01 00 00 00 00)
31701e24.1910: \Device\HarddiskVolume2\Windows\System32\ResourcePolicyClient.dll: Relaxing the TrustedInstaller requirement for this DLL (it's in system32).
31711e24.1910: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
31721e24.1910: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'rpcrt4.dll'.
31731e24.1910: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ResourcePolicyClient.dll)
31741e24.1910: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ResourcePolicyClient.dll
31751e24.1910: supR3HardenedDllNotificationCallback: load 00007ff934c80000 LB 0x00014000 C:\WINDOWS\SYSTEM32\resourcepolicyclient.dll [fFlags=0x0]
31761e24.1910: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ResourcePolicyClient.dll [avoiding WinVerifyTrust]
31771e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
31781e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
31791e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
31801e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
31811e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
31821e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
31831e24.60c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\ResourcePolicyClient.dll'
31841e24.60c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
31851e24.60c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\winmm.dll (Input=winmm.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
31861e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff92b3b0000 'C:\WINDOWS\System32\winmm.dll'
31871e24.60c: \Device\HarddiskVolume2\Windows\System32\wdmaud.drv: Owner is not trusted installer (01 01 00 00 00 00 00 01 00 00 00 00)
31881e24.60c: \Device\HarddiskVolume2\Windows\System32\wdmaud.drv: Relaxing the TrustedInstaller requirement for this DLL (it's in system32).
31891e24.60c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000001140 pwszName=\Device\HarddiskVolume2\Windows\System32\wdmaud.drv
31901e24.60c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000001743050
31911e24.60c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000001743050
31921e24.60c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=38EA8D6D625C6A0A9075DAE17FD33652FF8FC23A
31931e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
31941e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
31951e24.60c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package~31bf3856ad364e35~amd64~~10.0.18362.476.cat'; file='\Device\HarddiskVolume2\Windows\System32\wdmaud.drv'
31961e24.60c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
31971e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
31981e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'mmdevapi.dll'.
31991e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #27 'ksuser.dll'.
32001e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #28 'avrt.dll'.
32011e24.60c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\wdmaud.drv) WinVerifyTrust
32021e24.60c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
32031e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'avrt.dll'...
32041e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'avrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\avrt.dll' [rcNtRedir=0xc0150008]
32051e24.60c: \Device\HarddiskVolume2\Windows\System32\avrt.dll: Owner is not trusted installer (01 01 00 00 00 00 00 01 00 00 00 00)
32061e24.60c: \Device\HarddiskVolume2\Windows\System32\avrt.dll: Relaxing the TrustedInstaller requirement for this DLL (it's in system32).
32071e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
32081e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
32091e24.60c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\avrt.dll) WinVerifyTrust
32101e24.60c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\avrt.dll
32111e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ksuser.dll'...
32121e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ksuser.dll' -> '\Device\HarddiskVolume2\Windows\System32\ksuser.dll' [rcNtRedir=0xc0150008]
32131e24.60c: \Device\HarddiskVolume2\Windows\System32\ksuser.dll: Owner is not trusted installer (01 01 00 00 00 00 00 01 00 00 00 00)
32141e24.60c: \Device\HarddiskVolume2\Windows\System32\ksuser.dll: Relaxing the TrustedInstaller requirement for this DLL (it's in system32).
32151e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
32161e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
32171e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
32181e24.60c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ksuser.dll) WinVerifyTrust
32191e24.60c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ksuser.dll
32201e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mmdevapi.dll'...
