VirtualBox

Ticket #19136: VBoxHardening.2.log

File VBoxHardening.2.log, 181.5 KB (added by Adelio Miranda, 5 years ago)
Line 
118c0.2284: Log file opened: 6.0.14r133895 g_hStartupLog=0000000000000074 g_uNtVerCombined=0xa047bb00
218c0.2284: \SystemRoot\System32\ntdll.dll:
318c0.2284: CreationTime: 2019-10-10T14:11:58.713323600Z
418c0.2284: LastWriteTime: 2019-10-10T14:11:58.802238300Z
518c0.2284: ChangeTime: 2019-11-14T16:05:50.146664100Z
618c0.2284: FileAttributes: 0x20
718c0.2284: Size: 0x1e8528
818c0.2284: NT Headers: 0xd8
918c0.2284: Timestamp: 0x99ca0526
1018c0.2284: Machine: 0x8664 - amd64
1118c0.2284: Timestamp: 0x99ca0526
1218c0.2284: Image Version: 10.0
1318c0.2284: SizeOfImage: 0x1f0000 (2031616)
1418c0.2284: Resource Dir: 0x17f000 LB 0x6f310
1518c0.2284: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
1618c0.2284: [Raw version resource data: 0x17f0f0 LB 0x380, codepage 0x0 (reserved 0x0)]
1718c0.2284: ProductName: Microsoft® Windows® Operating System
1818c0.2284: ProductVersion: 10.0.18362.418
1918c0.2284: FileVersion: 10.0.18362.418 (WinBuild.160101.0800)
2018c0.2284: FileDescription: NT Layer DLL
2118c0.2284: \SystemRoot\System32\kernel32.dll:
2218c0.2284: CreationTime: 2019-09-13T19:37:38.549674400Z
2318c0.2284: LastWriteTime: 2019-09-13T19:37:38.586602800Z
2418c0.2284: ChangeTime: 2019-11-14T16:05:49.709071400Z
2518c0.2284: FileAttributes: 0x20
2618c0.2284: Size: 0xb0570
2718c0.2284: NT Headers: 0xe8
2818c0.2284: Timestamp: 0xd0cecc10
2918c0.2284: Machine: 0x8664 - amd64
3018c0.2284: Timestamp: 0xd0cecc10
3118c0.2284: Image Version: 10.0
3218c0.2284: SizeOfImage: 0xb2000 (729088)
3318c0.2284: Resource Dir: 0xb0000 LB 0x520
3418c0.2284: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
3518c0.2284: [Raw version resource data: 0xb00b0 LB 0x3a4, codepage 0x0 (reserved 0x0)]
3618c0.2284: ProductName: Microsoft® Windows® Operating System
3718c0.2284: ProductVersion: 10.0.18362.329
3818c0.2284: FileVersion: 10.0.18362.329 (WinBuild.160101.0800)
3918c0.2284: FileDescription: Windows NT BASE API Client DLL
4018c0.2284: \SystemRoot\System32\KernelBase.dll:
4118c0.2284: CreationTime: 2019-11-14T16:03:37.286662400Z
4218c0.2284: LastWriteTime: 2019-11-14T16:03:37.415540100Z
4318c0.2284: ChangeTime: 2019-11-14T19:08:57.586841900Z
4418c0.2284: FileAttributes: 0x20
4518c0.2284: Size: 0x2a2908
4618c0.2284: NT Headers: 0xf0
4718c0.2284: Timestamp: 0x83c3d83a
4818c0.2284: Machine: 0x8664 - amd64
4918c0.2284: Timestamp: 0x83c3d83a
5018c0.2284: Image Version: 10.0
5118c0.2284: SizeOfImage: 0x2a3000 (2764800)
5218c0.2284: Resource Dir: 0x27d000 LB 0x548
5318c0.2284: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
5418c0.2284: [Raw version resource data: 0x27d0b0 LB 0x3bc, codepage 0x0 (reserved 0x0)]
5518c0.2284: ProductName: Microsoft® Windows® Operating System
5618c0.2284: ProductVersion: 10.0.18362.476
5718c0.2284: FileVersion: 10.0.18362.476 (WinBuild.160101.0800)
5818c0.2284: FileDescription: Windows NT BASE API Client DLL
5918c0.2284: \SystemRoot\System32\apisetschema.dll:
6018c0.2284: CreationTime: 2019-03-19T04:43:54.837151500Z
6118c0.2284: LastWriteTime: 2019-03-19T04:43:54.837151500Z
6218c0.2284: ChangeTime: 2019-11-14T16:05:49.339411400Z
6318c0.2284: FileAttributes: 0x20
6418c0.2284: Size: 0x1d028
6518c0.2284: NT Headers: 0xc8
6618c0.2284: Timestamp: 0xd6ced080
6718c0.2284: Machine: 0x8664 - amd64
6818c0.2284: Timestamp: 0xd6ced080
6918c0.2284: Image Version: 10.0
7018c0.2284: SizeOfImage: 0x1e000 (122880)
7118c0.2284: Resource Dir: 0x1d000 LB 0x408
7218c0.2284: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
7318c0.2284: [Raw version resource data: 0x1d060 LB 0x3a8, codepage 0x0 (reserved 0x0)]
7418c0.2284: ProductName: Microsoft® Windows® Operating System
7518c0.2284: ProductVersion: 10.0.18362.1
7618c0.2284: FileVersion: 10.0.18362.1 (WinBuild.160101.0800)
7718c0.2284: FileDescription: ApiSet Schema DLL
7818c0.2284: Found driver klkbdflt (0x40)
7918c0.2284: Found driver klmouflt (0x40)
8018c0.2284: Found driver KLIM6 (0x40)
8118c0.2284: Found driver kneps (0x40)
8218c0.2284: Found driver klflt (0x40)
8318c0.2284: supR3HardenedWinFindAdversaries: 0x40
8418c0.2284: \SystemRoot\System32\drivers\klflt.sys:
8518c0.2284: CreationTime: 2018-11-20T09:50:50.978328500Z
8618c0.2284: LastWriteTime: 2019-08-07T13:01:58.292832100Z
8718c0.2284: ChangeTime: 2019-09-02T18:03:17.094878400Z
8818c0.2284: FileAttributes: 0x20
8918c0.2284: Size: 0x39c80
9018c0.2284: NT Headers: 0xf8
9118c0.2284: Timestamp: 0x5d0ce55e
9218c0.2284: Machine: 0x8664 - amd64
9318c0.2284: Timestamp: 0x5d0ce55e
9418c0.2284: Image Version: 6.2
9518c0.2284: SizeOfImage: 0x47000 (290816)
9618c0.2284: Resource Dir: 0x44000 LB 0x420
9718c0.2284: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
9818c0.2284: [Raw version resource data: 0x44060 LB 0x3c0, codepage 0x0 (reserved 0x0)]
9918c0.2284: ProductName: System Interceptors PDK
10018c0.2284: ProductVersion: 15.1.244.0
10118c0.2284: FileVersion: 15.1.244.0
10218c0.2284: FileDescription: Filter Core [fre_win8_x64]
10318c0.2284: \SystemRoot\System32\drivers\klif.sys:
10418c0.2284: CreationTime: 2018-11-20T09:50:50.982331000Z
10518c0.2284: LastWriteTime: 2019-08-07T13:01:58.766393500Z
10618c0.2284: ChangeTime: 2019-09-02T18:03:17.094878400Z
10718c0.2284: FileAttributes: 0x20
10818c0.2284: Size: 0x11d280
10918c0.2284: NT Headers: 0x108
11018c0.2284: Timestamp: 0x5d0ce567
11118c0.2284: Machine: 0x8664 - amd64
11218c0.2284: Timestamp: 0x5d0ce567
11318c0.2284: Image Version: 6.2
11418c0.2284: SizeOfImage: 0x121000 (1183744)
11518c0.2284: Resource Dir: 0x118000 LB 0x29a0
11618c0.2284: [Version info resource found at 0x150! (ID/Name: 0x1; SubID/SubName: 0x409)]
11718c0.2284: [Raw version resource data: 0x118618 LB 0x3d8, codepage 0x0 (reserved 0x0)]
11818c0.2284: ProductName: System Interceptors PDK
11918c0.2284: ProductVersion: 15.1.244.0
12018c0.2284: FileVersion: 15.1.244.0
12118c0.2284: FileDescription: Core System Interceptors [fre_win8_x64]
12218c0.2284: \SystemRoot\System32\drivers\klim6.sys:
12318c0.2284: CreationTime: 2018-02-12T03:17:16.000000000Z
12418c0.2284: LastWriteTime: 2019-04-15T10:39:11.262715200Z
12518c0.2284: ChangeTime: 2019-10-30T20:14:04.378005300Z
12618c0.2284: FileAttributes: 0x20
12718c0.2284: Size: 0xe550
12818c0.2284: NT Headers: 0xf0
12918c0.2284: Timestamp: 0x5c543766
13018c0.2284: Machine: 0x8664 - amd64
13118c0.2284: Timestamp: 0x5c543766
13218c0.2284: Image Version: 6.2
13318c0.2284: SizeOfImage: 0xb000 (45056)
13418c0.2284: Resource Dir: 0x9000 LB 0x438
13518c0.2284: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
13618c0.2284: [Raw version resource data: 0x9060 LB 0x3d4, codepage 0x0 (reserved 0x0)]
13718c0.2284: ProductName: System Interceptors PDK
13818c0.2284: ProductVersion: 15.1.203.0
13918c0.2284: FileVersion: 15.1.203.0
14018c0.2284: FileDescription: Packet Network Filter [fre_win8_x64]
14118c0.2284: \SystemRoot\System32\drivers\klkbdflt.sys:
14218c0.2284: CreationTime: 2018-11-20T09:50:50.988333100Z
14318c0.2284: LastWriteTime: 2019-04-15T10:40:00.034381700Z
14418c0.2284: ChangeTime: 2019-09-02T18:03:17.094878400Z
14518c0.2284: FileAttributes: 0x20
14618c0.2284: Size: 0xec78
14718c0.2284: NT Headers: 0xe8
14818c0.2284: Timestamp: 0x5c516e05
14918c0.2284: Machine: 0x8664 - amd64
15018c0.2284: Timestamp: 0x5c516e05
15118c0.2284: Image Version: 6.2
15218c0.2284: SizeOfImage: 0xd000 (53248)
15318c0.2284: Resource Dir: 0xb000 LB 0x440
15418c0.2284: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
15518c0.2284: [Raw version resource data: 0xb060 LB 0x3dc, codepage 0x0 (reserved 0x0)]
15618c0.2284: ProductName: System Interceptors PDK
15718c0.2284: ProductVersion: 15.1.204.0
15818c0.2284: FileVersion: 15.1.204.0
15918c0.2284: FileDescription: Keyboard Device Filter [fre_win8_x64]
16018c0.2284: \SystemRoot\System32\drivers\klmouflt.sys:
16118c0.2284: CreationTime: 2018-11-20T09:50:50.991334300Z
16218c0.2284: LastWriteTime: 2019-04-15T10:40:00.105316500Z
16318c0.2284: ChangeTime: 2019-09-02T18:03:17.094878400Z
16418c0.2284: FileAttributes: 0x20
16518c0.2284: Size: 0xed70
16618c0.2284: NT Headers: 0xd8
16718c0.2284: Timestamp: 0x5c4c6ef9
16818c0.2284: Machine: 0x8664 - amd64
16918c0.2284: Timestamp: 0x5c4c6ef9
17018c0.2284: Image Version: 6.2
17118c0.2284: SizeOfImage: 0xf000 (61440)
17218c0.2284: Resource Dir: 0xd000 LB 0x438
17318c0.2284: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
17418c0.2284: [Raw version resource data: 0xd060 LB 0x3d8, codepage 0x0 (reserved 0x0)]
17518c0.2284: ProductName: System Interceptors PDK
17618c0.2284: ProductVersion: 15.1.202.0
17718c0.2284: FileVersion: 15.1.202.0
17818c0.2284: FileDescription: Mouse Device Filter [fre_win8_x64]
17918c0.2284: \SystemRoot\System32\drivers\kneps.sys:
18018c0.2284: CreationTime: 2018-11-20T09:50:51.023345600Z
18118c0.2284: LastWriteTime: 2019-04-15T10:40:00.763705300Z
18218c0.2284: ChangeTime: 2019-09-02T18:03:17.110503200Z
18318c0.2284: FileAttributes: 0x20
18418c0.2284: Size: 0x35480
18518c0.2284: NT Headers: 0xf8
18618c0.2284: Timestamp: 0x5c7e4b42
18718c0.2284: Machine: 0x8664 - amd64
18818c0.2284: Timestamp: 0x5c7e4b42
18918c0.2284: Image Version: 6.2
19018c0.2284: SizeOfImage: 0x33000 (208896)
19118c0.2284: Resource Dir: 0x30000 LB 0x430
19218c0.2284: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
19318c0.2284: [Raw version resource data: 0x30060 LB 0x3cc, codepage 0x0 (reserved 0x0)]
19418c0.2284: ProductName: System Interceptors PDK
19518c0.2284: ProductVersion: 15.1.215.0
19618c0.2284: FileVersion: 15.1.215.0
19718c0.2284: FileDescription: Network Processor [fre_win8_x64]
19818c0.2284: \SystemRoot\System32\klfphc.dll:
19918c0.2284: CreationTime: 2018-11-20T09:50:00.439136800Z
20018c0.2284: LastWriteTime: 2013-05-06T07:13:26.000000000Z
20118c0.2284: ChangeTime: 2019-09-02T18:03:16.860513700Z
20218c0.2284: FileAttributes: 0x2020
20318c0.2284: Size: 0x1ae60
20418c0.2284: NT Headers: 0xe8
20518c0.2284: Timestamp: 0x51873bf2
20618c0.2284: Machine: 0x8664 - amd64
20718c0.2284: Timestamp: 0x51873bf2
20818c0.2284: Image Version: 0.0
20918c0.2284: SizeOfImage: 0x1d000 (118784)
21018c0.2284: Resource Dir: 0x18000 LB 0x3c80
21118c0.2284: [Version info resource found at 0x188! (ID/Name: 0x1; SubID/SubName: 0x409)]
21218c0.2284: [Raw version resource data: 0x1b800 LB 0x324, codepage 0x4e4 (reserved 0x0)]
21318c0.2284: ProductName: Kaspersky™ Anti-Virus ®
21418c0.2284: ProductVersion: 1.0.0.12
21518c0.2284: FileVersion: 1.0.0.12
21618c0.2284: FileDescription: Filtering Platform Helper Class
21718c0.2284: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
21818c0.2284: Calling main()
21918c0.2284: SUPR3HardenedMain: pszProgName=VirtualBoxVM fFlags=0x2
22018c0.2284: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
22118c0.2284: SUPR3HardenedMain: Respawn #1
22218c0.2284: System32: \Device\HarddiskVolume2\Windows\System32
22318c0.2284: WinSxS: \Device\HarddiskVolume2\Windows\WinSxS
22418c0.2284: KnownDllPath: C:\WINDOWS\System32
22518c0.2284: supR3HardenedWinInit: Performing a limited self purification...
