VirtualBox

Ticket #19576: VBoxHardening.log

File VBoxHardening.log, 503.7 KB (added by ci-zephyurus, 4 years ago)

VBoxHardening.log when virtualbox crashed under host windows 10

Line 
16cec.6cf0: Log file opened: 6.1.4r136177 g_hStartupLog=0000000000000090 g_uNtVerCombined=0xa047bb00
26cec.6cf0: \SystemRoot\System32\ntdll.dll:
36cec.6cf0: CreationTime: 2020-05-03T03:29:33.075535900Z
46cec.6cf0: LastWriteTime: 2020-05-03T03:29:33.128546900Z
56cec.6cf0: ChangeTime: 2020-05-04T03:07:36.221273200Z
66cec.6cf0: FileAttributes: 0x20
76cec.6cf0: Size: 0x1e8460
86cec.6cf0: NT Headers: 0xd8
96cec.6cf0: Timestamp: 0xb29ecf52
106cec.6cf0: Machine: 0x8664 - amd64
116cec.6cf0: Timestamp: 0xb29ecf52
126cec.6cf0: Image Version: 10.0
136cec.6cf0: SizeOfImage: 0x1f0000 (2031616)
146cec.6cf0: Resource Dir: 0x17f000 LB 0x6f310
156cec.6cf0: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
166cec.6cf0: [Raw version resource data: 0x17f0f0 LB 0x380, codepage 0x0 (reserved 0x0)]
176cec.6cf0: ProductName: Microsoft® Windows® Operating System
186cec.6cf0: ProductVersion: 10.0.18362.815
196cec.6cf0: FileVersion: 10.0.18362.815 (WinBuild.160101.0800)
206cec.6cf0: FileDescription: NT Layer DLL
216cec.6cf0: \SystemRoot\System32\kernel32.dll:
226cec.6cf0: CreationTime: 2020-04-15T16:13:02.961257500Z
236cec.6cf0: LastWriteTime: 2020-04-15T16:13:02.986662000Z
246cec.6cf0: ChangeTime: 2020-05-03T03:30:23.798603800Z
256cec.6cf0: FileAttributes: 0x20
266cec.6cf0: Size: 0xb0498
276cec.6cf0: NT Headers: 0xe8
286cec.6cf0: Timestamp: 0x21b07e83
296cec.6cf0: Machine: 0x8664 - amd64
306cec.6cf0: Timestamp: 0x21b07e83
316cec.6cf0: Image Version: 10.0
326cec.6cf0: SizeOfImage: 0xb2000 (729088)
336cec.6cf0: Resource Dir: 0xb0000 LB 0x520
346cec.6cf0: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
356cec.6cf0: [Raw version resource data: 0xb00b0 LB 0x3a4, codepage 0x0 (reserved 0x0)]
366cec.6cf0: ProductName: Microsoft® Windows® Operating System
376cec.6cf0: ProductVersion: 10.0.18362.778
386cec.6cf0: FileVersion: 10.0.18362.778 (WinBuild.160101.0800)
396cec.6cf0: FileDescription: Windows NT BASE API Client DLL
406cec.6cf0: \SystemRoot\System32\KernelBase.dll:
416cec.6cf0: CreationTime: 2020-05-03T03:29:33.628657500Z
426cec.6cf0: LastWriteTime: 2020-05-03T03:29:33.729681700Z
436cec.6cf0: ChangeTime: 2020-05-04T03:07:35.945225300Z
446cec.6cf0: FileAttributes: 0x20
456cec.6cf0: Size: 0x2a4068
466cec.6cf0: NT Headers: 0xf8
476cec.6cf0: Timestamp: 0xb89efff3
486cec.6cf0: Machine: 0x8664 - amd64
496cec.6cf0: Timestamp: 0xb89efff3
506cec.6cf0: Image Version: 10.0
516cec.6cf0: SizeOfImage: 0x2a4000 (2768896)
526cec.6cf0: Resource Dir: 0x27e000 LB 0x548
536cec.6cf0: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
546cec.6cf0: [Raw version resource data: 0x27e0b0 LB 0x3bc, codepage 0x0 (reserved 0x0)]
556cec.6cf0: ProductName: Microsoft® Windows® Operating System
566cec.6cf0: ProductVersion: 10.0.18362.815
576cec.6cf0: FileVersion: 10.0.18362.815 (WinBuild.160101.0800)
586cec.6cf0: FileDescription: Windows NT BASE API Client DLL
596cec.6cf0: \SystemRoot\System32\apisetschema.dll:
606cec.6cf0: CreationTime: 2019-03-19T04:43:54.837151500Z
616cec.6cf0: LastWriteTime: 2019-03-19T04:43:54.837151500Z
626cec.6cf0: ChangeTime: 2020-05-03T03:30:23.758596400Z
636cec.6cf0: FileAttributes: 0x20
646cec.6cf0: Size: 0x1d028
656cec.6cf0: NT Headers: 0xc8
666cec.6cf0: Timestamp: 0xd6ced080
676cec.6cf0: Machine: 0x8664 - amd64
686cec.6cf0: Timestamp: 0xd6ced080
696cec.6cf0: Image Version: 10.0
706cec.6cf0: SizeOfImage: 0x1e000 (122880)
716cec.6cf0: Resource Dir: 0x1d000 LB 0x408
726cec.6cf0: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
736cec.6cf0: [Raw version resource data: 0x1d060 LB 0x3a8, codepage 0x0 (reserved 0x0)]
746cec.6cf0: ProductName: Microsoft® Windows® Operating System
756cec.6cf0: ProductVersion: 10.0.18362.1
766cec.6cf0: FileVersion: 10.0.18362.1 (WinBuild.160101.0800)
776cec.6cf0: FileDescription: ApiSet Schema DLL
786cec.6cf0: Found driver SymNetS (0x2)
796cec.6cf0: Found driver SRTSPX (0x2)
806cec.6cf0: Found driver SymEvent (0x2)
816cec.6cf0: Found driver SymIRON (0x2)
826cec.6cf0: supR3HardenedWinFindAdversaries: 0x2
836cec.6cf0: \SystemRoot\System32\drivers\symevent64x86.sys:
846cec.6cf0: CreationTime: 2018-05-07T20:10:45.241730500Z
856cec.6cf0: LastWriteTime: 2019-03-21T09:37:41.102289300Z
866cec.6cf0: ChangeTime: 2019-10-07T03:10:05.970074600Z
876cec.6cf0: FileAttributes: 0x20
886cec.6cf0: Size: 0x186e0
896cec.6cf0: NT Headers: 0xf0
906cec.6cf0: Timestamp: 0x5bbbe164
916cec.6cf0: Machine: 0x8664 - amd64
926cec.6cf0: Timestamp: 0x5bbbe164
936cec.6cf0: Image Version: 6.3
946cec.6cf0: SizeOfImage: 0x21000 (135168)
956cec.6cf0: Resource Dir: 0x1f000 LB 0x3c8
966cec.6cf0: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
976cec.6cf0: [Raw version resource data: 0x1f0b8 LB 0x310, codepage 0x4e4 (reserved 0x0)]
986cec.6cf0: ProductName: SYMEVENT
996cec.6cf0: ProductVersion: 14.0.7.71
1006cec.6cf0: FileVersion: 14.0.7.71
1016cec.6cf0: FileDescription: Symantec Event Library
1026cec.6cf0: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox'
1036cec.6cf0: Calling main()
1046cec.6cf0: SUPR3HardenedMain: pszProgName=VirtualBoxVM fFlags=0x2
1056cec.6cf0: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox'
1066cec.6cf0: SUPR3HardenedMain: Respawn #1
1076cec.6cf0: System32: \Device\HarddiskVolume8\Windows\System32
1086cec.6cf0: WinSxS: \Device\HarddiskVolume8\Windows\WinSxS
1096cec.6cf0: KnownDllPath: C:\WINDOWS\System32
1106cec.6cf0: supR3HardenedWinInit: Performing a limited self purification...
1116cec.6cf0: supHardNtVpScanVirtualMemory: enmKind=SELF_PURIFICATION
1126cec.6cf0: *0000000000000000-00000000004affff 0x0001/0x0000 0x0000000
1136cec.6cf0: *00000000004b0000-00000000004bffff 0x0004/0x0004 0x0040000
1146cec.6cf0: 00000000004c0000-00000000004cffff 0x0001/0x0000 0x0000000
1156cec.6cf0: *00000000004d0000-00000000004eafff 0x0002/0x0002 0x0040000
1166cec.6cf0: 00000000004eb000-00000000004effff 0x0001/0x0000 0x0000000
1176cec.6cf0: *00000000004f0000-00000000005a0fff 0x0000/0x0004 0x0020000
1186cec.6cf0: 00000000005a1000-00000000005a3fff 0x0104/0x0004 0x0020000
1196cec.6cf0: 00000000005a4000-00000000005effff 0x0004/0x0004 0x0020000
1206cec.6cf0: *00000000005f0000-00000000005f3fff 0x0002/0x0002 0x0040000
1216cec.6cf0: 00000000005f4000-00000000005fffff 0x0001/0x0000 0x0000000
1226cec.6cf0: *0000000000600000-0000000000647fff 0x0000/0x0004 0x0020000
1236cec.6cf0: 0000000000648000-000000000064afff 0x0004/0x0004 0x0020000
1246cec.6cf0: 000000000064b000-00000000007fffff 0x0000/0x0004 0x0020000
1256cec.6cf0: *0000000000800000-0000000000801fff 0x0004/0x0004 0x0020000
1266cec.6cf0: 0000000000802000-000000000080ffff 0x0001/0x0000 0x0000000
1276cec.6cf0: *0000000000810000-00000000008d6fff 0x0002/0x0002 0x0040000
1286cec.6cf0: 00000000008d7000-000000000093ffff 0x0001/0x0000 0x0000000
1296cec.6cf0: *0000000000940000-000000000094efff 0x0004/0x0004 0x0020000
1306cec.6cf0: 000000000094f000-0000000000a3ffff 0x0000/0x0004 0x0020000
1316cec.6cf0: *0000000000a40000-0000000000a41fff 0x0004/0x0004 0x0020000
1326cec.6cf0: 0000000000a42000-0000000000aa1fff 0x0000/0x0004 0x0020000
1336cec.6cf0: 0000000000aa2000-0000000000aaffff 0x0001/0x0000 0x0000000
1346cec.6cf0: *0000000000ab0000-0000000000ab1fff 0x0004/0x0004 0x0020000
1356cec.6cf0: 0000000000ab2000-0000000000b11fff 0x0000/0x0004 0x0020000
1366cec.6cf0: 0000000000b12000-0000000000b1ffff 0x0001/0x0000 0x0000000
1376cec.6cf0: *0000000000b20000-0000000000b3cfff 0x0004/0x0004 0x0020000
1386cec.6cf0: 0000000000b3d000-0000000000c1ffff 0x0000/0x0004 0x0020000
1396cec.6cf0: *0000000000c20000-0000000000c2efff 0x0004/0x0004 0x0020000
1406cec.6cf0: 0000000000c2f000-0000000000c2ffff 0x0000/0x0004 0x0020000
1416cec.6cf0: *0000000000c30000-0000000000c34fff 0x0000/0x0004 0x0020000
1426cec.6cf0: 0000000000c35000-0000000000e25fff 0x0004/0x0004 0x0020000
1436cec.6cf0: 0000000000e26000-0000000000e26fff 0x0000/0x0004 0x0020000
1446cec.6cf0: 0000000000e27000-000000007ffdffff 0x0001/0x0000 0x0000000
1456cec.6cf0: *000000007ffe0000-000000007ffe0fff 0x0002/0x0002 0x0020000
1466cec.6cf0: 000000007ffe1000-000000007ffe5fff 0x0001/0x0000 0x0000000
1476cec.6cf0: *000000007ffe6000-000000007ffe6fff 0x0002/0x0002 0x0020000
1486cec.6cf0: 000000007ffe7000-00007ff4f122ffff 0x0001/0x0000 0x0000000
1496cec.6cf0: *00007ff4f1230000-00007ff4f1234fff 0x0002/0x0002 0x0040000
1506cec.6cf0: 00007ff4f1235000-00007ff4f132ffff 0x0000/0x0002 0x0040000
1516cec.6cf0: *00007ff4f1330000-00007ff5f134ffff 0x0000/0x0004 0x0020000
1526cec.6cf0: *00007ff5f1350000-00007ff5f334ffff 0x0000/0x0004 0x0020000
1536cec.6cf0: 00007ff5f3350000-00007ff5f3350fff 0x0004/0x0004 0x0020000
1546cec.6cf0: 00007ff5f3351000-00007ff5f335ffff 0x0001/0x0000 0x0000000
1556cec.6cf0: *00007ff5f3360000-00007ff5f3360fff 0x0002/0x0002 0x0040000
1566cec.6cf0: 00007ff5f3361000-00007ff5f336ffff 0x0001/0x0000 0x0000000
1576cec.6cf0: *00007ff5f3370000-00007ff5f339afff 0x0002/0x0002 0x0040000
1586cec.6cf0: 00007ff5f339b000-00007ff6c471ffff 0x0001/0x0000 0x0000000
1596cec.6cf0: *00007ff6c4720000-00007ff6c4720fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
1606cec.6cf0: 00007ff6c4721000-00007ff6c4796fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
1616cec.6cf0: 00007ff6c4797000-00007ff6c4797fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
1626cec.6cf0: 00007ff6c4798000-00007ff6c47dffff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
1636cec.6cf0: 00007ff6c47e0000-00007ff6c47e2fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
1646cec.6cf0: 00007ff6c47e3000-00007ff6c47e5fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
1656cec.6cf0: 00007ff6c47e6000-00007ff6c47e8fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
1666cec.6cf0: 00007ff6c47e9000-00007ff6c47e9fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
1676cec.6cf0: 00007ff6c47ea000-00007ff6c47ebfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
1686cec.6cf0: 00007ff6c47ec000-00007ff6c47ecfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
1696cec.6cf0: 00007ff6c47ed000-00007ff6c4835fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
1706cec.6cf0: 00007ff6c4836000-00007fffa342ffff 0x0001/0x0000 0x0000000
1716cec.6cf0: *00007fffa3430000-00007fffa3430fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume8\Windows\System32\apphelp.dll
1726cec.6cf0: 00007fffa3431000-00007fffa347dfff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume8\Windows\System32\apphelp.dll
1736cec.6cf0: 00007fffa347e000-00007fffa349ffff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume8\Windows\System32\apphelp.dll
1746cec.6cf0: 00007fffa34a0000-00007fffa34a2fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume8\Windows\System32\apphelp.dll
1756cec.6cf0: 00007fffa34a3000-00007fffa34befff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume8\Windows\System32\apphelp.dll
1766cec.6cf0: 00007fffa34bf000-00007fffa570ffff 0x0001/0x0000 0x0000000
1776cec.6cf0: *00007fffa5710000-00007fffa5710fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume8\Windows\System32\KernelBase.dll
1786cec.6cf0: 00007fffa5711000-00007fffa5815fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume8\Windows\System32\KernelBase.dll
1796cec.6cf0: 00007fffa5816000-00007fffa5978fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume8\Windows\System32\KernelBase.dll
1806cec.6cf0: 00007fffa5979000-00007fffa597cfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume8\Windows\System32\KernelBase.dll
1816cec.6cf0: 00007fffa597d000-00007fffa597dfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume8\Windows\System32\KernelBase.dll
1826cec.6cf0: 00007fffa597e000-00007fffa59b3fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume8\Windows\System32\KernelBase.dll
1836cec.6cf0: 00007fffa59b4000-00007fffa70bffff 0x0001/0x0000 0x0000000
1846cec.6cf0: *00007fffa70c0000-00007fffa70c0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume8\Windows\System32\kernel32.dll
1856cec.6cf0: 00007fffa70c1000-00007fffa7135fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume8\Windows\System32\kernel32.dll
1866cec.6cf0: 00007fffa7136000-00007fffa7167fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume8\Windows\System32\kernel32.dll
1876cec.6cf0: 00007fffa7168000-00007fffa7168fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume8\Windows\System32\kernel32.dll
1886cec.6cf0: 00007fffa7169000-00007fffa7169fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume8\Windows\System32\kernel32.dll
1896cec.6cf0: 00007fffa716a000-00007fffa7171fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume8\Windows\System32\kernel32.dll
1906cec.6cf0: 00007fffa7172000-00007fffa859ffff 0x0001/0x0000 0x0000000
1916cec.6cf0: *00007fffa85a0000-00007fffa85a0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume8\Windows\System32\ntdll.dll
1926cec.6cf0: 00007fffa85a1000-00007fffa86b7fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume8\Windows\System32\ntdll.dll
1936cec.6cf0: 00007fffa86b8000-00007fffa86fefff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume8\Windows\System32\ntdll.dll
1946cec.6cf0: 00007fffa86ff000-00007fffa86fffff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume8\Windows\System32\ntdll.dll
1956cec.6cf0: 00007fffa8700000-00007fffa8701fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume8\Windows\System32\ntdll.dll
1966cec.6cf0: 00007fffa8702000-00007fffa870afff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume8\Windows\System32\ntdll.dll
1976cec.6cf0: 00007fffa870b000-00007fffa878ffff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume8\Windows\System32\ntdll.dll
1986cec.6cf0: 00007fffa8790000-00007ffffffeffff 0x0001/0x0000 0x0000000
1996cec.6cf0: kernel32.dll: timestamp 0x21b07e83 (rc=VINF_SUCCESS)
2006cec.6cf0: kernelbase.dll: timestamp 0xb89efff3 (rc=VINF_SUCCESS)
2016cec.6cf0: apphelp.dll: timestamp 0xff74693c (rc=VINF_SUCCESS)
2026cec.6cf0: VirtualBoxVM.exe: timestamp 0x5e4c1d19 (rc=VINF_SUCCESS)
2036cec.6cf0: '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
2046cec.6cf0: '\Device\HarddiskVolume8\Windows\System32\ntdll.dll' has no imports
2056cec.6cf0: kernel32.dll: Differences in section #2 (.rdata) between file and memory:
2066cec.6cf0: 00007fffa71390e0 / 0x00790e0: 50 != 00
2076cec.6cf0: 00007fffa71390e1 / 0x00790e1: cc != 14
2086cec.6cf0: 00007fffa71390e2 / 0x00790e2: 63 != 47
2096cec.6cf0: 00007fffa71390e3 / 0x00790e3: a8 != a3
2106cec.6cf0: 00007fffa7139490 / 0x0079490: 40 != 70
2116cec.6cf0: 00007fffa7139491 / 0x0079491: c5 != 13
2126cec.6cf0: 00007fffa7139492 / 0x0079492: 63 != 47
2136cec.6cf0: 00007fffa7139493 / 0x0079493: a8 != a3
2146cec.6cf0: 00007fffa7139668 / 0x0079668: 00 != 90
2156cec.6cf0: 00007fffa7139669 / 0x0079669: cb != 11
2166cec.6cf0: 00007fffa713966a / 0x007966a: 63 != 47
2176cec.6cf0: 00007fffa713966b / 0x007966b: a8 != a3
2186cec.6cf0: 00007fffa7139a50 / 0x0079a50: 00 != 90
2196cec.6cf0: 00007fffa7139a51 / 0x0079a51: cb != 11
2206cec.6cf0: 00007fffa7139a52 / 0x0079a52: 63 != 47
2216cec.6cf0: 00007fffa7139a53 / 0x0079a53: a8 != a3
2226cec.6cf0: Restored 0x2000 bytes of original file content at 00007fffa7138000
2236cec.6cf0: kernelbase.dll: Differences in section #2 (.rdata) between file and memory:
2246cec.6cf0: 00007fffa58b68d0 / 0x01a68d0: 40 != 70
2256cec.6cf0: 00007fffa58b68d1 / 0x01a68d1: c5 != 13
2266cec.6cf0: 00007fffa58b68d2 / 0x01a68d2: 63 != 47
2276cec.6cf0: 00007fffa58b68d3 / 0x01a68d3: a8 != a3
2286cec.6cf0: 00007fffa58b6908 / 0x01a6908: 00 != 90
2296cec.6cf0: 00007fffa58b6909 / 0x01a6909: cb != 11
2306cec.6cf0: 00007fffa58b690a / 0x01a690a: 63 != 47
2316cec.6cf0: 00007fffa58b690b / 0x01a690b: a8 != a3
2326cec.6cf0: 00007fffa58b6a40 / 0x01a6a40: 50 != 00
2336cec.6cf0: 00007fffa58b6a41 / 0x01a6a41: cc != 14
2346cec.6cf0: 00007fffa58b6a42 / 0x01a6a42: 63 != 47
2356cec.6cf0: 00007fffa58b6a43 / 0x01a6a43: a8 != a3
2366cec.6cf0: 00007fffa58b7190 / 0x01a7190: 50 != 00
2376cec.6cf0: 00007fffa58b7191 / 0x01a7191: cc != 14
2386cec.6cf0: 00007fffa58b7192 / 0x01a7192: 63 != 47
2396cec.6cf0: 00007fffa58b7193 / 0x01a7193: a8 != a3
2406cec.6cf0: Restored 0x2000 bytes of original file content at 00007fffa58b6000
2416cec.6cf0: apphelp.dll: Differences in section #2 (.rdata) between file and memory:
2426cec.6cf0: 00007fffa347fe98 / 0x004fe98: a0 != e0
2436cec.6cf0: 00007fffa347fe99 / 0x004fe99: e1 != ed
2446cec.6cf0: 00007fffa347fe9a / 0x004fe9a: 78 != 0d
2456cec.6cf0: 00007fffa347fe9b / 0x004fe9b: a5 != a7
2466cec.6cf0: 00007fffa347fea0 / 0x004fea0: 10 != 50
2476cec.6cf0: 00007fffa347fea1 / 0x004fea1: 0a != 5e
2486cec.6cf0: 00007fffa347fea2 / 0x004fea2: 76 != 0d
2496cec.6cf0: 00007fffa347fea3 / 0x004fea3: a5 != a7
2506cec.6cf0: 00007fffa347fea8 / 0x004fea8: 10 != b0
2516cec.6cf0: 00007fffa347fea9 / 0x004fea9: 48 != 1d
2526cec.6cf0: 00007fffa347feaa / 0x004feaa: 77 != 0e
2536cec.6cf0: 00007fffa347feab / 0x004feab: a5 != a7
2546cec.6cf0: 00007fffa347feb0 / 0x004feb0: 60 != 50
2556cec.6cf0: 00007fffa347feb1 / 0x004feb1: a7 != b7
2566cec.6cf0: 00007fffa347feb2 / 0x004feb2: 77 != 0d
2576cec.6cf0: 00007fffa347feb3 / 0x004feb3: a5 != a7
2586cec.6cf0: 00007fffa347feb8 / 0x004feb8: d0 != c0
2596cec.6cf0: 00007fffa347feb9 / 0x004feb9: 22 != 1d
2606cec.6cf0: 00007fffa347feba / 0x004feba: 77 != 0e
2616cec.6cf0: 00007fffa347febb / 0x004febb: a5 != a7
2626cec.6cf0: 00007fffa347fec0 / 0x004fec0: a0 != 40
2636cec.6cf0: 00007fffa347fec1 / 0x004fec1: bc != be
2646cec.6cf0: 00007fffa347fec2 / 0x004fec2: 76 != 0d
2656cec.6cf0: 00007fffa347fec3 / 0x004fec3: a5 != a7
2666cec.6cf0: 00007fffa347fec8 / 0x004fec8: c0 != 60
2676cec.6cf0: 00007fffa347fec9 / 0x004fec9: 66 != a1
2686cec.6cf0: 00007fffa347feca / 0x004feca: 77 != 0d
2696cec.6cf0: 00007fffa347fecb / 0x004fecb: a5 != a7
2706cec.6cf0: 00007fffa347fed8 / 0x004fed8: 20 != a0
2716cec.6cf0: 00007fffa347fed9 / 0x004fed9: 72 != a1
2726cec.6cf0: 00007fffa347feda / 0x004feda: 73 != 0d
2736cec.6cf0: 00007fffa347fedb / 0x004fedb: a5 != a7
2746cec.6cf0: Restored 0x2000 bytes of original file content at 00007fffa347e000
2756cec.6cf0: supR3HardenedWinInit: SUPHARDNTVPKIND_SELF_PURIFICATION_LIMITED -> VINF_SUCCESS, cFixes=3
2766cec.6cf0: '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
2776cec.6cf0: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe)
2786cec.6cf0: supR3HardNtEnableThreadCreationEx:
2796cec.6cf0: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007fffa8611770 pvNtTerminateThread=00007fffa863cac0
2806cec.6cf0: supR3HardenedWinDoReSpawn(1): New child 6d10.6d14 [kernel32].