32211e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'mmdevapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\mmdevapi.dll' [rcNtRedir=0xc0150008]
32221e24.60c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
32231e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
32241e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
32251e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
32261e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
32271e24.60c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
32281e24.60c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
32291e24.60c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ksuser.dll
32301e24.60c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\avrt.dll
32311e24.60c: supR3HardenedDllNotificationCallback: load 00007ff923650000 LB 0x00009000 C:\WINDOWS\SYSTEM32\ksuser.dll [fFlags=0x0]
32321e24.60c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ksuser.dll
32331e24.60c: supR3HardenedDllNotificationCallback: load 00007ff931990000 LB 0x0000a000 C:\WINDOWS\SYSTEM32\AVRT.dll [fFlags=0x0]
32341e24.60c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\avrt.dll
32351e24.60c: supR3HardenedDllNotificationCallback: load 00007ff91a5e0000 LB 0x00044000 C:\WINDOWS\System32\wdmaud.drv [fFlags=0x0]
32361e24.60c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
32371e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff91a5e0000 'C:\WINDOWS\System32\wdmaud.drv'
32381e24.60c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
32391e24.60c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
32401e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff91a5e0000 'C:\WINDOWS\System32\wdmaud.drv'
32411e24.60c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
32421e24.60c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
32431e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff91a5e0000 'C:\WINDOWS\System32\wdmaud.drv'
32441e24.60c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
32451e24.60c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
32461e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff91a5e0000 'C:\WINDOWS\System32\wdmaud.drv'
32471e24.60c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
32481e24.60c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
32491e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff91a5e0000 'C:\WINDOWS\System32\wdmaud.drv'
32501e24.60c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
32511e24.60c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
32521e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff91a5e0000 'C:\WINDOWS\System32\wdmaud.drv'
32531e24.60c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
32541e24.60c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
32551e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff91a5e0000 'C:\WINDOWS\System32\wdmaud.drv'
32561e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff91a5e0000 'C:\WINDOWS\System32\wdmaud.drv'
32571e24.60c: \Device\HarddiskVolume2\Windows\System32\msacm32.drv: Owner is not trusted installer (01 01 00 00 00 00 00 01 00 00 00 00)
32581e24.60c: \Device\HarddiskVolume2\Windows\System32\msacm32.drv: Relaxing the TrustedInstaller requirement for this DLL (it's in system32).
32591e24.60c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000011b0 pwszName=\Device\HarddiskVolume2\Windows\System32\msacm32.drv
32601e24.60c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000001743050
32611e24.60c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000001743050
32621e24.60c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=763C5E89A8DA653902990733D245B99CC7C40BEA
32631e24.60c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll
32641e24.60c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
32651e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
32661e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
32671e24.60c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package~31bf3856ad364e35~amd64~~10.0.18362.476.cat'; file='\Device\HarddiskVolume2\Windows\System32\msacm32.drv'
32681e24.60c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
32691e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
32701e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'mmdevapi.dll'.
32711e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'msacm32.dll'.
32721e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'winmmbase.dll'.
32731e24.60c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\msacm32.drv) WinVerifyTrust
32741e24.60c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msacm32.drv
32751e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmmbase.dll'...
32761e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmmbase.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmmbase.dll' [rcNtRedir=0xc0150008]
32771e24.60c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmmbase.dll [redoing WinVerifyTrust]
32781e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
32791e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
32801e24.60c: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\winmmbase.dll'
32811e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msacm32.dll'...
32821e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msacm32.dll' -> '\Device\HarddiskVolume2\Windows\System32\msacm32.dll' [rcNtRedir=0xc0150008]
32831e24.60c: \Device\HarddiskVolume2\Windows\System32\msacm32.dll: Owner is not trusted installer (01 01 00 00 00 00 00 01 00 00 00 00)
32841e24.60c: \Device\HarddiskVolume2\Windows\System32\msacm32.dll: Relaxing the TrustedInstaller requirement for this DLL (it's in system32).
32851e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
32861e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
32871e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
32881e24.60c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\msacm32.dll) WinVerifyTrust
32891e24.60c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msacm32.dll
32901e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mmdevapi.dll'...