22618c0.2284: supHardNtVpScanVirtualMemory: enmKind=SELF_PURIFICATION
22718c0.2284: *0000000000000000-0000000000d2ffff 0x0001/0x0000 0x0000000
22818c0.2284: *0000000000d30000-0000000000d3ffff 0x0004/0x0004 0x0040000
22918c0.2284: 0000000000d40000-0000000000d4ffff 0x0001/0x0000 0x0000000
23018c0.2284: *0000000000d50000-0000000000d6afff 0x0002/0x0002 0x0040000
23118c0.2284: 0000000000d6b000-0000000000d6ffff 0x0001/0x0000 0x0000000
23218c0.2284: *0000000000d70000-0000000000d73fff 0x0002/0x0002 0x0040000
23318c0.2284: 0000000000d74000-0000000000d7ffff 0x0001/0x0000 0x0000000
23418c0.2284: *0000000000d80000-0000000000d81fff 0x0004/0x0004 0x0020000
23518c0.2284: 0000000000d82000-0000000000d8ffff 0x0001/0x0000 0x0000000
23618c0.2284: *0000000000d90000-0000000000d91fff 0x0004/0x0004 0x0020000
23718c0.2284: 0000000000d92000-0000000000da9fff 0x0000/0x0004 0x0020000
23818c0.2284: 0000000000daa000-0000000000dfffff 0x0001/0x0000 0x0000000
23918c0.2284: *0000000000e00000-0000000000f32fff 0x0000/0x0004 0x0020000
24018c0.2284: 0000000000f33000-0000000000f35fff 0x0004/0x0004 0x0020000
24118c0.2284: 0000000000f36000-0000000000ffffff 0x0000/0x0004 0x0020000
24218c0.2284: *0000000001000000-00000000010b0fff 0x0000/0x0004 0x0020000
24318c0.2284: 00000000010b1000-00000000010b3fff 0x0104/0x0004 0x0020000
24418c0.2284: 00000000010b4000-00000000010fffff 0x0004/0x0004 0x0020000
24518c0.2284: *0000000001100000-00000000011c6fff 0x0002/0x0002 0x0040000
24618c0.2284: 00000000011c7000-000000000122ffff 0x0001/0x0000 0x0000000
24718c0.2284: *0000000001230000-0000000001235fff 0x0004/0x0004 0x0020000
24818c0.2284: 0000000001236000-000000000132ffff 0x0000/0x0004 0x0020000
24918c0.2284: *0000000001330000-000000000134cfff 0x0004/0x0004 0x0020000
25018c0.2284: 000000000134d000-000000000142ffff 0x0000/0x0004 0x0020000
25118c0.2284: 0000000001430000-00000000014dffff 0x0001/0x0000 0x0000000
25218c0.2284: *00000000014e0000-00000000014eefff 0x0004/0x0004 0x0020000
25318c0.2284: 00000000014ef000-00000000014effff 0x0000/0x0004 0x0020000
25418c0.2284: *00000000014f0000-00000000014f2fff 0x0000/0x0004 0x0020000
25518c0.2284: 00000000014f3000-00000000016e3fff 0x0004/0x0004 0x0020000
25618c0.2284: 00000000016e4000-00000000016e4fff 0x0000/0x0004 0x0020000
25718c0.2284: 00000000016e5000-000000007ffdffff 0x0001/0x0000 0x0000000
25818c0.2284: *000000007ffe0000-000000007ffe0fff 0x0002/0x0002 0x0020000
25918c0.2284: 000000007ffe1000-000000007ffedfff 0x0001/0x0000 0x0000000
26018c0.2284: *000000007ffee000-000000007ffeefff 0x0002/0x0002 0x0020000
26118c0.2284: 000000007ffef000-00007ff4c6ecffff 0x0001/0x0000 0x0000000
26218c0.2284: *00007ff4c6ed0000-00007ff4c6ed4fff 0x0002/0x0002 0x0040000
26318c0.2284: 00007ff4c6ed5000-00007ff4c6fcffff 0x0000/0x0002 0x0040000
26418c0.2284: *00007ff4c6fd0000-00007ff5c6feffff 0x0000/0x0004 0x0020000
26518c0.2284: *00007ff5c6ff0000-00007ff5c8feffff 0x0000/0x0004 0x0020000
26618c0.2284: 00007ff5c8ff0000-00007ff5c8ff0fff 0x0004/0x0004 0x0020000
26718c0.2284: 00007ff5c8ff1000-00007ff5c8ffffff 0x0001/0x0000 0x0000000
26818c0.2284: *00007ff5c9000000-00007ff5c9000fff 0x0002/0x0002 0x0040000
26918c0.2284: 00007ff5c9001000-00007ff5c900ffff 0x0001/0x0000 0x0000000
27018c0.2284: *00007ff5c9010000-00007ff5c9032fff 0x0002/0x0002 0x0040000
27118c0.2284: 00007ff5c9033000-00007ff6e359ffff 0x0001/0x0000 0x0000000
27218c0.2284: *00007ff6e35a0000-00007ff6e35a0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
27318c0.2284: 00007ff6e35a1000-00007ff6e3615fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
27418c0.2284: 00007ff6e3616000-00007ff6e3616fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
27518c0.2284: 00007ff6e3617000-00007ff6e365efff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
27618c0.2284: 00007ff6e365f000-00007ff6e3661fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
27718c0.2284: 00007ff6e3662000-00007ff6e3664fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
27818c0.2284: 00007ff6e3665000-00007ff6e3667fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
27918c0.2284: 00007ff6e3668000-00007ff6e3668fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
28018c0.2284: 00007ff6e3669000-00007ff6e366afff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
28118c0.2284: 00007ff6e366b000-00007ff6e366bfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
28218c0.2284: 00007ff6e366c000-00007ff6e36b4fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
28318c0.2284: 00007ff6e36b5000-00007ffedaeaffff 0x0001/0x0000 0x0000000
28418c0.2284: *00007ffedaeb0000-00007ffedaeb0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\KernelBase.dll
28518c0.2284: 00007ffedaeb1000-00007ffedafb5fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\KernelBase.dll
28618c0.2284: 00007ffedafb6000-00007ffedb117fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\KernelBase.dll
28718c0.2284: 00007ffedb118000-00007ffedb11bfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\KernelBase.dll
28818c0.2284: 00007ffedb11c000-00007ffedb11cfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\KernelBase.dll
28918c0.2284: 00007ffedb11d000-00007ffedb152fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\KernelBase.dll
29018c0.2284: 00007ffedb153000-00007ffedbd2ffff 0x0001/0x0000 0x0000000
29118c0.2284: *00007ffedbd30000-00007ffedbd30fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\kernel32.dll
29218c0.2284: 00007ffedbd31000-00007ffedbda5fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\kernel32.dll
29318c0.2284: 00007ffedbda6000-00007ffedbdd7fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\kernel32.dll
29418c0.2284: 00007ffedbdd8000-00007ffedbdd8fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\kernel32.dll
29518c0.2284: 00007ffedbdd9000-00007ffedbdd9fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\kernel32.dll
29618c0.2284: 00007ffedbdda000-00007ffedbde1fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\kernel32.dll
29718c0.2284: 00007ffedbde2000-00007ffedd9dffff 0x0001/0x0000 0x0000000
29818c0.2284: *00007ffedd9e0000-00007ffedd9e0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
29918c0.2284: 00007ffedd9e1000-00007ffeddaf7fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
30018c0.2284: 00007ffeddaf8000-00007ffeddb3efff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
30118c0.2284: 00007ffeddb3f000-00007ffeddb3ffff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
30218c0.2284: 00007ffeddb40000-00007ffeddb41fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
30318c0.2284: 00007ffeddb42000-00007ffeddb4afff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
30418c0.2284: 00007ffeddb4b000-00007ffeddbcffff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
30518c0.2284: 00007ffeddbd0000-00007ffffffeffff 0x0001/0x0000 0x0000000
30618c0.2284: kernel32.dll: timestamp 0xd0cecc10 (rc=VINF_SUCCESS)
30718c0.2284: kernelbase.dll: timestamp 0x83c3d83a (rc=VINF_SUCCESS)
30818c0.2284: VirtualBoxVM.exe: timestamp 0x5d9f7c37 (rc=VINF_SUCCESS)
30918c0.2284: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
31018c0.2284: '\Device\HarddiskVolume2\Windows\System32\ntdll.dll' has no imports
31118c0.2284: supR3HardenedWinInit: SUPHARDNTVPKIND_SELF_PURIFICATION_LIMITED -> VINF_SUCCESS, cFixes=0
31218c0.2284: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
31318c0.2284: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe)
31418c0.2284: supR3HardNtEnableThreadCreationEx:
31518c0.2284: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffedda517f0 pvNtTerminateThread=00007ffedda7cb10
31618c0.2284: supR3HardenedWinDoReSpawn(1): New child 15e8.2fc8 [kernel32].
31718c0.2284: supR3HardNtChildGatherData: PebBaseAddress=0000000000abd000 cbPeb=0x388
31818c0.2284: supR3HardNtPuChFindNtdll: uNtDllParentAddr=00007ffedd9e0000 uNtDllChildAddr=00007ffedd9e0000
31918c0.2284: supR3HardenedWinSetupChildInit: uLdrInitThunk=00007ffedda517f0
32018c0.2284: supR3HardenedWinSetupChildInit: Start child.
32118c0.2284: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 1 ms.
32218c0.2284: supR3HardNtChildPurify: Startup delay kludge #1/0: 515 ms, 55 sleeps
32318c0.2284: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
32418c0.2284: *0000000000000000-000000000082ffff 0x0001/0x0000 0x0000000
32518c0.2284: *0000000000830000-000000000084ffff 0x0004/0x0004 0x0020000
32618c0.2284: *0000000000850000-000000000086afff 0x0002/0x0002 0x0040000
32718c0.2284: 000000000086b000-000000000086ffff 0x0001/0x0000 0x0000000
32818c0.2284: *0000000000870000-000000000096afff 0x0000/0x0004 0x0020000
32918c0.2284: 000000000096b000-000000000096dfff 0x0104/0x0004 0x0020000
33018c0.2284: 000000000096e000-000000000096ffff 0x0004/0x0004 0x0020000
33118c0.2284: *0000000000970000-0000000000973fff 0x0002/0x0002 0x0040000
33218c0.2284: 0000000000974000-000000000097ffff 0x0001/0x0000 0x0000000
33318c0.2284: *0000000000980000-0000000000981fff 0x0004/0x0004 0x0020000
33418c0.2284: 0000000000982000-00000000009fffff 0x0001/0x0000 0x0000000
33518c0.2284: *0000000000a00000-0000000000abcfff 0x0000/0x0004 0x0020000
33618c0.2284: 0000000000abd000-0000000000abffff 0x0004/0x0004 0x0020000
33718c0.2284: 0000000000ac0000-0000000000bfffff 0x0000/0x0004 0x0020000
33818c0.2284: 0000000000c00000-000000007ffdffff 0x0001/0x0000 0x0000000
33918c0.2284: *000000007ffe0000-000000007ffe0fff 0x0002/0x0002 0x0020000
34018c0.2284: 000000007ffe1000-000000007ffedfff 0x0001/0x0000 0x0000000
34118c0.2284: *000000007ffee000-000000007ffeefff 0x0002/0x0002 0x0020000
34218c0.2284: 000000007ffef000-00007ff55582ffff 0x0001/0x0000 0x0000000
34318c0.2284: *00007ff555830000-00007ff555830fff 0x0002/0x0002 0x0040000
34418c0.2284: 00007ff555831000-00007ff55583ffff 0x0001/0x0000 0x0000000
34518c0.2284: *00007ff555840000-00007ff555862fff 0x0002/0x0002 0x0040000
34618c0.2284: 00007ff555863000-00007ff6e359ffff 0x0001/0x0000 0x0000000
34718c0.2284: *00007ff6e35a0000-00007ff6e35a0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
34818c0.2284: 00007ff6e35a1000-00007ff6e3615fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
34918c0.2284: 00007ff6e3616000-00007ff6e3616fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
35018c0.2284: 00007ff6e3617000-00007ff6e365efff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
35118c0.2284: 00007ff6e365f000-00007ff6e365ffff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
35218c0.2284: 00007ff6e3660000-00007ff6e3660fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
35318c0.2284: 00007ff6e3661000-00007ff6e3665fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
35418c0.2284: 00007ff6e3666000-00007ff6e3666fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
35518c0.2284: 00007ff6e3667000-00007ff6e3667fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
35618c0.2284: 00007ff6e3668000-00007ff6e366bfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
35718c0.2284: 00007ff6e366c000-00007ff6e36b4fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
35818c0.2284: 00007ff6e36b5000-00007ffedd9dffff 0x0001/0x0000 0x0000000
35918c0.2284: *00007ffedd9e0000-00007ffedd9e0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
36018c0.2284: 00007ffedd9e1000-00007ffeddaf7fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
36118c0.2284: 00007ffeddaf8000-00007ffeddb3efff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
36218c0.2284: 00007ffeddb3f000-00007ffeddb4afff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
36318c0.2284: 00007ffeddb4b000-00007ffeddb59fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
36418c0.2284: 00007ffeddb5a000-00007ffeddb5afff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
36518c0.2284: 00007ffeddb5b000-00007ffeddb5dfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
36618c0.2284: 00007ffeddb5e000-00007ffeddbcffff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
36718c0.2284: 00007ffeddbd0000-00007ffffffeffff 0x0001/0x0000 0x0000000
36818c0.2284: supR3HardNtChildPurify: Done after 522 ms and 0 fixes (loop #0).
36915e8.2fc8: Log file opened: 6.0.14r133895 g_hStartupLog=0000000000000004 g_uNtVerCombined=0xa047bb00
37015e8.2fc8: supR3HardenedVmProcessInit: uNtDllAddr=00007ffedd9e0000 g_uNtVerCombined=0xa047bb00
37115e8.2fc8: ntdll.dll: timestamp 0x99ca0526 (rc=VINF_SUCCESS)
37215e8.2fc8: New simple heap: #1 0000000000d00000 LB 0x400000 (for 2031616 allocation)
37318c0.2284: supR3HardNtEnableThreadCreationEx:
37415e8.2fc8: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
37515e8.2fc8: System32: \Device\HarddiskVolume2\Windows\System32
37615e8.2fc8: WinSxS: \Device\HarddiskVolume2\Windows\WinSxS
37715e8.2fc8: KnownDllPath: C:\WINDOWS\System32
37815e8.2fc8: supR3HardenedVmProcessInit: Opening vboxdrv stub...
37915e8.2fc8: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
38015e8.2fc8: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
38115e8.2fc8: Registered Dll notification callback with NTDLL.
38215e8.2fc8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\kernel32.dll)
38315e8.2fc8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\kernel32.dll
38415e8.2fc8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\KERNEL32.DLL (Input=KERNEL32.DLL, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000004001:<flags> [calling]
38515e8.2fc8: supR3HardenedDllNotificationCallback: load 00007ffedaeb0000 LB 0x002a3000 C:\WINDOWS\System32\KERNELBASE.dll [fFlags=0x0]
38615e8.2fc8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\KernelBase.dll)
38715e8.2fc8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\KernelBase.dll
38815e8.2fc8: supR3HardenedDllNotificationCallback: load 00007ffedbd30000 LB 0x000b2000 C:\WINDOWS\System32\KERNEL32.DLL [fFlags=0x0]
38915e8.2fc8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
39015e8.2fc8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffedbd30000 'C:\WINDOWS\System32\KERNEL32.DLL'
39115e8.2fc8: supR3HardenedDllNotificationCallback: load 00007ff6e35a0000 LB 0x00115000 C:\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe [fFlags=0x0]
39215e8.2fc8: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
39315e8.2fc8: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe)
39415e8.2fc8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
39515e8.2fc8: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffedda517f0 pvNtTerminateThread=00007ffedda7cb10
39618c0.2284: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 218 ms.