2816cec.6cf0: supR3HardNtChildGatherData: PebBaseAddress=0000000001054000 cbPeb=0x388
2826cec.6cf0: supR3HardNtPuChFindNtdll: uNtDllParentAddr=00007fffa85a0000 uNtDllChildAddr=00007fffa85a0000
2836cec.6cf0: supR3HardenedWinSetupChildInit: uLdrInitThunk=00007fffa8611770
2846cec.6cf0: supR3HardenedWinSetupChildInit: Initial context:
285 rax=0000000000000000 rbx=0000000000000000 rcx=00007ff6c4727900 rdx=0000000001054000
286 rsi=0000000000000000 rdi=0000000000000000 r8 =0000000000000000 r9 =0000000000000000
287 r10=0000000000000000 r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
288 r14=0000000000000000 r15=0000000000000000 P1=0000000000000000 P2=0000000000000000
289 rip=00007fffa860ce30 rsp=00000000012ffc68 rbp=0000000000000000 ctxflags=0010001b
290 cs=0033 ss=002b ds=0000 es=0000 fs=0000 gs=0000 eflags=00000200 mxcrx=00001f80
291 P3=0000000000000000 P4=0000000000000000 P5=0000000000000000 P6=0000000000000000
292 dr0=0000000000000000 dr1=0000000000000000 dr2=0000000000000000 dr3=0000000000000000
293 dr6=0000000000000000 dr7=0000000000000000 vcr=0000000000000000 dcr=0000000000000000
294 lbt=0000000000000000 lbf=0000000000000000 lxt=0000000000000000 lxf=0000000000000000
2956cec.6cf0: supR3HardenedWinSetupChildInit: Start child.
2966cec.6cf0: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 1 ms.
2976cec.6cf0: supR3HardNtChildPurify: Startup delay kludge #1/0: 520 ms, 58 sleeps
2986cec.6cf0: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
2996cec.6cf0: *0000000000000000-0000000000faffff 0x0001/0x0000 0x0000000
3006cec.6cf0: *0000000000fb0000-0000000000fcffff 0x0004/0x0004 0x0020000
3016cec.6cf0: *0000000000fd0000-0000000000feafff 0x0002/0x0002 0x0040000
3026cec.6cf0: 0000000000feb000-0000000000feffff 0x0001/0x0000 0x0000000
3036cec.6cf0: *0000000000ff0000-0000000000ff3fff 0x0002/0x0002 0x0040000
3046cec.6cf0: 0000000000ff4000-0000000000ffffff 0x0001/0x0000 0x0000000
3056cec.6cf0: *0000000001000000-0000000001053fff 0x0000/0x0004 0x0020000
3066cec.6cf0: 0000000001054000-0000000001056fff 0x0004/0x0004 0x0020000
3076cec.6cf0: 0000000001057000-00000000011fffff 0x0000/0x0004 0x0020000
3086cec.6cf0: *0000000001200000-00000000012fafff 0x0000/0x0004 0x0020000
3096cec.6cf0: 00000000012fb000-00000000012fdfff 0x0104/0x0004 0x0020000
3106cec.6cf0: 00000000012fe000-00000000012fffff 0x0004/0x0004 0x0020000
3116cec.6cf0: *0000000001300000-0000000001301fff 0x0004/0x0004 0x0020000
3126cec.6cf0: 0000000001302000-000000007ffdffff 0x0001/0x0000 0x0000000
3136cec.6cf0: *000000007ffe0000-000000007ffe0fff 0x0002/0x0002 0x0020000
3146cec.6cf0: 000000007ffe1000-000000007ffe5fff 0x0001/0x0000 0x0000000
3156cec.6cf0: *000000007ffe6000-000000007ffe6fff 0x0002/0x0002 0x0020000
3166cec.6cf0: 000000007ffe7000-00007ff5089effff 0x0001/0x0000 0x0000000
3176cec.6cf0: *00007ff5089f0000-00007ff5089f0fff 0x0002/0x0002 0x0040000
3186cec.6cf0: 00007ff5089f1000-00007ff5089fffff 0x0001/0x0000 0x0000000
3196cec.6cf0: *00007ff508a00000-00007ff508a2afff 0x0002/0x0002 0x0040000
3206cec.6cf0: 00007ff508a2b000-00007ff6c471ffff 0x0001/0x0000 0x0000000
3216cec.6cf0: *00007ff6c4720000-00007ff6c4720fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
3226cec.6cf0: 00007ff6c4721000-00007ff6c4796fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
3236cec.6cf0: 00007ff6c4797000-00007ff6c4797fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
3246cec.6cf0: 00007ff6c4798000-00007ff6c47dffff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
3256cec.6cf0: 00007ff6c47e0000-00007ff6c47e0fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
3266cec.6cf0: 00007ff6c47e1000-00007ff6c47e1fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
3276cec.6cf0: 00007ff6c47e2000-00007ff6c47e6fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
3286cec.6cf0: 00007ff6c47e7000-00007ff6c47e7fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
3296cec.6cf0: 00007ff6c47e8000-00007ff6c47e8fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
3306cec.6cf0: 00007ff6c47e9000-00007ff6c47ecfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
3316cec.6cf0: 00007ff6c47ed000-00007ff6c4835fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
3326cec.6cf0: 00007ff6c4836000-00007fffa859ffff 0x0001/0x0000 0x0000000
3336cec.6cf0: *00007fffa85a0000-00007fffa85a0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume8\Windows\System32\ntdll.dll
3346cec.6cf0: 00007fffa85a1000-00007fffa86b7fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume8\Windows\System32\ntdll.dll
3356cec.6cf0: 00007fffa86b8000-00007fffa86fefff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume8\Windows\System32\ntdll.dll
3366cec.6cf0: 00007fffa86ff000-00007fffa870afff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume8\Windows\System32\ntdll.dll
3376cec.6cf0: 00007fffa870b000-00007fffa8719fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume8\Windows\System32\ntdll.dll
3386cec.6cf0: 00007fffa871a000-00007fffa871afff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume8\Windows\System32\ntdll.dll
3396cec.6cf0: 00007fffa871b000-00007fffa871dfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume8\Windows\System32\ntdll.dll
3406cec.6cf0: 00007fffa871e000-00007fffa878ffff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume8\Windows\System32\ntdll.dll
3416cec.6cf0: 00007fffa8790000-00007ffffffeffff 0x0001/0x0000 0x0000000
3426cec.6cf0: supR3HardNtChildPurify: Done after 524 ms and 0 fixes (loop #0).
3436cec.6cf0: supR3HardNtEnableThreadCreationEx:
3446d10.6d14: Log file opened: 6.1.4r136177 g_hStartupLog=0000000000000004 g_uNtVerCombined=0xa047bb00
3456d10.6d14: supR3HardenedVmProcessInit: uNtDllAddr=00007fffa85a0000 g_uNtVerCombined=0xa047bb00 (stack ~00000000012ff6f8)
3466d10.6d14: ntdll.dll: timestamp 0xb29ecf52 (rc=VINF_SUCCESS)
3476d10.6d14: New simple heap: #1 0000000001410000 LB 0x400000 (for 2031616 allocation)
3486d10.6d14: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox'
3496d10.6d14: System32: \Device\HarddiskVolume8\Windows\System32
3506d10.6d14: WinSxS: \Device\HarddiskVolume8\Windows\WinSxS
3516d10.6d14: KnownDllPath: C:\WINDOWS\System32
3526d10.6d14: supR3HardenedVmProcessInit: Opening vboxdrv stub...
3536d10.6d14: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
3546d10.6d14: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
3556d10.6d14: Registered Dll notification callback with NTDLL.
3566d10.6d14: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\kernel32.dll)
3576d10.6d14: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\kernel32.dll
3586d10.6d14: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\KERNEL32.DLL (Input=KERNEL32.DLL, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000004001:<flags> [calling]
3596d10.6d14: supR3HardenedDllNotificationCallback: load 00007fffa5710000 LB 0x002a4000 C:\WINDOWS\System32\KERNELBASE.dll [fFlags=0x0]
3606d10.6d14: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\KernelBase.dll)
3616d10.6d14: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\KernelBase.dll
3626d10.6d14: supR3HardenedDllNotificationCallback: load 00007fffa70c0000 LB 0x000b2000 C:\WINDOWS\System32\KERNEL32.DLL [fFlags=0x0]
3636d10.6d14: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
3646d10.6d14: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa70c0000 'C:\WINDOWS\System32\KERNEL32.DLL'
3656d10.6d14: supR3HardenedDllNotificationCallback: load 00007ff6c4720000 LB 0x00116000 C:\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe [fFlags=0x0]
3666d10.6d14: '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
3676d10.6d14: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe)
3686d10.6d14: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
3696d10.6d14: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007fffa8611770 pvNtTerminateThread=00007fffa863cac0
3706cec.6cf0: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 79 ms.
3716d10.6d14: \SystemRoot\System32\ntdll.dll:
3726d10.6d14: CreationTime: 2020-05-03T03:29:33.075535900Z
3736d10.6d14: LastWriteTime: 2020-05-03T03:29:33.128546900Z
3746d10.6d14: ChangeTime: 2020-05-04T03:07:36.221273200Z
3756d10.6d14: FileAttributes: 0x20
3766d10.6d14: Size: 0x1e8460
3776d10.6d14: NT Headers: 0xd8
3786d10.6d14: Timestamp: 0xb29ecf52
3796d10.6d14: Machine: 0x8664 - amd64
3806d10.6d14: Timestamp: 0xb29ecf52
3816d10.6d14: Image Version: 10.0
3826d10.6d14: SizeOfImage: 0x1f0000 (2031616)
3836d10.6d14: Resource Dir: 0x17f000 LB 0x6f310
3846d10.6d14: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
3856d10.6d14: [Raw version resource data: 0x17f0f0 LB 0x380, codepage 0x0 (reserved 0x0)]
3866d10.6d14: ProductName: Microsoft® Windows® Operating System
3876d10.6d14: ProductVersion: 10.0.18362.815
3886d10.6d14: FileVersion: 10.0.18362.815 (WinBuild.160101.0800)
3896d10.6d14: FileDescription: NT Layer DLL
3906d10.6d14: \SystemRoot\System32\kernel32.dll:
3916d10.6d14: CreationTime: 2020-04-15T16:13:02.961257500Z
3926d10.6d14: LastWriteTime: 2020-04-15T16:13:02.986662000Z
3936d10.6d14: ChangeTime: 2020-05-03T03:30:23.798603800Z
3946d10.6d14: FileAttributes: 0x20
3956d10.6d14: Size: 0xb0498
3966d10.6d14: NT Headers: 0xe8
3976d10.6d14: Timestamp: 0x21b07e83
3986d10.6d14: Machine: 0x8664 - amd64
3996d10.6d14: Timestamp: 0x21b07e83
4006d10.6d14: Image Version: 10.0
4016d10.6d14: SizeOfImage: 0xb2000 (729088)
4026d10.6d14: Resource Dir: 0xb0000 LB 0x520
4036d10.6d14: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
4046d10.6d14: [Raw version resource data: 0xb00b0 LB 0x3a4, codepage 0x0 (reserved 0x0)]
4056d10.6d14: ProductName: Microsoft® Windows® Operating System
4066d10.6d14: ProductVersion: 10.0.18362.778
4076d10.6d14: FileVersion: 10.0.18362.778 (WinBuild.160101.0800)
4086d10.6d14: FileDescription: Windows NT BASE API Client DLL
4096d10.6d14: \SystemRoot\System32\KernelBase.dll:
4106d10.6d14: CreationTime: 2020-05-03T03:29:33.628657500Z
4116d10.6d14: LastWriteTime: 2020-05-03T03:29:33.729681700Z
4126d10.6d14: ChangeTime: 2020-05-04T03:07:35.945225300Z
4136d10.6d14: FileAttributes: 0x20
4146d10.6d14: Size: 0x2a4068
4156d10.6d14: NT Headers: 0xf8
4166d10.6d14: Timestamp: 0xb89efff3
4176d10.6d14: Machine: 0x8664 - amd64
4186d10.6d14: Timestamp: 0xb89efff3
4196d10.6d14: Image Version: 10.0
4206d10.6d14: SizeOfImage: 0x2a4000 (2768896)
4216d10.6d14: Resource Dir: 0x27e000 LB 0x548
4226d10.6d14: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
4236d10.6d14: [Raw version resource data: 0x27e0b0 LB 0x3bc, codepage 0x0 (reserved 0x0)]
4246d10.6d14: ProductName: Microsoft® Windows® Operating System
4256d10.6d14: ProductVersion: 10.0.18362.815
4266d10.6d14: FileVersion: 10.0.18362.815 (WinBuild.160101.0800)
4276d10.6d14: FileDescription: Windows NT BASE API Client DLL
4286d10.6d14: \SystemRoot\System32\apisetschema.dll:
4296d10.6d14: CreationTime: 2019-03-19T04:43:54.837151500Z
4306d10.6d14: LastWriteTime: 2019-03-19T04:43:54.837151500Z
4316d10.6d14: ChangeTime: 2020-05-03T03:30:23.758596400Z
4326d10.6d14: FileAttributes: 0x20
4336d10.6d14: Size: 0x1d028
4346d10.6d14: NT Headers: 0xc8
4356d10.6d14: Timestamp: 0xd6ced080
4366d10.6d14: Machine: 0x8664 - amd64
4376d10.6d14: Timestamp: 0xd6ced080
4386d10.6d14: Image Version: 10.0
4396d10.6d14: SizeOfImage: 0x1e000 (122880)
4406d10.6d14: Resource Dir: 0x1d000 LB 0x408
4416d10.6d14: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
4426d10.6d14: [Raw version resource data: 0x1d060 LB 0x3a8, codepage 0x0 (reserved 0x0)]
4436d10.6d14: ProductName: Microsoft® Windows® Operating System
4446d10.6d14: ProductVersion: 10.0.18362.1
4456d10.6d14: FileVersion: 10.0.18362.1 (WinBuild.160101.0800)
4466d10.6d14: FileDescription: ApiSet Schema DLL
4476d10.6d14: Found driver SymNetS (0x2)
4486d10.6d14: Found driver SRTSPX (0x2)
4496d10.6d14: Found driver SymEvent (0x2)
4506d10.6d14: Found driver SymIRON (0x2)
4516d10.6d14: supR3HardenedWinFindAdversaries: 0x2
4526d10.6d14: \SystemRoot\System32\drivers\symevent64x86.sys:
4536d10.6d14: CreationTime: 2018-05-07T20:10:45.241730500Z
4546d10.6d14: LastWriteTime: 2019-03-21T09:37:41.102289300Z
4556d10.6d14: ChangeTime: 2019-10-07T03:10:05.970074600Z
4566d10.6d14: FileAttributes: 0x20
4576d10.6d14: Size: 0x186e0
4586d10.6d14: NT Headers: 0xf0
4596d10.6d14: Timestamp: 0x5bbbe164
4606d10.6d14: Machine: 0x8664 - amd64
4616d10.6d14: Timestamp: 0x5bbbe164
4626d10.6d14: Image Version: 6.3
4636d10.6d14: SizeOfImage: 0x21000 (135168)
4646d10.6d14: Resource Dir: 0x1f000 LB 0x3c8
4656d10.6d14: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
4666d10.6d14: [Raw version resource data: 0x1f0b8 LB 0x310, codepage 0x4e4 (reserved 0x0)]
4676d10.6d14: ProductName: SYMEVENT
4686d10.6d14: ProductVersion: 14.0.7.71
4696d10.6d14: FileVersion: 14.0.7.71
4706d10.6d14: FileDescription: Symantec Event Library
4716d10.6d14: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox'
4726d10.6d14: Calling main()
4736d10.6d14: SUPR3HardenedMain: pszProgName=VirtualBoxVM fFlags=0x2
4746d10.6d14: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox'
4756d10.6d14: '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
4766d10.6d14: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe)
4776d10.6d14: SUPR3HardenedMain: Respawn #2
4786d10.6d14: supR3HardNtEnableThreadCreationEx:
4796d10.6d14: supR3HardenedDllNotificationCallback: load 00007fffa81b0000 LB 0x00120000 C:\WINDOWS\System32\RPCRT4.dll [fFlags=0x0]
4806d10.6d14: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\rpcrt4.dll)
4816d10.6d14: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\rpcrt4.dll
4826d10.6d14: supR3HardenedDllNotificationCallback: load 00007fffa6650000 LB 0x00097000 C:\WINDOWS\System32\sechost.dll [fFlags=0x0]
4836d10.6d14: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'rpcrt4.dll'.
4846d10.6d14: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\sechost.dll)
4856d10.6d14: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\sechost.dll
4866d10.6d14: '\Device\HarddiskVolume8\Windows\System32\ntdll.dll' has no imports
4876d10.6d14: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\ntdll.dll)
4886d10.6d14: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\ntdll.dll
4896d10.6d14: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
4906d10.6d14: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume8\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
4916d10.6d14: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
4926d10.6d14: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\ntdll.dll (Input=ntdll.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
4936d10.6d14: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa85a0000 'C:\WINDOWS\System32\ntdll.dll'
4946d10.6d14: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume8\Windows\System32\apphelp.dll)
4956d10.6d14: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\apphelp.dll
4966d10.6d14: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\apphelp.dll (rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
4976d10.6d14: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume8\Windows\System32\apphelp.dll [lacks WinVerifyTrust]
4986d10.6d14: supR3HardenedDllNotificationCallback: load 00007fffa3430000 LB 0x0008f000 C:\WINDOWS\system32\apphelp.dll [fFlags=0x0]
4996d10.6d14: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume8\Windows\System32\apphelp.dll [lacks WinVerifyTrust]
5006d10.6d14: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\ntdll.dll [lacks WinVerifyTrust]
5016d10.6d14: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\ntdll.dll (Input=ntdll.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
5026d10.6d14: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa85a0000 'C:\WINDOWS\System32\ntdll.dll'
5036d10.6d14: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa3430000 'C:\WINDOWS\system32\apphelp.dll'
5046d10.6d14: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007fffa8611770 pvNtTerminateThread=00007fffa863cac0
5056d10.6d14: supR3HardenedWinDoReSpawn(2): New child 6d24.6d28 [kernel32].
5066d10.6d14: supR3HardNtChildGatherData: PebBaseAddress=0000000001119000 cbPeb=0x388
5076d10.6d14: supR3HardNtPuChFindNtdll: uNtDllParentAddr=00007fffa85a0000 uNtDllChildAddr=00007fffa85a0000
5086d10.6d14: supR3HardenedWinSetupChildInit: uLdrInitThunk=00007fffa8611770
5096d10.6d14: supR3HardenedWinSetupChildInit: Initial context:
510 rax=0000000000000000 rbx=0000000000000000 rcx=00007ff6c4727900 rdx=0000000001119000
511 rsi=0000000000000000 rdi=0000000000000000 r8 =0000000000000000 r9 =0000000000000000
512 r10=0000000000000000 r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
513 r14=0000000000000000 r15=0000000000000000 P1=0000000000000000 P2=0000000000000000
514 rip=00007fffa860ce30 rsp=0000000000f8f7f8 rbp=0000000000000000 ctxflags=0010001b
515 cs=0033 ss=002b ds=0000 es=0000 fs=0000 gs=0000 eflags=00000200 mxcrx=00001f80
516 P3=0000000000000000 P4=0000000000000000 P5=0000000000000000 P6=0000000000000000
517 dr0=0000000000000000 dr1=0000000000000000 dr2=0000000000000000 dr3=0000000000000000
518 dr6=0000000000000000 dr7=0000000000000000 vcr=0000000000000000 dcr=0000000000000000
519 lbt=0000000000000000 lbf=0000000000000000 lxt=0000000000000000 lxf=0000000000000000
5206d10.6d14: kernel32.dll: timestamp 0x21b07e83 (rc=VINF_SUCCESS)
5216d10.6d14: supR3HardenedWinSetupChildInit: Start child.
5226d10.6d14: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 1 ms.
5236d10.6d14: supR3HardNtChildPurify: Startup delay kludge #1/0: 521 ms, 58 sleeps
5246d10.6d14: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
5256d10.6d14: *0000000000000000-0000000000e4ffff 0x0001/0x0000 0x0000000
5266d10.6d14: *0000000000e50000-0000000000e6ffff 0x0004/0x0004 0x0020000
5276d10.6d14: *0000000000e70000-0000000000e8afff 0x0002/0x0002 0x0040000
5286d10.6d14: 0000000000e8b000-0000000000e8ffff 0x0001/0x0000 0x0000000
5296d10.6d14: *0000000000e90000-0000000000f8afff 0x0000/0x0004 0x0020000
5306d10.6d14: 0000000000f8b000-0000000000f8dfff 0x0104/0x0004 0x0020000
5316d10.6d14: 0000000000f8e000-0000000000f8ffff 0x0004/0x0004 0x0020000
5326d10.6d14: *0000000000f90000-0000000000f93fff 0x0002/0x0002 0x0040000
5336d10.6d14: 0000000000f94000-0000000000f9ffff 0x0001/0x0000 0x0000000
5346d10.6d14: *0000000000fa0000-0000000000fa1fff 0x0004/0x0004 0x0020000
5356d10.6d14: 0000000000fa2000-0000000000ffffff 0x0001/0x0000 0x0000000
5366d10.6d14: *0000000001000000-0000000001118fff 0x0000/0x0004 0x0020000
5376d10.6d14: 0000000001119000-000000000111bfff 0x0004/0x0004 0x0020000
5386d10.6d14: 000000000111c000-00000000011fffff 0x0000/0x0004 0x0020000
5396d10.6d14: 0000000001200000-000000007ffdffff 0x0001/0x0000 0x0000000
5406d10.6d14: *000000007ffe0000-000000007ffe0fff 0x0002/0x0002 0x0020000
5416d10.6d14: 000000007ffe1000-000000007ffe5fff 0x0001/0x0000 0x0000000
5426d10.6d14: *000000007ffe6000-000000007ffe6fff 0x0002/0x0002 0x0020000
5436d10.6d14: 000000007ffe7000-00007ff54dfaffff 0x0001/0x0000 0x0000000
5446d10.6d14: *00007ff54dfb0000-00007ff54dfb0fff 0x0002/0x0002 0x0040000
5456d10.6d14: 00007ff54dfb1000-00007ff54dfbffff 0x0001/0x0000 0x0000000
5466d10.6d14: *00007ff54dfc0000-00007ff54dfeafff 0x0002/0x0002 0x0040000
5476d10.6d14: 00007ff54dfeb000-00007ff6c471ffff 0x0001/0x0000 0x0000000
5486d10.6d14: *00007ff6c4720000-00007ff6c4720fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
5496d10.6d14: 00007ff6c4721000-00007ff6c4796fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
5506d10.6d14: 00007ff6c4797000-00007ff6c4797fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
5516d10.6d14: 00007ff6c4798000-00007ff6c47dffff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
5526d10.6d14: 00007ff6c47e0000-00007ff6c47e0fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
5536d10.6d14: 00007ff6c47e1000-00007ff6c47e1fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
5546d10.6d14: 00007ff6c47e2000-00007ff6c47e6fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
5556d10.6d14: 00007ff6c47e7000-00007ff6c47e7fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
5566d10.6d14: 00007ff6c47e8000-00007ff6c47e8fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
5576d10.6d14: 00007ff6c47e9000-00007ff6c47ecfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
5586d10.6d14: 00007ff6c47ed000-00007ff6c4835fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
5596d10.6d14: 00007ff6c4836000-00007fffa859ffff 0x0001/0x0000 0x0000000
5606d10.6d14: *00007fffa85a0000-00007fffa85a0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume8\Windows\System32\ntdll.dll
5616d10.6d14: 00007fffa85a1000-00007fffa86b7fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume8\Windows\System32\ntdll.dll
5626d10.6d14: 00007fffa86b8000-00007fffa86fefff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume8\Windows\System32\ntdll.dll
5636d10.6d14: 00007fffa86ff000-00007fffa870afff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume8\Windows\System32\ntdll.dll
5646d10.6d14: 00007fffa870b000-00007fffa8719fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume8\Windows\System32\ntdll.dll
5656d10.6d14: 00007fffa871a000-00007fffa871afff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume8\Windows\System32\ntdll.dll
5666d10.6d14: 00007fffa871b000-00007fffa871dfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume8\Windows\System32\ntdll.dll
5676d10.6d14: 00007fffa871e000-00007fffa878ffff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume8\Windows\System32\ntdll.dll
5686d10.6d14: 00007fffa8790000-00007ffffffeffff 0x0001/0x0000 0x0000000
5696d10.6d14: VirtualBoxVM.exe: timestamp 0x5e4c1d19 (rc=VINF_SUCCESS)
5706d10.6d14: '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
5716d10.6d14: '\Device\HarddiskVolume8\Windows\System32\ntdll.dll' has no imports
5726d10.6d14: supR3HardNtChildPurify: Done after 552 ms and 0 fixes (loop #0).