32911e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'mmdevapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\mmdevapi.dll' [rcNtRedir=0xc0150008]
32921e24.60c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
32931e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
32941e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
32951e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
32961e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
32971e24.60c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
32981e24.60c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
32991e24.60c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.dll
33001e24.60c: supR3HardenedDllNotificationCallback: load 00007ff91a490000 LB 0x0001c000 C:\WINDOWS\SYSTEM32\MSACM32.dll [fFlags=0x0]
33011e24.60c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.dll
33021e24.60c: supR3HardenedDllNotificationCallback: load 00007ff923050000 LB 0x0000d000 C:\WINDOWS\System32\msacm32.drv [fFlags=0x0]
33031e24.60c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
33041e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff923050000 'C:\WINDOWS\System32\msacm32.drv'
33051e24.60c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
33061e24.60c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
33071e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff923050000 'C:\WINDOWS\System32\msacm32.drv'
33081e24.60c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
33091e24.60c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
33101e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff923050000 'C:\WINDOWS\System32\msacm32.drv'
33111e24.60c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
33121e24.60c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
33131e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff923050000 'C:\WINDOWS\System32\msacm32.drv'
33141e24.60c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
33151e24.60c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
33161e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff923050000 'C:\WINDOWS\System32\msacm32.drv'
33171e24.60c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
33181e24.60c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
33191e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff923050000 'C:\WINDOWS\System32\msacm32.drv'
33201e24.60c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
33211e24.60c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
33221e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff923050000 'C:\WINDOWS\System32\msacm32.drv'
33231e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff923050000 'C:\WINDOWS\System32\msacm32.drv'
33241e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff923050000 'C:\WINDOWS\System32\msacm32.drv'
33251e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff923050000 'C:\WINDOWS\System32\msacm32.drv'
33261e24.60c: \Device\HarddiskVolume2\Windows\System32\midimap.dll: Owner is not trusted installer (01 01 00 00 00 00 00 01 00 00 00 00)
33271e24.60c: \Device\HarddiskVolume2\Windows\System32\midimap.dll: Relaxing the TrustedInstaller requirement for this DLL (it's in system32).
33281e24.60c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000001130 pwszName=\Device\HarddiskVolume2\Windows\System32\midimap.dll
33291e24.60c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000001743050
33301e24.60c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000001743050
33311e24.60c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=EB34EC166C3F780657AB67E557E6C2E60C398D10
33321e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
33331e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff936770000 'C:\WINDOWS\System32\crypt32.dll'
33341e24.60c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package~31bf3856ad364e35~amd64~~10.0.18362.476.cat'; file='\Device\HarddiskVolume2\Windows\System32\midimap.dll'
33351e24.60c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
33361e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
33371e24.60c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'winmm.dll'.
33381e24.60c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\midimap.dll) WinVerifyTrust
33391e24.60c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\midimap.dll
33401e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
33411e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
33421e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
33431e24.60c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