39715e8.2fc8: \SystemRoot\System32\ntdll.dll:
39815e8.2fc8: CreationTime: 2019-10-10T14:11:58.713323600Z
39915e8.2fc8: LastWriteTime: 2019-10-10T14:11:58.802238300Z
40015e8.2fc8: ChangeTime: 2019-11-14T16:05:50.146664100Z
40115e8.2fc8: FileAttributes: 0x20
40215e8.2fc8: Size: 0x1e8528
40315e8.2fc8: NT Headers: 0xd8
40415e8.2fc8: Timestamp: 0x99ca0526
40515e8.2fc8: Machine: 0x8664 - amd64
40615e8.2fc8: Timestamp: 0x99ca0526
40715e8.2fc8: Image Version: 10.0
40815e8.2fc8: SizeOfImage: 0x1f0000 (2031616)
40915e8.2fc8: Resource Dir: 0x17f000 LB 0x6f310
41015e8.2fc8: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
41115e8.2fc8: [Raw version resource data: 0x17f0f0 LB 0x380, codepage 0x0 (reserved 0x0)]
41215e8.2fc8: ProductName: Microsoft® Windows® Operating System
41315e8.2fc8: ProductVersion: 10.0.18362.418
41415e8.2fc8: FileVersion: 10.0.18362.418 (WinBuild.160101.0800)
41515e8.2fc8: FileDescription: NT Layer DLL
41615e8.2fc8: \SystemRoot\System32\kernel32.dll:
41715e8.2fc8: CreationTime: 2019-09-13T19:37:38.549674400Z
41815e8.2fc8: LastWriteTime: 2019-09-13T19:37:38.586602800Z
41915e8.2fc8: ChangeTime: 2019-11-14T16:05:49.709071400Z
42015e8.2fc8: FileAttributes: 0x20
42115e8.2fc8: Size: 0xb0570
42215e8.2fc8: NT Headers: 0xe8
42315e8.2fc8: Timestamp: 0xd0cecc10
42415e8.2fc8: Machine: 0x8664 - amd64
42515e8.2fc8: Timestamp: 0xd0cecc10
42615e8.2fc8: Image Version: 10.0
42715e8.2fc8: SizeOfImage: 0xb2000 (729088)
42815e8.2fc8: Resource Dir: 0xb0000 LB 0x520
42915e8.2fc8: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
43015e8.2fc8: [Raw version resource data: 0xb00b0 LB 0x3a4, codepage 0x0 (reserved 0x0)]
43115e8.2fc8: ProductName: Microsoft® Windows® Operating System
43215e8.2fc8: ProductVersion: 10.0.18362.329
43315e8.2fc8: FileVersion: 10.0.18362.329 (WinBuild.160101.0800)
43415e8.2fc8: FileDescription: Windows NT BASE API Client DLL
43515e8.2fc8: \SystemRoot\System32\KernelBase.dll:
43615e8.2fc8: CreationTime: 2019-11-14T16:03:37.286662400Z
43715e8.2fc8: LastWriteTime: 2019-11-14T16:03:37.415540100Z
43815e8.2fc8: ChangeTime: 2019-11-14T19:08:57.586841900Z
43915e8.2fc8: FileAttributes: 0x20
44015e8.2fc8: Size: 0x2a2908
44115e8.2fc8: NT Headers: 0xf0
44215e8.2fc8: Timestamp: 0x83c3d83a
44315e8.2fc8: Machine: 0x8664 - amd64
44415e8.2fc8: Timestamp: 0x83c3d83a
44515e8.2fc8: Image Version: 10.0
44615e8.2fc8: SizeOfImage: 0x2a3000 (2764800)
44715e8.2fc8: Resource Dir: 0x27d000 LB 0x548
44815e8.2fc8: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
44915e8.2fc8: [Raw version resource data: 0x27d0b0 LB 0x3bc, codepage 0x0 (reserved 0x0)]
45015e8.2fc8: ProductName: Microsoft® Windows® Operating System
45115e8.2fc8: ProductVersion: 10.0.18362.476
45215e8.2fc8: FileVersion: 10.0.18362.476 (WinBuild.160101.0800)
45315e8.2fc8: FileDescription: Windows NT BASE API Client DLL
45415e8.2fc8: \SystemRoot\System32\apisetschema.dll:
45515e8.2fc8: CreationTime: 2019-03-19T04:43:54.837151500Z
45615e8.2fc8: LastWriteTime: 2019-03-19T04:43:54.837151500Z
45715e8.2fc8: ChangeTime: 2019-11-14T16:05:49.339411400Z
45815e8.2fc8: FileAttributes: 0x20
45915e8.2fc8: Size: 0x1d028
46015e8.2fc8: NT Headers: 0xc8
46115e8.2fc8: Timestamp: 0xd6ced080
46215e8.2fc8: Machine: 0x8664 - amd64
46315e8.2fc8: Timestamp: 0xd6ced080
46415e8.2fc8: Image Version: 10.0
46515e8.2fc8: SizeOfImage: 0x1e000 (122880)
46615e8.2fc8: Resource Dir: 0x1d000 LB 0x408
46715e8.2fc8: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
46815e8.2fc8: [Raw version resource data: 0x1d060 LB 0x3a8, codepage 0x0 (reserved 0x0)]
46915e8.2fc8: ProductName: Microsoft® Windows® Operating System
47015e8.2fc8: ProductVersion: 10.0.18362.1
47115e8.2fc8: FileVersion: 10.0.18362.1 (WinBuild.160101.0800)
47215e8.2fc8: FileDescription: ApiSet Schema DLL
47315e8.2fc8: Found driver klkbdflt (0x40)
47415e8.2fc8: Found driver klmouflt (0x40)
47515e8.2fc8: Found driver KLIM6 (0x40)
47615e8.2fc8: Found driver kneps (0x40)
47715e8.2fc8: Found driver klflt (0x40)
47815e8.2fc8: supR3HardenedWinFindAdversaries: 0x40
47915e8.2fc8: \SystemRoot\System32\drivers\klflt.sys:
48015e8.2fc8: CreationTime: 2018-11-20T09:50:50.978328500Z
48115e8.2fc8: LastWriteTime: 2019-08-07T13:01:58.292832100Z
48215e8.2fc8: ChangeTime: 2019-09-02T18:03:17.094878400Z
48315e8.2fc8: FileAttributes: 0x20
48415e8.2fc8: Size: 0x39c80
48515e8.2fc8: NT Headers: 0xf8
48615e8.2fc8: Timestamp: 0x5d0ce55e
48715e8.2fc8: Machine: 0x8664 - amd64
48815e8.2fc8: Timestamp: 0x5d0ce55e
48915e8.2fc8: Image Version: 6.2
49015e8.2fc8: SizeOfImage: 0x47000 (290816)
49115e8.2fc8: Resource Dir: 0x44000 LB 0x420
49215e8.2fc8: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
49315e8.2fc8: [Raw version resource data: 0x44060 LB 0x3c0, codepage 0x0 (reserved 0x0)]
49415e8.2fc8: ProductName: System Interceptors PDK
49515e8.2fc8: ProductVersion: 15.1.244.0
49615e8.2fc8: FileVersion: 15.1.244.0
49715e8.2fc8: FileDescription: Filter Core [fre_win8_x64]
49815e8.2fc8: \SystemRoot\System32\drivers\klif.sys:
49915e8.2fc8: CreationTime: 2018-11-20T09:50:50.982331000Z
50015e8.2fc8: LastWriteTime: 2019-08-07T13:01:58.766393500Z
50115e8.2fc8: ChangeTime: 2019-09-02T18:03:17.094878400Z
50215e8.2fc8: FileAttributes: 0x20
50315e8.2fc8: Size: 0x11d280
50415e8.2fc8: NT Headers: 0x108
50515e8.2fc8: Timestamp: 0x5d0ce567
50615e8.2fc8: Machine: 0x8664 - amd64
50715e8.2fc8: Timestamp: 0x5d0ce567
50815e8.2fc8: Image Version: 6.2
50915e8.2fc8: SizeOfImage: 0x121000 (1183744)
51015e8.2fc8: Resource Dir: 0x118000 LB 0x29a0
51115e8.2fc8: [Version info resource found at 0x150! (ID/Name: 0x1; SubID/SubName: 0x409)]
51215e8.2fc8: [Raw version resource data: 0x118618 LB 0x3d8, codepage 0x0 (reserved 0x0)]
51315e8.2fc8: ProductName: System Interceptors PDK
51415e8.2fc8: ProductVersion: 15.1.244.0
51515e8.2fc8: FileVersion: 15.1.244.0
51615e8.2fc8: FileDescription: Core System Interceptors [fre_win8_x64]
51715e8.2fc8: \SystemRoot\System32\drivers\klim6.sys:
51815e8.2fc8: CreationTime: 2018-02-12T03:17:16.000000000Z
51915e8.2fc8: LastWriteTime: 2019-04-15T10:39:11.262715200Z
52015e8.2fc8: ChangeTime: 2019-10-30T20:14:04.378005300Z
52115e8.2fc8: FileAttributes: 0x20
52215e8.2fc8: Size: 0xe550
52315e8.2fc8: NT Headers: 0xf0
52415e8.2fc8: Timestamp: 0x5c543766
52515e8.2fc8: Machine: 0x8664 - amd64
52615e8.2fc8: Timestamp: 0x5c543766
52715e8.2fc8: Image Version: 6.2
52815e8.2fc8: SizeOfImage: 0xb000 (45056)
52915e8.2fc8: Resource Dir: 0x9000 LB 0x438
53015e8.2fc8: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
53115e8.2fc8: [Raw version resource data: 0x9060 LB 0x3d4, codepage 0x0 (reserved 0x0)]
53215e8.2fc8: ProductName: System Interceptors PDK
53315e8.2fc8: ProductVersion: 15.1.203.0
53415e8.2fc8: FileVersion: 15.1.203.0
53515e8.2fc8: FileDescription: Packet Network Filter [fre_win8_x64]
53615e8.2fc8: \SystemRoot\System32\drivers\klkbdflt.sys:
53715e8.2fc8: CreationTime: 2018-11-20T09:50:50.988333100Z
53815e8.2fc8: LastWriteTime: 2019-04-15T10:40:00.034381700Z
53915e8.2fc8: ChangeTime: 2019-09-02T18:03:17.094878400Z
54015e8.2fc8: FileAttributes: 0x20
54115e8.2fc8: Size: 0xec78
54215e8.2fc8: NT Headers: 0xe8
54315e8.2fc8: Timestamp: 0x5c516e05
54415e8.2fc8: Machine: 0x8664 - amd64
54515e8.2fc8: Timestamp: 0x5c516e05
54615e8.2fc8: Image Version: 6.2
54715e8.2fc8: SizeOfImage: 0xd000 (53248)
54815e8.2fc8: Resource Dir: 0xb000 LB 0x440
54915e8.2fc8: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
55015e8.2fc8: [Raw version resource data: 0xb060 LB 0x3dc, codepage 0x0 (reserved 0x0)]
55115e8.2fc8: ProductName: System Interceptors PDK
55215e8.2fc8: ProductVersion: 15.1.204.0
55315e8.2fc8: FileVersion: 15.1.204.0
55415e8.2fc8: FileDescription: Keyboard Device Filter [fre_win8_x64]
55515e8.2fc8: \SystemRoot\System32\drivers\klmouflt.sys:
55615e8.2fc8: CreationTime: 2018-11-20T09:50:50.991334300Z
55715e8.2fc8: LastWriteTime: 2019-04-15T10:40:00.105316500Z
55815e8.2fc8: ChangeTime: 2019-09-02T18:03:17.094878400Z
55915e8.2fc8: FileAttributes: 0x20
56015e8.2fc8: Size: 0xed70
56115e8.2fc8: NT Headers: 0xd8
56215e8.2fc8: Timestamp: 0x5c4c6ef9
56315e8.2fc8: Machine: 0x8664 - amd64
56415e8.2fc8: Timestamp: 0x5c4c6ef9
56515e8.2fc8: Image Version: 6.2
56615e8.2fc8: SizeOfImage: 0xf000 (61440)
56715e8.2fc8: Resource Dir: 0xd000 LB 0x438
56815e8.2fc8: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
56915e8.2fc8: [Raw version resource data: 0xd060 LB 0x3d8, codepage 0x0 (reserved 0x0)]
57015e8.2fc8: ProductName: System Interceptors PDK
57115e8.2fc8: ProductVersion: 15.1.202.0
57215e8.2fc8: FileVersion: 15.1.202.0
57315e8.2fc8: FileDescription: Mouse Device Filter [fre_win8_x64]
57415e8.2fc8: \SystemRoot\System32\drivers\kneps.sys:
57515e8.2fc8: CreationTime: 2018-11-20T09:50:51.023345600Z
57615e8.2fc8: LastWriteTime: 2019-04-15T10:40:00.763705300Z
57715e8.2fc8: ChangeTime: 2019-09-02T18:03:17.110503200Z
57815e8.2fc8: FileAttributes: 0x20
57915e8.2fc8: Size: 0x35480
58015e8.2fc8: NT Headers: 0xf8
58115e8.2fc8: Timestamp: 0x5c7e4b42
58215e8.2fc8: Machine: 0x8664 - amd64
58315e8.2fc8: Timestamp: 0x5c7e4b42
58415e8.2fc8: Image Version: 6.2
58515e8.2fc8: SizeOfImage: 0x33000 (208896)
58615e8.2fc8: Resource Dir: 0x30000 LB 0x430
58715e8.2fc8: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
58815e8.2fc8: [Raw version resource data: 0x30060 LB 0x3cc, codepage 0x0 (reserved 0x0)]
58915e8.2fc8: ProductName: System Interceptors PDK
59015e8.2fc8: ProductVersion: 15.1.215.0
59115e8.2fc8: FileVersion: 15.1.215.0
59215e8.2fc8: FileDescription: Network Processor [fre_win8_x64]
59315e8.2fc8: \SystemRoot\System32\klfphc.dll:
59415e8.2fc8: CreationTime: 2018-11-20T09:50:00.439136800Z
59515e8.2fc8: LastWriteTime: 2013-05-06T07:13:26.000000000Z
59615e8.2fc8: ChangeTime: 2019-09-02T18:03:16.860513700Z
59715e8.2fc8: FileAttributes: 0x2020
59815e8.2fc8: Size: 0x1ae60
59915e8.2fc8: NT Headers: 0xe8
60015e8.2fc8: Timestamp: 0x51873bf2
60115e8.2fc8: Machine: 0x8664 - amd64
60215e8.2fc8: Timestamp: 0x51873bf2
60315e8.2fc8: Image Version: 0.0
60415e8.2fc8: SizeOfImage: 0x1d000 (118784)
60515e8.2fc8: Resource Dir: 0x18000 LB 0x3c80
60615e8.2fc8: [Version info resource found at 0x188! (ID/Name: 0x1; SubID/SubName: 0x409)]
60715e8.2fc8: [Raw version resource data: 0x1b800 LB 0x324, codepage 0x4e4 (reserved 0x0)]
60815e8.2fc8: ProductName: Kaspersky™ Anti-Virus ®
60915e8.2fc8: ProductVersion: 1.0.0.12
61015e8.2fc8: FileVersion: 1.0.0.12
61115e8.2fc8: FileDescription: Filtering Platform Helper Class
61215e8.2fc8: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
61315e8.2fc8: Calling main()
61415e8.2fc8: SUPR3HardenedMain: pszProgName=VirtualBoxVM fFlags=0x2
61515e8.2fc8: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
61615e8.2fc8: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
61715e8.2fc8: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe)
61815e8.2fc8: SUPR3HardenedMain: Respawn #2
61915e8.2fc8: supR3HardNtEnableThreadCreationEx:
62015e8.2fc8: supR3HardenedDllNotificationCallback: load 00007ffedbab0000 LB 0x00120000 C:\WINDOWS\System32\RPCRT4.dll [fFlags=0x0]
62115e8.2fc8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll)
62215e8.2fc8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
62315e8.2fc8: supR3HardenedDllNotificationCallback: load 00007ffedcac0000 LB 0x00097000 C:\WINDOWS\System32\sechost.dll [fFlags=0x0]
62415e8.2fc8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'rpcrt4.dll'.