5736d10.6d14: supR3HardenedEarlyCompact: Removed heap 1 (0x00000001410000 LB 0x400000)
5746d10.6d14: supR3HardNtEnableThreadCreationEx:
5756d24.6d28: Log file opened: 6.1.4r136177 g_hStartupLog=0000000000000004 g_uNtVerCombined=0xa047bb00
5766d24.6d28: supR3HardenedVmProcessInit: uNtDllAddr=00007fffa85a0000 g_uNtVerCombined=0xa047bb00 (stack ~0000000000f8f288)
5776d24.6d28: ntdll.dll: timestamp 0xb29ecf52 (rc=VINF_SUCCESS)
5786d24.6d28: New simple heap: #1 0000000001300000 LB 0x400000 (for 2031616 allocation)
5796d24.6d28: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox'
5806d24.6d28: System32: \Device\HarddiskVolume8\Windows\System32
5816d24.6d28: WinSxS: \Device\HarddiskVolume8\Windows\WinSxS
5826d24.6d28: KnownDllPath: C:\WINDOWS\System32
5836d24.6d28: supR3HardenedVmProcessInit: Opening vboxdrv...
5846d24.6d28: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
5856d24.6d28: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
5866d24.6d28: Registered Dll notification callback with NTDLL.
5876d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\kernel32.dll)
5886d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\kernel32.dll
5896d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\KERNEL32.DLL (Input=KERNEL32.DLL, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000004001:<flags> [calling]
5906d24.6d28: supR3HardenedDllNotificationCallback: load 00007fffa5710000 LB 0x002a4000 C:\WINDOWS\System32\KERNELBASE.dll [fFlags=0x0]
5916d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\KernelBase.dll)
5926d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\KernelBase.dll
5936d24.6d28: supR3HardenedDllNotificationCallback: load 00007fffa70c0000 LB 0x000b2000 C:\WINDOWS\System32\KERNEL32.DLL [fFlags=0x0]
5946d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
5956d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa70c0000 'C:\WINDOWS\System32\KERNEL32.DLL'
5966d24.6d28: supR3HardenedDllNotificationCallback: load 00007ff6c4720000 LB 0x00116000 C:\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe [fFlags=0x0]
5976d24.6d28: '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
5986d24.6d28: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe)
5996d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
6006d24.6d28: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007fffa8611770 pvNtTerminateThread=00007fffa863cac0
6016d10.6d14: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 86 ms.
6026d24.6d28: \SystemRoot\System32\ntdll.dll:
6036d24.6d28: CreationTime: 2020-05-03T03:29:33.075535900Z
6046d24.6d28: LastWriteTime: 2020-05-03T03:29:33.128546900Z
6056d24.6d28: ChangeTime: 2020-05-04T03:07:36.221273200Z
6066d24.6d28: FileAttributes: 0x20
6076d24.6d28: Size: 0x1e8460
6086d24.6d28: NT Headers: 0xd8
6096d24.6d28: Timestamp: 0xb29ecf52
6106d24.6d28: Machine: 0x8664 - amd64
6116d24.6d28: Timestamp: 0xb29ecf52
6126d24.6d28: Image Version: 10.0
6136d24.6d28: SizeOfImage: 0x1f0000 (2031616)
6146d24.6d28: Resource Dir: 0x17f000 LB 0x6f310
6156d24.6d28: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
6166d24.6d28: [Raw version resource data: 0x17f0f0 LB 0x380, codepage 0x0 (reserved 0x0)]
6176d24.6d28: ProductName: Microsoft® Windows® Operating System
6186d24.6d28: ProductVersion: 10.0.18362.815
6196d24.6d28: FileVersion: 10.0.18362.815 (WinBuild.160101.0800)
6206d24.6d28: FileDescription: NT Layer DLL
6216d24.6d28: \SystemRoot\System32\kernel32.dll:
6226d24.6d28: CreationTime: 2020-04-15T16:13:02.961257500Z
6236d24.6d28: LastWriteTime: 2020-04-15T16:13:02.986662000Z
6246d24.6d28: ChangeTime: 2020-05-03T03:30:23.798603800Z
6256d24.6d28: FileAttributes: 0x20
6266d24.6d28: Size: 0xb0498
6276d24.6d28: NT Headers: 0xe8
6286d24.6d28: Timestamp: 0x21b07e83
6296d24.6d28: Machine: 0x8664 - amd64
6306d24.6d28: Timestamp: 0x21b07e83
6316d24.6d28: Image Version: 10.0
6326d24.6d28: SizeOfImage: 0xb2000 (729088)
6336d24.6d28: Resource Dir: 0xb0000 LB 0x520
6346d24.6d28: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
6356d24.6d28: [Raw version resource data: 0xb00b0 LB 0x3a4, codepage 0x0 (reserved 0x0)]
6366d24.6d28: ProductName: Microsoft® Windows® Operating System
6376d24.6d28: ProductVersion: 10.0.18362.778
6386d24.6d28: FileVersion: 10.0.18362.778 (WinBuild.160101.0800)
6396d24.6d28: FileDescription: Windows NT BASE API Client DLL
6406d24.6d28: \SystemRoot\System32\KernelBase.dll:
6416d24.6d28: CreationTime: 2020-05-03T03:29:33.628657500Z
6426d24.6d28: LastWriteTime: 2020-05-03T03:29:33.729681700Z
6436d24.6d28: ChangeTime: 2020-05-04T03:07:35.945225300Z
6446d24.6d28: FileAttributes: 0x20
6456d24.6d28: Size: 0x2a4068
6466d24.6d28: NT Headers: 0xf8
6476d24.6d28: Timestamp: 0xb89efff3
6486d24.6d28: Machine: 0x8664 - amd64
6496d24.6d28: Timestamp: 0xb89efff3
6506d24.6d28: Image Version: 10.0
6516d24.6d28: SizeOfImage: 0x2a4000 (2768896)
6526d24.6d28: Resource Dir: 0x27e000 LB 0x548
6536d24.6d28: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
6546d24.6d28: [Raw version resource data: 0x27e0b0 LB 0x3bc, codepage 0x0 (reserved 0x0)]
6556d24.6d28: ProductName: Microsoft® Windows® Operating System
6566d24.6d28: ProductVersion: 10.0.18362.815
6576d24.6d28: FileVersion: 10.0.18362.815 (WinBuild.160101.0800)
6586d24.6d28: FileDescription: Windows NT BASE API Client DLL
6596d24.6d28: \SystemRoot\System32\apisetschema.dll:
6606d24.6d28: CreationTime: 2019-03-19T04:43:54.837151500Z
6616d24.6d28: LastWriteTime: 2019-03-19T04:43:54.837151500Z
6626d24.6d28: ChangeTime: 2020-05-03T03:30:23.758596400Z
6636d24.6d28: FileAttributes: 0x20
6646d24.6d28: Size: 0x1d028
6656d24.6d28: NT Headers: 0xc8
6666d24.6d28: Timestamp: 0xd6ced080
6676d24.6d28: Machine: 0x8664 - amd64
6686d24.6d28: Timestamp: 0xd6ced080
6696d24.6d28: Image Version: 10.0
6706d24.6d28: SizeOfImage: 0x1e000 (122880)
6716d24.6d28: Resource Dir: 0x1d000 LB 0x408
6726d24.6d28: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
6736d24.6d28: [Raw version resource data: 0x1d060 LB 0x3a8, codepage 0x0 (reserved 0x0)]
6746d24.6d28: ProductName: Microsoft® Windows® Operating System
6756d24.6d28: ProductVersion: 10.0.18362.1
6766d24.6d28: FileVersion: 10.0.18362.1 (WinBuild.160101.0800)
6776d24.6d28: FileDescription: ApiSet Schema DLL
6786d24.6d28: Found driver SymNetS (0x2)
6796d24.6d28: Found driver SRTSPX (0x2)
6806d24.6d28: Found driver SymEvent (0x2)
6816d24.6d28: Found driver SymIRON (0x2)
6826d24.6d28: supR3HardenedWinFindAdversaries: 0x2
6836d24.6d28: \SystemRoot\System32\drivers\symevent64x86.sys:
6846d24.6d28: CreationTime: 2018-05-07T20:10:45.241730500Z
6856d24.6d28: LastWriteTime: 2019-03-21T09:37:41.102289300Z
6866d24.6d28: ChangeTime: 2019-10-07T03:10:05.970074600Z
6876d24.6d28: FileAttributes: 0x20
6886d24.6d28: Size: 0x186e0
6896d24.6d28: NT Headers: 0xf0
6906d24.6d28: Timestamp: 0x5bbbe164
6916d24.6d28: Machine: 0x8664 - amd64
6926d24.6d28: Timestamp: 0x5bbbe164
6936d24.6d28: Image Version: 6.3
6946d24.6d28: SizeOfImage: 0x21000 (135168)
6956d24.6d28: Resource Dir: 0x1f000 LB 0x3c8
6966d24.6d28: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
6976d24.6d28: [Raw version resource data: 0x1f0b8 LB 0x310, codepage 0x4e4 (reserved 0x0)]
6986d24.6d28: ProductName: SYMEVENT
6996d24.6d28: ProductVersion: 14.0.7.71
7006d24.6d28: FileVersion: 14.0.7.71
7016d24.6d28: FileDescription: Symantec Event Library
7026d24.6d28: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox'
7036d24.6d28: Calling main()
7046d24.6d28: SUPR3HardenedMain: pszProgName=VirtualBoxVM fFlags=0x2
7056d24.6d28: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox'
7066d24.6d28: '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
7076d24.6d28: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe)
7086d24.6d28: SUPR3HardenedMain: Final process, opening VBoxDrv...
7096d24.6d28: supR3HardenedEarlyCompact: Removed heap 1 (0x00000001300000 LB 0x400000)
7106d24.6d28: supR3HardNtEnableThreadCreationEx:
7116d24.6d28: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxSupLib.dll)
7126d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxSupLib.dll
7136d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
7146d24.6d28: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
7156d24.6d28: supR3HardenedDllNotificationCallback: load 00007fff9d750000 LB 0x00005000 C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL [fFlags=0x0]
7166d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
7176d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
7186d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
7196d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff9d750000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
7206d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
7216d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
7226d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff9d750000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
7236d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff9d750000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
7246d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
7256d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msasn1.dll'.
7266d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'crypt32.dll'.
7276d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #27 'rpcrt4.dll'.
7286d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\wintrust.dll)
7296d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\wintrust.dll
7306d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
7316d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume8\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
7326d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\rpcrt4.dll)
7336d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\rpcrt4.dll
7346d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
7356d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume8\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
7366d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #32 'msasn1.dll'.
7376d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\crypt32.dll)
7386d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\crypt32.dll
7396d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
7406d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume8\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
7416d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\msasn1.dll)
7426d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\msasn1.dll
7436d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
7446d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume8\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
7456d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\msvcrt.dll)
7466d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\msvcrt.dll
7476d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
7486d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume8\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
7496d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
7506d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
7516d24.6d28: supR3HardenedDllNotificationCallback: load 00007fffa68a0000 LB 0x0009e000 C:\WINDOWS\System32\msvcrt.dll [fFlags=0x0]
7526d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
7536d24.6d28: supR3HardenedDllNotificationCallback: load 00007fffa5510000 LB 0x00012000 C:\WINDOWS\System32\MSASN1.dll [fFlags=0x0]
7546d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
7556d24.6d28: supR3HardenedDllNotificationCallback: load 00007fffa61c0000 LB 0x000fa000 C:\WINDOWS\System32\ucrtbase.dll [fFlags=0x0]
7566d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\ucrtbase.dll)
7576d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\ucrtbase.dll
7586d24.6d28: supR3HardenedDllNotificationCallback: load 00007fffa6500000 LB 0x00149000 C:\WINDOWS\System32\CRYPT32.dll [fFlags=0x0]
7596d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
7606d24.6d28: supR3HardenedDllNotificationCallback: load 00007fffa81b0000 LB 0x00120000 C:\WINDOWS\System32\RPCRT4.dll [fFlags=0x0]
7616d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
7626d24.6d28: supR3HardenedDllNotificationCallback: load 00007fffa5600000 LB 0x0005c000 C:\WINDOWS\System32\Wintrust.dll [fFlags=0x0]
7636d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
7646d24.6d28: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
7656d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
7666d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa5710000 'api-ms-win-core-synch-l1-2-0'
7676d24.6d28: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-fibers-l1-1-1) -> 0x0, fPresent=1
7686d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
7696d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa5710000 'api-ms-win-core-fibers-l1-1-1'
7706d24.6d28: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-fibers-l1-1-1) -> 0x0, fPresent=1
7716d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
7726d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa5710000 'api-ms-win-core-fibers-l1-1-1'
7736d24.6d28: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
7746d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
7756d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa5710000 'api-ms-win-core-synch-l1-2-0'
7766d24.6d28: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-l1-2-1) -> 0x0, fPresent=1
7776d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-l1-2-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
7786d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa5710000 'api-ms-win-core-localization-l1-2-1'
7796d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa5600000 'C:\WINDOWS\system32\Wintrust.dll'
7806d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\bcrypt.dll)
7816d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\bcrypt.dll
7826d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\bcrypt.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
7836d24.6d28: supR3HardenedDllNotificationCallback: load 00007fffa6310000 LB 0x00026000 C:\WINDOWS\System32\bcrypt.dll [fFlags=0x0]
7846d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
7856d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6310000 'C:\WINDOWS\system32\bcrypt.dll'
7866d24.6d28: bcrypt.dll loaded at 00007fffa6310000, BCryptOpenAlgorithmProvider at 00007fffa6314c70, preloading providers:
7876d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\bcryptprimitives.dll)
7886d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\bcryptprimitives.dll
7896d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\bcryptprimitives.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
7906d24.6d28: supR3HardenedDllNotificationCallback: load 00007fffa6140000 LB 0x00080000 C:\WINDOWS\System32\bcryptprimitives.dll [fFlags=0x0]
7916d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
7926d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6140000 'C:\WINDOWS\system32\bcryptprimitives.dll'
7936d24.6d28: BCryptOpenAlgorithmProvider(,'MD2',0,0) -> 0x0 (hAlgo=000000000180a9b0)
7946d24.6d28: BCryptOpenAlgorithmProvider(,'MD4',0,0) -> 0x0 (hAlgo=000000000180fd50)
7956d24.6d28: BCryptOpenAlgorithmProvider(,'MD5',0,0) -> 0x0 (hAlgo=0000000001810050)
7966d24.6d28: BCryptOpenAlgorithmProvider(,'SHA1',0,0) -> 0x0 (hAlgo=0000000001810350)
7976d24.6d28: BCryptOpenAlgorithmProvider(,'SHA256',0,0) -> 0x0 (hAlgo=0000000001810650)
7986d24.6d28: BCryptOpenAlgorithmProvider(,'SHA512',0,0) -> 0x0 (hAlgo=0000000001810950)
7996d24.6d28: BCryptOpenAlgorithmProvider(,'RSA',0,0) -> 0x0 (hAlgo=0000000001810c50)
8006d24.6d28: BCryptOpenAlgorithmProvider(,'DSA',0,0) -> 0x0 (hAlgo=0000000001810f50)
8016d24.6d28: supR3HardenedDllNotificationCallback: load 00007fffa6340000 LB 0x00017000 C:\WINDOWS\System32\CRYPTSP.dll [fFlags=0x0]
8026d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\cryptsp.dll)
8036d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\cryptsp.dll
8046d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'bcrypt.dll'.
8056d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\rsaenh.dll)
8066d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\rsaenh.dll
8076d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
8086d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume8\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
8096d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
8106d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
8116d24.6d28: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
8126d24.6d28: supR3HardenedDllNotificationCallback: load 00007fffa4840000 LB 0x00033000 C:\WINDOWS\system32\rsaenh.dll [fFlags=0x0]
8136d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
8146d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
8156d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'bcryptprimitives.dll'.
8166d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\cryptbase.dll)
8176d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\cryptbase.dll
8186d24.6d28: supR3HardenedDllNotificationCallback: load 00007fffa4ea0000 LB 0x0000c000 C:\WINDOWS\SYSTEM32\CRYPTBASE.dll [fFlags=0x0]
8196d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\cryptbase.dll [lacks WinVerifyTrust]
8206d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
8216d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcryptprimitives.dll'...
8226d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcryptprimitives.dll' -> '\Device\HarddiskVolume8\Windows\System32\bcryptprimitives.dll' [rcNtRedir=0xc0150008]
8236d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
8246d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
8256d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa70c0000 'C:\WINDOWS\System32\kernel32.dll'
8266d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
8276d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\WINTRUST.DLL (Input=WINTRUST.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
8286d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa5600000 'C:\WINDOWS\System32\WINTRUST.DLL'
8296d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
8306d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\CRYPT32.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
8316d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\CRYPT32.dll'
8326d24.6d28: supR3HardenedDllNotificationCallback: load 00007fffa6950000 LB 0x0001d000 C:\WINDOWS\System32\imagehlp.dll [fFlags=0x0]
8336d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #20 'rpcrt4.dll'.
8346d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\imagehlp.dll)
8356d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\imagehlp.dll
8366d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
8376d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
8386d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume8\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
8396d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
8406d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
8416d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
8426d24.6d28: supR3HardenedDllNotificationCallback: load 00007fffa6650000 LB 0x00097000 C:\WINDOWS\System32\sechost.dll [fFlags=0x0]
8436d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'rpcrt4.dll'.
8446d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\sechost.dll)
8456d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\sechost.dll
8466d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
8476d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'rpcrt4.dll'.
8486d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\gpapi.dll)
8496d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\gpapi.dll
8506d24.6d28: supR3HardenedDllNotificationCallback: load 00007fffa3ea0000 LB 0x00022000 C:\WINDOWS\SYSTEM32\gpapi.dll [fFlags=0x0]
8516d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\gpapi.dll [lacks WinVerifyTrust]
8526d24.6d28: supR3HardenedDllNotificationCallback: load 00007fffa54e0000 LB 0x00023000 C:\WINDOWS\System32\profapi.dll [fFlags=0x0]
8536d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\profapi.dll)
8546d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\profapi.dll
8556d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
8566d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'crypt32.dll'.
8576d24.6d28: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume8\Windows\System32\cryptnet.dll)
8586d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\cryptnet.dll
8596d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
8606d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume8\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
8616d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
8626d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
8636d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume8\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
8646d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
8656d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
8666d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume8\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
8676d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
8686d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
8696d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume8\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
8706d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
8716d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
8726d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume8\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
8736d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
8746d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (Input=cryptnet.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
8756d24.6d28: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume8\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
8766d24.6d28: supR3HardenedDllNotificationCallback: load 00007fff9f4c0000 LB 0x0002f000 C:\WINDOWS\System32\cryptnet.dll [fFlags=0x0]
8776d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume8\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
8786d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume8\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
8796d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
8806d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff9f4c0000 'C:\WINDOWS\System32\cryptnet.dll'
8816d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume8\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
8826d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
8836d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff9f4c0000 'C:\WINDOWS\System32\cryptnet.dll'
8846d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume8\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
8856d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
8866d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff9f4c0000 'C:\WINDOWS\System32\cryptnet.dll'
8876d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume8\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
8886d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
8896d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff9f4c0000 'C:\WINDOWS\System32\cryptnet.dll'
8906d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume8\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
8916d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
8926d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff9f4c0000 'C:\WINDOWS\System32\cryptnet.dll'
8936d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume8\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
8946d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
8956d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff9f4c0000 'C:\WINDOWS\System32\cryptnet.dll'
8966d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume8\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
8976d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff9f4c0000 'C:\WINDOWS\System32\cryptnet.dll'
8986d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume8\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
8996d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff9f4c0000 'C:\WINDOWS\System32\cryptnet.dll'
9006d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume8\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
9016d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff9f4c0000 'C:\WINDOWS\System32\cryptnet.dll'
9026d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume8\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
9036d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff9f4c0000 'C:\WINDOWS\System32\cryptnet.dll'
9046d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume8\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
9056d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff9f4c0000 'C:\WINDOWS\System32\cryptnet.dll'
9066d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff9f4c0000 'C:\WINDOWS\System32\cryptnet.dll'
9076d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume8\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
9086d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff9f4c0000 'C:\Windows\System32\cryptnet.dll'
9096d24.6d28: supR3HardenedDllNotificationCallback: load 00007fffa82d0000 LB 0x000a3000 C:\WINDOWS\System32\advapi32.dll [fFlags=0x0]
9106d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
9116d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'sechost.dll'.
9126d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #27 'rpcrt4.dll'.
9136d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\advapi32.dll)
9146d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\advapi32.dll
9156d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
9166d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
9176d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume8\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
9186d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
9196d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'sechost.dll'...
9206d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'sechost.dll' -> '\Device\HarddiskVolume8\Windows\System32\sechost.dll' [rcNtRedir=0xc0150008]
9216d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\sechost.dll [lacks WinVerifyTrust]
9226d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
9236d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume8\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
9246d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
9256d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
9266d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
9276d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
9286d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
9296d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
9306d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000000 pwszName=\SystemRoot\System32\ntdll.dll
9316d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: New context 000000000187dd30
9326d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000187dd30
9336d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2F110B40CF67FEF4EFA84C23431B3B42233E381F
9346d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
9356d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\rpcrt4.dll (Input=rpcrt4.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
9366d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa81b0000 'C:\WINDOWS\System32\rpcrt4.dll'
9376d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
9386d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
9396d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
9406d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
9416d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
9426d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
9436d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0416~31bf3856ad364e35~amd64~~10.0.18362.815.cat'; file='\SystemRoot\System32\ntdll.dll'
9446d24.6d28: g_pfnWinVerifyTrust=00007fffa56061f0
9456d24.6d28: supR3HardenedScreenImage/preload: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\crypt32.dll [redoing WinVerifyTrust]
9466d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
9476d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
9486d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
9496d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
9506d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
9516d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
9526d24.6d28: supR3HardenedScreenImage/preload: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume8\Windows\System32\crypt32.dll'
9536d24.6d28: supR3HardenedScreenImage/preload: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\wintrust.dll [redoing WinVerifyTrust]
9546d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
9556d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
9566d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
9576d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\crypt32.dll
9586d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
9596d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
9606d24.6d28: supR3HardenedScreenImage/preload: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume8\Windows\System32\wintrust.dll'
9616d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
9626d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
9636d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
9646d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
9656d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume8\Windows\System32\advapi32.dll'
9666d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000388 pwszName=\Device\HarddiskVolume8\Windows\System32\cryptnet.dll
9676d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000187dd30
9686d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000187dd30
9696d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=09032EBC3D9D9BDDC0EE4A6463C043296B79FF20
9706d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
9716d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
9726d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
9736d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0416~31bf3856ad364e35~amd64~~10.0.18362.815.cat'; file='\Device\HarddiskVolume8\Windows\System32\cryptnet.dll'
9746d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
9756d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume8\Windows\System32\cryptnet.dll'
9766d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
9776d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
9786d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
9796d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume8\Windows\System32\profapi.dll'
9806d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
9816d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
9826d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
9836d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume8\Windows\System32\gpapi.dll'
9846d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
9856d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
9866d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
9876d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume8\Windows\System32\sechost.dll'
9886d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
9896d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
9906d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
9916d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume8\Windows\System32\imagehlp.dll'
9926d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
9936d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
9946d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
9956d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume8\Windows\System32\cryptbase.dll'
9966d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
9976d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
9986d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\crypt32.dll
9996d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
10006d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
10016d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume8\Windows\System32\rsaenh.dll'
10026d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\rsaenh.dll
10036d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
10046d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
10056d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
10066d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume8\Windows\System32\cryptsp.dll'
10076d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
10086d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
10096d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume8\Windows\System32\bcryptprimitives.dll'
10106d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
10116d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
10126d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume8\Windows\System32\bcrypt.dll'
10136d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
10146d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
10156d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume8\Windows\System32\ucrtbase.dll'
10166d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
10176d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
10186d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume8\Windows\System32\msvcrt.dll'
10196d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
10206d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
10216d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume8\Windows\System32\msasn1.dll'
10226d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
10236d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
10246d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume8\Windows\System32\rpcrt4.dll'
10256d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
10266d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 24202) fWinVerifyTrust=1 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxSupLib.dll'
10276d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
10286d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 24202) fWinVerifyTrust=1 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe'
10296d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
10306d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
10316d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume8\Windows\System32\KernelBase.dll'
10326d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
10336d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
10346d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume8\Windows\System32\kernel32.dll'
10356d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\system32\crypt32.dll'
10366d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0x5ad46780fa5df300 DC=com, DC=microsoft, CN=Microsoft Root Certificate Authority
10376d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0xea5386456178582b C=ZA, ST=Western Cape, L=Durbanville, O=Thawte, OU=Thawte Certification, CN=Thawte Timestamping CA
10386d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0xcb6ade9265bfb800 O=AO Kaspersky Lab, CN=Kaspersky Anti-Virus Personal Root Certificate
10396d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0x3be670c1bd02a900 OU=Copyright (c) 1997 Microsoft Corp., OU=Microsoft Corporation, CN=Microsoft Root Authority
10406d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0xe991ee72b03db500 C=US, O=Symantec Corporation, CN=Symantec Enterprise Mobile Root for Microsoft
10416d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0x4d3835aa4180b200 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2011
10426d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0x646e3fe3ba08df00 C=US, O=MSFT, CN=Microsoft Authenticode(tm) Root Authority
10436d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0xec15846517d9ac00 C=CA, ST=Ontario, L=Toronto, O=SurfEasy, CN=SurfEasy CA, Email=ops@surfeasy.com
10446d24.6d28: supR3HardenedWinIsDesiredRootCA: skipping - not-self-signed: C=BZ, ST=Belize, L=Belize City, O=DT Soft Ltd, OU=Digital ID Class 3 - Microsoft Software Validation v2, CN=DT Soft Ltd
10456d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0xece4e4289e08b900 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010
10466d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0xf3bb4d7e894b420 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft ECC TS Root Certificate Authority 2018
10476d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0x43a9cc371ff5385a O=Microsoft Trust Network, OU=Microsoft Corporation, OU=Microsoft Time Stamping Service Root, OU=Copyright (c) 1997 Microsoft Corp.