33441e24.60c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
33451e24.60c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\midimap.dll
33461e24.60c: supR3HardenedDllNotificationCallback: load 00007ff923000000 LB 0x0000a000 C:\WINDOWS\System32\midimap.dll [fFlags=0x0]
33471e24.60c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\midimap.dll
33481e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff923000000 'C:\WINDOWS\System32\midimap.dll'
33491e24.60c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\midimap.dll
33501e24.60c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
33511e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff923000000 'C:\WINDOWS\System32\midimap.dll'
33521e24.60c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\midimap.dll
33531e24.60c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
33541e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff923000000 'C:\WINDOWS\System32\midimap.dll'
33551e24.60c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\midimap.dll
33561e24.60c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
33571e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff923000000 'C:\WINDOWS\System32\midimap.dll'
33581e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff92b3b0000 'C:\WINDOWS\System32\winmm.dll'
33591e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff92b3b0000 'C:\WINDOWS\System32\winmm.dll'
33601e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff92b3b0000 'C:\WINDOWS\System32\winmm.dll'
33611e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff92b3b0000 'C:\WINDOWS\System32\winmm.dll'
33621e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff92b3b0000 'C:\WINDOWS\System32\winmm.dll'
33631e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff92b3b0000 'C:\WINDOWS\System32\winmm.dll'
33641e24.60c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
33651e24.60c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\winmm.dll (Input=winmm.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
33661e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff92b3b0000 'C:\WINDOWS\System32\winmm.dll'
33671e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff92b3b0000 'C:\WINDOWS\System32\winmm.dll'
33681e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff92b3b0000 'C:\WINDOWS\System32\winmm.dll'
33691e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff92b3b0000 'C:\WINDOWS\System32\winmm.dll'
33701e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff92b3b0000 'C:\WINDOWS\System32\winmm.dll'
33711e24.60c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dsound.dll
33721e24.60c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
33731e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff90c840000 'C:\WINDOWS\system32\dsound.dll'
33741e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff92b3b0000 'C:\WINDOWS\System32\winmm.dll'
33751e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff92b3b0000 'C:\WINDOWS\System32\winmm.dll'
33761e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff92b3b0000 'C:\WINDOWS\System32\winmm.dll'
33771e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff92b3b0000 'C:\WINDOWS\System32\winmm.dll'
33781e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff92b3b0000 'C:\WINDOWS\System32\winmm.dll'
33791e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff92b3b0000 'C:\WINDOWS\System32\winmm.dll'
33801e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff901c60000 'C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL'
33811e24.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9359d0000 'C:\WINDOWS\system32\rsaenh.dll'
33821e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff937c00000 'C:\WINDOWS\system32\shell32.dll'
33831e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff937c00000 'C:\WINDOWS\system32\shell32.dll'
33841e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff937c00000 'C:\WINDOWS\system32\shell32.dll'
33851e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff937c00000 'C:\WINDOWS\system32\shell32.dll'
33861e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff937c00000 'C:\WINDOWS\system32\shell32.dll'
33871e24.48c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff937c00000 'C:\WINDOWS\system32\shell32.dll'
33881e24.1c9c: supR3HardenedDllNotificationCallback: Unload 00007ff92be80000 LB 0x0000d000 C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL [flags=0x0]
33891e24.e38: supR3HardenedDllNotificationCallback: Unload 00007ff92c570000 LB 0x0000c000 C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL [flags=0x0]