62515e8.2fc8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\sechost.dll)
62615e8.2fc8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\sechost.dll
62715e8.2fc8: '\Device\HarddiskVolume2\Windows\System32\ntdll.dll' has no imports
62815e8.2fc8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ntdll.dll)
62915e8.2fc8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ntdll.dll
63015e8.2fc8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
63115e8.2fc8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
63215e8.2fc8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
63315e8.2fc8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\ntdll.dll (Input=ntdll.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
63415e8.2fc8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffedd9e0000 'C:\WINDOWS\System32\ntdll.dll'
63515e8.2fc8: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffedda517f0 pvNtTerminateThread=00007ffedda7cb10
63615e8.2fc8: supR3HardenedWinDoReSpawn(2): New child 506c.5344 [kernel32].
63715e8.2fc8: supR3HardenedWinReSpawn: NtSetInformationThread/ThreadHideFromDebugger failed: 0xc0000022 (harmless)
63815e8.2fc8: supR3HardNtChildGatherData: PebBaseAddress=00000000010d5000 cbPeb=0x388
63915e8.2fc8: supR3HardNtPuChFindNtdll: uNtDllParentAddr=00007ffedd9e0000 uNtDllChildAddr=00007ffedd9e0000
64015e8.2fc8: supR3HardenedWinSetupChildInit: uLdrInitThunk=00007ffedda517f0
64115e8.2fc8: supR3HardenedWinSetupChildInit: Start child.
64215e8.2fc8: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 1 ms.
64315e8.2fc8: supR3HardNtChildPurify: Startup delay kludge #1/0: 518 ms, 56 sleeps
64415e8.2fc8: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
64515e8.2fc8: *0000000000000000-0000000000e1ffff 0x0001/0x0000 0x0000000
64615e8.2fc8: *0000000000e20000-0000000000e3ffff 0x0004/0x0004 0x0020000
64715e8.2fc8: *0000000000e40000-0000000000e5afff 0x0002/0x0002 0x0040000
64815e8.2fc8: 0000000000e5b000-0000000000e5ffff 0x0001/0x0000 0x0000000
64915e8.2fc8: *0000000000e60000-0000000000f5afff 0x0000/0x0004 0x0020000
65015e8.2fc8: 0000000000f5b000-0000000000f5dfff 0x0104/0x0004 0x0020000
65115e8.2fc8: 0000000000f5e000-0000000000f5ffff 0x0004/0x0004 0x0020000
65215e8.2fc8: *0000000000f60000-0000000000f63fff 0x0002/0x0002 0x0040000
65315e8.2fc8: 0000000000f64000-0000000000f6ffff 0x0001/0x0000 0x0000000
65415e8.2fc8: *0000000000f70000-0000000000f71fff 0x0004/0x0004 0x0020000
65515e8.2fc8: 0000000000f72000-0000000000ffffff 0x0001/0x0000 0x0000000
65615e8.2fc8: *0000000001000000-00000000010d4fff 0x0000/0x0004 0x0020000
65715e8.2fc8: 00000000010d5000-00000000010d7fff 0x0004/0x0004 0x0020000
65815e8.2fc8: 00000000010d8000-00000000011fffff 0x0000/0x0004 0x0020000
65915e8.2fc8: 0000000001200000-000000007ffdffff 0x0001/0x0000 0x0000000
66015e8.2fc8: *000000007ffe0000-000000007ffe0fff 0x0002/0x0002 0x0020000
66115e8.2fc8: 000000007ffe1000-000000007ffedfff 0x0001/0x0000 0x0000000
66215e8.2fc8: *000000007ffee000-000000007ffeefff 0x0002/0x0002 0x0020000
66315e8.2fc8: 000000007ffef000-00007ff567acffff 0x0001/0x0000 0x0000000
66415e8.2fc8: *00007ff567ad0000-00007ff567ad0fff 0x0002/0x0002 0x0040000
66515e8.2fc8: 00007ff567ad1000-00007ff567adffff 0x0001/0x0000 0x0000000
66615e8.2fc8: *00007ff567ae0000-00007ff567b02fff 0x0002/0x0002 0x0040000
66715e8.2fc8: 00007ff567b03000-00007ff6e359ffff 0x0001/0x0000 0x0000000
66815e8.2fc8: *00007ff6e35a0000-00007ff6e35a0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
66915e8.2fc8: 00007ff6e35a1000-00007ff6e3615fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
67015e8.2fc8: 00007ff6e3616000-00007ff6e3616fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
67115e8.2fc8: 00007ff6e3617000-00007ff6e365efff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
67215e8.2fc8: 00007ff6e365f000-00007ff6e365ffff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
67315e8.2fc8: 00007ff6e3660000-00007ff6e3660fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
67415e8.2fc8: 00007ff6e3661000-00007ff6e3665fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
67515e8.2fc8: 00007ff6e3666000-00007ff6e3666fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
67615e8.2fc8: 00007ff6e3667000-00007ff6e3667fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
67715e8.2fc8: 00007ff6e3668000-00007ff6e366bfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
67815e8.2fc8: 00007ff6e366c000-00007ff6e36b4fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
67915e8.2fc8: 00007ff6e36b5000-00007ffedd9dffff 0x0001/0x0000 0x0000000
68015e8.2fc8: *00007ffedd9e0000-00007ffedd9e0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
68115e8.2fc8: 00007ffedd9e1000-00007ffeddaf7fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
68215e8.2fc8: 00007ffeddaf8000-00007ffeddb3efff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
68315e8.2fc8: 00007ffeddb3f000-00007ffeddb4afff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
68415e8.2fc8: 00007ffeddb4b000-00007ffeddb59fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
68515e8.2fc8: 00007ffeddb5a000-00007ffeddb5afff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
68615e8.2fc8: 00007ffeddb5b000-00007ffeddb5dfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
68715e8.2fc8: 00007ffeddb5e000-00007ffeddbcffff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
68815e8.2fc8: 00007ffeddbd0000-00007ffffffeffff 0x0001/0x0000 0x0000000
68915e8.2fc8: VirtualBoxVM.exe: timestamp 0x5d9f7c37 (rc=VINF_SUCCESS)
69015e8.2fc8: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
69115e8.2fc8: '\Device\HarddiskVolume2\Windows\System32\ntdll.dll' has no imports
69215e8.2fc8: supR3HardNtChildPurify: Done after 593 ms and 0 fixes (loop #0).
693506c.5344: Log file opened: 6.0.14r133895 g_hStartupLog=0000000000000004 g_uNtVerCombined=0xa047bb00
694506c.5344: supR3HardenedVmProcessInit: uNtDllAddr=00007ffedd9e0000 g_uNtVerCombined=0xa047bb00
695506c.5344: ntdll.dll: timestamp 0x99ca0526 (rc=VINF_SUCCESS)
696506c.5344: New simple heap: #1 0000000001300000 LB 0x400000 (for 2031616 allocation)
69715e8.2fc8: supR3HardenedEarlyCompact: Removed heap 1 (0x00000000d00000 LB 0x400000)
69815e8.2fc8: supR3HardNtEnableThreadCreationEx:
699506c.5344: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
700506c.5344: System32: \Device\HarddiskVolume2\Windows\System32
701506c.5344: WinSxS: \Device\HarddiskVolume2\Windows\WinSxS
702506c.5344: KnownDllPath: C:\WINDOWS\System32
703506c.5344: supR3HardenedVmProcessInit: Opening vboxdrv...
704506c.5344: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
705506c.5344: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
706506c.5344: Registered Dll notification callback with NTDLL.
707506c.5344: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\kernel32.dll)
708506c.5344: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\kernel32.dll
709506c.5344: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\KERNEL32.DLL (Input=KERNEL32.DLL, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000004001:<flags> [calling]
710506c.5344: supR3HardenedDllNotificationCallback: load 00007ffedaeb0000 LB 0x002a3000 C:\WINDOWS\System32\KERNELBASE.dll [fFlags=0x0]
711506c.5344: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\KernelBase.dll)
712506c.5344: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\KernelBase.dll
713506c.5344: supR3HardenedDllNotificationCallback: load 00007ffedbd30000 LB 0x000b2000 C:\WINDOWS\System32\KERNEL32.DLL [fFlags=0x0]
714506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
715506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffedbd30000 'C:\WINDOWS\System32\KERNEL32.DLL'
716506c.5344: supR3HardenedDllNotificationCallback: load 00007ff6e35a0000 LB 0x00115000 C:\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe [fFlags=0x0]
717506c.5344: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
718506c.5344: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe)
719506c.5344: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
720506c.5344: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffedda517f0 pvNtTerminateThread=00007ffedda7cb10
72115e8.2fc8: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 448 ms.
722506c.5344: \SystemRoot\System32\ntdll.dll:
723506c.5344: CreationTime: 2019-10-10T14:11:58.713323600Z
724506c.5344: LastWriteTime: 2019-10-10T14:11:58.802238300Z
725506c.5344: ChangeTime: 2019-11-14T16:05:50.146664100Z
726506c.5344: FileAttributes: 0x20
727506c.5344: Size: 0x1e8528
728506c.5344: NT Headers: 0xd8
729506c.5344: Timestamp: 0x99ca0526
730506c.5344: Machine: 0x8664 - amd64
731506c.5344: Timestamp: 0x99ca0526
732506c.5344: Image Version: 10.0
733506c.5344: SizeOfImage: 0x1f0000 (2031616)
734506c.5344: Resource Dir: 0x17f000 LB 0x6f310
735506c.5344: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
736506c.5344: [Raw version resource data: 0x17f0f0 LB 0x380, codepage 0x0 (reserved 0x0)]
737506c.5344: ProductName: Microsoft® Windows® Operating System
738506c.5344: ProductVersion: 10.0.18362.418
739506c.5344: FileVersion: 10.0.18362.418 (WinBuild.160101.0800)
740506c.5344: FileDescription: NT Layer DLL
741506c.5344: \SystemRoot\System32\kernel32.dll:
742506c.5344: CreationTime: 2019-09-13T19:37:38.549674400Z
743506c.5344: LastWriteTime: 2019-09-13T19:37:38.586602800Z
744506c.5344: ChangeTime: 2019-11-14T16:05:49.709071400Z
745506c.5344: FileAttributes: 0x20
746506c.5344: Size: 0xb0570
747506c.5344: NT Headers: 0xe8
748506c.5344: Timestamp: 0xd0cecc10
749506c.5344: Machine: 0x8664 - amd64
750506c.5344: Timestamp: 0xd0cecc10
751506c.5344: Image Version: 10.0
752506c.5344: SizeOfImage: 0xb2000 (729088)
753506c.5344: Resource Dir: 0xb0000 LB 0x520
754506c.5344: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
755506c.5344: [Raw version resource data: 0xb00b0 LB 0x3a4, codepage 0x0 (reserved 0x0)]
756506c.5344: ProductName: Microsoft® Windows® Operating System
757506c.5344: ProductVersion: 10.0.18362.329
758506c.5344: FileVersion: 10.0.18362.329 (WinBuild.160101.0800)
759506c.5344: FileDescription: Windows NT BASE API Client DLL
760506c.5344: \SystemRoot\System32\KernelBase.dll:
761506c.5344: CreationTime: 2019-11-14T16:03:37.286662400Z
762506c.5344: LastWriteTime: 2019-11-14T16:03:37.415540100Z
763506c.5344: ChangeTime: 2019-11-14T19:08:57.586841900Z
764506c.5344: FileAttributes: 0x20
765506c.5344: Size: 0x2a2908
766506c.5344: NT Headers: 0xf0
767506c.5344: Timestamp: 0x83c3d83a
768506c.5344: Machine: 0x8664 - amd64
769506c.5344: Timestamp: 0x83c3d83a
770506c.5344: Image Version: 10.0
771506c.5344: SizeOfImage: 0x2a3000 (2764800)
772506c.5344: Resource Dir: 0x27d000 LB 0x548
773506c.5344: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
774506c.5344: [Raw version resource data: 0x27d0b0 LB 0x3bc, codepage 0x0 (reserved 0x0)]
775506c.5344: ProductName: Microsoft® Windows® Operating System
776506c.5344: ProductVersion: 10.0.18362.476
777506c.5344: FileVersion: 10.0.18362.476 (WinBuild.160101.0800)
778506c.5344: FileDescription: Windows NT BASE API Client DLL
779506c.5344: \SystemRoot\System32\apisetschema.dll:
780506c.5344: CreationTime: 2019-03-19T04:43:54.837151500Z
781506c.5344: LastWriteTime: 2019-03-19T04:43:54.837151500Z
782506c.5344: ChangeTime: 2019-11-14T16:05:49.339411400Z
783506c.5344: FileAttributes: 0x20
784506c.5344: Size: 0x1d028
785506c.5344: NT Headers: 0xc8
786506c.5344: Timestamp: 0xd6ced080
787506c.5344: Machine: 0x8664 - amd64
788506c.5344: Timestamp: 0xd6ced080
789506c.5344: Image Version: 10.0
790506c.5344: SizeOfImage: 0x1e000 (122880)
791506c.5344: Resource Dir: 0x1d000 LB 0x408
792506c.5344: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
793506c.5344: [Raw version resource data: 0x1d060 LB 0x3a8, codepage 0x0 (reserved 0x0)]
794506c.5344: ProductName: Microsoft® Windows® Operating System
795506c.5344: ProductVersion: 10.0.18362.1
796506c.5344: FileVersion: 10.0.18362.1 (WinBuild.160101.0800)
797506c.5344: FileDescription: ApiSet Schema DLL
798506c.5344: Found driver klkbdflt (0x40)
799506c.5344: Found driver klmouflt (0x40)
800506c.5344: Found driver KLIM6 (0x40)
801506c.5344: Found driver kneps (0x40)
802506c.5344: Found driver klflt (0x40)
803506c.5344: supR3HardenedWinFindAdversaries: 0x40
804506c.5344: \SystemRoot\System32\drivers\klflt.sys:
805506c.5344: CreationTime: 2018-11-20T09:50:50.978328500Z
806506c.5344: LastWriteTime: 2019-08-07T13:01:58.292832100Z
807506c.5344: ChangeTime: 2019-09-02T18:03:17.094878400Z
808506c.5344: FileAttributes: 0x20
809506c.5344: Size: 0x39c80
810506c.5344: NT Headers: 0xf8
811506c.5344: Timestamp: 0x5d0ce55e
812506c.5344: Machine: 0x8664 - amd64
813506c.5344: Timestamp: 0x5d0ce55e
814506c.5344: Image Version: 6.2
815506c.5344: SizeOfImage: 0x47000 (290816)
816506c.5344: Resource Dir: 0x44000 LB 0x420
817506c.5344: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
818506c.5344: [Raw version resource data: 0x44060 LB 0x3c0, codepage 0x0 (reserved 0x0)]
819506c.5344: ProductName: System Interceptors PDK
820506c.5344: ProductVersion: 15.1.244.0
821506c.5344: FileVersion: 15.1.244.0
822506c.5344: FileDescription: Filter Core [fre_win8_x64]
823506c.5344: \SystemRoot\System32\drivers\klif.sys:
824506c.5344: CreationTime: 2018-11-20T09:50:50.982331000Z
825506c.5344: LastWriteTime: 2019-08-07T13:01:58.766393500Z
826506c.5344: ChangeTime: 2019-09-02T18:03:17.094878400Z
827506c.5344: FileAttributes: 0x20
828506c.5344: Size: 0x11d280
829506c.5344: NT Headers: 0x108
830506c.5344: Timestamp: 0x5d0ce567
831506c.5344: Machine: 0x8664 - amd64
832506c.5344: Timestamp: 0x5d0ce567
833506c.5344: Image Version: 6.2
834506c.5344: SizeOfImage: 0x121000 (1183744)
835506c.5344: Resource Dir: 0x118000 LB 0x29a0
836506c.5344: [Version info resource found at 0x150! (ID/Name: 0x1; SubID/SubName: 0x409)]
837506c.5344: [Raw version resource data: 0x118618 LB 0x3d8, codepage 0x0 (reserved 0x0)]
838506c.5344: ProductName: System Interceptors PDK
839506c.5344: ProductVersion: 15.1.244.0
840506c.5344: FileVersion: 15.1.244.0
841506c.5344: FileDescription: Core System Interceptors [fre_win8_x64]
842506c.5344: \SystemRoot\System32\drivers\klim6.sys:
843506c.5344: CreationTime: 2018-02-12T03:17:16.000000000Z
844506c.5344: LastWriteTime: 2019-04-15T10:39:11.262715200Z
845506c.5344: ChangeTime: 2019-10-30T20:14:04.378005300Z
846506c.5344: FileAttributes: 0x20
847506c.5344: Size: 0xe550
848506c.5344: NT Headers: 0xf0
849506c.5344: Timestamp: 0x5c543766
850506c.5344: Machine: 0x8664 - amd64
851506c.5344: Timestamp: 0x5c543766
852506c.5344: Image Version: 6.2
853506c.5344: SizeOfImage: 0xb000 (45056)
854506c.5344: Resource Dir: 0x9000 LB 0x438
855506c.5344: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
856506c.5344: [Raw version resource data: 0x9060 LB 0x3d4, codepage 0x0 (reserved 0x0)]
857506c.5344: ProductName: System Interceptors PDK
858506c.5344: ProductVersion: 15.1.203.0
859506c.5344: FileVersion: 15.1.203.0
860506c.5344: FileDescription: Packet Network Filter [fre_win8_x64]
861506c.5344: \SystemRoot\System32\drivers\klkbdflt.sys:
862506c.5344: CreationTime: 2018-11-20T09:50:50.988333100Z