10486d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0x2e2d2c7c68f0202e O=VeriSign Trust Network, OU=VeriSign, Inc., OU=VeriSign Time Stamping Service Root, OU=NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.
10496d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0xcec3d46562b9be8e C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft ECC Product Root Certificate Authority 2018
10506d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0xca58a05dd401ae00 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Time Stamp Root Certificate Authority 2014
10516d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0xa12b07674f1bf600 C=US, O=AffirmTrust, CN=AffirmTrust Commercial
10526d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0xd8dbfb2c27bfb200 C=US, O=thawte, Inc., OU=Certification Services Division, OU=(c) 2008 thawte, Inc. - For authorized use only, CN=thawte Primary Root CA - G3
10536d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0xd66525adaaa600 C=JP, O=Japanese Government, OU=GPKI, CN=ApplicationCA2 Root
10546d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0x91e3728b8b40d000 C=GB, ST=Greater Manchester, L=Salford, O=COMODO CA Limited, CN=COMODO Certification Authority
10556d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0x61a3a33f81aace00 C=US, ST=UT, L=Salt Lake City, O=The USERTRUST Network, OU=http://www.usertrust.com, CN=UTN-USERFirst-Object
10566d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0x6b7bdc34cd37bb00 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root G2
10576d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0x57ba5395b561bf00 C=BM, O=QuoVadis Limited, OU=Root Certification Authority, CN=QuoVadis Root Certification Authority
10586d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0xf4fd306318ccda00 C=US, O=GeoTrust Inc., CN=GeoTrust Global CA
10596d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0x83085097e9afdf00 O=Digital Signature Trust Co., CN=DST Root CA X3
10606d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0x780679907625cc00 OU=GlobalSign Root CA - R3, O=GlobalSign, CN=GlobalSign
10616d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0x3d98ab22bb04a300 C=IE, O=Baltimore, OU=CyberTrust, CN=Baltimore CyberTrust Root
10626d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0xa0ee62086758b15d C=US, O=Equifax, OU=Equifax Secure Certificate Authority
10636d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0xd944bca189a00 C=BM, O=QuoVadis Limited, CN=QuoVadis Root CA 2
10646d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0x8ff6fc03c1edbd00 C=US, ST=Arizona, L=Scottsdale, O=Starfield Technologies, Inc., CN=Starfield Root Certificate Authority - G2
10656d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0xc6fa4243b695b600 C=US, O=Entrust, Inc., OU=www.entrust.net/CPS is incorporated by reference, OU=(c) 2006 Entrust, Inc., CN=Entrust Root Certification Authority
10666d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0xa3ce8d99e60eda00 C=BE, O=GlobalSign nv-sa, OU=Root CA, CN=GlobalSign Root CA
10676d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0x560ad29254e89100 C=GB, ST=Greater Manchester, L=Salford, O=COMODO CA Limited, CN=COMODO RSA Certification Authority
10686d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0xa671e9fec832b700 C=US, O=Starfield Technologies, Inc., OU=Starfield Class 2 Certification Authority
10696d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0xa8de7211e13be200 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root CA
10706d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0x7ae89c50f0b6a00f C=US, O=GTE Corporation, OU=GTE CyberTrust Solutions, Inc., CN=GTE CyberTrust Global Root
10716d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0xd45980fbf0a0ac00 C=US, O=thawte, Inc., OU=Certification Services Division, OU=(c) 2006 thawte, Inc. - For authorized use only, CN=thawte Primary Root CA
10726d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0x4d3835aa4180b200 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2011
10736d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0xc9edb72b684ba00 C=US, O=Entrust, Inc., OU=See www.entrust.net/legal-terms, OU=(c) 2009 Entrust, Inc. - for authorized use only, CN=Entrust Root Certification Authority - G2
10746d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0xf5cd95e581a4ab00 C=US, O=SecureTrust Corporation, CN=SecureTrust CA
10756d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0xabd0695c5d11d15e C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority - G2, OU=(c) 1998 VeriSign, Inc. - For authorized use only, OU=VeriSign Trust Network
10766d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0x5534b165029017e7 C=US, O=Equifax Secure Inc., CN=Equifax Secure Global eBusiness CA-1
10776d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0xbebef0d2217f0bfb C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root G3
10786d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0x6f2ebe0e24cfa600 OU=GlobalSign Root CA - R2, O=GlobalSign, CN=GlobalSign
10796d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0x14018a1bf29e595c C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority
10806d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0x9e5bc2d78b6a3636 C=ZA, ST=Western Cape, L=Cape Town, O=Thawte Consulting cc, OU=Certification Services Division, CN=Thawte Premium Server CA, Email=premium-server@thawte.com
10816d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0x7c4fd32ec1b1ce00 C=PL, O=Unizeto Sp. z o.o., CN=Certum CA
10826d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0xd4fbe673e5ccc600 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA
10836d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0xb352b1523915d000 C=JP, O=SECOM Trust Systems CO.,LTD., OU=Security Communication RootCA2
10846d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0x16e64d2a56ccf200 C=US, ST=Arizona, L=Scottsdale, O=Starfield Technologies, Inc., OU=http://certificates.starfieldtech.com/repository/, CN=Starfield Services Root Certificate Authority
10856d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0xef477acf4ab2d300 C=DE, O=D-Trust GmbH, CN=D-TRUST Root Class 3 CA 2 2009
10866d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0x1b8578514b74ac00 C=US, O=WFA Hotspot 2.0, CN=Hotspot 2.0 Trust Root CA - 03
10876d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0xb28612a94b4dad00 O=Entrust.net, OU=www.entrust.net/CPS_2048 incorp. by ref. (limits liab.), OU=(c) 1999 Entrust.net Limited, CN=Entrust.net Certification Authority (2048)
10886d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0x357a29080824af00 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2006 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G5
10896d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0x59faf1086271bf00 C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com, Inc., CN=Go Daddy Root Certificate Authority - G2
10906d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0x466cbc09db88c100 C=IL, O=StartCom Ltd., OU=Secure Digital Certificate Signing, CN=StartCom Certification Authority
10916d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0x30669a4e82fa800 C=US, O=America Online Inc., CN=America Online Root Certification Authority 1
10926d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0xb16dd37ffeb3b300 C=JP, O=SECOM Trust.net, OU=Security Communication RootCA1
10936d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0x3401b15e3761c700 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2008 VeriSign, Inc. - For authorized use only, CN=VeriSign Universal Root Certification Authority
10946d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0x7cd4ff7b15b8be00 C=US, O=GeoTrust Inc., CN=GeoTrust Primary Certification Authority
10956d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0x491857ead79dde00 C=US, O=The Go Daddy Group, Inc., OU=Go Daddy Class 2 Certification Authority
10966d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0xab549401526569d3 L=Internet, O=VeriSign, Inc., OU=VeriSign Commercial Software Publishers CA
10976d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0xe66b56ffc86e50a4 C=ZA, ST=Western Cape, L=Cape Town, O=Thawte Consulting cc, OU=Certification Services Division, CN=Thawte Server CA, Email=server-certs@thawte.com
10986d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0x1f78fc529cbacb00 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 1999 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G3
10996d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0xc2ba72a37dfbe300 C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Trusted Network CA
11006d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0xcec3d46562b9be8e C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft ECC Product Root Certificate Authority 2018
11016d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0x8043e4ce150ead00 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID Root CA
11026d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0xa8b43f38c3f7b100 C=US, ST=UT, L=Salt Lake City, O=The USERTRUST Network, OU=http://www.usertrust.com, CN=UTN-USERFirst-Hardware
11036d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0x331d58625ee2dc00 C=US, O=GeoTrust Inc., OU=(c) 2008 GeoTrust Inc. - For authorized use only, CN=GeoTrust Primary Certification Authority - G3
11046d24.6d28: supR3HardenedWinIsDesiredRootCA: Adding 0xf2e6331af7b700 C=SE, O=AddTrust AB, OU=AddTrust External TTP Network, CN=AddTrust External CA Root
11056d24.6d28: supR3HardenedWinRetrieveTrustedRootCAs: cAdded=68
11066d24.6d28: SUPR3HardenedMain: Load Runtime...
11076d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
11086d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
11096d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
11106d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rpcrt4.dll'.
11116d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ws2_32.dll'.
11126d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxRT.dll) WinVerifyTrust
11136d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxRT.dll
11146d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
11156d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume8\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
11166d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
11176d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
11186d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'rpcrt4.dll'.
11196d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\ws2_32.dll) WinVerifyTrust
11206d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\ws2_32.dll
11216d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
11226d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume8\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
11236d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\rpcrt4.dll
11246d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
11256d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
11266d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
11276d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume8\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
11286d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\rpcrt4.dll
11296d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
11306d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
11316d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcp100.dll) WinVerifyTrust
11326d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcp100.dll
11336d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
11346d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
11356d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
11366d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
11376d24.6d28: Detected WinVerifyTrust recursion: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
11386d24.6d28: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll)
11396d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll
11406d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
11416d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll) WinVerifyTrust
11426d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000a01:<flags> [calling]
11436d24.6d28: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxRT.dll
11446d24.6d28: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll [avoiding WinVerifyTrust]
11456d24.6d28: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcp100.dll
11466d24.6d28: supR3HardenedDllNotificationCallback: load 0000000073420000 LB 0x000d2000 C:\Program Files\Oracle\VirtualBox\MSVCR100.dll [fFlags=0x0]
11476d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll [avoiding WinVerifyTrust]
11486d24.6d28: supR3HardenedDllNotificationCallback: load 0000000072e10000 LB 0x00098000 C:\Program Files\Oracle\VirtualBox\MSVCP100.dll [fFlags=0x0]
11496d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcp100.dll
11506d24.6d28: supR3HardenedDllNotificationCallback: load 00007fffa6fe0000 LB 0x0006f000 C:\WINDOWS\System32\WS2_32.dll [fFlags=0x0]
11516d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\ws2_32.dll
11526d24.6d28: supR3HardenedDllNotificationCallback: load 00007fff3a190000 LB 0x005ed000 C:\Program Files\Oracle\VirtualBox\VBoxRT.dll [fFlags=0x0]
11536d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxRT.dll
11546d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
11556d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
11566d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxRT.dll
11576d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
11586d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff3a190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11596d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
11606d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
11616d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
11626d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
11636d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxRT.dll
11646d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
11656d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff3a190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11666d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
11676d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
11686d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
11696d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
11706d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxRT.dll
11716d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
11726d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff3a190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11736d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
11746d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
11756d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
11766d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
11776d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxRT.dll
11786d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
11796d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff3a190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11806d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
11816d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
11826d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
11836d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
11846d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxRT.dll
11856d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
11866d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff3a190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11876d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
11886d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
11896d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
11906d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
11916d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxRT.dll
11926d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
11936d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff3a190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11946d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
11956d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
11966d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
11976d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
11986d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff3a190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
11996d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
12006d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
12016d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
12026d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
12036d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff3a190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
12046d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
12056d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
12066d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
12076d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
12086d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff3a190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
12096d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
12106d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
12116d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
12126d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
12136d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff3a190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
12146d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
12156d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
12166d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
12176d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
12186d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff3a190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
12196d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
12206d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
12216d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
12226d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
12236d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff3a190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
12246d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
12256d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
12266d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
12276d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
12286d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff3a190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
12296d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
12306d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
12316d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
12326d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
12336d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxRT.dll
12346d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
12356d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff3a190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
12366d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
12376d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
12386d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
12396d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
12406d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff3a190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
12416d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
12426d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
12436d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
12446d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
12456d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff3a190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
12466d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
12476d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
12486d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
12496d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
12506d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff3a190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
12516d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
12526d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
12536d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
12546d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
12556d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff3a190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
12566d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
12576d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
12586d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
12596d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
12606d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff3a190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
12616d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
12626d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
12636d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
12646d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
12656d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff3a190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
12666d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
12676d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
12686d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
12696d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
12706d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff3a190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
12716d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
12726d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
12736d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
12746d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
12756d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff3a190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
12766d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
12776d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
12786d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
12796d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
12806d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff3a190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
12816d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
12826d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
12836d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
12846d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
12856d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff3a190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
12866d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
12876d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
12886d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
12896d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
12906d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff3a190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
12916d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
12926d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
12936d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
12946d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
12956d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff3a190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
12966d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
12976d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
12986d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
12996d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
13006d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff3a190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13016d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
13026d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
13036d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
13046d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
13056d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff3a190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13066d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
13076d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
13086d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
13096d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
13106d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff3a190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13116d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
13126d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
13136d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
13146d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
13156d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxRT.dll
13166d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
13176d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff3a190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13186d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
13196d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
13206d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
13216d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
13226d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff3a190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13236d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
13246d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
13256d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
13266d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
13276d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff3a190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13286d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'.
13296d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
13306d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff3a190000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
13316d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
13326d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 24202) fWinVerifyTrust=1 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll'
13336d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\wintrust.dll
13346d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
13356d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa5600000 'C:\WINDOWS\system32\Wintrust.dll'
13366d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\rsaenh.dll
13376d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
13386d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
13396d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
13406d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
13416d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
13426d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\system32\crypt32.dll'
13436d24.6d28: SUPR3HardenedMain: Load TrustedMain...
13446d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
13456d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'opengl32.dll'.
13466d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'uicommon.dll'.
13476d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
13486d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcp100.dll'.
13496d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msvcr100.dll'.
13506d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'qt5corevbox.dll'.
13516d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'qt5guivbox.dll'.
13526d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'qt5widgetsvbox.dll'.
13536d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'qt5openglvbox.dll'.
13546d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'user32.dll'.
13556d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'ole32.dll'.
13566d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'oleaut32.dll'.
13576d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'winmm.dll'.
13586d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll) WinVerifyTrust
13596d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll
13606d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
13616d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume8\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
13626d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
13636d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
13646d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'winmmbase.dll'.
13656d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msvcrt.dll'.
13666d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\winmm.dll) WinVerifyTrust
13676d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\winmm.dll
13686d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
13696d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume8\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
13706d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
13716d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume8\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
13726d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\msvcrt.dll
13736d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmmbase.dll'...
13746d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmmbase.dll' -> '\Device\HarddiskVolume8\Windows\System32\winmmbase.dll' [rcNtRedir=0xc0150008]
13756d24.6d28: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\winmmbase.dll'.
13766d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
13776d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\winmmbase.dll)
13786d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\winmmbase.dll
13796d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
13806d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume8\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
13816d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\msvcrt.dll
13826d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
13836d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\crypt32.dll
13846d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
13856d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
13866d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
13876d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'combase.dll'.
13886d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'rpcrt4.dll'.
13896d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\oleaut32.dll) WinVerifyTrust
13906d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\oleaut32.dll
13916d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
13926d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume8\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
13936d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
13946d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume8\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
13956d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
13966d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume8\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
13976d24.6d28: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\combase.dll'.
13986d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rpcrt4.dll'.
13996d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #45 'bcryptprimitives.dll'.
14006d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\combase.dll)
14016d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\combase.dll
14026d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
14036d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume8\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
14046d24.6d28: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\msvcp_win.dll'.
14056d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\msvcp_win.dll)
14066d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\msvcp_win.dll
14076d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcryptprimitives.dll'...
14086d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcryptprimitives.dll' -> '\Device\HarddiskVolume8\Windows\System32\bcryptprimitives.dll' [rcNtRedir=0xc0150008]
14096d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\bcryptprimitives.dll
14106d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
14116d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume8\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
14126d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
14136d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
14146d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #22 'rpcrt4.dll'.
14156d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #56 'gdi32.dll'.
14166d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #57 'user32.dll'.
14176d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #58 'combase.dll'.
14186d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\ole32.dll) WinVerifyTrust
14196d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\ole32.dll
14206d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
14216d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume8\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
14226d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
14236d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume8\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
14246d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\combase.dll [lacks WinVerifyTrust]
14256d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
14266d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume8\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
14276d24.6d28: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\user32.dll'.
14286d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'win32u.dll'.
14296d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #34 'gdi32.dll'.
14306d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\user32.dll)
14316d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\user32.dll
14326d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
14336d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume8\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
14346d24.6d28: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\gdi32.dll'.
14356d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'win32u.dll'.
14366d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\gdi32.dll)
14376d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\gdi32.dll
14386d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
14396d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume8\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
14406d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
14416d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume8\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
14426d24.6d28: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\win32u.dll'.
14436d24.6d28: '\Device\HarddiskVolume8\Windows\System32\win32u.dll' has no imports
14446d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\win32u.dll)
14456d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\win32u.dll
14466d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
14476d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume8\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
14486d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
14496d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
14506d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume8\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
14516d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\win32u.dll [lacks WinVerifyTrust]
14526d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
14536d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
14546d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'win32u.dll'.
14556d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #34 'gdi32.dll'.
14566d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\user32.dll) WinVerifyTrust
14576d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5openglvbox.dll'...
14586d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5openglvbox.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\qt5openglvbox.dll' [rcNtRedir=0xc0150008]
14596d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
14606d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume8\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
14616d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
14626d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
14636d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume8\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
14646d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\win32u.dll [lacks WinVerifyTrust]
14656d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
14666d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'qt5widgetsvbox.dll'.
14676d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'qt5guivbox.dll'.
14686d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5corevbox.dll'.
14696d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcr100.dll'.
14706d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll) WinVerifyTrust
14716d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll
14726d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
14736d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
14746d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
14756d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
14766d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll
14776d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
14786d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
14796d24.6d28: Detected WinVerifyTrust recursion: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll'.
14806d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
14816d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'shell32.dll'.
14826d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ole32.dll'.
14836d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
14846d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ws2_32.dll'.
14856d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'mpr.dll'.
14866d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'msvcp100.dll'.
14876d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'msvcr100.dll'.
14886d24.6d28: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll)
14896d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
14906d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
14916d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
14926d24.6d28: Detected WinVerifyTrust recursion: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll'.
14936d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ole32.dll'.
14946d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'opengl32.dll'.
14956d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
14966d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
14976d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qt5corevbox.dll'.
14986d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcp100.dll'.
14996d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msvcr100.dll'.
15006d24.6d28: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll)
15016d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
15026d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
15036d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
15046d24.6d28: Detected WinVerifyTrust recursion: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll'.
15056d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
15066d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
15076d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5guivbox.dll'.
15086d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qt5corevbox.dll'.
15096d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'shell32.dll'.
15106d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcp100.dll'.
15116d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msvcr100.dll'.
15126d24.6d28: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll)
15136d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll
15146d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
15156d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
15166d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll
15176d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
15186d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
15196d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcp100.dll
15206d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
15216d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume8\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
15226d24.6d28: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\shell32.dll'.
15236d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #77 'user32.dll'.
15246d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #79 'gdi32.dll'.
15256d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\shell32.dll)
15266d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\shell32.dll
15276d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
15286d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
15296d24.6d28: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [lacks WinVerifyTrust]
15306d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
15316d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
15326d24.6d28: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll [lacks WinVerifyTrust]
15336d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
15346d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume8\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
15356d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\user32.dll [lacks WinVerifyTrust]
15366d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
15376d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume8\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
15386d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
15396d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
15406d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
15416d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll
15426d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
15436d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
15446d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcp100.dll
15456d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
15466d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
15476d24.6d28: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [lacks WinVerifyTrust]
15486d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
15496d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume8\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
15506d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\user32.dll [lacks WinVerifyTrust]
15516d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
15526d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume8\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
15536d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
15546d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
15556d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume8\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
15566d24.6d28: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume8\Windows\System32\opengl32.dll'.
15576d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
15586d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'advapi32.dll'.
15596d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
15606d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
15616d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'glu32.dll'.
15626d24.6d28: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume8\Windows\System32\opengl32.dll)
15636d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\opengl32.dll
15646d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
15656d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume8\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
15666d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\ole32.dll
15676d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
15686d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
15696d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll
15706d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
15716d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
15726d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcp100.dll
15736d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mpr.dll'...
15746d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'mpr.dll' -> '\Device\HarddiskVolume8\Windows\System32\mpr.dll' [rcNtRedir=0xc0150008]
15756d24.6d28: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\mpr.dll'.
15766d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\mpr.dll)
15776d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\mpr.dll
15786d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
15796d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume8\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
15806d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\ws2_32.dll
15816d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
15826d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume8\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
15836d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\advapi32.dll
15846d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
15856d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume8\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
15866d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\ole32.dll
15876d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
15886d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume8\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
15896d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\shell32.dll [lacks WinVerifyTrust]
15906d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
15916d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume8\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
15926d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\user32.dll [lacks WinVerifyTrust]
15936d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'glu32.dll'...
15946d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'glu32.dll' -> '\Device\HarddiskVolume8\Windows\System32\glu32.dll' [rcNtRedir=0xc0150008]
15956d24.6d28: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume8\Windows\System32\glu32.dll'.
15966d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
15976d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
15986d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'opengl32.dll'.
15996d24.6d28: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume8\Windows\System32\glu32.dll)
16006d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\glu32.dll
16016d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
16026d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume8\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
16036d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
16046d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
16056d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume8\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
16066d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\user32.dll [lacks WinVerifyTrust]
16076d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
16086d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume8\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
16096d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\advapi32.dll
16106d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
16116d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume8\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
16126d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\msvcrt.dll
16136d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
16146d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume8\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
16156d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
16166d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
16176d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume8\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
16186d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\user32.dll [lacks WinVerifyTrust]
16196d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
16206d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume8\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
16216d24.6d28: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume8\Windows\System32\opengl32.dll [lacks WinVerifyTrust]
16226d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
16236d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume8\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
16246d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\user32.dll [lacks WinVerifyTrust]
16256d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
16266d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume8\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
16276d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\msvcrt.dll
16286d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
16296d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
16306d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
16316d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5guivbox.dll'.
16326d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qt5corevbox.dll'.
16336d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'shell32.dll'.
16346d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcp100.dll'.
16356d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msvcr100.dll'.