33901e24.105c: supR3HardenedDllNotificationCallback: Unload 00007ff91dc30000 LB 0x00014000 C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL [flags=0x0]
33911e24.99c: supR3HardenedDllNotificationCallback: Unload 00007ff92c5a0000 LB 0x0000d000 C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL [flags=0x0]
33921e24.d9c: supR3HardenedDllNotificationCallback: Unload 00007ff930190000 LB 0x0000b000 C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL [flags=0x0]
33931e24.60c: supR3HardenedDllNotificationCallback: Unload 00007ff91dc50000 LB 0x00019000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.DLL [flags=0x0]
33941e24.60c: supR3HardenedDllNotificationCallback: Unload 00007ff9289e0000 LB 0x00018000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.DLL [flags=0x0]
33951e24.60c: supR3HardenedDllNotificationCallback: Unload 00007ff928a00000 LB 0x00018000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.DLL [flags=0x0]
33961e24.60c: supR3HardenedDllNotificationCallback: Unload 00007ff92a040000 LB 0x0001e000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.DLL [flags=0x0]
33971e24.60c: supR3HardenedDllNotificationCallback: Unload 00007ff91a630000 LB 0x00041000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL [flags=0x0]
33981e24.60c: supR3HardenedDllNotificationCallback: Unload 00007ff901280000 LB 0x009da000 C:\Program Files\Oracle\VirtualBox\VBoxDD.DLL [flags=0x0]
33991e24.60c: supR3HardenedDllNotificationCallback: Unload 00007ff911c50000 LB 0x00064000 C:\Program Files\Oracle\VirtualBox\VBoxDDU.dll [flags=0x0]
34001e24.60c: supR3HardenedDllNotificationCallback: Unload 00007ff920a10000 LB 0x0005c000 C:\Program Files\Oracle\VirtualBox\VBoxDD2.dll [flags=0x0]
34011e24.60c: supR3HardenedDllNotificationCallback: Unload 00007ff935b70000 LB 0x0003a000 C:\WINDOWS\SYSTEM32\IPHLPAPI.DLL [flags=0x0]
34021e24.48c: supR3HardenedDllNotificationCallback: Unload 00007ff9319f0000 LB 0x0000e000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMainVM.DLL [flags=0x0]
34031e24.48c: supR3HardenedDllNotificationCallback: Unload 00007ff9310b0000 LB 0x00014000 C:\WINDOWS\system32\wbem\wbemsvc.dll [flags=0x0]
34041e24.48c: supR3HardenedDllNotificationCallback: Unload 00007ff9314d0000 LB 0x0003a000 C:\WINDOWS\system32\dataexchange.dll [flags=0x0]
34051e24.48c: supR3HardenedDllNotificationCallback: Unload 00007ff933270000 LB 0x0025b000 C:\WINDOWS\system32\d3d11.dll [flags=0x0]
34061e24.48c: supR3HardenedDllNotificationCallback: Unload 00007ff9334d0000 LB 0x001db000 C:\WINDOWS\system32\dcomp.dll [flags=0x0]
34071e24.48c: supR3HardenedDllNotificationCallback: Unload 00007ff934a20000 LB 0x0025a000 C:\WINDOWS\system32\twinapi.appcore.dll [flags=0x0]
34081e24.48c: supR3HardenedDllNotificationCallback: Unload 00007ff934e50000 LB 0x00029000 C:\WINDOWS\system32\RMCLIENT.dll [flags=0x0]
34091e24.48c: supR3HardenedDllNotificationCallback: Unload 00007ff92fab0000 LB 0x00101000 C:\WINDOWS\system32\wbem\fastprox.dll [flags=0x0]
34101e24.48c: supR3HardenedDllNotificationCallback: Unload 00007ff90c9b0000 LB 0x000d5000 C:\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll [flags=0x0]
34111e24.48c: supR3HardenedDllNotificationCallback: Unload 00007ff92ffd0000 LB 0x00011000 C:\WINDOWS\system32\wbem\wbemprox.dll [flags=0x0]
34121e24.48c: supR3HardenedDllNotificationCallback: Unload 00007ff92fc60000 LB 0x00084000 C:\WINDOWS\SYSTEM32\wbemcomn.dll [flags=0x0]
34131e24.48c: supR3HardenedDllNotificationCallback: Unload 00007ff9049d0000 LB 0x003a4000 C:\Program Files\Oracle\VirtualBox\VBoxC.dll [flags=0x0]
34141e24.48c: supR3HardenedDllNotificationCallback: Unload 00007ff924820000 LB 0x00081000 C:\Windows\System32\NetSetupShim.dll [flags=0x0]
34151e24.48c: supR3HardenedDllNotificationCallback: Unload 00007ff92d700000 LB 0x00025000 C:\Windows\System32\NetSetupApi.dll [flags=0x0]
34161e24.48c: supR3HardenedDllNotificationCallback: Unload 00007ff9388f0000 LB 0x00470000 C:\WINDOWS\System32\setupapi.dll [flags=0x0]
34171e24.48c: supR3HardenedDllNotificationCallback: Unload 00007ff924800000 LB 0x00013000 C:\Windows\System32\DEVRTL.dll [flags=0x0]
34181e24.48c: Terminating the normal way: rcExit=0
34191c54.1028: supR3HardNtChildWaitFor[2]: Quitting: ExitCode=0x0 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 24147 ms, the end);
34201b98.b54: supR3HardNtChildWaitFor[1]: Quitting: ExitCode=0x0 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 25563 ms, the end);

© 2024 Oracle Support Privacy / Do Not Sell My Info Terms of Use Trademark Policy Automated Access Etiquette