863506c.5344: LastWriteTime: 2019-04-15T10:40:00.034381700Z
864506c.5344: ChangeTime: 2019-09-02T18:03:17.094878400Z
865506c.5344: FileAttributes: 0x20
866506c.5344: Size: 0xec78
867506c.5344: NT Headers: 0xe8
868506c.5344: Timestamp: 0x5c516e05
869506c.5344: Machine: 0x8664 - amd64
870506c.5344: Timestamp: 0x5c516e05
871506c.5344: Image Version: 6.2
872506c.5344: SizeOfImage: 0xd000 (53248)
873506c.5344: Resource Dir: 0xb000 LB 0x440
874506c.5344: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
875506c.5344: [Raw version resource data: 0xb060 LB 0x3dc, codepage 0x0 (reserved 0x0)]
876506c.5344: ProductName: System Interceptors PDK
877506c.5344: ProductVersion: 15.1.204.0
878506c.5344: FileVersion: 15.1.204.0
879506c.5344: FileDescription: Keyboard Device Filter [fre_win8_x64]
880506c.5344: \SystemRoot\System32\drivers\klmouflt.sys:
881506c.5344: CreationTime: 2018-11-20T09:50:50.991334300Z
882506c.5344: LastWriteTime: 2019-04-15T10:40:00.105316500Z
883506c.5344: ChangeTime: 2019-09-02T18:03:17.094878400Z
884506c.5344: FileAttributes: 0x20
885506c.5344: Size: 0xed70
886506c.5344: NT Headers: 0xd8
887506c.5344: Timestamp: 0x5c4c6ef9
888506c.5344: Machine: 0x8664 - amd64
889506c.5344: Timestamp: 0x5c4c6ef9
890506c.5344: Image Version: 6.2
891506c.5344: SizeOfImage: 0xf000 (61440)
892506c.5344: Resource Dir: 0xd000 LB 0x438
893506c.5344: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
894506c.5344: [Raw version resource data: 0xd060 LB 0x3d8, codepage 0x0 (reserved 0x0)]
895506c.5344: ProductName: System Interceptors PDK
896506c.5344: ProductVersion: 15.1.202.0
897506c.5344: FileVersion: 15.1.202.0
898506c.5344: FileDescription: Mouse Device Filter [fre_win8_x64]
899506c.5344: \SystemRoot\System32\drivers\kneps.sys:
900506c.5344: CreationTime: 2018-11-20T09:50:51.023345600Z
901506c.5344: LastWriteTime: 2019-04-15T10:40:00.763705300Z
902506c.5344: ChangeTime: 2019-09-02T18:03:17.110503200Z
903506c.5344: FileAttributes: 0x20
904506c.5344: Size: 0x35480
905506c.5344: NT Headers: 0xf8
906506c.5344: Timestamp: 0x5c7e4b42
907506c.5344: Machine: 0x8664 - amd64
908506c.5344: Timestamp: 0x5c7e4b42
909506c.5344: Image Version: 6.2
910506c.5344: SizeOfImage: 0x33000 (208896)
911506c.5344: Resource Dir: 0x30000 LB 0x430
912506c.5344: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
913506c.5344: [Raw version resource data: 0x30060 LB 0x3cc, codepage 0x0 (reserved 0x0)]
914506c.5344: ProductName: System Interceptors PDK
915506c.5344: ProductVersion: 15.1.215.0
916506c.5344: FileVersion: 15.1.215.0
917506c.5344: FileDescription: Network Processor [fre_win8_x64]
918506c.5344: \SystemRoot\System32\klfphc.dll:
919506c.5344: CreationTime: 2018-11-20T09:50:00.439136800Z
920506c.5344: LastWriteTime: 2013-05-06T07:13:26.000000000Z
921506c.5344: ChangeTime: 2019-09-02T18:03:16.860513700Z
922506c.5344: FileAttributes: 0x2020
923506c.5344: Size: 0x1ae60
924506c.5344: NT Headers: 0xe8
925506c.5344: Timestamp: 0x51873bf2
926506c.5344: Machine: 0x8664 - amd64
927506c.5344: Timestamp: 0x51873bf2
928506c.5344: Image Version: 0.0
929506c.5344: SizeOfImage: 0x1d000 (118784)
930506c.5344: Resource Dir: 0x18000 LB 0x3c80
931506c.5344: [Version info resource found at 0x188! (ID/Name: 0x1; SubID/SubName: 0x409)]
932506c.5344: [Raw version resource data: 0x1b800 LB 0x324, codepage 0x4e4 (reserved 0x0)]
933506c.5344: ProductName: Kaspersky™ Anti-Virus ®
934506c.5344: ProductVersion: 1.0.0.12
935506c.5344: FileVersion: 1.0.0.12
936506c.5344: FileDescription: Filtering Platform Helper Class
937506c.5344: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
938506c.5344: Calling main()
939506c.5344: SUPR3HardenedMain: pszProgName=VirtualBoxVM fFlags=0x2
940506c.5344: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
941506c.5344: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
942506c.5344: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe)
943506c.5344: SUPR3HardenedMain: Final process, opening VBoxDrv...
944506c.5344: supR3HardenedEarlyCompact: Removed heap 1 (0x00000001300000 LB 0x400000)
945506c.5344: supR3HardNtEnableThreadCreationEx:
946506c.5344: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll)
947506c.5344: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll
948506c.5344: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
949506c.5344: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
950506c.5344: supR3HardenedDllNotificationCallback: load 00007ffed7120000 LB 0x00005000 C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL [fFlags=0x0]
951506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
952506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
953506c.5344: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
954506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffed7120000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
955506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
956506c.5344: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
957506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffed7120000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
958506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffed7120000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
959506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
960506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msasn1.dll'.
961506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'crypt32.dll'.
962506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #27 'rpcrt4.dll'.
963506c.5344: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\wintrust.dll)
964506c.5344: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wintrust.dll
965506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
966506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
967506c.5344: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll)
968506c.5344: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
969506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
970506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume2\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
971506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #34 'msasn1.dll'.
972506c.5344: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\crypt32.dll)
973506c.5344: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\crypt32.dll
974506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
975506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume2\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
976506c.5344: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\msasn1.dll)
977506c.5344: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msasn1.dll
978506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
979506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
980506c.5344: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\msvcrt.dll)
981506c.5344: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
982506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
983506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume2\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
984506c.5344: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
985506c.5344: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
986506c.5344: supR3HardenedDllNotificationCallback: load 00007ffedc080000 LB 0x0009e000 C:\WINDOWS\System32\msvcrt.dll [fFlags=0x0]
987506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
988506c.5344: supR3HardenedDllNotificationCallback: load 00007ffeda900000 LB 0x00012000 C:\WINDOWS\System32\MSASN1.dll [fFlags=0x0]
989506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
990506c.5344: supR3HardenedDllNotificationCallback: load 00007ffeda9b0000 LB 0x000fa000 C:\WINDOWS\System32\ucrtbase.dll [fFlags=0x0]
991506c.5344: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ucrtbase.dll)
992506c.5344: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ucrtbase.dll
993506c.5344: supR3HardenedDllNotificationCallback: load 00007ffedb190000 LB 0x00149000 C:\WINDOWS\System32\CRYPT32.dll [fFlags=0x0]
994506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
995506c.5344: supR3HardenedDllNotificationCallback: load 00007ffedbab0000 LB 0x00120000 C:\WINDOWS\System32\RPCRT4.dll [fFlags=0x0]
996506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
997506c.5344: supR3HardenedDllNotificationCallback: load 00007ffedaab0000 LB 0x0005c000 C:\WINDOWS\System32\Wintrust.dll [fFlags=0x0]
998506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
999506c.5344: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
1000506c.5344: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
1001506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffedaeb0000 'api-ms-win-core-synch-l1-2-0'
1002506c.5344: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-fibers-l1-1-1) -> 0x0, fPresent=1
1003506c.5344: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
1004506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffedaeb0000 'api-ms-win-core-fibers-l1-1-1'
1005506c.5344: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-fibers-l1-1-1) -> 0x0, fPresent=1
1006506c.5344: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
1007506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffedaeb0000 'api-ms-win-core-fibers-l1-1-1'
1008506c.5344: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
1009506c.5344: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
1010506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffedaeb0000 'api-ms-win-core-synch-l1-2-0'
1011506c.5344: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-l1-2-1) -> 0x0, fPresent=1
1012506c.5344: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-l1-2-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
1013506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffedaeb0000 'api-ms-win-core-localization-l1-2-1'
1014506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffedaab0000 'C:\WINDOWS\system32\Wintrust.dll'
1015506c.5344: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\bcrypt.dll)
1016506c.5344: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\bcrypt.dll
1017506c.5344: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\bcrypt.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
1018506c.5344: supR3HardenedDllNotificationCallback: load 00007ffedb160000 LB 0x00026000 C:\WINDOWS\System32\bcrypt.dll [fFlags=0x0]
1019506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
1020506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffedb160000 'C:\WINDOWS\system32\bcrypt.dll'
1021506c.5344: bcrypt.dll loaded at 00007ffedb160000, BCryptOpenAlgorithmProvider at 00007ffedb164c70, preloading providers:
1022506c.5344: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll)
1023506c.5344: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll
1024506c.5344: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\bcryptprimitives.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
1025506c.5344: supR3HardenedDllNotificationCallback: load 00007ffedad60000 LB 0x00080000 C:\WINDOWS\System32\bcryptprimitives.dll [fFlags=0x0]
1026506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
1027506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffedad60000 'C:\WINDOWS\system32\bcryptprimitives.dll'
1028506c.5344: BCryptOpenAlgorithmProvider(,'MD2',0,0) -> 0x0 (hAlgo=000000000182fd90)
1029506c.5344: BCryptOpenAlgorithmProvider(,'MD4',0,0) -> 0x0 (hAlgo=00000000018302e0)
1030506c.5344: BCryptOpenAlgorithmProvider(,'MD5',0,0) -> 0x0 (hAlgo=00000000018305e0)
1031506c.5344: BCryptOpenAlgorithmProvider(,'SHA1',0,0) -> 0x0 (hAlgo=00000000018308e0)
1032506c.5344: BCryptOpenAlgorithmProvider(,'SHA256',0,0) -> 0x0 (hAlgo=0000000001830be0)
1033506c.5344: BCryptOpenAlgorithmProvider(,'SHA512',0,0) -> 0x0 (hAlgo=0000000001830ee0)
1034506c.5344: BCryptOpenAlgorithmProvider(,'RSA',0,0) -> 0x0 (hAlgo=00000000018311e0)
1035506c.5344: BCryptOpenAlgorithmProvider(,'DSA',0,0) -> 0x0 (hAlgo=00000000018318f0)
1036506c.5344: supR3HardenedDllNotificationCallback: load 00007ffeda990000 LB 0x00017000 C:\WINDOWS\System32\CRYPTSP.dll [fFlags=0x0]
1037506c.5344: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\cryptsp.dll)
1038506c.5344: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cryptsp.dll
1039506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'bcrypt.dll'.
1040506c.5344: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\rsaenh.dll)
1041506c.5344: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\rsaenh.dll
1042506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
1043506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume2\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
1044506c.5344: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
1045506c.5344: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
1046506c.5344: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
1047506c.5344: supR3HardenedDllNotificationCallback: load 00007ffed9bc0000 LB 0x00033000 C:\WINDOWS\system32\rsaenh.dll [fFlags=0x0]
1048506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
1049506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffed9bc0000 'C:\WINDOWS\system32\rsaenh.dll'
1050506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'bcryptprimitives.dll'.
1051506c.5344: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\cryptbase.dll)
1052506c.5344: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cryptbase.dll
1053506c.5344: supR3HardenedDllNotificationCallback: load 00007ffeda1c0000 LB 0x0000c000 C:\WINDOWS\SYSTEM32\CRYPTBASE.dll [fFlags=0x0]
1054506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cryptbase.dll [lacks WinVerifyTrust]
1055506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
1056506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcryptprimitives.dll'...
1057506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcryptprimitives.dll' -> '\Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll' [rcNtRedir=0xc0150008]
1058506c.5344: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
1059506c.5344: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
1060506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffedbd30000 'C:\WINDOWS\System32\kernel32.dll'
1061506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
1062506c.5344: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\WINTRUST.DLL (Input=WINTRUST.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
1063506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffedaab0000 'C:\WINDOWS\System32\WINTRUST.DLL'
1064506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
1065506c.5344: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\CRYPT32.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
1066506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffedb190000 'C:\WINDOWS\System32\CRYPT32.dll'
1067506c.5344: supR3HardenedDllNotificationCallback: load 00007ffedba90000 LB 0x0001d000 C:\WINDOWS\System32\imagehlp.dll [fFlags=0x0]
1068506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #20 'rpcrt4.dll'.