16366d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll) WinVerifyTrust
16376d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
16386d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
16396d24.6d28: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll [redoing WinVerifyTrust]
16406d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
16416d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
16426d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll
16436d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
16446d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
16456d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcp100.dll
16466d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
16476d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume8\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
16486d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\shell32.dll [lacks WinVerifyTrust]
16496d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
16506d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
16516d24.6d28: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [lacks WinVerifyTrust]
16526d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
16536d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
16546d24.6d28: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll [lacks WinVerifyTrust]
16556d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
16566d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume8\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
16576d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\user32.dll [lacks WinVerifyTrust]
16586d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
16596d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume8\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
16606d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
16616d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
16626d24.6d28: supR3HardenedScreenImage/Imports: 0 (was 24202) fWinVerifyTrust=1 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll'
16636d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
16646d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
16656d24.6d28: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [redoing WinVerifyTrust]
16666d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
16676d24.6d28: supR3HardenedScreenImage/Imports: 0 (was 24202) fWinVerifyTrust=1 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll'
16686d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
16696d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
16706d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll
16716d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
16726d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
16736d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcp100.dll
16746d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
16756d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
16766d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'uicommon.dll'...
16776d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'uicommon.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\uicommon.dll' [rcNtRedir=0xc0150008]
16786d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
16796d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'vboxrt.dll'.
16806d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcr100.dll'.
16816d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5corevbox.dll'.
16826d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qt5guivbox.dll'.
16836d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qt5widgetsvbox.dll'.
16846d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
16856d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'advapi32.dll'.
16866d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'ole32.dll'.
16876d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'oleaut32.dll'.
16886d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'rpcrt4.dll'.
16896d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\UICommon.dll) WinVerifyTrust
16906d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\UICommon.dll
16916d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
16926d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume8\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
16936d24.6d28: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume8\Windows\System32\opengl32.dll [redoing WinVerifyTrust]
16946d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000470 pwszName=\Device\HarddiskVolume8\Windows\System32\opengl32.dll
16956d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000187dd30
16966d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000187dd30
16976d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=0837440FAE05EB650168FFA2D15E73182F6A3A26
16986d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
16996d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume8\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
17006d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
17016d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume8\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
17026d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\oleaut32.dll
17036d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
17046d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume8\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
17056d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\ole32.dll
17066d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
17076d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume8\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
17086d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\advapi32.dll
17096d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
17106d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume8\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
17116d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\user32.dll [lacks WinVerifyTrust]
17126d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
17136d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
17146d24.6d28: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll [lacks WinVerifyTrust]
17156d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
17166d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
17176d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
17186d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
17196d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
17206d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
17216d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
17226d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
17236d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
17246d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
17256d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
17266d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
17276d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0212~31bf3856ad364e35~amd64~~10.0.18362.752.cat'; file='\Device\HarddiskVolume8\Windows\System32\opengl32.dll'
17286d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
17296d24.6d28: supR3HardenedScreenImage/Imports: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume8\Windows\System32\opengl32.dll'
17306d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000a01:<flags> [calling]
17316d24.6d28: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll
17326d24.6d28: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\opengl32.dll
17336d24.6d28: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\UICommon.dll
17346d24.6d28: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
17356d24.6d28: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
17366d24.6d28: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll [avoiding WinVerifyTrust]
17376d24.6d28: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll
17386d24.6d28: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\winmm.dll
17396d24.6d28: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume8\Windows\System32\glu32.dll [avoiding WinVerifyTrust]
17406d24.6d28: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\mpr.dll [avoiding WinVerifyTrust]
17416d24.6d28: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\winmmbase.dll [avoiding WinVerifyTrust]
17426d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
17436d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #22 'win32u.dll'.
17446d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\DXCore.dll)
17456d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\DXCore.dll
17466d24.6d28: supR3HardenedDllNotificationCallback: load 00007fffa55d0000 LB 0x00021000 C:\WINDOWS\System32\win32u.dll [fFlags=0x0]
17476d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\win32u.dll [avoiding WinVerifyTrust]
17486d24.6d28: supR3HardenedDllNotificationCallback: load 00007fffa5530000 LB 0x0009e000 C:\WINDOWS\System32\msvcp_win.dll [fFlags=0x0]
17496d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\msvcp_win.dll [avoiding WinVerifyTrust]
17506d24.6d28: supR3HardenedDllNotificationCallback: load 00007fffa6360000 LB 0x00194000 C:\WINDOWS\System32\gdi32full.dll [fFlags=0x0]
17516d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
17526d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #33 'gdi32.dll'.
17536d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #35 'user32.dll'.
17546d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #36 'win32u.dll'.
17556d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\gdi32full.dll)
17566d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\gdi32full.dll
17576d24.6d28: supR3HardenedDllNotificationCallback: load 00007fffa6d90000 LB 0x00026000 C:\WINDOWS\System32\GDI32.dll [fFlags=0x0]
17586d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\gdi32.dll [avoiding WinVerifyTrust]
17596d24.6d28: supR3HardenedDllNotificationCallback: load 00007fffa69f0000 LB 0x00194000 C:\WINDOWS\System32\USER32.dll [fFlags=0x0]
17606d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\user32.dll [avoiding WinVerifyTrust]
17616d24.6d28: supR3HardenedDllNotificationCallback: load 00007fffa7780000 LB 0x00336000 C:\WINDOWS\System32\combase.dll [fFlags=0x0]
17626d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\combase.dll [avoiding WinVerifyTrust]
17636d24.6d28: supR3HardenedDllNotificationCallback: load 00007fffa62c0000 LB 0x0004a000 C:\WINDOWS\System32\cfgmgr32.dll [fFlags=0x0]
17646d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\cfgmgr32.dll)
17656d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\cfgmgr32.dll
17666d24.6d28: supR3HardenedDllNotificationCallback: load 00007fffa40b0000 LB 0x00020000 C:\WINDOWS\SYSTEM32\dxcore.dll [fFlags=0x0]
17676d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\DXCore.dll [avoiding WinVerifyTrust]
17686d24.6d28: supR3HardenedDllNotificationCallback: load 00007fff910a0000 LB 0x0002c000 C:\WINDOWS\SYSTEM32\GLU32.dll [fFlags=0x0]
17696d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume8\Windows\System32\glu32.dll [avoiding WinVerifyTrust]
17706d24.6d28: supR3HardenedDllNotificationCallback: load 00007fff3a030000 LB 0x00156000 C:\WINDOWS\SYSTEM32\OPENGL32.dll [fFlags=0x0]
17716d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\opengl32.dll
17726d24.6d28: supR3HardenedDllNotificationCallback: load 00007fffa7180000 LB 0x000a9000 C:\WINDOWS\System32\shcore.dll [fFlags=0x0]
17736d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
17746d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #36 'rpcrt4.dll'.
17756d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #43 'combase.dll'.
17766d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\SHCore.dll)
17776d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\SHCore.dll
17786d24.6d28: supR3HardenedDllNotificationCallback: load 00007fffa5460000 LB 0x00010000 C:\WINDOWS\System32\UMPDC.dll [fFlags=0x0]
17796d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\umpdc.dll)
17806d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\umpdc.dll
17816d24.6d28: supR3HardenedDllNotificationCallback: load 00007fffa5490000 LB 0x0004a000 C:\WINDOWS\System32\powrprof.dll [fFlags=0x0]
17826d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'rpcrt4.dll'.
17836d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #19 'umpdc.dll'.
17846d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\powrprof.dll)
17856d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\powrprof.dll
17866d24.6d28: supR3HardenedDllNotificationCallback: load 00007fffa6d30000 LB 0x00052000 C:\WINDOWS\System32\shlwapi.dll [fFlags=0x0]
17876d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
17886d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #44 'gdi32.dll'.
17896d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #45 'user32.dll'.
17906d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\shlwapi.dll)
17916d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\shlwapi.dll
17926d24.6d28: supR3HardenedDllNotificationCallback: load 00007fffa5470000 LB 0x00011000 C:\WINDOWS\System32\kernel.appcore.dll [fFlags=0x0]
17936d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'msvcrt.dll'.
17946d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'rpcrt4.dll'.
17956d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\kernel.appcore.dll)
17966d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\kernel.appcore.dll
17976d24.6d28: supR3HardenedDllNotificationCallback: load 00007fffa59c0000 LB 0x0077d000 C:\WINDOWS\System32\windows.storage.dll [fFlags=0x0]
17986d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #31 'combase.dll'.
17996d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #32 'msvcp_win.dll'.
18006d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #39 'rpcrt4.dll'.
18016d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #56 'profapi.dll'.
18026d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\windows.storage.dll)
18036d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\windows.storage.dll
18046d24.6d28: supR3HardenedDllNotificationCallback: load 00007fffa7ac0000 LB 0x006e4000 C:\WINDOWS\System32\SHELL32.dll [fFlags=0x0]
18056d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\shell32.dll [avoiding WinVerifyTrust]
18066d24.6d28: supR3HardenedDllNotificationCallback: load 00007fffa6e70000 LB 0x00157000 C:\WINDOWS\System32\ole32.dll [fFlags=0x0]
18076d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\ole32.dll
18086d24.6d28: supR3HardenedDllNotificationCallback: load 00007fff8a210000 LB 0x0001b000 C:\WINDOWS\SYSTEM32\MPR.dll [fFlags=0x0]
18096d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\mpr.dll [avoiding WinVerifyTrust]
18106d24.6d28: supR3HardenedDllNotificationCallback: load 0000000072eb0000 LB 0x00565000 C:\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [fFlags=0x0]
18116d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
18126d24.6d28: supR3HardenedDllNotificationCallback: load 00007fff37130000 LB 0x005f7000 C:\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll [fFlags=0x0]
18136d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
18146d24.6d28: supR3HardenedDllNotificationCallback: load 00000000728a0000 LB 0x00561000 C:\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll [fFlags=0x0]
18156d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll [avoiding WinVerifyTrust]
18166d24.6d28: supR3HardenedDllNotificationCallback: load 00007fffa8490000 LB 0x000c4000 C:\WINDOWS\System32\OLEAUT32.dll [fFlags=0x0]
18176d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\oleaut32.dll
18186d24.6d28: supR3HardenedDllNotificationCallback: load 00007fff37730000 LB 0x02614000 C:\Program Files\Oracle\VirtualBox\UICommon.dll [fFlags=0x0]
18196d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\UICommon.dll
18206d24.6d28: supR3HardenedDllNotificationCallback: load 0000000072840000 LB 0x00054000 C:\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll [fFlags=0x0]
18216d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll
18226d24.6d28: supR3HardenedDllNotificationCallback: load 00007fffa31d0000 LB 0x0002d000 C:\WINDOWS\SYSTEM32\WINMMBASE.dll [fFlags=0x0]
18236d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\winmmbase.dll [avoiding WinVerifyTrust]
18246d24.6d28: supR3HardenedDllNotificationCallback: load 00007fffa3330000 LB 0x00024000 C:\WINDOWS\SYSTEM32\WINMM.dll [fFlags=0x0]
18256d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\winmm.dll
18266d24.6d28: supR3HardenedDllNotificationCallback: load 00007fff369b0000 LB 0x001c8000 C:\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll [fFlags=0x0]
18276d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll
18286d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\windows.storage.dll'.
18296d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\windows.storage.dll' [rescheduled]
18306d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\kernel.appcore.dll'.
18316d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\kernel.appcore.dll' [rescheduled]
18326d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\shlwapi.dll'.
18336d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\shlwapi.dll' [rescheduled]
18346d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\powrprof.dll'.
18356d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\powrprof.dll' [rescheduled]
18366d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\umpdc.dll'.
18376d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\umpdc.dll' [rescheduled]
18386d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\SHCore.dll'.
18396d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\SHCore.dll' [rescheduled]
18406d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\cfgmgr32.dll'.
18416d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\cfgmgr32.dll' [rescheduled]
18426d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\gdi32full.dll'.
18436d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\gdi32full.dll' [rescheduled]
18446d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\DXCore.dll'.
18456d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\DXCore.dll' [rescheduled]
18466d24.6d28: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume8\Windows\System32\glu32.dll'.
18476d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\glu32.dll' [rescheduled]
18486d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\mpr.dll'.
18496d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\mpr.dll' [rescheduled]
18506d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\shell32.dll'.
18516d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\shell32.dll' [rescheduled]
18526d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll'.
18536d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll' [rescheduled]
18546d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\win32u.dll'.
18556d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\win32u.dll' [rescheduled]
18566d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\gdi32.dll'.
18576d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\gdi32.dll' [rescheduled]
18586d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\user32.dll'.
18596d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\user32.dll' [rescheduled]
18606d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\msvcp_win.dll'.
18616d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\msvcp_win.dll' [rescheduled]
18626d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\combase.dll'.
18636d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\combase.dll' [rescheduled]
18646d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\winmmbase.dll'.
18656d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\winmmbase.dll' [rescheduled]
18666d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\kernel32.dll
18676d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'profapi.dll'...
18686d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'profapi.dll' -> '\Device\HarddiskVolume8\Windows\System32\profapi.dll' [rcNtRedir=0xc0150008]
18696d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\profapi.dll
18706d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
18716d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume8\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
18726d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
18736d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume8\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
18746d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\msvcp_win.dll [redoing WinVerifyTrust]
18756d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\msvcp_win.dll'.
18766d24.6d28: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume8\Windows\System32\msvcp_win.dll
18776d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
18786d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume8\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
18796d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\combase.dll [redoing WinVerifyTrust]
18806d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\combase.dll'.
18816d24.6d28: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume8\Windows\System32\combase.dll
18826d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
18836d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume8\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
18846d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
18856d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume8\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
18866d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
18876d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume8\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
18886d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\user32.dll [redoing WinVerifyTrust]
18896d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\user32.dll'.
18906d24.6d28: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume8\Windows\System32\user32.dll
18916d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
18926d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume8\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
18936d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\gdi32.dll [redoing WinVerifyTrust]
18946d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\gdi32.dll'.
18956d24.6d28: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume8\Windows\System32\gdi32.dll
18966d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
18976d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume8\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
18986d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'umpdc.dll'...
18996d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'umpdc.dll' -> '\Device\HarddiskVolume8\Windows\System32\umpdc.dll' [rcNtRedir=0xc0150008]
19006d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\umpdc.dll [redoing WinVerifyTrust]
19016d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\umpdc.dll'.
19026d24.6d28: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume8\Windows\System32\umpdc.dll
19036d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
19046d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume8\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
19056d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
19066d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume8\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
19076d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\combase.dll [redoing WinVerifyTrust]
19086d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\combase.dll'.
19096d24.6d28: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume8\Windows\System32\combase.dll
19106d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
19116d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume8\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
19126d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\rpcrt4.dll
19136d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
19146d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume8\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
19156d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
19166d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume8\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
19176d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\win32u.dll [redoing WinVerifyTrust]
19186d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\win32u.dll'.
19196d24.6d28: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume8\Windows\System32\win32u.dll
19206d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
19216d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume8\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
19226d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\user32.dll [redoing WinVerifyTrust]
19236d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\user32.dll'.
19246d24.6d28: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume8\Windows\System32\user32.dll
19256d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
19266d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume8\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
19276d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\gdi32.dll [redoing WinVerifyTrust]
19286d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\gdi32.dll'.
19296d24.6d28: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume8\Windows\System32\gdi32.dll
19306d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
19316d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume8\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
19326d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\msvcp_win.dll [redoing WinVerifyTrust]
19336d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\msvcp_win.dll'.
19346d24.6d28: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume8\Windows\System32\msvcp_win.dll
19356d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
19366d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume8\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
19376d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\win32u.dll [redoing WinVerifyTrust]
19386d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\win32u.dll'.
19396d24.6d28: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume8\Windows\System32\win32u.dll
19406d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
19416d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume8\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
19426d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\msvcp_win.dll [redoing WinVerifyTrust]
19436d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\msvcp_win.dll'.
19446d24.6d28: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume8\Windows\System32\msvcp_win.dll
19456d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\kernel32.dll (Input=kernel32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
19466d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa70c0000 'C:\WINDOWS\System32\kernel32.dll'
19476d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\windows.storage.dll'.
19486d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\windows.storage.dll' [rescheduled]
19496d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\kernel.appcore.dll'.
19506d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\kernel.appcore.dll' [rescheduled]
19516d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\shlwapi.dll'.
19526d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\shlwapi.dll' [rescheduled]
19536d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\powrprof.dll'.
19546d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\powrprof.dll' [rescheduled]
19556d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\umpdc.dll'.
19566d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\umpdc.dll' [rescheduled]
19576d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\SHCore.dll'.
19586d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\SHCore.dll' [rescheduled]
19596d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\cfgmgr32.dll'.
19606d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\cfgmgr32.dll' [rescheduled]
19616d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\gdi32full.dll'.
19626d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\gdi32full.dll' [rescheduled]
19636d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\DXCore.dll'.
19646d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\DXCore.dll' [rescheduled]
19656d24.6d28: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume8\Windows\System32\glu32.dll'.
19666d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\glu32.dll' [rescheduled]
19676d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\mpr.dll'.
19686d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\mpr.dll' [rescheduled]
19696d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\shell32.dll'.
19706d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\shell32.dll' [rescheduled]
19716d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll'.
19726d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll' [rescheduled]
19736d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\win32u.dll'.
19746d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\win32u.dll' [rescheduled]
19756d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\gdi32.dll'.
19766d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\gdi32.dll' [rescheduled]
19776d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\user32.dll'.
19786d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\user32.dll' [rescheduled]
19796d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\msvcp_win.dll'.
19806d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\msvcp_win.dll' [rescheduled]
19816d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\combase.dll'.
19826d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\combase.dll' [rescheduled]
19836d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\winmmbase.dll'.
19846d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\winmmbase.dll' [rescheduled]
19856d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\windows.storage.dll'.
19866d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\windows.storage.dll' [rescheduled]
19876d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\kernel.appcore.dll'.
19886d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\kernel.appcore.dll' [rescheduled]
19896d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\shlwapi.dll'.
19906d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\shlwapi.dll' [rescheduled]
19916d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\powrprof.dll'.
19926d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\powrprof.dll' [rescheduled]
19936d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\umpdc.dll'.
19946d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\umpdc.dll' [rescheduled]
19956d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\SHCore.dll'.
19966d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\SHCore.dll' [rescheduled]
19976d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\cfgmgr32.dll'.
19986d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\cfgmgr32.dll' [rescheduled]
19996d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\gdi32full.dll'.
20006d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\gdi32full.dll' [rescheduled]
20016d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\DXCore.dll'.
20026d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\DXCore.dll' [rescheduled]
20036d24.6d28: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume8\Windows\System32\glu32.dll'.
20046d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\glu32.dll' [rescheduled]
20056d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\mpr.dll'.
20066d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\mpr.dll' [rescheduled]
20076d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\shell32.dll'.
20086d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\shell32.dll' [rescheduled]
20096d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll'.
20106d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll' [rescheduled]
20116d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\win32u.dll'.
20126d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\win32u.dll' [rescheduled]
20136d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\gdi32.dll'.
20146d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\gdi32.dll' [rescheduled]
20156d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\user32.dll'.
20166d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\user32.dll' [rescheduled]
20176d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\msvcp_win.dll'.
20186d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\msvcp_win.dll' [rescheduled]
20196d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\combase.dll'.
20206d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\combase.dll' [rescheduled]
20216d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\winmmbase.dll'.
20226d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\winmmbase.dll' [rescheduled]
20236d24.6d28: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-string-l1-1-0) -> 0x0, fPresent=1
20246d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-string-l1-1-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
20256d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa5710000 'api-ms-win-core-string-l1-1-0'
20266d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\windows.storage.dll'.
20276d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\windows.storage.dll' [rescheduled]
20286d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\kernel.appcore.dll'.
20296d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\kernel.appcore.dll' [rescheduled]
20306d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\shlwapi.dll'.
20316d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\shlwapi.dll' [rescheduled]
20326d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\powrprof.dll'.
20336d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\powrprof.dll' [rescheduled]
20346d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\umpdc.dll'.
20356d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\umpdc.dll' [rescheduled]
20366d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\SHCore.dll'.
20376d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\SHCore.dll' [rescheduled]
20386d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\cfgmgr32.dll'.
20396d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\cfgmgr32.dll' [rescheduled]
20406d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\gdi32full.dll'.
20416d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\gdi32full.dll' [rescheduled]
20426d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\DXCore.dll'.
20436d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\DXCore.dll' [rescheduled]
20446d24.6d28: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume8\Windows\System32\glu32.dll'.
20456d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\glu32.dll' [rescheduled]
20466d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\mpr.dll'.
20476d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\mpr.dll' [rescheduled]
20486d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\shell32.dll'.
20496d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\shell32.dll' [rescheduled]
20506d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll'.
20516d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll' [rescheduled]
20526d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\win32u.dll'.
20536d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\win32u.dll' [rescheduled]
20546d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\gdi32.dll'.
20556d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\gdi32.dll' [rescheduled]
20566d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\user32.dll'.
20576d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\user32.dll' [rescheduled]
20586d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\msvcp_win.dll'.
20596d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\msvcp_win.dll' [rescheduled]
20606d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\combase.dll'.
20616d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\combase.dll' [rescheduled]
20626d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\winmmbase.dll'.
20636d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\winmmbase.dll' [rescheduled]
20646d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\windows.storage.dll'.
20656d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\windows.storage.dll' [rescheduled]
20666d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\kernel.appcore.dll'.
20676d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\kernel.appcore.dll' [rescheduled]
20686d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\shlwapi.dll'.
20696d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\shlwapi.dll' [rescheduled]
20706d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\powrprof.dll'.
20716d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\powrprof.dll' [rescheduled]
20726d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\umpdc.dll'.
20736d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\umpdc.dll' [rescheduled]
20746d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\SHCore.dll'.
20756d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\SHCore.dll' [rescheduled]
20766d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\cfgmgr32.dll'.
20776d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\cfgmgr32.dll' [rescheduled]
20786d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\gdi32full.dll'.
20796d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\gdi32full.dll' [rescheduled]
20806d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\DXCore.dll'.
20816d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\DXCore.dll' [rescheduled]
20826d24.6d28: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume8\Windows\System32\glu32.dll'.
20836d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\glu32.dll' [rescheduled]
20846d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\mpr.dll'.
20856d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\mpr.dll' [rescheduled]
20866d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\shell32.dll'.
20876d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\shell32.dll' [rescheduled]
20886d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll'.
20896d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll' [rescheduled]
20906d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\win32u.dll'.
20916d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\win32u.dll' [rescheduled]
20926d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\gdi32.dll'.
20936d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\gdi32.dll' [rescheduled]
20946d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\user32.dll'.
20956d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\user32.dll' [rescheduled]
20966d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\msvcp_win.dll'.
20976d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\msvcp_win.dll' [rescheduled]
20986d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\combase.dll'.
20996d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\combase.dll' [rescheduled]
21006d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\winmmbase.dll'.
21016d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\winmmbase.dll' [rescheduled]
21026d24.6d28: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-datetime-l1-1-1) -> 0x0, fPresent=1
21036d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-datetime-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
21046d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa5710000 'api-ms-win-core-datetime-l1-1-1'
21056d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\windows.storage.dll'.
21066d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\windows.storage.dll' [rescheduled]
21076d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\kernel.appcore.dll'.
21086d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\kernel.appcore.dll' [rescheduled]
21096d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\shlwapi.dll'.
21106d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\shlwapi.dll' [rescheduled]
21116d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\powrprof.dll'.
21126d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\powrprof.dll' [rescheduled]
21136d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\umpdc.dll'.
21146d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\umpdc.dll' [rescheduled]
21156d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\SHCore.dll'.
21166d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\SHCore.dll' [rescheduled]
21176d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\cfgmgr32.dll'.
21186d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\cfgmgr32.dll' [rescheduled]
21196d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\gdi32full.dll'.
21206d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\gdi32full.dll' [rescheduled]
21216d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\DXCore.dll'.
21226d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\DXCore.dll' [rescheduled]
21236d24.6d28: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume8\Windows\System32\glu32.dll'.
21246d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\glu32.dll' [rescheduled]
21256d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\mpr.dll'.
21266d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\mpr.dll' [rescheduled]
21276d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\shell32.dll'.
21286d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\shell32.dll' [rescheduled]
21296d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll'.
21306d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll' [rescheduled]
21316d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\win32u.dll'.
21326d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\win32u.dll' [rescheduled]
21336d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\gdi32.dll'.
21346d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\gdi32.dll' [rescheduled]
21356d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\user32.dll'.
21366d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\user32.dll' [rescheduled]
21376d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\msvcp_win.dll'.
21386d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\msvcp_win.dll' [rescheduled]
21396d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\combase.dll'.
21406d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\combase.dll' [rescheduled]
21416d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\winmmbase.dll'.
21426d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\winmmbase.dll' [rescheduled]
21436d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\windows.storage.dll'.
21446d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\windows.storage.dll' [rescheduled]
21456d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\kernel.appcore.dll'.
21466d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\kernel.appcore.dll' [rescheduled]
21476d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\shlwapi.dll'.
21486d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\shlwapi.dll' [rescheduled]
21496d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\powrprof.dll'.
21506d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\powrprof.dll' [rescheduled]
21516d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\umpdc.dll'.
21526d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\umpdc.dll' [rescheduled]
21536d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\SHCore.dll'.
21546d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\SHCore.dll' [rescheduled]
21556d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\cfgmgr32.dll'.
21566d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\cfgmgr32.dll' [rescheduled]
21576d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\gdi32full.dll'.
21586d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\gdi32full.dll' [rescheduled]
21596d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\DXCore.dll'.
21606d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\DXCore.dll' [rescheduled]
21616d24.6d28: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume8\Windows\System32\glu32.dll'.
21626d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\glu32.dll' [rescheduled]
21636d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\mpr.dll'.
21646d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\mpr.dll' [rescheduled]
21656d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\shell32.dll'.
21666d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\shell32.dll' [rescheduled]
21676d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll'.
21686d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll' [rescheduled]
21696d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\win32u.dll'.
21706d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\win32u.dll' [rescheduled]
21716d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\gdi32.dll'.
21726d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\gdi32.dll' [rescheduled]
21736d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\user32.dll'.
21746d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\user32.dll' [rescheduled]
21756d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\msvcp_win.dll'.
21766d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\msvcp_win.dll' [rescheduled]
21776d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\combase.dll'.
21786d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\combase.dll' [rescheduled]
21796d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\winmmbase.dll'.
21806d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\winmmbase.dll' [rescheduled]
21816d24.6d28: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-obsolete-l1-2-0) -> 0x0, fPresent=1
21826d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-obsolete-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
21836d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa5710000 'api-ms-win-core-localization-obsolete-l1-2-0'
21846d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\windows.storage.dll'.
21856d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\windows.storage.dll' [rescheduled]
21866d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\kernel.appcore.dll'.
21876d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\kernel.appcore.dll' [rescheduled]
21886d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\shlwapi.dll'.
21896d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\shlwapi.dll' [rescheduled]
21906d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\powrprof.dll'.
21916d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\powrprof.dll' [rescheduled]
21926d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\umpdc.dll'.
21936d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\umpdc.dll' [rescheduled]
21946d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\SHCore.dll'.
21956d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\SHCore.dll' [rescheduled]
21966d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\cfgmgr32.dll'.
21976d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\cfgmgr32.dll' [rescheduled]
21986d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\gdi32full.dll'.
21996d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\gdi32full.dll' [rescheduled]
22006d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\DXCore.dll'.
22016d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\DXCore.dll' [rescheduled]
22026d24.6d28: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume8\Windows\System32\glu32.dll'.
22036d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\glu32.dll' [rescheduled]
22046d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\mpr.dll'.
22056d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\mpr.dll' [rescheduled]
22066d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\shell32.dll'.
22076d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\shell32.dll' [rescheduled]
22086d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll'.
22096d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll' [rescheduled]
22106d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\win32u.dll'.
22116d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\win32u.dll' [rescheduled]
22126d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\gdi32.dll'.
22136d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\gdi32.dll' [rescheduled]
22146d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\user32.dll'.
22156d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\user32.dll' [rescheduled]
22166d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\msvcp_win.dll'.
22176d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\msvcp_win.dll' [rescheduled]
22186d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\combase.dll'.
22196d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\combase.dll' [rescheduled]
22206d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\winmmbase.dll'.
22216d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\winmmbase.dll' [rescheduled]
22226d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\windows.storage.dll'.
22236d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\windows.storage.dll' [rescheduled]
22246d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\kernel.appcore.dll'.
22256d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\kernel.appcore.dll' [rescheduled]
22266d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\shlwapi.dll'.
22276d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\shlwapi.dll' [rescheduled]
22286d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\powrprof.dll'.
22296d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\powrprof.dll' [rescheduled]
22306d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\umpdc.dll'.
22316d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\umpdc.dll' [rescheduled]
22326d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\SHCore.dll'.
22336d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\SHCore.dll' [rescheduled]
22346d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\cfgmgr32.dll'.
22356d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\cfgmgr32.dll' [rescheduled]
22366d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\gdi32full.dll'.
22376d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\gdi32full.dll' [rescheduled]
22386d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\DXCore.dll'.
22396d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\DXCore.dll' [rescheduled]
22406d24.6d28: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume8\Windows\System32\glu32.dll'.
22416d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\glu32.dll' [rescheduled]
22426d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\mpr.dll'.
22436d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\mpr.dll' [rescheduled]
22446d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\shell32.dll'.
22456d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\shell32.dll' [rescheduled]
22466d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll'.
22476d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll' [rescheduled]
22486d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\win32u.dll'.
22496d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\win32u.dll' [rescheduled]
22506d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\gdi32.dll'.
22516d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\gdi32.dll' [rescheduled]
22526d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\user32.dll'.
22536d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\user32.dll' [rescheduled]
22546d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\msvcp_win.dll'.
22556d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\msvcp_win.dll' [rescheduled]
22566d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\combase.dll'.
22576d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\combase.dll' [rescheduled]
22586d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\winmmbase.dll'.
22596d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\winmmbase.dll' [rescheduled]
22606d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\imm32.dll'.
22616d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'user32.dll'.
22626d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'win32u.dll'.
22636d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\imm32.dll)
22646d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\imm32.dll
22656d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
22666d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume8\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
22676d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\win32u.dll [redoing WinVerifyTrust]
22686d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\win32u.dll'.
22696d24.6d28: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume8\Windows\System32\win32u.dll
22706d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
22716d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume8\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
22726d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\user32.dll [redoing WinVerifyTrust]
22736d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\user32.dll'.
22746d24.6d28: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume8\Windows\System32\user32.dll
22756d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\IMM32.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
22766d24.6d28: supR3HardenedDllNotificationCallback: load 00007fffa8460000 LB 0x0002e000 C:\WINDOWS\System32\IMM32.DLL [fFlags=0x0]
22776d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\imm32.dll [avoiding WinVerifyTrust]
22786d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa8460000 'C:\WINDOWS\system32\IMM32.DLL'
22796d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\imm32.dll'.
22806d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\imm32.dll' [rescheduled]
22816d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\windows.storage.dll'.
22826d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\windows.storage.dll' [rescheduled]
22836d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\kernel.appcore.dll'.
22846d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\kernel.appcore.dll' [rescheduled]
22856d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\shlwapi.dll'.
22866d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\shlwapi.dll' [rescheduled]
22876d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\powrprof.dll'.
22886d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\powrprof.dll' [rescheduled]
22896d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\umpdc.dll'.
22906d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\umpdc.dll' [rescheduled]
22916d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\SHCore.dll'.
22926d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\SHCore.dll' [rescheduled]
22936d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\cfgmgr32.dll'.
22946d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\cfgmgr32.dll' [rescheduled]
22956d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\gdi32full.dll'.
22966d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\gdi32full.dll' [rescheduled]
22976d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\DXCore.dll'.
22986d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\DXCore.dll' [rescheduled]
22996d24.6d28: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume8\Windows\System32\glu32.dll'.
23006d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\glu32.dll' [rescheduled]
23016d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\mpr.dll'.
23026d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\mpr.dll' [rescheduled]
23036d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\shell32.dll'.
23046d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\shell32.dll' [rescheduled]
23056d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll'.
23066d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll' [rescheduled]
23076d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\win32u.dll'.
23086d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\win32u.dll' [rescheduled]
23096d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\gdi32.dll'.
23106d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\gdi32.dll' [rescheduled]
23116d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\user32.dll'.
23126d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\user32.dll' [rescheduled]
23136d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\msvcp_win.dll'.
23146d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\msvcp_win.dll' [rescheduled]
23156d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\combase.dll'.
23166d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\combase.dll' [rescheduled]
23176d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\winmmbase.dll'.
23186d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\winmmbase.dll' [rescheduled]
23196d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\imm32.dll'.
23206d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\imm32.dll' [rescheduled]
23216d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\windows.storage.dll'.
23226d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\windows.storage.dll' [rescheduled]
23236d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\kernel.appcore.dll'.
23246d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\kernel.appcore.dll' [rescheduled]
23256d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\shlwapi.dll'.
23266d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\shlwapi.dll' [rescheduled]
23276d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\powrprof.dll'.
23286d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\powrprof.dll' [rescheduled]
23296d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\umpdc.dll'.
23306d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\umpdc.dll' [rescheduled]
23316d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\SHCore.dll'.
23326d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\SHCore.dll' [rescheduled]
23336d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\cfgmgr32.dll'.
23346d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\cfgmgr32.dll' [rescheduled]
23356d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\gdi32full.dll'.
23366d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\gdi32full.dll' [rescheduled]
23376d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\DXCore.dll'.
23386d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\DXCore.dll' [rescheduled]
23396d24.6d28: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume8\Windows\System32\glu32.dll'.
23406d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\glu32.dll' [rescheduled]
23416d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\mpr.dll'.
23426d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\mpr.dll' [rescheduled]
23436d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\shell32.dll'.
23446d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\shell32.dll' [rescheduled]
23456d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll'.
23466d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll' [rescheduled]
23476d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\win32u.dll'.
23486d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\win32u.dll' [rescheduled]
23496d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\gdi32.dll'.
23506d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\gdi32.dll' [rescheduled]
23516d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\user32.dll'.
23526d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\user32.dll' [rescheduled]
23536d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\msvcp_win.dll'.
23546d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\msvcp_win.dll' [rescheduled]
23556d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\combase.dll'.
23566d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\combase.dll' [rescheduled]
23576d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\winmmbase.dll'.
23586d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\winmmbase.dll' [rescheduled]
23596d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\advapi32.dll
23606d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\ADVAPI32.DLL (Input=ADVAPI32.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
23616d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa82d0000 'C:\WINDOWS\System32\ADVAPI32.DLL'
23626d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\imm32.dll'.
23636d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\imm32.dll' [rescheduled]
23646d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\windows.storage.dll'.
23656d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\windows.storage.dll' [rescheduled]
23666d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\kernel.appcore.dll'.
23676d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\kernel.appcore.dll' [rescheduled]
23686d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\shlwapi.dll'.
23696d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\shlwapi.dll' [rescheduled]
23706d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\powrprof.dll'.
23716d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\powrprof.dll' [rescheduled]
23726d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\umpdc.dll'.
23736d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\umpdc.dll' [rescheduled]
23746d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\SHCore.dll'.
23756d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\SHCore.dll' [rescheduled]
23766d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\cfgmgr32.dll'.
23776d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\cfgmgr32.dll' [rescheduled]
23786d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\gdi32full.dll'.
23796d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\gdi32full.dll' [rescheduled]
23806d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\DXCore.dll'.
23816d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\DXCore.dll' [rescheduled]
23826d24.6d28: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume8\Windows\System32\glu32.dll'.
23836d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\glu32.dll' [rescheduled]
23846d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\mpr.dll'.
23856d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\mpr.dll' [rescheduled]
23866d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\shell32.dll'.
23876d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\shell32.dll' [rescheduled]
23886d24.6d28: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll'.
23896d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll' [rescheduled]
23906d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\win32u.dll'.
23916d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\win32u.dll' [rescheduled]
23926d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\gdi32.dll'.
23936d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\gdi32.dll' [rescheduled]
23946d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\user32.dll'.
23956d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\user32.dll' [rescheduled]
23966d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\msvcp_win.dll'.
23976d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\msvcp_win.dll' [rescheduled]
23986d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\combase.dll'.
23996d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\combase.dll' [rescheduled]
24006d24.6d28: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\winmmbase.dll'.
24016d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume8\Windows\System32\winmmbase.dll' [rescheduled]
24026d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff369b0000 'C:\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll'
24036d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
24046d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
24056d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume8\Windows\System32\imm32.dll'
24066d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
24076d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
24086d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume8\Windows\System32\windows.storage.dll'
24096d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
24106d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
24116d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume8\Windows\System32\kernel.appcore.dll'
24126d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
24136d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
24146d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume8\Windows\System32\shlwapi.dll'
24156d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
24166d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
24176d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume8\Windows\System32\powrprof.dll'
24186d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
24196d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
24206d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume8\Windows\System32\umpdc.dll'
24216d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
24226d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
24236d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume8\Windows\System32\SHCore.dll'
24246d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
24256d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
24266d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume8\Windows\System32\cfgmgr32.dll'
24276d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
24286d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
24296d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume8\Windows\System32\gdi32full.dll'
24306d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
24316d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
24326d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume8\Windows\System32\DXCore.dll'
24336d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000474 pwszName=\Device\HarddiskVolume8\Windows\System32\glu32.dll
24346d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000187dd30
24356d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000187dd30
24366d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=F356C86D0A2DBA0570D09B39D4AF818DFCB17010
24376d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
24386d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
24396d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0212~31bf3856ad364e35~amd64~~10.0.18362.752.cat'; file='\Device\HarddiskVolume8\Windows\System32\glu32.dll'
24406d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
24416d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume8\Windows\System32\glu32.dll'
24426d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
24436d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
24446d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume8\Windows\System32\mpr.dll'
24456d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
24466d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
24476d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume8\Windows\System32\shell32.dll'
24486d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
24496d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 24202) fWinVerifyTrust=1 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll'
24506d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
24516d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
24526d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume8\Windows\System32\win32u.dll'
24536d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
24546d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
24556d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume8\Windows\System32\gdi32.dll'
24566d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
24576d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
24586d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume8\Windows\System32\user32.dll'
24596d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
24606d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
24616d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume8\Windows\System32\msvcp_win.dll'
24626d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
24636d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
24646d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume8\Windows\System32\combase.dll'
24656d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\rsaenh.dll
24666d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
24676d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
24686d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
24696d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume8\Windows\System32\winmmbase.dll'
24706d24.6d28: SUPR3HardenedMain: Calling TrustedMain (00007fff369b16c0)...
24716d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
24726d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
24736d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'ole32.dll'.
24746d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
24756d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'imm32.dll'.
24766d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'winmm.dll'.
24776d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'oleaut32.dll'.
24786d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'shell32.dll'.
24796d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'advapi32.dll'.
24806d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'qt5guivbox.dll'.
24816d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'qt5corevbox.dll'.
24826d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'msvcr100.dll'.
24836d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\platforms\qwindows.dll) WinVerifyTrust
24846d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\platforms\qwindows.dll
24856d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
24866d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
24876d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
24886d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
24896d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
24906d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
24916d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
24926d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
24936d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
24946d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume8\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
24956d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\advapi32.dll
24966d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
24976d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume8\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
24986d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\shell32.dll
24996d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
25006d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume8\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
25016d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\oleaut32.dll
25026d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
25036d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume8\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
25046d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\winmm.dll
25056d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
25066d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume8\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
25076d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\imm32.dll
25086d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
25096d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume8\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
25106d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
25116d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume8\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
25126d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\ole32.dll
25136d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
25146d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume8\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
25156d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\platforms\qwindows.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
25166d24.6d28: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\platforms\qwindows.dll
25176d24.6d28: supR3HardenedDllNotificationCallback: load 00007fff4fc30000 LB 0x0012e000 C:\Program Files\Oracle\VirtualBox\platforms\qwindows.dll [fFlags=0x0]
25186d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\platforms\qwindows.dll
25196d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff4fc30000 'C:\Program Files\Oracle\VirtualBox\platforms\qwindows.dll'
25206d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000664 pwszName=\Device\HarddiskVolume8\Windows\System32\uxtheme.dll
25216d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000187dd30
25226d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000187dd30
25236d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=286AD1CEC16EFDCA5718925D19E68A486A5851A0
25246d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
25256d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
25266d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0415~31bf3856ad364e35~amd64~~10.0.18362.778.cat'; file='\Device\HarddiskVolume8\Windows\System32\uxtheme.dll'
25276d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
25286d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
25296d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #33 'gdi32.dll'.
25306d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #34 'user32.dll'.
25316d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\uxtheme.dll) WinVerifyTrust
25326d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\uxtheme.dll
25336d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
25346d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume8\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
25356d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
25366d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume8\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
25376d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
25386d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume8\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
25396d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
25406d24.6d28: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\uxtheme.dll
25416d24.6d28: supR3HardenedDllNotificationCallback: load 00007fffa3600000 LB 0x00099000 C:\WINDOWS\system32\uxtheme.dll [fFlags=0x0]
25426d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\uxtheme.dll
25436d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa3600000 'C:\WINDOWS\system32\uxtheme.dll'
25446d24.6d28: \Device\HarddiskVolume8\Program Files (x86)\Common Files\Portrait Displays\Plugins\DP\MsgHook64.dll: Owner is administrators group.
25456d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
25466d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'psapi.dll'.
25476d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
25486d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'gdi32.dll'.
25496d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
25506d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Program Files (x86)\Common Files\Portrait Displays\Plugins\DP\MsgHook64.dll) WinVerifyTrust
25516d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Program Files (x86)\Common Files\Portrait Displays\Plugins\DP\MsgHook64.dll
25526d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
25536d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume8\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
25546d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\advapi32.dll
25556d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
25566d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume8\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
25576d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
25586d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume8\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
25596d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'psapi.dll'...
25606d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'psapi.dll' -> '\Device\HarddiskVolume8\Windows\System32\psapi.dll' [rcNtRedir=0xc0150008]
25616d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
25626d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
25636d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\psapi.dll) WinVerifyTrust
25646d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\psapi.dll
25656d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files (x86)\Common Files\Portrait Displays\Plugins\DP\msgHook64.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
25666d24.6d28: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files (x86)\Common Files\Portrait Displays\Plugins\DP\MsgHook64.dll
25676d24.6d28: supR3HardenedDllNotificationCallback: load 00007fffa6940000 LB 0x00008000 C:\WINDOWS\System32\PSAPI.DLL [fFlags=0x0]
25686d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\psapi.dll
25696d24.6d28: supR3HardenedDllNotificationCallback: load 0000000180000000 LB 0x0001b000 C:\Program Files (x86)\Common Files\Portrait Displays\Plugins\DP\msgHook64.dll [fFlags=0x0]
25706d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files (x86)\Common Files\Portrait Displays\Plugins\DP\MsgHook64.dll
25716d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000180000000 'C:\Program Files (x86)\Common Files\Portrait Displays\Plugins\DP\msgHook64.dll'
25726d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\user32.dll
25736d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\user32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
25746d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa69f0000 'C:\WINDOWS\system32\user32.dll'
25756d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\shell32.dll
25766d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
25776d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa7ac0000 'C:\WINDOWS\system32\shell32.dll'
25786d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\SHCore.dll
25796d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\SHCore.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
25806d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa7180000 'C:\WINDOWS\system32\SHCore.dll'
25816d24.6d28: supR3HardenedMonitor_LdrLoadDll: error opening 'C:\WINDOWS\system32\wintab32.dll': 0 (NtPath=\??\C:\WINDOWS\system32\wintab32.dll; Input=C:\WINDOWS\system32\wintab32.dll; rcNtGetDll=0x0
25826d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000034 'C:\WINDOWS\system32\wintab32.dll'
25836d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\winmm.dll
25846d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\winmm.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
25856d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa3330000 'C:\WINDOWS\system32\winmm.dll'
25866d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\winmm.dll
25876d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\winmm.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
25886d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa3330000 'C:\WINDOWS\system32\winmm.dll'
25896d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\shell32.dll
25906d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
25916d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa7ac0000 'C:\WINDOWS\system32\shell32.dll'
25926d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\uxtheme.dll
25936d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
25946d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa3600000 'C:\WINDOWS\system32\uxtheme.dll'
25956d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\advapi32.dll
25966d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\advapi32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
25976d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa82d0000 'C:\WINDOWS\system32\advapi32.dll'
25986d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
25996d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
26006d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'rpcrt4.dll'.
26016d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #30 'profapi.dll'.
26026d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\userenv.dll) WinVerifyTrust
26036d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\userenv.dll
26046d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'profapi.dll'...
26056d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'profapi.dll' -> '\Device\HarddiskVolume8\Windows\System32\profapi.dll' [rcNtRedir=0xc0150008]
26066d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\profapi.dll
26076d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
26086d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume8\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
26096d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\userenv.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
26106d24.6d28: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\userenv.dll
26116d24.6d28: supR3HardenedDllNotificationCallback: load 00007fffa5380000 LB 0x00025000 C:\WINDOWS\system32\userenv.dll [fFlags=0x0]
26126d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\userenv.dll
26136d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa5380000 'C:\WINDOWS\system32\userenv.dll'
26146d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\kernel32.dll
26156d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\kernel32.dll (Input=kernel32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
26166d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa70c0000 'C:\WINDOWS\System32\kernel32.dll'
26176d24.6d28: supR3HardenedDllNotificationCallback: load 00007fffa6dc0000 LB 0x000a2000 C:\WINDOWS\System32\clbcatq.dll [fFlags=0x0]
26186d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
26196d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #30 'rpcrt4.dll'.
26206d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\clbcatq.dll)
26216d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\clbcatq.dll
26226d24.6d5c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
26236d24.6d5c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume8\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
26246d24.6d5c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
26256d24.6d5c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume8\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
26266d24.6d5c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
26276d24.6d5c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
26286d24.6d5c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume8\Windows\System32\clbcatq.dll'
26296d24.6d5c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
26306d24.6d5c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
26316d24.6d5c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
26326d24.6d5c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
26336d24.6d5c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
26346d24.6d5c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ole32.dll'.
26356d24.6d5c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'oleaut32.dll'.
26366d24.6d5c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxC.dll) WinVerifyTrust
26376d24.6d5c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxC.dll
26386d24.6d5c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
26396d24.6d5c: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume8\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
26406d24.6d5c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\oleaut32.dll
26416d24.6d5c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
26426d24.6d5c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume8\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
26436d24.6d5c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\ole32.dll
26446d24.6d5c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
26456d24.6d5c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume8\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
26466d24.6d5c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\advapi32.dll
26476d24.6d5c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
26486d24.6d5c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
26496d24.6d5c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
26506d24.6d5c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
26516d24.6d5c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcp100.dll
26526d24.6d5c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
26536d24.6d5c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
26546d24.6d5c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxC.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
26556d24.6d5c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxC.dll
26566d24.6d5c: supR3HardenedDllNotificationCallback: load 00007fff36d80000 LB 0x003b0000 C:\Program Files\Oracle\VirtualBox\VBoxC.dll [fFlags=0x0]
26576d24.6d5c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxC.dll
26586d24.6d5c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff36d80000 'C:\Program Files\Oracle\VirtualBox\VBoxC.dll'
26596d24.6d5c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
26606d24.6d5c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
26616d24.6d5c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
26626d24.6d5c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
26636d24.6d5c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'shlwapi.dll'.
26646d24.6d5c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ole32.dll'.
26656d24.6d5c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'oleaut32.dll'.
26666d24.6d5c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
26676d24.6d5c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll) WinVerifyTrust
26686d24.6d5c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll
26696d24.6d5c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
26706d24.6d5c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume8\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
26716d24.6d5c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
26726d24.6d5c: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume8\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
26736d24.6d5c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\oleaut32.dll
26746d24.6d5c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
26756d24.6d5c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume8\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
26766d24.6d5c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\ole32.dll
26776d24.6d5c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
26786d24.6d5c: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume8\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
26796d24.6d5c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\shlwapi.dll
26806d24.6d5c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
26816d24.6d5c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume8\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
26826d24.6d5c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
26836d24.6d5c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
26846d24.6d5c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
26856d24.6d5c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
26866d24.6d5c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
26876d24.6d5c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll
26886d24.6d5c: supR3HardenedDllNotificationCallback: load 00007fff3b0b0000 LB 0x000ed000 C:\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll [fFlags=0x0]
26896d24.6d5c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll
26906d24.6d5c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff3b0b0000 'C:\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll'
26916d24.6d5c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\oleaut32.dll
26926d24.6d5c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\oleaut32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
26936d24.6d5c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa8490000 'C:\Windows\System32\oleaut32.dll'
26946d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000007b0 pwszName=\Device\HarddiskVolume8\Windows\System32\DWrite.dll
26956d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000187dd30
26966d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000187dd30
26976d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=4B120F7CFDE097724D5BD2D636015877A1771CAB
26986d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
26996d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
27006d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0417~31bf3856ad364e35~amd64~~10.0.18362.753.cat'; file='\Device\HarddiskVolume8\Windows\System32\DWrite.dll'
27016d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
27026d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
27036d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'rpcrt4.dll'.