1069506c.5344: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\imagehlp.dll)
1070506c.5344: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\imagehlp.dll
1071506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
1072506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
1073506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
1074506c.5344: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
1075506c.5344: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
1076506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffed9bc0000 'C:\WINDOWS\system32\rsaenh.dll'
1077506c.5344: supR3HardenedDllNotificationCallback: load 00007ffedcac0000 LB 0x00097000 C:\WINDOWS\System32\sechost.dll [fFlags=0x0]
1078506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'rpcrt4.dll'.
1079506c.5344: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\sechost.dll)
1080506c.5344: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\sechost.dll
1081506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1082506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'rpcrt4.dll'.
1083506c.5344: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\gpapi.dll)
1084506c.5344: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\gpapi.dll
1085506c.5344: supR3HardenedDllNotificationCallback: load 00007ffed9460000 LB 0x00022000 C:\WINDOWS\SYSTEM32\gpapi.dll [fFlags=0x0]
1086506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gpapi.dll [lacks WinVerifyTrust]
1087506c.5344: supR3HardenedDllNotificationCallback: load 00007ffeda8e0000 LB 0x0001f000 C:\WINDOWS\System32\profapi.dll [fFlags=0x0]
1088506c.5344: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\profapi.dll)
1089506c.5344: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\profapi.dll
1090506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1091506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'crypt32.dll'.
1092506c.5344: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\cryptnet.dll)
1093506c.5344: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cryptnet.dll
1094506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
1095506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume2\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
1096506c.5344: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
1097506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1098506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1099506c.5344: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
1100506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
1101506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
1102506c.5344: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
1103506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1104506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1105506c.5344: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
1106506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
1107506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
1108506c.5344: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
1109506c.5344: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (Input=cryptnet.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
1110506c.5344: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
1111506c.5344: supR3HardenedDllNotificationCallback: load 00007ffec95a0000 LB 0x0002f000 C:\WINDOWS\System32\cryptnet.dll [fFlags=0x0]
1112506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
1113506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
1114506c.5344: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
1115506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffec95a0000 'C:\WINDOWS\System32\cryptnet.dll'
1116506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
1117506c.5344: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
1118506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffec95a0000 'C:\WINDOWS\System32\cryptnet.dll'
1119506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
1120506c.5344: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
1121506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffec95a0000 'C:\WINDOWS\System32\cryptnet.dll'
1122506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
1123506c.5344: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
1124506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffec95a0000 'C:\WINDOWS\System32\cryptnet.dll'
1125506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
1126506c.5344: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
1127506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffec95a0000 'C:\WINDOWS\System32\cryptnet.dll'
1128506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
1129506c.5344: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
1130506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffec95a0000 'C:\WINDOWS\System32\cryptnet.dll'
1131506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
1132506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffec95a0000 'C:\WINDOWS\System32\cryptnet.dll'
1133506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
1134506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffec95a0000 'C:\WINDOWS\System32\cryptnet.dll'
1135506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
1136506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffec95a0000 'C:\WINDOWS\System32\cryptnet.dll'
1137506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
1138506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffec95a0000 'C:\WINDOWS\System32\cryptnet.dll'
1139506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
1140506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffec95a0000 'C:\WINDOWS\System32\cryptnet.dll'
1141506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffec95a0000 'C:\WINDOWS\System32\cryptnet.dll'
1142506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
1143506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffec95a0000 'C:\Windows\System32\cryptnet.dll'
1144506c.5344: supR3HardenedDllNotificationCallback: load 00007ffedc2e0000 LB 0x000a3000 C:\WINDOWS\System32\advapi32.dll [fFlags=0x0]
1145506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1146506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'sechost.dll'.
1147506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #27 'rpcrt4.dll'.
1148506c.5344: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\advapi32.dll)
1149506c.5344: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\advapi32.dll
1150506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
1151506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
1152506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
1153506c.5344: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
1154506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'sechost.dll'...
1155506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'sechost.dll' -> '\Device\HarddiskVolume2\Windows\System32\sechost.dll' [rcNtRedir=0xc0150008]
1156506c.5344: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\sechost.dll [lacks WinVerifyTrust]
1157506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1158506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1159506c.5344: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
1160506c.5344: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
1161506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffed9bc0000 'C:\WINDOWS\system32\rsaenh.dll'
1162506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
1163506c.5344: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
1164506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffedb190000 'C:\WINDOWS\System32\crypt32.dll'
1165506c.5344: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000000 pwszName=\SystemRoot\System32\ntdll.dll
1166506c.5344: supR3HardNtViCallWinVerifyTrustCatFile: New context 000000000187bb80
1167506c.5344: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000187bb80
1168506c.5344: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=E42142C43484BA84DDDB10D97303487D47E882DE
1169506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
1170506c.5344: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\rpcrt4.dll (Input=rpcrt4.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
1171506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffedbab0000 'C:\WINDOWS\System32\rpcrt4.dll'
1172506c.5344: supR3HardNtViCallWinVerifyTrustCatFile: CryptCATAdminEnumCatalogFromHash failed ERROR_NOT_FOUND (1168)
1173506c.5344: supR3HardNtViCallWinVerifyTrustCatFile: New context 00000000018937a0
1174506c.5344: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000018937a0
1175506c.5344: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=32 wszDigest=F51F53D8DB5F3ADE5E8F8D8375422AD759A6C4A6995384A6D9FC758F803C765B
1176506c.5344: supR3HardNtViCallWinVerifyTrustCatFile: CryptCATAdminEnumCatalogFromHash failed ERROR_NOT_FOUND (1168)
1177506c.5344: g_pfnWinVerifyTrust=00007ffedaab61f0
1178506c.5344: supR3HardenedScreenImage/preload: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [redoing WinVerifyTrust]
1179506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
1180506c.5344: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
1181506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffed9bc0000 'C:\WINDOWS\system32\rsaenh.dll'
1182506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
1183506c.5344: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
1184506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffedb190000 'C:\WINDOWS\System32\crypt32.dll'
1185506c.5344: supR3HardenedScreenImage/preload: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\crypt32.dll'
1186506c.5344: supR3HardenedScreenImage/preload: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [redoing WinVerifyTrust]
1187506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
1188506c.5344: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
1189506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffed9bc0000 'C:\WINDOWS\system32\rsaenh.dll'
1190506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll
1191506c.5344: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
1192506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffedb190000 'C:\WINDOWS\System32\crypt32.dll'
1193506c.5344: supR3HardenedScreenImage/preload: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\wintrust.dll'
1194506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
1195506c.5344: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
1196506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffed9bc0000 'C:\WINDOWS\system32\rsaenh.dll'
1197506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll
1198506c.5344: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
1199506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffedb190000 'C:\WINDOWS\System32\crypt32.dll'
1200506c.5344: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\advapi32.dll'
1201506c.5344: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000374 pwszName=\Device\HarddiskVolume2\Windows\System32\cryptnet.dll
1202506c.5344: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000187bb80
1203506c.5344: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000187bb80
1204506c.5344: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=09032EBC3D9D9BDDC0EE4A6463C043296B79FF20
1205506c.5344: supR3HardNtViCallWinVerifyTrustCatFile: Retrying with fresh context (CryptCATAdminEnumCatalogFromHash -> 1168; iCat=0x0)
1206506c.5344: supR3HardNtViCallWinVerifyTrustCatFile: New context 0000000001840a20
1207506c.5344: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000001840a20
1208506c.5344: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=09032EBC3D9D9BDDC0EE4A6463C043296B79FF20
1209506c.5344: supR3HardNtViCallWinVerifyTrustCatFile: CryptCATAdminEnumCatalogFromHash failed ERROR_NOT_FOUND (1168)
1210506c.5344: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000018937a0
1211506c.5344: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000018937a0
1212506c.5344: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=32 wszDigest=22186588BDA4845FA9E0DBF8BEA457D094106A66CEA15B5F867FB5BDCE35A45C
1213506c.5344: supR3HardNtViCallWinVerifyTrustCatFile: Retrying with fresh context (CryptCATAdminEnumCatalogFromHash -> 1168; iCat=0x0)
1214506c.5344: supR3HardNtViCallWinVerifyTrustCatFile: New context 00000000018407e0
1215506c.5344: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000018407e0
1216506c.5344: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=32 wszDigest=22186588BDA4845FA9E0DBF8BEA457D094106A66CEA15B5F867FB5BDCE35A45C
1217506c.5344: supR3HardNtViCallWinVerifyTrustCatFile: CryptCATAdminEnumCatalogFromHash failed ERROR_NOT_FOUND (1168)
1218506c.5344: supR3HardNtViCallWinVerifyTrustCatFile -> -22900 (org 22900)
1219506c.5344: supR3HardenedWinVerifyCacheProcessWvtTodos: -22900 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\cryptnet.dll'
1220506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
1221506c.5344: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
1222506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffed9bc0000 'C:\WINDOWS\system32\rsaenh.dll'
1223506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffedb190000 'C:\WINDOWS\System32\crypt32.dll'
1224506c.5344: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\profapi.dll'
1225506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
1226506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffed9bc0000 'C:\WINDOWS\system32\rsaenh.dll'
1227506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffedb190000 'C:\WINDOWS\System32\crypt32.dll'
1228506c.5344: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\gpapi.dll'
1229506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
1230506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffed9bc0000 'C:\WINDOWS\system32\rsaenh.dll'
1231506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffedb190000 'C:\WINDOWS\System32\crypt32.dll'
1232506c.5344: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\sechost.dll'
1233506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
1234506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffed9bc0000 'C:\WINDOWS\system32\rsaenh.dll'
1235506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffedb190000 'C:\WINDOWS\System32\crypt32.dll'
1236506c.5344: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\imagehlp.dll'
1237506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
1238506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffed9bc0000 'C:\WINDOWS\system32\rsaenh.dll'
1239506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffedb190000 'C:\WINDOWS\System32\crypt32.dll'
1240506c.5344: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\cryptbase.dll'
1241506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
1242506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffed9bc0000 'C:\WINDOWS\system32\rsaenh.dll'
1243506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffedb190000 'C:\WINDOWS\System32\crypt32.dll'
1244506c.5344: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\rsaenh.dll'
1245506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffed9bc0000 'C:\WINDOWS\system32\rsaenh.dll'
1246506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffedb190000 'C:\WINDOWS\System32\crypt32.dll'
1247506c.5344: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\cryptsp.dll'
1248506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffed9bc0000 'C:\WINDOWS\system32\rsaenh.dll'
1249506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll
1250506c.5344: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
1251506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffedb190000 'C:\WINDOWS\System32\crypt32.dll'
1252506c.5344: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll'
1253506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll
1254506c.5344: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
1255506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffed9bc0000 'C:\WINDOWS\system32\rsaenh.dll'
1256506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffedb190000 'C:\WINDOWS\System32\crypt32.dll'
1257506c.5344: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\bcrypt.dll'
1258506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffed9bc0000 'C:\WINDOWS\system32\rsaenh.dll'
1259506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffedb190000 'C:\WINDOWS\System32\crypt32.dll'
1260506c.5344: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\ucrtbase.dll'
1261506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffed9bc0000 'C:\WINDOWS\system32\rsaenh.dll'
1262506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffedb190000 'C:\WINDOWS\System32\crypt32.dll'
1263506c.5344: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll'
1264506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffed9bc0000 'C:\WINDOWS\system32\rsaenh.dll'
1265506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffedb190000 'C:\WINDOWS\System32\crypt32.dll'
1266506c.5344: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\msasn1.dll'
1267506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffed9bc0000 'C:\WINDOWS\system32\rsaenh.dll'
1268506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffedb190000 'C:\WINDOWS\System32\crypt32.dll'
1269506c.5344: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll'
1270506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffed9bc0000 'C:\WINDOWS\system32\rsaenh.dll'
1271506c.5344: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 24202) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxSupLib.dll'
1272506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffed9bc0000 'C:\WINDOWS\system32\rsaenh.dll'
1273506c.5344: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 24202) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe'
1274506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffed9bc0000 'C:\WINDOWS\system32\rsaenh.dll'
1275506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffedb190000 'C:\WINDOWS\System32\crypt32.dll'
1276506c.5344: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\KernelBase.dll'
1277506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffed9bc0000 'C:\WINDOWS\system32\rsaenh.dll'
1278506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffedb190000 'C:\WINDOWS\System32\crypt32.dll'
1279506c.5344: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\kernel32.dll'
1280506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffedb190000 'C:\WINDOWS\system32\crypt32.dll'
1281506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0x5ad46780fa5df300 DC=com, DC=microsoft, CN=Microsoft Root Certificate Authority
1282506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0xea5386456178582b C=ZA, ST=Western Cape, L=Durbanville, O=Thawte, OU=Thawte Certification, CN=Thawte Timestamping CA
1283506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0x3be670c1bd02a900 OU=Copyright (c) 1997 Microsoft Corp., OU=Microsoft Corporation, CN=Microsoft Root Authority
1284506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0xe991ee72b03db500 C=US, O=Symantec Corporation, CN=Symantec Enterprise Mobile Root for Microsoft
1285506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0x4d3835aa4180b200 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2011
1286506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0x646e3fe3ba08df00 C=US, O=MSFT, CN=Microsoft Authenticode(tm) Root Authority
1287506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0x2bc683c58e2cbc00 O=AO Kaspersky Lab, CN=Kaspersky Anti-Virus Personal Root Certificate
1288506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0x5d69cb6e161d56a6 CN=ADELIO-TOSH
1289506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0x5e15181e66d5693c CN=Schneider Electric (XBTZG935)
1290506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0x9942683711eed300 CN=ADELIO-TOSH
1291506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0xece4e4289e08b900 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010
1292506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0x8cfc0497215eae81 CN=Delta Electronics Inc.
1293506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0xf3bb4d7e894b420 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft ECC TS Root Certificate Authority 2018
1294506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0x43a9cc371ff5385a O=Microsoft Trust Network, OU=Microsoft Corporation, OU=Microsoft Time Stamping Service Root, OU=Copyright (c) 1997 Microsoft Corp.
1295506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0x2e2d2c7c68f0202e O=VeriSign Trust Network, OU=VeriSign, Inc., OU=VeriSign Time Stamping Service Root, OU=NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.