27046d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\DWrite.dll) WinVerifyTrust
27056d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\DWrite.dll
27066d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
27076d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume8\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
27086d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
27096d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume8\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
27106d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\dwrite.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
27116d24.6d28: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\DWrite.dll
27126d24.6d28: supR3HardenedDllNotificationCallback: load 00007fff9ac70000 LB 0x002fe000 C:\WINDOWS\system32\dwrite.dll [fFlags=0x0]
27136d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\DWrite.dll
27146d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff9ac70000 'C:\WINDOWS\system32\dwrite.dll'
27156d24.6d58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
27166d24.6d58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
27176d24.6d58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
27186d24.6d58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
27196d24.6d58: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
27206d24.6d58: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMainVM.dll) WinVerifyTrust
27216d24.6d58: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMainVM.dll
27226d24.6d58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
27236d24.6d58: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
27246d24.6d58: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
27256d24.6d58: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
27266d24.6d58: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMainVM.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
27276d24.6d58: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMainVM.dll
27286d24.6d58: supR3HardenedDllNotificationCallback: load 00007fff9d720000 LB 0x0000e000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMainVM.DLL [fFlags=0x0]
27296d24.6d58: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMainVM.dll
27306d24.6d58: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff9d720000 'C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMainVM.DLL'
27316d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\shell32.dll
27326d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
27336d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa7ac0000 'C:\WINDOWS\system32\shell32.dll'
27346d24.6d28: supR3HardenedDllNotificationCallback: load 00007fffa6b90000 LB 0x00136000 C:\WINDOWS\System32\MSCTF.dll [fFlags=0x0]
27356d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
27366d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'oleaut32.dll'.
27376d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #38 'user32.dll'.
27386d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #39 'gdi32.dll'.
27396d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #40 'imm32.dll'.
27406d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #41 'advapi32.dll'.
27416d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\msctf.dll)
27426d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\msctf.dll
27436d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
27446d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume8\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
27456d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
27466d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume8\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
27476d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\imm32.dll
27486d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
27496d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume8\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
27506d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
27516d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume8\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
27526d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
27536d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume8\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
27546d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\oleaut32.dll
27556d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
27566d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume8\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
27576d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
27586d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
27596d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume8\Windows\System32\msctf.dll'
27606d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000009f4 pwszName=\Device\HarddiskVolume8\Windows\System32\DataExchange.dll
27616d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000187dd30
27626d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000187dd30
27636d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=3632E0380EF7C400BBC7C4B0B9ED8D9F9860503B
27646d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
27656d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
27666d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0410~31bf3856ad364e35~amd64~~10.0.18362.753.cat'; file='\Device\HarddiskVolume8\Windows\System32\DataExchange.dll'
27676d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
27686d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
27696d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'shcore.dll'.
27706d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #29 'combase.dll'.
27716d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #34 'd3d11.dll'.
27726d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #35 'dcomp.dll'.
27736d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\DataExchange.dll) WinVerifyTrust
27746d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\DataExchange.dll
27756d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dcomp.dll'...
27766d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'dcomp.dll' -> '\Device\HarddiskVolume8\Windows\System32\dcomp.dll' [rcNtRedir=0xc0150008]
27776d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
27786d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
27796d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'win32u.dll'.
27806d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp_win.dll'.
27816d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\dcomp.dll) WinVerifyTrust
27826d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\dcomp.dll
27836d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'd3d11.dll'...
27846d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'd3d11.dll' -> '\Device\HarddiskVolume8\Windows\System32\d3d11.dll' [rcNtRedir=0xc0150008]
27856d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
27866d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume8\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
27876d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\msvcp_win.dll
27886d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
27896d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume8\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
27906d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\win32u.dll
27916d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
27926d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
27936d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
27946d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #24 'dxgi.dll'.
27956d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #27 'win32u.dll'.
27966d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\d3d11.dll) WinVerifyTrust
27976d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\d3d11.dll
27986d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
27996d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume8\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
28006d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\combase.dll
28016d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shcore.dll'...
28026d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'shcore.dll' -> '\Device\HarddiskVolume8\Windows\System32\shcore.dll' [rcNtRedir=0xc0150008]
28036d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\SHCore.dll
28046d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
28056d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume8\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
28066d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\msvcrt.dll
28076d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
28086d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume8\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
28096d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\win32u.dll
28106d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dxgi.dll'...
28116d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'dxgi.dll' -> '\Device\HarddiskVolume8\Windows\System32\dxgi.dll' [rcNtRedir=0xc0150008]
28126d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
28136d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\crypt32.dll
28146d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
28156d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
28166d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
28176d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'win32u.dll'.
28186d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\dxgi.dll) WinVerifyTrust
28196d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\dxgi.dll
28206d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
28216d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume8\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
28226d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
28236d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume8\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
28246d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
28256d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume8\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
28266d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\dataexchange.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
28276d24.6d28: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\DataExchange.dll
28286d24.6d28: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\d3d11.dll
28296d24.6d28: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\dcomp.dll
28306d24.6d28: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\dxgi.dll
28316d24.6d28: supR3HardenedDllNotificationCallback: load 00007fffa4140000 LB 0x000eb000 C:\WINDOWS\system32\dxgi.dll [fFlags=0x0]
28326d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\dxgi.dll
28336d24.6d28: supR3HardenedDllNotificationCallback: load 00007fffa2940000 LB 0x0025b000 C:\WINDOWS\system32\d3d11.dll [fFlags=0x0]
28346d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\d3d11.dll
28356d24.6d28: supR3HardenedDllNotificationCallback: load 00007fffa2ba0000 LB 0x001dc000 C:\WINDOWS\system32\dcomp.dll [fFlags=0x0]
28366d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\dcomp.dll
28376d24.6d28: supR3HardenedDllNotificationCallback: load 00007fff737e0000 LB 0x0003a000 C:\WINDOWS\system32\dataexchange.dll [fFlags=0x0]
28386d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\DataExchange.dll
28396d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6d90000 'C:\WINDOWS\System32\gdi32.dll'
28406d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff737e0000 'C:\WINDOWS\system32\dataexchange.dll'
28416d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rmclient.dll'.
28426d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #31 'rpcrt4.dll'.
28436d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #47 'combase.dll'.
28446d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #50 'msvcp_win.dll'.
28456d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\twinapi.appcore.dll)
28466d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\twinapi.appcore.dll
28476d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
28486d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'rpcrt4.dll'.
28496d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\rmclient.dll)
28506d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\rmclient.dll
28516d24.6d28: supR3HardenedDllNotificationCallback: load 00007fffa3bf0000 LB 0x00029000 C:\WINDOWS\system32\RMCLIENT.dll [fFlags=0x0]
28526d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\rmclient.dll [avoiding WinVerifyTrust]
28536d24.6d28: supR3HardenedDllNotificationCallback: load 00007fffa36e0000 LB 0x0025a000 C:\WINDOWS\system32\twinapi.appcore.dll [fFlags=0x0]
28546d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\twinapi.appcore.dll [avoiding WinVerifyTrust]
28556d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
28566d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume8\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
28576d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
28586d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume8\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
28596d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
28606d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume8\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
28616d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\msvcp_win.dll
28626d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
28636d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume8\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
28646d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\combase.dll
28656d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
28666d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume8\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
28676d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rmclient.dll'...
28686d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'rmclient.dll' -> '\Device\HarddiskVolume8\Windows\System32\rmclient.dll' [rcNtRedir=0xc0150008]
28696d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\rmclient.dll [lacks WinVerifyTrust]
28706d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
28716d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
28726d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume8\Windows\System32\rmclient.dll'
28736d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
28746d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
28756d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume8\Windows\System32\twinapi.appcore.dll'
28766d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\SHCore.dll
28776d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\Shcore.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
28786d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa7180000 'C:\WINDOWS\system32\Shcore.dll'
28796d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
28806d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
28816d24.6d28: '\Device\HarddiskVolume8\Windows\System32\ntdll.dll' has no imports
28826d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\ntdll.dll) WinVerifyTrust
28836d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\ntdll.dll
28846d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\ntdll.dll (Input=ntdll.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
28856d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa85a0000 'C:\WINDOWS\System32\ntdll.dll'
28866d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'vboxrt.dll'.
28876d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcr100.dll'.
28886d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5corevbox.dll'.
28896d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qt5openglvbox.dll'.
28906d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qt5widgetsvbox.dll'.
28916d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'opengl32.dll'.
28926d24.6d28: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxTestOGL.exe)
28936d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxTestOGL.exe
28946d24.6d28: supR3HardenedMonitor_NtCreateSection: NtMapViewOfSection failed on 0000000000000af0 (hFile=0000000000000ad4) with 0xc0000022 -> STATUS_TRUST_FAILURE
28956d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
28966d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume8\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
28976d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\opengl32.dll
28986d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
28996d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
29006d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll
29016d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5openglvbox.dll'...
29026d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5openglvbox.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\qt5openglvbox.dll' [rcNtRedir=0xc0150008]
29036d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll
29046d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
29056d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
29066d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
29076d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
29086d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
29096d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
29106d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
29116d24.6d28: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 24202) fWinVerifyTrust=1 for '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxTestOGL.exe'
29126d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000ae8 pwszName=\Device\HarddiskVolume8\Windows\System32\apphelp.dll
29136d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000187dd30
29146d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000187dd30
29156d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=CAB05C7236BF75A3E9746E25E1039005E1268927
29166d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
29176d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
29186d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0414~31bf3856ad364e35~amd64~~10.0.18362.752.cat'; file='\Device\HarddiskVolume8\Windows\System32\apphelp.dll'
29196d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
29206d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\apphelp.dll) WinVerifyTrust
29216d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\apphelp.dll
29226d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\apphelp.dll (rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
29236d24.6d28: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\apphelp.dll
29246d24.6d28: supR3HardenedDllNotificationCallback: load 00007fffa3430000 LB 0x0008f000 C:\WINDOWS\system32\apphelp.dll [fFlags=0x0]
29256d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\apphelp.dll
29266d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\ntdll.dll
29276d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\ntdll.dll (Input=ntdll.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
29286d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa85a0000 'C:\WINDOWS\System32\ntdll.dll'
29296d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa3430000 'C:\WINDOWS\system32\apphelp.dll'
29306d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\ole32.dll
29316d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\ole32.dll (Input=ole32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
29326d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6e70000 'C:\WINDOWS\System32\ole32.dll'
29336d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\oleaut32.dll
29346d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\OLEAUT32.dll (Input=OLEAUT32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
29356d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa8490000 'C:\WINDOWS\System32\OLEAUT32.dll'
29366d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000b54 pwszName=\Device\HarddiskVolume8\Windows\System32\wbem\wbemprox.dll
29376d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000187dd30
29386d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000187dd30
29396d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=DB1AA7E2E4704C908EC9382E1F9E64808B9E5E1D
29406d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
29416d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
29426d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package03~31bf3856ad364e35~amd64~~10.0.18362.753.cat'; file='\Device\HarddiskVolume8\Windows\System32\wbem\wbemprox.dll'
29436d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
29446d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
29456d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ws2_32.dll'.
29466d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'wbemcomn.dll'.
29476d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\wbem\wbemprox.dll) WinVerifyTrust
29486d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\wbem\wbemprox.dll
29496d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wbemcomn.dll'...
29506d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'wbemcomn.dll' -> '\Device\HarddiskVolume8\Windows\System32\wbemcomn.dll' [rcNtRedir=0xc0150008]
29516d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000a38 pwszName=\Device\HarddiskVolume8\Windows\System32\wbemcomn.dll
29526d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000187dd30
29536d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000187dd30
29546d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=22EAF38FA276D7A374D3945ACD556FA0953D3440
29556d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
29566d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
29576d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package03~31bf3856ad364e35~amd64~~10.0.18362.753.cat'; file='\Device\HarddiskVolume8\Windows\System32\wbemcomn.dll'
29586d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
29596d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
29606d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'bcrypt.dll'.
29616d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'ws2_32.dll'.
29626d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\wbemcomn.dll) WinVerifyTrust
29636d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\wbemcomn.dll
29646d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
29656d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume8\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
29666d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\ws2_32.dll
29676d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
29686d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume8\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
29696d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
29706d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume8\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
29716d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\ws2_32.dll
29726d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
29736d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume8\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
29746d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\bcrypt.dll
29756d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
29766d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume8\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
29776d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\wbem\wbemprox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
29786d24.6d28: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\wbem\wbemprox.dll
29796d24.6d28: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\wbemcomn.dll
29806d24.6d28: supR3HardenedDllNotificationCallback: load 00007fff9e2b0000 LB 0x00084000 C:\WINDOWS\SYSTEM32\wbemcomn.dll [fFlags=0x0]
29816d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\wbemcomn.dll
29826d24.6d28: supR3HardenedDllNotificationCallback: load 00007fff9e360000 LB 0x00011000 C:\WINDOWS\system32\wbem\wbemprox.dll [fFlags=0x0]
29836d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\wbem\wbemprox.dll
29846d24.6d28: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(API-MS-Win-Core-LocalRegistry-L1-1-0.dll) -> 0x0, fPresent=1
29856d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Core-LocalRegistry-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
29866d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa5710000 'API-MS-Win-Core-LocalRegistry-L1-1-0.dll'
29876d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff9e360000 'C:\WINDOWS\system32\wbem\wbemprox.dll'
29886d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000a44 pwszName=\Device\HarddiskVolume8\Windows\System32\wbem\wbemsvc.dll
29896d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000187dd30
29906d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000187dd30
29916d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=00C864D7F76A7AD25E7D0DA164B0B66188F5B7FF
29926d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
29936d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
29946d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package03~31bf3856ad364e35~amd64~~10.0.18362.753.cat'; file='\Device\HarddiskVolume8\Windows\System32\wbem\wbemsvc.dll'
29956d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
29966d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
29976d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'rpcrt4.dll'.
29986d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\wbem\wbemsvc.dll) WinVerifyTrust
29996d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\wbem\wbemsvc.dll
30006d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
30016d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume8\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
30026d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
30036d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume8\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
30046d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\wbem\wbemsvc.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
30056d24.6d28: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\wbem\wbemsvc.dll
30066d24.6d28: supR3HardenedDllNotificationCallback: load 00007fff9c900000 LB 0x00014000 C:\WINDOWS\system32\wbem\wbemsvc.dll [fFlags=0x0]
30076d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\wbem\wbemsvc.dll
30086d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff9c900000 'C:\WINDOWS\system32\wbem\wbemsvc.dll'
30096d24.6d28: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-l1-2-0.dll) -> 0x0, fPresent=1
30106d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-l1-2-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
30116d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa5710000 'api-ms-win-core-localization-l1-2-0.dll'
30126d24.6d28: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-obsolete-l1-1-0.dll) -> 0x0, fPresent=1
30136d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-obsolete-l1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
30146d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa5710000 'api-ms-win-core-localization-obsolete-l1-1-0.dll'
30156d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000b5c pwszName=\Device\HarddiskVolume8\Windows\System32\wbem\fastprox.dll
30166d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000187dd30
30176d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000187dd30
30186d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=0708A64F48237CD4D5092546CE9C373F20B30CA1
30196d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
30206d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
30216d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package03~31bf3856ad364e35~amd64~~10.0.18362.753.cat'; file='\Device\HarddiskVolume8\Windows\System32\wbem\fastprox.dll'
30226d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
30236d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
30246d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #20 'wbemcomn.dll'.
30256d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\wbem\fastprox.dll) WinVerifyTrust
30266d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\wbem\fastprox.dll
30276d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wbemcomn.dll'...
30286d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'wbemcomn.dll' -> '\Device\HarddiskVolume8\Windows\System32\wbemcomn.dll' [rcNtRedir=0xc0150008]
30296d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\wbemcomn.dll
30306d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
30316d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume8\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
30326d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\wbem\fastprox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
30336d24.6d28: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\wbem\fastprox.dll
30346d24.6d28: supR3HardenedDllNotificationCallback: load 00007fff9c480000 LB 0x00101000 C:\WINDOWS\system32\wbem\fastprox.dll [fFlags=0x0]
30356d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\wbem\fastprox.dll
30366d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff9c480000 'C:\WINDOWS\system32\wbem\fastprox.dll'
30376d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000b78 pwszName=\Device\HarddiskVolume8\Windows\System32\amsi.dll
30386d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000187dd30
30396d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000187dd30
30406d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B5D4D58A583ACAD5AA76D7DD0F2DB8ADE903942B
30416d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
30426d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
30436d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package04~31bf3856ad364e35~amd64~~10.0.18362.753.cat'; file='\Device\HarddiskVolume8\Windows\System32\amsi.dll'
30446d24.6d28: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
30456d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
30466d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'rpcrt4.dll'.
30476d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'userenv.dll'.
30486d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\amsi.dll) WinVerifyTrust
30496d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\amsi.dll
30506d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'userenv.dll'...
30516d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'userenv.dll' -> '\Device\HarddiskVolume8\Windows\System32\userenv.dll' [rcNtRedir=0xc0150008]
30526d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\userenv.dll
30536d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
30546d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume8\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
30556d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
30566d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume8\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
30576d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\amsi.dll (Input=amsi.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
30586d24.6d28: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\amsi.dll
30596d24.6d28: supR3HardenedDllNotificationCallback: load 00007fff97ca0000 LB 0x00015000 C:\WINDOWS\System32\amsi.dll [fFlags=0x0]
30606d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\amsi.dll
30616d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff97ca0000 'C:\WINDOWS\System32\amsi.dll'
30626d24.6d28: \Device\HarddiskVolume8\Program Files\Norton Internet Security\Engine\22.20.2.57\symamsi.dll: Owner is administrators group.
30636d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
30646d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'wintrust.dll'.
30656d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'crypt32.dll'.
30666d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rpcrt4.dll'.
30676d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'user32.dll'.
30686d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'advapi32.dll'.
30696d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'ole32.dll'.
30706d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'shlwapi.dll'.
30716d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'userenv.dll'.
30726d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'shell32.dll'.
30736d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'oleaut32.dll'.
30746d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Program Files\Norton Internet Security\Engine\22.20.2.57\symamsi.dll) WinVerifyTrust
30756d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Program Files\Norton Internet Security\Engine\22.20.2.57\symamsi.dll
30766d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
30776d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume8\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
30786d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
30796d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume8\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
30806d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\shell32.dll
30816d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'userenv.dll'...
30826d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'userenv.dll' -> '\Device\HarddiskVolume8\Windows\System32\userenv.dll' [rcNtRedir=0xc0150008]
30836d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\userenv.dll
30846d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
30856d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume8\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
30866d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\shlwapi.dll
30876d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
30886d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume8\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
30896d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
30906d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume8\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
30916d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
30926d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume8\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
30936d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
30946d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume8\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
30956d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
30966d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume8\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
30976d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wintrust.dll'...
30986d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'wintrust.dll' -> '\Device\HarddiskVolume8\Windows\System32\wintrust.dll' [rcNtRedir=0xc0150008]
30996d24.6d28: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\wintrust.dll
31006d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Norton Internet Security\Engine\22.20.2.57\symamsi.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
31016d24.6d28: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Norton Internet Security\Engine\22.20.2.57\symamsi.dll
31026d24.6d28: supR3HardenedDllNotificationCallback: load 00007fff971f0000 LB 0x000ae000 C:\Program Files\Norton Internet Security\Engine\22.20.2.57\symamsi.dll [fFlags=0x0]
31036d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Norton Internet Security\Engine\22.20.2.57\symamsi.dll
31046d24.6d28: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
31056d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
31066d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa5710000 'api-ms-win-core-synch-l1-2-0'
31076d24.6d28: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-fibers-l1-1-1) -> 0x0, fPresent=1
31086d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
31096d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa5710000 'api-ms-win-core-fibers-l1-1-1'
31106d24.6d28: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
31116d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
31126d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa5710000 'api-ms-win-core-synch-l1-2-0'
31136d24.6d28: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-fibers-l1-1-1) -> 0x0, fPresent=1
31146d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
31156d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa5710000 'api-ms-win-core-fibers-l1-1-1'
31166d24.6d28: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-l1-2-1) -> 0x0, fPresent=1
31176d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-l1-2-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
31186d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa5710000 'api-ms-win-core-localization-l1-2-1'
31196d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff971f0000 'C:\Program Files\Norton Internet Security\Engine\22.20.2.57\symamsi.dll'
31206d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
31216d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
31226d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
31236d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxVMM.dll) WinVerifyTrust
31246d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxVMM.dll
31256d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
31266d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
31276d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
31286d24.6d28: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
31296d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
31306d24.6d28: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxVMM.dll
31316d24.6d28: supR3HardenedDllNotificationCallback: load 00007fff36630000 LB 0x0037d000 C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL [fFlags=0x0]
31326d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxVMM.dll
31336d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff36630000 'C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL'
31346d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
31356d24.6dc0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000c58 pwszName=\Device\HarddiskVolume8\Windows\System32\NetSetupShim.dll
31366d24.6dc0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000187dd30
31376d24.6dc0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000187dd30
31386d24.6dc0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=7F5B666FF2CFCD1394E450AF7141F0F82A5730F3
31396d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
31406d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
31416d24.6dc0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package04113~31bf3856ad364e35~amd64~~10.0.18362.752.cat'; file='\Device\HarddiskVolume8\Windows\System32\NetSetupShim.dll'
31426d24.6dc0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
31436d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
31446d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #31 'rpcrt4.dll'.
31456d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #32 'oleaut32.dll'.
31466d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #34 'ws2_32.dll'.
31476d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #35 'netsetupapi.dll'.
31486d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #36 'setupapi.dll'.
31496d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #37 'devrtl.dll'.
31506d24.6dc0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\NetSetupShim.dll) WinVerifyTrust
31516d24.6dc0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\NetSetupShim.dll
31526d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'devrtl.dll'...
31536d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'devrtl.dll' -> '\Device\HarddiskVolume8\Windows\System32\devrtl.dll' [rcNtRedir=0xc0150008]
31546d24.6dc0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000ce4 pwszName=\Device\HarddiskVolume8\Windows\System32\devrtl.dll
31556d24.6dc0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000187dd30
31566d24.6dc0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000187dd30
31576d24.6dc0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=D2E5A6C3AFA14B1D9C532760FD646C3AC357C7AB
31586d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
31596d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
31606d24.6dc0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0416~31bf3856ad364e35~amd64~~10.0.18362.815.cat'; file='\Device\HarddiskVolume8\Windows\System32\devrtl.dll'
31616d24.6dc0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
31626d24.6dc0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\devrtl.dll) WinVerifyTrust
31636d24.6dc0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\devrtl.dll
31646d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
31656d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume8\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
31666d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
31676d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
31686d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
31696d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #29 'rpcrt4.dll'.
31706d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #36 'cfgmgr32.dll'.
31716d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #41 'bcrypt.dll'.
31726d24.6dc0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\setupapi.dll) WinVerifyTrust
31736d24.6dc0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\setupapi.dll
31746d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'netsetupapi.dll'...
31756d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'netsetupapi.dll' -> '\Device\HarddiskVolume8\Windows\System32\netsetupapi.dll' [rcNtRedir=0xc0150008]
31766d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
31776d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume8\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
31786d24.6dc0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\bcrypt.dll
31796d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
31806d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume8\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
31816d24.6dc0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\cfgmgr32.dll
31826d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
31836d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume8\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
31846d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
31856d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume8\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
31866d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
31876d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
31886d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
31896d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'rpcrt4.dll'.