1296506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0xcec3d46562b9be8e C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft ECC Product Root Certificate Authority 2018
1297506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0xca58a05dd401ae00 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Time Stamp Root Certificate Authority 2014
1298506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0x2ca429a5c4c6a700 C=IT, L=Milan, O=Actalis S.p.A./03358520967, CN=Actalis Authentication Root CA
1299506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0xd8dbfb2c27bfb200 C=US, O=thawte, Inc., OU=Certification Services Division, OU=(c) 2008 thawte, Inc. - For authorized use only, CN=thawte Primary Root CA - G3
1300506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0x61a3a33f81aace00 C=US, ST=UT, L=Salt Lake City, O=The USERTRUST Network, OU=http://www.usertrust.com, CN=UTN-USERFirst-Object
1301506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0x50bb81640c01cb00 C=TW, O=TAIWAN-CA, OU=Root CA, CN=TWCA Root Certification Authority
1302506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0x6b7bdc34cd37bb00 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root G2
1303506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0xf4fd306318ccda00 C=US, O=GeoTrust Inc., CN=GeoTrust Global CA
1304506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0x83085097e9afdf00 O=Digital Signature Trust Co., CN=DST Root CA X3
1305506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0xe248b7eeee4af00 C=CH, O=SwissSign AG, CN=SwissSign Gold CA - G2
1306506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0x780679907625cc00 OU=GlobalSign Root CA - R3, O=GlobalSign, CN=GlobalSign
1307506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0x3d98ab22bb04a300 C=IE, O=Baltimore, OU=CyberTrust, CN=Baltimore CyberTrust Root
1308506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0xa0ee62086758b15d C=US, O=Equifax, OU=Equifax Secure Certificate Authority
1309506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0xeae16ef49d40be00 C=GB, ST=Greater Manchester, L=Salford, O=Comodo CA Limited, CN=AAA Certificate Services
1310506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0xc6536f24d57ae723 C=US, ST=New Jersey, L=Jersey City, O=The USERTRUST Network, CN=USERTrust ECC Certification Authority
1311506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0x9403a4b8727eb000 C=TW, O=TAIWAN-CA, OU=Root CA, CN=TWCA Root Certification Authority
1312506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0xd944bca189a00 C=BM, O=QuoVadis Limited, CN=QuoVadis Root CA 2
1313506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0x8ff6fc03c1edbd00 C=US, ST=Arizona, L=Scottsdale, O=Starfield Technologies, Inc., CN=Starfield Root Certificate Authority - G2
1314506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0xc6fa4243b695b600 C=US, O=Entrust, Inc., OU=www.entrust.net/CPS is incorporated by reference, OU=(c) 2006 Entrust, Inc., CN=Entrust Root Certification Authority
1315506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0xa3ce8d99e60eda00 C=BE, O=GlobalSign nv-sa, OU=Root CA, CN=GlobalSign Root CA
1316506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0x560ad29254e89100 C=GB, ST=Greater Manchester, L=Salford, O=COMODO CA Limited, CN=COMODO RSA Certification Authority
1317506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0xa671e9fec832b700 C=US, O=Starfield Technologies, Inc., OU=Starfield Class 2 Certification Authority
1318506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0xa8de7211e13be200 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root CA
1319506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0x7ae89c50f0b6a00f C=US, O=GTE Corporation, OU=GTE CyberTrust Solutions, Inc., CN=GTE CyberTrust Global Root
1320506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0xd45980fbf0a0ac00 C=US, O=thawte, Inc., OU=Certification Services Division, OU=(c) 2006 thawte, Inc. - For authorized use only, CN=thawte Primary Root CA
1321506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0xc9edb72b684ba00 C=US, O=Entrust, Inc., OU=See www.entrust.net/legal-terms, OU=(c) 2009 Entrust, Inc. - for authorized use only, CN=Entrust Root Certification Authority - G2
1322506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0xf5cd95e581a4ab00 C=US, O=SecureTrust Corporation, CN=SecureTrust CA
1323506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0xbebef0d2217f0bfb C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root G3
1324506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0x802b3770cb00af00 C=EU, L=Madrid (see current address at www.camerfirma.com/address), SRN=A82743287, O=AC Camerfirma S.A., CN=Chambers of Commerce Root - 2008
1325506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0x6f2ebe0e24cfa600 OU=GlobalSign Root CA - R2, O=GlobalSign, CN=GlobalSign
1326506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0x14018a1bf29e595c C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority
1327506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0x9e5bc2d78b6a3636 C=ZA, ST=Western Cape, L=Cape Town, O=Thawte Consulting cc, OU=Certification Services Division, CN=Thawte Premium Server CA, Email=premium-server@thawte.com
1328506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0x7c4fd32ec1b1ce00 C=PL, O=Unizeto Sp. z o.o., CN=Certum CA
1329506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0xdb2cd5c20d0aaf00 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 1999 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 2 Public Primary Certification Authority - G3
1330506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0xd4fbe673e5ccc600 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA
1331506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0xb352b1523915d000 C=JP, O=SECOM Trust Systems CO.,LTD., OU=Security Communication RootCA2
1332506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0x73e85f1bda5faa00 C=DE, O=T-Systems Enterprise Services GmbH, OU=T-Systems Trust Center, CN=T-TeleSec GlobalRoot Class 2
1333506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0xef477acf4ab2d300 C=DE, O=D-Trust GmbH, CN=D-TRUST Root Class 3 CA 2 2009
1334506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0x1b8578514b74ac00 C=US, O=WFA Hotspot 2.0, CN=Hotspot 2.0 Trust Root CA - 03
1335506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0xb28612a94b4dad00 O=Entrust.net, OU=www.entrust.net/CPS_2048 incorp. by ref. (limits liab.), OU=(c) 1999 Entrust.net Limited, CN=Entrust.net Certification Authority (2048)
1336506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0x357a29080824af00 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2006 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G5
1337506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0x9b3ae4d356dfc000 C=EU, L=Madrid (see current address at www.camerfirma.com/address), SRN=A82743287, O=AC Camerfirma S.A., CN=Global Chambersign Root - 2008
1338506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0x59faf1086271bf00 C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com, Inc., CN=Go Daddy Root Certificate Authority - G2
1339506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0xbb6e19f43fdcce00 C=PT, O=MULTICERT - Serviços de Certificação Electrónica S.A., CN=MULTICERT Root Certification Authority 01
1340506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0xa321f027ebbec200 O=TeliaSonera, CN=TeliaSonera Root CA v1
1341506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0x466cbc09db88c100 C=IL, O=StartCom Ltd., OU=Secure Digital Certificate Signing, CN=StartCom Certification Authority
1342506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0xb16dd37ffeb3b300 C=JP, O=SECOM Trust.net, OU=Security Communication RootCA1
1343506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0x3401b15e3761c700 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2008 VeriSign, Inc. - For authorized use only, CN=VeriSign Universal Root Certification Authority
1344506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0x7cd4ff7b15b8be00 C=US, O=GeoTrust Inc., CN=GeoTrust Primary Certification Authority
1345506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0xac1e0fca7ad3c900 C=ES, O=IZENPE S.A., CN=Izenpe.com
1346506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0x3b2a6f973b859500 CN=Atos TrustedRoot 2011, O=Atos, C=DE
1347506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0xc30e361765128000 C=US, ST=New Jersey, L=Jersey City, O=The USERTRUST Network, CN=USERTrust RSA Certification Authority
1348506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0x491857ead79dde00 C=US, O=The Go Daddy Group, Inc., OU=Go Daddy Class 2 Certification Authority
1349506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0xab549401526569d3 L=Internet, O=VeriSign, Inc., OU=VeriSign Commercial Software Publishers CA
1350506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0xa7f9b4b9d484dd00 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 1999 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 1 Public Primary Certification Authority - G3
1351506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0xdc1801b225aea100 C=BM, O=QuoVadis Limited, CN=QuoVadis Root CA 2 G3
1352506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0xc2ba72a37dfbe300 C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Trusted Network CA
1353506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0xcec3d46562b9be8e C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft ECC Product Root Certificate Authority 2018
1354506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0x8043e4ce150ead00 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID Root CA
1355506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0x331d58625ee2dc00 C=US, O=GeoTrust Inc., OU=(c) 2008 GeoTrust Inc. - For authorized use only, CN=GeoTrust Primary Certification Authority - G3
1356506c.5344: supR3HardenedWinIsDesiredRootCA: Adding 0xf2e6331af7b700 C=SE, O=AddTrust AB, OU=AddTrust External TTP Network, CN=AddTrust External CA Root
1357506c.5344: supR3HardenedWinRetrieveTrustedRootCAs: cAdded=76
1358506c.5344: SUPR3HardenedMain: Load Runtime...
1359506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffed9bc0000 'C:\WINDOWS\system32\rsaenh.dll'
1360506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
1361506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
1362506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rpcrt4.dll'.
1363506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ws2_32.dll'.
1364506c.5344: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll) WinVerifyTrust
1365506c.5344: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
1366506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
1367506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
1368506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffed9bc0000 'C:\WINDOWS\system32\rsaenh.dll'
1369506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffedb190000 'C:\WINDOWS\System32\crypt32.dll'
1370506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'rpcrt4.dll'.
1371506c.5344: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ws2_32.dll) WinVerifyTrust
1372506c.5344: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
1373506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
1374506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
1375506c.5344: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
1376506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
1377506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
1378506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
1379506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
1380506c.5344: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
1381506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffed9bc0000 'C:\WINDOWS\system32\rsaenh.dll'
1382506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
1383506c.5344: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll) WinVerifyTrust
1384506c.5344: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
1385506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
1386506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
1387506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
1388506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
1389506c.5344: Detected WinVerifyTrust recursion: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll'.
1390506c.5344: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll)
1391506c.5344: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
1392506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffed9bc0000 'C:\WINDOWS\system32\rsaenh.dll'
1393506c.5344: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll) WinVerifyTrust
1394506c.5344: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000a01:<flags> [calling]
1395506c.5344: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
1396506c.5344: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll [avoiding WinVerifyTrust]
1397506c.5344: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
1398506c.5344: supR3HardenedDllNotificationCallback: load 0000000077570000 LB 0x000d2000 C:\Program Files\Oracle\VirtualBox\MSVCR100.dll [fFlags=0x0]
1399506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll [avoiding WinVerifyTrust]
1400506c.5344: supR3HardenedDllNotificationCallback: load 00000000769f0000 LB 0x00098000 C:\Program Files\Oracle\VirtualBox\MSVCP100.dll [fFlags=0x0]
1401506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
1402506c.5344: supR3HardenedDllNotificationCallback: load 00007ffedc530000 LB 0x0006f000 C:\WINDOWS\System32\WS2_32.dll [fFlags=0x0]
1403506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
1404506c.5344: supR3HardenedDllNotificationCallback: load 00007ffea0270000 LB 0x005e2000 C:\Program Files\Oracle\VirtualBox\VBoxRT.dll [fFlags=0x0]
1405506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
1406506c.5344: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll'.
1407506c.5344: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
1408506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
1409506c.5344: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
1410506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffea0270000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1411506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
1412506c.5344: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
1413506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffea0270000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1414506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
1415506c.5344: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
1416506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffea0270000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1417506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
1418506c.5344: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
1419506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffea0270000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1420506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
1421506c.5344: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
1422506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffea0270000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1423506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
1424506c.5344: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
1425506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffea0270000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1426506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffea0270000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1427506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffea0270000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1428506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffea0270000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1429506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffea0270000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1430506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffea0270000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1431506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffea0270000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1432506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffea0270000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1433506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
1434506c.5344: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
1435506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffea0270000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1436506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffea0270000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1437506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffea0270000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1438506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffea0270000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1439506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffea0270000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1440506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffea0270000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1441506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffea0270000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1442506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffea0270000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1443506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffea0270000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1444506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffea0270000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1445506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffea0270000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1446506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffea0270000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1447506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffea0270000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1448506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffea0270000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1449506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffea0270000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1450506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffea0270000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1451506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
1452506c.5344: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
1453506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffea0270000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1454506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffea0270000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1455506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffea0270000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1456506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffea0270000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
1457506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll
1458506c.5344: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
1459506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffedaab0000 'C:\WINDOWS\system32\Wintrust.dll'
1460506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffed9bc0000 'C:\WINDOWS\system32\rsaenh.dll'
1461506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffedb190000 'C:\WINDOWS\System32\crypt32.dll'
1462506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffedb190000 'C:\WINDOWS\system32\crypt32.dll'
1463506c.5344: SUPR3HardenedMain: Load TrustedMain...
1464506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffed9bc0000 'C:\WINDOWS\system32\rsaenh.dll'
1465506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'opengl32.dll'.
1466506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxglobal.dll'.
1467506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
1468506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcp100.dll'.
1469506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msvcr100.dll'.
1470506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'qt5corevbox.dll'.
1471506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'qt5guivbox.dll'.
1472506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'qt5widgetsvbox.dll'.
1473506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'qt5openglvbox.dll'.
1474506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'user32.dll'.
1475506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'ole32.dll'.
1476506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'oleaut32.dll'.
1477506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'winmm.dll'.
1478506c.5344: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll) WinVerifyTrust
1479506c.5344: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll
1480506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
1481506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
1482506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffed9bc0000 'C:\WINDOWS\system32\rsaenh.dll'
1483506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffedb190000 'C:\WINDOWS\System32\crypt32.dll'
1484506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'winmmbase.dll'.
1485506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msvcrt.dll'.
1486506c.5344: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\winmm.dll) WinVerifyTrust
1487506c.5344: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\winmm.dll
1488506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
1489506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
1490506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll
1491506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1492506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1493506c.5344: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
1494506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmmbase.dll'...
1495506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmmbase.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmmbase.dll' [rcNtRedir=0xc0150008]
1496506c.5344: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\winmmbase.dll'.
1497506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1498506c.5344: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\winmmbase.dll)
1499506c.5344: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\winmmbase.dll
1500506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1501506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1502506c.5344: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
1503506c.5344: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
1504506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffed9bc0000 'C:\WINDOWS\system32\rsaenh.dll'
1505506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffedb190000 'C:\WINDOWS\System32\crypt32.dll'
1506506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
1507506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'combase.dll'.
1508506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'rpcrt4.dll'.
1509506c.5344: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\oleaut32.dll) WinVerifyTrust
1510506c.5344: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
1511506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
1512506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
1513506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
1514506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
1515506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
1516506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume2\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
1517506c.5344: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\combase.dll'.
1518506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rpcrt4.dll'.
1519506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #46 'bcryptprimitives.dll'.
1520506c.5344: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\combase.dll)
1521506c.5344: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\combase.dll
1522506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
1523506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
1524506c.5344: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\msvcp_win.dll'.
1525506c.5344: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\msvcp_win.dll)
1526506c.5344: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msvcp_win.dll
1527506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcryptprimitives.dll'...
1528506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcryptprimitives.dll' -> '\Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll' [rcNtRedir=0xc0150008]
1529506c.5344: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll
1530506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
1531506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
1532506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffed9bc0000 'C:\WINDOWS\system32\rsaenh.dll'
1533506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffedb190000 'C:\WINDOWS\System32\crypt32.dll'
1534506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #22 'rpcrt4.dll'.
1535506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #56 'gdi32.dll'.
1536506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #57 'user32.dll'.
1537506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #58 'combase.dll'.
1538506c.5344: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ole32.dll) WinVerifyTrust
1539506c.5344: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ole32.dll
1540506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1541506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1542506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
1543506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume2\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
1544506c.5344: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\combase.dll [lacks WinVerifyTrust]
1545506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1546506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1547506c.5344: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\user32.dll'.
1548506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'win32u.dll'.
1549506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #34 'gdi32.dll'.
1550506c.5344: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\user32.dll)
1551506c.5344: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\user32.dll
1552506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1553506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1554506c.5344: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\gdi32.dll'.
1555506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'win32u.dll'.
1556506c.5344: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\gdi32.dll)
1557506c.5344: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\gdi32.dll
1558506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
1559506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
1560506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
1561506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume2\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
1562506c.5344: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\win32u.dll'.
1563506c.5344: '\Device\HarddiskVolume2\Windows\System32\win32u.dll' has no imports
1564506c.5344: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\win32u.dll)
1565506c.5344: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\win32u.dll
1566506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1567506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1568506c.5344: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
1569506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
1570506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume2\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
1571506c.5344: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\win32u.dll [lacks WinVerifyTrust]
1572506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffed9bc0000 'C:\WINDOWS\system32\rsaenh.dll'
1573506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffedb190000 'C:\WINDOWS\System32\crypt32.dll'
1574506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'win32u.dll'.
1575506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #34 'gdi32.dll'.
1576506c.5344: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\user32.dll) WinVerifyTrust
1577506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5openglvbox.dll'...
1578506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5openglvbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5openglvbox.dll' [rcNtRedir=0xc0150008]
1579506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1580506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1581506c.5344: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
1582506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
1583506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume2\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
1584506c.5344: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\win32u.dll [lacks WinVerifyTrust]
1585506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffed9bc0000 'C:\WINDOWS\system32\rsaenh.dll'
1586506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'qt5widgetsvbox.dll'.
1587506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'qt5guivbox.dll'.
1588506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5corevbox.dll'.
1589506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcr100.dll'.
1590506c.5344: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll) WinVerifyTrust
1591506c.5344: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll
1592506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
1593506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
1594506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
1595506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
1596506c.5344: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
1597506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
1598506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
1599506c.5344: Detected WinVerifyTrust recursion: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll'.
1600506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
1601506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'shell32.dll'.
1602506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ole32.dll'.
1603506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
1604506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ws2_32.dll'.
1605506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'mpr.dll'.
1606506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'msvcp100.dll'.
1607506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'msvcr100.dll'.
1608506c.5344: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll)
1609506c.5344: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
1610506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
1611506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
1612506c.5344: Detected WinVerifyTrust recursion: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll'.
1613506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ole32.dll'.
1614506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'opengl32.dll'.
1615506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
1616506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
1617506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qt5corevbox.dll'.
1618506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcp100.dll'.
1619506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msvcr100.dll'.
1620506c.5344: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll)
1621506c.5344: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
1622506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
1623506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
1624506c.5344: Detected WinVerifyTrust recursion: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll'.
1625506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
1626506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
1627506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5guivbox.dll'.
1628506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qt5corevbox.dll'.
1629506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'shell32.dll'.
1630506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcp100.dll'.
1631506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msvcr100.dll'.
1632506c.5344: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll)
1633506c.5344: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll
1634506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
1635506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
1636506c.5344: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
1637506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
1638506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
1639506c.5344: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
1640506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
1641506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
1642506c.5344: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\shell32.dll'.
1643506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #77 'user32.dll'.
1644506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #79 'gdi32.dll'.
1645506c.5344: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\shell32.dll)
1646506c.5344: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\shell32.dll
1647506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
1648506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
1649506c.5344: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [lacks WinVerifyTrust]
1650506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
1651506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
1652506c.5344: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll [lacks WinVerifyTrust]
1653506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1654506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1655506c.5344: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
1656506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1657506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1658506c.5344: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
1659506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
1660506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
1661506c.5344: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
1662506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
1663506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
1664506c.5344: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
1665506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
1666506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
1667506c.5344: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [lacks WinVerifyTrust]
1668506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1669506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1670506c.5344: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
1671506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1672506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1673506c.5344: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
1674506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
1675506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
1676506c.5344: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume2\Windows\System32\opengl32.dll'.
1677506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1678506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'advapi32.dll'.
1679506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
1680506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
1681506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'glu32.dll'.
1682506c.5344: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\opengl32.dll)
1683506c.5344: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\opengl32.dll
1684506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
1685506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
1686506c.5344: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
1687506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
1688506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
1689506c.5344: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
1690506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
1691506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
1692506c.5344: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
1693506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mpr.dll'...
1694506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'mpr.dll' -> '\Device\HarddiskVolume2\Windows\System32\mpr.dll' [rcNtRedir=0xc0150008]
1695506c.5344: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume2\Windows\System32\mpr.dll'.
1696506c.5344: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\mpr.dll)
1697506c.5344: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\mpr.dll
1698506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
1699506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
1700506c.5344: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
1701506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
1702506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
1703506c.5344: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
1704506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
1705506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
1706506c.5344: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
1707506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
1708506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
1709506c.5344: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll [lacks WinVerifyTrust]
1710506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1711506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1712506c.5344: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
1713506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'glu32.dll'...
1714506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'glu32.dll' -> '\Device\HarddiskVolume2\Windows\System32\glu32.dll' [rcNtRedir=0xc0150008]
1715506c.5344: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume2\Windows\System32\glu32.dll'.
1716506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
1717506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
1718506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'opengl32.dll'.
1719506c.5344: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\glu32.dll)
1720506c.5344: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\glu32.dll
1721506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1722506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1723506c.5344: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
1724506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1725506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1726506c.5344: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
1727506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
1728506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
1729506c.5344: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
1730506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1731506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1732506c.5344: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
1733506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1734506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1735506c.5344: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
1736506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1737506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1738506c.5344: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
1739506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
1740506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
1741506c.5344: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll [lacks WinVerifyTrust]
1742506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1743506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1744506c.5344: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
1745506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
1746506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
1747506c.5344: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
1748506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffed9bc0000 'C:\WINDOWS\system32\rsaenh.dll'
1749506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
1750506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
1751506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5guivbox.dll'.
1752506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qt5corevbox.dll'.
1753506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'shell32.dll'.
1754506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcp100.dll'.
1755506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msvcr100.dll'.
1756506c.5344: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll) WinVerifyTrust
1757506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
1758506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
1759506c.5344: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll [redoing WinVerifyTrust]
1760506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
1761506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
1762506c.5344: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
1763506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
1764506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
1765506c.5344: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
1766506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
1767506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
1768506c.5344: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll [lacks WinVerifyTrust]
1769506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
1770506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
1771506c.5344: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [lacks WinVerifyTrust]
1772506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
1773506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
1774506c.5344: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll [lacks WinVerifyTrust]
1775506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1776506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1777506c.5344: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
1778506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
1779506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
1780506c.5344: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
1781506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffed9bc0000 'C:\WINDOWS\system32\rsaenh.dll'
1782506c.5344: supR3HardenedScreenImage/Imports: 0 (was 24202) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll'
1783506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
1784506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
1785506c.5344: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [redoing WinVerifyTrust]
1786506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffed9bc0000 'C:\WINDOWS\system32\rsaenh.dll'
1787506c.5344: supR3HardenedScreenImage/Imports: 0 (was 24202) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll'
1788506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
1789506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
1790506c.5344: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll [redoing WinVerifyTrust]
1791506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffed9bc0000 'C:\WINDOWS\system32\rsaenh.dll'
1792506c.5344: supR3HardenedScreenImage/Imports: 0 (was 24202) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll'
1793506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
1794506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
1795506c.5344: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
1796506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
1797506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
1798506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxglobal.dll'...
1799506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxglobal.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxglobal.dll' [rcNtRedir=0xc0150008]
1800506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffed9bc0000 'C:\WINDOWS\system32\rsaenh.dll'
1801506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'vboxrt.dll'.
1802506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcr100.dll'.
1803506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5corevbox.dll'.
1804506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qt5guivbox.dll'.
1805506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qt5widgetsvbox.dll'.
1806506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
1807506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'advapi32.dll'.
1808506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'ole32.dll'.
1809506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'oleaut32.dll'.
1810506c.5344: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'rpcrt4.dll'.
1811506c.5344: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxGlobal.dll) WinVerifyTrust
1812506c.5344: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxGlobal.dll
1813506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
1814506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
1815506c.5344: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll [redoing WinVerifyTrust]
1816506c.5344: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000464 pwszName=\Device\HarddiskVolume2\Windows\System32\opengl32.dll
1817506c.5344: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000001840a20
1818506c.5344: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000001840a20
1819506c.5344: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=0837440FAE05EB650168FFA2D15E73182F6A3A26
1820506c.5344: supR3HardNtViCallWinVerifyTrustCatFile: Retrying with fresh context (CryptCATAdminEnumCatalogFromHash -> 1168; iCat=0x0)
1821506c.5344: supR3HardNtViCallWinVerifyTrustCatFile: New context 00000000018401e0
1822506c.5344: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000018401e0
1823506c.5344: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=0837440FAE05EB650168FFA2D15E73182F6A3A26
1824506c.5344: supR3HardNtViCallWinVerifyTrustCatFile: CryptCATAdminEnumCatalogFromHash failed ERROR_NOT_FOUND (1168)
1825506c.5344: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000018407e0
1826506c.5344: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000018407e0
1827506c.5344: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=32 wszDigest=6622493BDCECA5422FCE0B921D6626202D89C04B3EFCC5A76BF19A9905D8BD33
1828506c.5344: supR3HardNtViCallWinVerifyTrustCatFile: Retrying with fresh context (CryptCATAdminEnumCatalogFromHash -> 1168; iCat=0x0)
1829506c.5344: supR3HardNtViCallWinVerifyTrustCatFile: New context 000000000183ffa0
1830506c.5344: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000183ffa0
1831506c.5344: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=32 wszDigest=6622493BDCECA5422FCE0B921D6626202D89C04B3EFCC5A76BF19A9905D8BD33
1832506c.5344: supR3HardNtViCallWinVerifyTrustCatFile: CryptCATAdminEnumCatalogFromHash failed ERROR_NOT_FOUND (1168)
1833506c.5344: supR3HardNtViCallWinVerifyTrustCatFile -> -22900 (org 22900)
1834506c.5344: supR3HardenedScreenImage/Imports: -22900 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\opengl32.dll'
1835506c.5344: Error (rc=0):
1836506c.5344: supR3HardenedScreenImage/Imports: cached rc=Unknown Status -22900 (0xffffa68c) fImage=1 fProtect=0x0 fAccess=0x0 cHits=2 \Device\HarddiskVolume2\Windows\System32\opengl32.dll
1837506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
1838506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
1839506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
1840506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
1841506c.5344: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
1842506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
1843506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
1844506c.5344: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
1845506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
1846506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
1847506c.5344: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
1848506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
1849506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
1850506c.5344: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll [redoing WinVerifyTrust]
1851506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffed9bc0000 'C:\WINDOWS\system32\rsaenh.dll'
1852506c.5344: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll
1853506c.5344: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
1854506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffedb190000 'C:\WINDOWS\System32\crypt32.dll'
1855506c.5344: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\user32.dll'
1856506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
1857506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
1858506c.5344: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll [redoing WinVerifyTrust]
1859506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffed9bc0000 'C:\WINDOWS\system32\rsaenh.dll'
1860506c.5344: supR3HardenedScreenImage/Imports: 0 (was 24202) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll'
1861506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
1862506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
1863506c.5344: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
1864506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
1865506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
1866506c.5344: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
1867506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
1868506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
1869506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
1870506c.5344: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
1871506c.5344: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000a01:<flags> [calling]
1872506c.5344: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll
1873506c.5344: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status -22900 (0xffffa68c)) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
1874506c.5344: Error (rc=0):
1875506c.5344: supR3HardenedScreenImage/NtCreateSection: cached rc=Unknown Status -22900 (0xffffa68c) fImage=1 fProtect=0x10 fAccess=0xd cHits=3 \Device\HarddiskVolume2\Windows\System32\opengl32.dll
1876506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000190 'C:\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll'
1877506c.5344: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000504 pwszName=\Device\HarddiskVolume2\Windows\System32\glu32.dll
1878506c.5344: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000018401e0
1879506c.5344: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000018401e0
1880506c.5344: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=F356C86D0A2DBA0570D09B39D4AF818DFCB17010
1881506c.5344: supR3HardNtViCallWinVerifyTrustCatFile: Retrying with fresh context (CryptCATAdminEnumCatalogFromHash -> 1168; iCat=0x0)
1882506c.5344: supR3HardNtViCallWinVerifyTrustCatFile: New context 00000000018401e0
1883506c.5344: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000018401e0
1884506c.5344: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=F356C86D0A2DBA0570D09B39D4AF818DFCB17010
1885506c.5344: supR3HardNtViCallWinVerifyTrustCatFile: CryptCATAdminEnumCatalogFromHash failed ERROR_NOT_FOUND (1168)
1886506c.5344: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000183ffa0
1887506c.5344: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000183ffa0
1888506c.5344: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=32 wszDigest=41D97903DE3C10BFE43059393A6DD1DB671F42BFA9627D4C98589CCC6ADA69C2
1889506c.5344: supR3HardNtViCallWinVerifyTrustCatFile: Retrying with fresh context (CryptCATAdminEnumCatalogFromHash -> 1168; iCat=0x0)
1890506c.5344: supR3HardNtViCallWinVerifyTrustCatFile: New context 0000000001840060
1891506c.5344: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000001840060
1892506c.5344: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=32 wszDigest=41D97903DE3C10BFE43059393A6DD1DB671F42BFA9627D4C98589CCC6ADA69C2
1893506c.5344: supR3HardNtViCallWinVerifyTrustCatFile: CryptCATAdminEnumCatalogFromHash failed ERROR_NOT_FOUND (1168)
1894506c.5344: supR3HardNtViCallWinVerifyTrustCatFile -> -22900 (org 22900)
1895506c.5344: supR3HardenedWinVerifyCacheProcessWvtTodos: -22900 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\glu32.dll'
1896506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffed9bc0000 'C:\WINDOWS\system32\rsaenh.dll'
1897506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffedb190000 'C:\WINDOWS\System32\crypt32.dll'
1898506c.5344: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\mpr.dll'
1899506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffed9bc0000 'C:\WINDOWS\system32\rsaenh.dll'
1900506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffedb190000 'C:\WINDOWS\System32\crypt32.dll'
1901506c.5344: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\shell32.dll'
1902506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffed9bc0000 'C:\WINDOWS\system32\rsaenh.dll'
1903506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffedb190000 'C:\WINDOWS\System32\crypt32.dll'
1904506c.5344: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\win32u.dll'
1905506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffed9bc0000 'C:\WINDOWS\system32\rsaenh.dll'
1906506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffedb190000 'C:\WINDOWS\System32\crypt32.dll'
1907506c.5344: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\gdi32.dll'
1908506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffed9bc0000 'C:\WINDOWS\system32\rsaenh.dll'
1909506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffedb190000 'C:\WINDOWS\System32\crypt32.dll'
1910506c.5344: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\msvcp_win.dll'
1911506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffed9bc0000 'C:\WINDOWS\system32\rsaenh.dll'
1912506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffedb190000 'C:\WINDOWS\System32\crypt32.dll'
1913506c.5344: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\combase.dll'
1914506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffed9bc0000 'C:\WINDOWS\system32\rsaenh.dll'
1915506c.5344: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffedb190000 'C:\WINDOWS\System32\crypt32.dll'
1916506c.5344: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\winmmbase.dll'
1917506c.5344: Fatal error:
1918506c.5344: supR3HardenedMainGetTrustedMain: LoadLibrary "C:\Program Files\Oracle\VirtualBox/VirtualBoxVM.dll" failed, rc=1790
191915e8.2fc8: supR3HardNtChildWaitFor[2]: Quitting: ExitCode=0x1 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 4957 ms, the end);
192018c0.2284: supR3HardNtChildWaitFor[1]: Quitting: ExitCode=0x1 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 6207 ms, the end);

© 2024 Oracle Support Privacy / Do Not Sell My Info Terms of Use Trademark Policy Automated Access Etiquette