31906d24.6dc0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\NetSetupApi.dll) WinVerifyTrust
31916d24.6dc0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\NetSetupApi.dll
31926d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
31936d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume8\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
31946d24.6dc0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\ws2_32.dll
31956d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
31966d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume8\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
31976d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
31986d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume8\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
31996d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
32006d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume8\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
32016d24.6dc0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\msvcp_win.dll
32026d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
32036d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume8\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
32046d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
32056d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume8\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
32066d24.6dc0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\NetSetupShim.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
32076d24.6dc0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\NetSetupShim.dll
32086d24.6dc0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\NetSetupApi.dll
32096d24.6dc0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\devrtl.dll
32106d24.6dc0: supR3HardenedDllNotificationCallback: load 00007fff92150000 LB 0x00025000 C:\Windows\System32\NetSetupApi.dll [fFlags=0x0]
32116d24.6dc0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\NetSetupApi.dll
32126d24.6dc0: supR3HardenedDllNotificationCallback: load 00007fffa7310000 LB 0x00470000 C:\WINDOWS\System32\setupapi.dll [fFlags=0x0]
32136d24.6dc0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\setupapi.dll
32146d24.6dc0: supR3HardenedDllNotificationCallback: load 00007fff9a930000 LB 0x00013000 C:\Windows\System32\DEVRTL.dll [fFlags=0x0]
32156d24.6dc0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\devrtl.dll
32166d24.6dc0: supR3HardenedDllNotificationCallback: load 00007fff4b840000 LB 0x00081000 C:\Windows\System32\NetSetupShim.dll [fFlags=0x0]
32176d24.6dc0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\NetSetupShim.dll
32186d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff4b840000 'C:\Windows\System32\NetSetupShim.dll'
32196d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
32206d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
32216d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
32226d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'rpcrt4.dll'.
32236d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #24 'nsi.dll'.
32246d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'winnsi.dll'.
32256d24.6dc0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\NetSetupEngine.dll) WinVerifyTrust
32266d24.6dc0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\NetSetupEngine.dll
32276d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winnsi.dll'...
32286d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'winnsi.dll' -> '\Device\HarddiskVolume8\Windows\System32\winnsi.dll' [rcNtRedir=0xc0150008]
32296d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
32306d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
32316d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rpcrt4.dll'.
32326d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'nsi.dll'.
32336d24.6dc0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\winnsi.dll) WinVerifyTrust
32346d24.6dc0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\winnsi.dll
32356d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
32366d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume8\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
32376d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
32386d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume8\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
32396d24.6dc0: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume8\Windows\System32\nsi.dll'.
32406d24.6dc0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\nsi.dll)
32416d24.6dc0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\nsi.dll
32426d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
32436d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume8\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
32446d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
32456d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
32466d24.6dc0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\nsi.dll) WinVerifyTrust
32476d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
32486d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume8\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
32496d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
32506d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume8\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
32516d24.6dc0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\NetSetupEngine.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
32526d24.6dc0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\NetSetupEngine.dll
32536d24.6dc0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\winnsi.dll
32546d24.6dc0: supR3HardenedDllNotificationCallback: load 00007fffa7230000 LB 0x00008000 C:\WINDOWS\System32\NSI.dll [fFlags=0x0]
32556d24.6dc0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\nsi.dll [avoiding WinVerifyTrust]
32566d24.6dc0: supR3HardenedDllNotificationCallback: load 00007fff9cc20000 LB 0x0000b000 C:\WINDOWS\SYSTEM32\WINNSI.DLL [fFlags=0x0]
32576d24.6dc0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\winnsi.dll
32586d24.6dc0: supR3HardenedDllNotificationCallback: load 00007fff36560000 LB 0x000ce000 C:\Windows\System32\NetSetupEngine.dll [fFlags=0x0]
32596d24.6dc0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\NetSetupEngine.dll
32606d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff36560000 'C:\Windows\System32\NetSetupEngine.dll'
32616d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
32626d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
32636d24.6dc0: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume8\Windows\System32\nsi.dll'
32646d24.6e10: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
32656d24.6e10: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
32666d24.6e10: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
32676d24.6e10: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxvmm.dll'.
32686d24.6e10: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vboxrt.dll'.
32696d24.6e10: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'user32.dll'.
32706d24.6e10: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll) WinVerifyTrust
32716d24.6e10: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll
32726d24.6e10: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
32736d24.6e10: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume8\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
32746d24.6e10: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
32756d24.6e10: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
32766d24.6e10: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
32776d24.6e10: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
32786d24.6e10: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxVMM.dll
32796d24.6e10: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
32806d24.6e10: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
32816d24.6e10: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
32826d24.6e10: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
32836d24.6e10: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll
32846d24.6e10: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
32856d24.6e10: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll
32866d24.6e10: supR3HardenedDllNotificationCallback: load 00007fff93e00000 LB 0x0000f000 C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL [fFlags=0x0]
32876d24.6e10: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll
32886d24.6e10: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff93e00000 'C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL'
32896d24.6e14: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
32906d24.6e14: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
32916d24.6e14: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
32926d24.6e14: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
32936d24.6e14: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll) WinVerifyTrust
32946d24.6e14: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll
32956d24.6e14: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
32966d24.6e14: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
32976d24.6e14: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
32986d24.6e14: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
32996d24.6e14: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
33006d24.6e14: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
33016d24.6e14: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
33026d24.6e14: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll
33036d24.6e14: supR3HardenedDllNotificationCallback: load 00007fff925a0000 LB 0x0000d000 C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL [fFlags=0x0]
33046d24.6e14: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll
33056d24.6e14: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff925a0000 'C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL'
33066d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa7ac0000 'C:\WINDOWS\system32\Shell32.dll'
33076d24.6dc0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxVMM.dll
33086d24.6dc0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
33096d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff36630000 'C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL'
33106d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
33116d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
33126d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
33136d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
33146d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ole32.dll'.
33156d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'oleaut32.dll'.
33166d24.6dc0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll) WinVerifyTrust
33176d24.6dc0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
33186d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
33196d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume8\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
33206d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
33216d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume8\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
33226d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
33236d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume8\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
33246d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
33256d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
33266d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
33276d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
33286d24.6dc0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
33296d24.6dc0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
33306d24.6dc0: supR3HardenedDllNotificationCallback: load 00007fff6d8c0000 LB 0x00041000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL [fFlags=0x0]
33316d24.6dc0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
33326d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff6d8c0000 'C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL'
33336d24.6dc0: supR3HardenedDllNotificationCallback: Unload 00007fff6d8c0000 LB 0x00041000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL [flags=0x0]
33346d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
33356d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
33366d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
33376d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
33386d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
33396d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vboxddu.dll'.
33406d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'vboxdd2.dll'.
33416d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
33426d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'setupapi.dll'.
33436d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'ws2_32.dll'.
33446d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'ole32.dll'.
33456d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'iphlpapi.dll'.
33466d24.6dc0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxDD.dll) WinVerifyTrust
33476d24.6dc0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxDD.dll
33486d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'iphlpapi.dll'...
33496d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'iphlpapi.dll' -> '\Device\HarddiskVolume8\Windows\System32\iphlpapi.dll' [rcNtRedir=0xc0150008]
33506d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
33516d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
33526d24.6dc0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\IPHLPAPI.DLL) WinVerifyTrust
33536d24.6dc0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\IPHLPAPI.DLL
33546d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
33556d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume8\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
33566d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
33576d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume8\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
33586d24.6dc0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\ws2_32.dll
33596d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
33606d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume8\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
33616d24.6dc0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\setupapi.dll
33626d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
33636d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume8\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
33646d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxdd2.dll'...
33656d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxdd2.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\vboxdd2.dll' [rcNtRedir=0xc0150008]
33666d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
33676d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
33686d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
33696d24.6dc0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxDD2.dll) WinVerifyTrust
33706d24.6dc0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxDD2.dll
33716d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxddu.dll'...
33726d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxddu.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\vboxddu.dll' [rcNtRedir=0xc0150008]
33736d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
33746d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
33756d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
33766d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
33776d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
33786d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
33796d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
33806d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
33816d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'setupapi.dll'.
33826d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'advapi32.dll'.
33836d24.6dc0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxDDU.dll) WinVerifyTrust
33846d24.6dc0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxDDU.dll
33856d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
33866d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
33876d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
33886d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
33896d24.6dc0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxVMM.dll
33906d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
33916d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
33926d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
33936d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume8\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
33946d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
33956d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume8\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
33966d24.6dc0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\setupapi.dll
33976d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
33986d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume8\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
33996d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
34006d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
34016d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
34026d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
34036d24.6dc0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxDD.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
34046d24.6dc0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxDD.dll
34056d24.6dc0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxDDU.dll
34066d24.6dc0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxDD2.dll
34076d24.6dc0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\IPHLPAPI.DLL
34086d24.6dc0: supR3HardenedDllNotificationCallback: load 00007fff4d9a0000 LB 0x00066000 C:\Program Files\Oracle\VirtualBox\VBoxDDU.dll [fFlags=0x0]
34096d24.6dc0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxDDU.dll
34106d24.6dc0: supR3HardenedDllNotificationCallback: load 00007fff35310000 LB 0x0085c000 C:\Program Files\Oracle\VirtualBox\VBoxDD2.dll [fFlags=0x0]
34116d24.6dc0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxDD2.dll
34126d24.6dc0: supR3HardenedDllNotificationCallback: load 00007fffa49e0000 LB 0x0003a000 C:\WINDOWS\SYSTEM32\IPHLPAPI.DLL [fFlags=0x0]
34136d24.6dc0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\IPHLPAPI.DLL
34146d24.6dc0: supR3HardenedDllNotificationCallback: load 00007fff35b70000 LB 0x009e4000 C:\Program Files\Oracle\VirtualBox\VBoxDD.DLL [fFlags=0x0]
34156d24.6dc0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxDD.dll
34166d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff35b70000 'C:\Program Files\Oracle\VirtualBox\VBoxDD.DLL'
34176d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
34186d24.6dc0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
34196d24.6dc0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
34206d24.6dc0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
34216d24.6dc0: supR3HardenedDllNotificationCallback: load 00007fff6d8c0000 LB 0x00041000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL [fFlags=0x0]
34226d24.6dc0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
34236d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff6d8c0000 'C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL'
34246d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
34256d24.6dc0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxC.dll
34266d24.6dc0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxC.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
34276d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff36d80000 'C:\Program Files\Oracle\VirtualBox\VBoxC.DLL'
34286d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
34296d24.6dc0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxDD2.dll
34306d24.6dc0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxDD2.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
34316d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff35310000 'C:\Program Files\Oracle\VirtualBox\VBoxDD2.DLL'
34326d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
34336d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
34346d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
34356d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
34366d24.6dc0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.dll) WinVerifyTrust
34376d24.6dc0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.dll
34386d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
34396d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
34406d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
34416d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
34426d24.6dc0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
34436d24.6dc0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.dll
34446d24.6dc0: supR3HardenedDllNotificationCallback: load 00007fff8a250000 LB 0x00018000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.DLL [fFlags=0x0]
34456d24.6dc0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.dll
34466d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff8a250000 'C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.DLL'
34476d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
34486d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
34496d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
34506d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
34516d24.6dc0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.dll) WinVerifyTrust
34526d24.6dc0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.dll
34536d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
34546d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
34556d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
34566d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
34576d24.6dc0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
34586d24.6dc0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.dll
34596d24.6dc0: supR3HardenedDllNotificationCallback: load 00007fff81090000 LB 0x00012000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.DLL [fFlags=0x0]
34606d24.6dc0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.dll
34616d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff81090000 'C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.DLL'
34626d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
34636d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
34646d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
34656d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
34666d24.6dc0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.dll) WinVerifyTrust
34676d24.6dc0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.dll
34686d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
34696d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
34706d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
34716d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
34726d24.6dc0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
34736d24.6dc0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.dll
34746d24.6dc0: supR3HardenedDllNotificationCallback: load 00007fff81070000 LB 0x00018000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.DLL [fFlags=0x0]
34756d24.6dc0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.dll
34766d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff81070000 'C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.DLL'
34776d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
34786d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
34796d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
34806d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
34816d24.6dc0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.dll) WinVerifyTrust
34826d24.6dc0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.dll
34836d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
34846d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
34856d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
34866d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
34876d24.6dc0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
34886d24.6dc0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.dll
34896d24.6dc0: supR3HardenedDllNotificationCallback: load 00007fff7ca10000 LB 0x00019000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.DLL [fFlags=0x0]
34906d24.6dc0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.dll
34916d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff7ca10000 'C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.DLL'
34926d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
34936d24.6e20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
34946d24.6e20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
34956d24.6e20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
34966d24.6e20: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
34976d24.6e20: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll) WinVerifyTrust
34986d24.6e20: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll
34996d24.6e20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
35006d24.6e20: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
35016d24.6e20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
35026d24.6e20: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
35036d24.6e20: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxVMM.dll
35046d24.6e20: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
35056d24.6e20: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
35066d24.6e20: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
35076d24.6e20: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll
35086d24.6e20: supR3HardenedDllNotificationCallback: load 00007fff7aea0000 LB 0x00014000 C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL [fFlags=0x0]
35096d24.6e20: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll
35106d24.6e20: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff7aea0000 'C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL'
35116d24.6e24: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
35126d24.6e24: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
35136d24.6e24: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
35146d24.6e24: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxvmm.dll'.
35156d24.6e24: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vboxrt.dll'.
35166d24.6e24: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll) WinVerifyTrust
35176d24.6e24: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll
35186d24.6e24: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
35196d24.6e24: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
35206d24.6e24: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
35216d24.6e24: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
35226d24.6e24: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxVMM.dll
35236d24.6e24: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
35246d24.6e24: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
35256d24.6e24: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
35266d24.6e24: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
35276d24.6e24: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
35286d24.6e24: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll
35296d24.6e24: supR3HardenedDllNotificationCallback: load 00007fff92520000 LB 0x0000c000 C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL [fFlags=0x0]
35306d24.6e24: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll
35316d24.6e24: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff92520000 'C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL'
35326d24.6e28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
35336d24.6e28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
35346d24.6e28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
35356d24.6e28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
35366d24.6e28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll) WinVerifyTrust
35376d24.6e28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll
35386d24.6e28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
35396d24.6e28: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
35406d24.6e28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
35416d24.6e28: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
35426d24.6e28: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
35436d24.6e28: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
35446d24.6e28: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
35456d24.6e28: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll
35466d24.6e28: supR3HardenedDllNotificationCallback: load 00007fff923e0000 LB 0x0000d000 C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL [fFlags=0x0]
35476d24.6e28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll
35486d24.6e28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff923e0000 'C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL'
35496d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
35506d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
35516d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
35526d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
35536d24.6dc0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.dll) WinVerifyTrust
35546d24.6dc0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.dll
35556d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
35566d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
35576d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
35586d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
35596d24.6dc0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
35606d24.6dc0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.dll
35616d24.6dc0: supR3HardenedDllNotificationCallback: load 00007fffa13d0000 LB 0x0000a000 C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.DLL [fFlags=0x0]
35626d24.6dc0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.dll
35636d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa13d0000 'C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.DLL'
35646d24.6dc0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\rsaenh.dll
35656d24.6dc0: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
35666d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
35676d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
35686d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
35696d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'rpcrt4.dll'.
35706d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #28 'devobj.dll'.
35716d24.6dc0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\MMDevAPI.dll) WinVerifyTrust
35726d24.6dc0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\MMDevAPI.dll
35736d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'devobj.dll'...
35746d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'devobj.dll' -> '\Device\HarddiskVolume8\Windows\System32\devobj.dll' [rcNtRedir=0xc0150008]
35756d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
35766d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
35776d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'cfgmgr32.dll'.
35786d24.6dc0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\devobj.dll) WinVerifyTrust
35796d24.6dc0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\devobj.dll
35806d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
35816d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume8\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
35826d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
35836d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume8\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
35846d24.6dc0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\msvcp_win.dll
35856d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
35866d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume8\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
35876d24.6dc0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\cfgmgr32.dll
35886d24.6dc0: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\MMDevApi.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
35896d24.6dc0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\MMDevAPI.dll
35906d24.6dc0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\devobj.dll
35916d24.6dc0: supR3HardenedDllNotificationCallback: load 00007fffa5260000 LB 0x0002a000 C:\WINDOWS\System32\DEVOBJ.dll [fFlags=0x0]
35926d24.6dc0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\devobj.dll
35936d24.6dc0: supR3HardenedDllNotificationCallback: load 00007fff9d1c0000 LB 0x00072000 C:\WINDOWS\System32\MMDevApi.dll [fFlags=0x0]
35946d24.6dc0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\MMDevAPI.dll
35956d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff9d1c0000 'C:\WINDOWS\System32\MMDevApi.dll'
35966d24.6dc0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000015e0 pwszName=\Device\HarddiskVolume8\Windows\System32\dsound.dll
35976d24.6dc0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000187dd30
35986d24.6dc0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000187dd30
35996d24.6dc0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=8184043CF3F3DF1E3CF96E74DBBF7D0836417373
36006d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
36016d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
36026d24.6dc0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package~31bf3856ad364e35~amd64~~10.0.18362.778.cat'; file='\Device\HarddiskVolume8\Windows\System32\dsound.dll'
36036d24.6dc0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
36046d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
36056d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #32 'winmm.dll'.
36066d24.6dc0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\dsound.dll) WinVerifyTrust
36076d24.6dc0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\dsound.dll
36086d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
36096d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume8\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
36106d24.6dc0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\winmm.dll
36116d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
36126d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume8\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
36136d24.6dc0: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
36146d24.6dc0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\dsound.dll
36156d24.6dc0: supR3HardenedDllNotificationCallback: load 00007fff4da10000 LB 0x00099000 C:\WINDOWS\System32\dsound.dll [fFlags=0x0]
36166d24.6dc0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\dsound.dll
36176d24.6dc0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\dsound.dll
36186d24.6dc0: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
36196d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff4da10000 'C:\WINDOWS\System32\dsound.dll'
36206d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff4da10000 'C:\WINDOWS\System32\dsound.dll'
36216d24.6dc0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\dsound.dll
36226d24.6dc0: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
36236d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff4da10000 'C:\WINDOWS\system32\dsound.dll'
36246d24.6dc0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\MMDevAPI.dll
36256d24.6dc0: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\MMDEVAPI.DLL (Input=MMDEVAPI.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
36266d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff9d1c0000 'C:\WINDOWS\System32\MMDEVAPI.DLL'
36276d24.6e9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
36286d24.6e9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
36296d24.6e9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
36306d24.6e9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'rpcrt4.dll'.
36316d24.6e9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'oleaut32.dll'.
36326d24.6e9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #29 'mmdevapi.dll'.
36336d24.6e9c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\AudioSes.dll) WinVerifyTrust
36346d24.6e9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\AudioSes.dll
36356d24.6e9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mmdevapi.dll'...
36366d24.6e9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'mmdevapi.dll' -> '\Device\HarddiskVolume8\Windows\System32\mmdevapi.dll' [rcNtRedir=0xc0150008]
36376d24.6e9c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\MMDevAPI.dll
36386d24.6e9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
36396d24.6e9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume8\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
36406d24.6e9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
36416d24.6e9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume8\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
36426d24.6e9c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\rpcrt4.dll
36436d24.6e9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
36446d24.6e9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume8\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
36456d24.6e9c: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\AUDIOSES.DLL (Input=AUDIOSES.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
36466d24.6e9c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\AudioSes.dll
36476d24.6e9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'combase.dll'.
36486d24.6e9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #24 'rpcrt4.dll'.
36496d24.6e9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #32 'bcryptprimitives.dll'.
36506d24.6e9c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\WinTypes.dll)
36516d24.6e9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\WinTypes.dll
36526d24.6e9c: supR3HardenedDllNotificationCallback: load 00007fffa0d60000 LB 0x00153000 C:\WINDOWS\SYSTEM32\wintypes.dll [fFlags=0x0]
36536d24.6e9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\WinTypes.dll [avoiding WinVerifyTrust]
36546d24.6e9c: supR3HardenedDllNotificationCallback: load 00007fff94970000 LB 0x0015d000 C:\WINDOWS\System32\AUDIOSES.DLL [fFlags=0x0]
36556d24.6e9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\AudioSes.dll
36566d24.6e9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff94970000 'C:\WINDOWS\System32\AUDIOSES.DLL'
36576d24.6e9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcryptprimitives.dll'...
36586d24.6e9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcryptprimitives.dll' -> '\Device\HarddiskVolume8\Windows\System32\bcryptprimitives.dll' [rcNtRedir=0xc0150008]
36596d24.6e9c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\bcryptprimitives.dll
36606d24.6e9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
36616d24.6e9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume8\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
36626d24.6e9c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
36636d24.6e9c: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume8\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
36646d24.6e9c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\combase.dll
36656d24.6e9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
36666d24.6e9c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
36676d24.6e9c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume8\Windows\System32\WinTypes.dll'
36686d24.6e9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
36696d24.6e9c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'rpcrt4.dll'.
36706d24.6e9c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\ResourcePolicyClient.dll)
36716d24.6e9c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\ResourcePolicyClient.dll
36726d24.6e9c: supR3HardenedDllNotificationCallback: load 00007fffa3940000 LB 0x00014000 C:\WINDOWS\SYSTEM32\resourcepolicyclient.dll [fFlags=0x0]
36736d24.6e9c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\ResourcePolicyClient.dll [avoiding WinVerifyTrust]
36746d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
36756d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume8\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
36766d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
36776d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume8\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
36786d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
36796d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
36806d24.6dc0: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume8\Windows\System32\ResourcePolicyClient.dll'
36816d24.6dc0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\winmm.dll
36826d24.6dc0: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\winmm.dll (Input=winmm.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
36836d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa3330000 'C:\WINDOWS\System32\winmm.dll'
36846d24.6dc0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000165c pwszName=\Device\HarddiskVolume8\Windows\System32\wdmaud.drv
36856d24.6dc0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000187dd30
36866d24.6dc0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000187dd30
36876d24.6dc0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=38EA8D6D625C6A0A9075DAE17FD33652FF8FC23A
36886d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
36896d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
36906d24.6dc0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package~31bf3856ad364e35~amd64~~10.0.18362.778.cat'; file='\Device\HarddiskVolume8\Windows\System32\wdmaud.drv'
36916d24.6dc0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
36926d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
36936d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'mmdevapi.dll'.
36946d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #27 'ksuser.dll'.
36956d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #28 'avrt.dll'.
36966d24.6dc0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\wdmaud.drv) WinVerifyTrust
36976d24.6dc0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\wdmaud.drv
36986d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'avrt.dll'...
36996d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'avrt.dll' -> '\Device\HarddiskVolume8\Windows\System32\avrt.dll' [rcNtRedir=0xc0150008]
37006d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
37016d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
37026d24.6dc0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\avrt.dll) WinVerifyTrust
37036d24.6dc0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\avrt.dll
37046d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ksuser.dll'...
37056d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'ksuser.dll' -> '\Device\HarddiskVolume8\Windows\System32\ksuser.dll' [rcNtRedir=0xc0150008]
37066d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
37076d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
37086d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
37096d24.6dc0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\ksuser.dll) WinVerifyTrust
37106d24.6dc0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\ksuser.dll
37116d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mmdevapi.dll'...
37126d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'mmdevapi.dll' -> '\Device\HarddiskVolume8\Windows\System32\mmdevapi.dll' [rcNtRedir=0xc0150008]
37136d24.6dc0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\MMDevAPI.dll
37146d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
37156d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume8\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
37166d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
37176d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume8\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
37186d24.6dc0: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
37196d24.6dc0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\wdmaud.drv
37206d24.6dc0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\ksuser.dll
37216d24.6dc0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\avrt.dll
37226d24.6dc0: supR3HardenedDllNotificationCallback: load 00007fff97c20000 LB 0x00009000 C:\WINDOWS\SYSTEM32\ksuser.dll [fFlags=0x0]
37236d24.6dc0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\ksuser.dll
37246d24.6dc0: supR3HardenedDllNotificationCallback: load 00007fffa17b0000 LB 0x0000a000 C:\WINDOWS\SYSTEM32\AVRT.dll [fFlags=0x0]
37256d24.6dc0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\avrt.dll
37266d24.6dc0: supR3HardenedDllNotificationCallback: load 00007fff5d540000 LB 0x00044000 C:\WINDOWS\System32\wdmaud.drv [fFlags=0x0]
37276d24.6dc0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\wdmaud.drv
37286d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff5d540000 'C:\WINDOWS\System32\wdmaud.drv'
37296d24.6dc0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\wdmaud.drv
37306d24.6dc0: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
37316d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff5d540000 'C:\WINDOWS\System32\wdmaud.drv'
37326d24.6dc0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\wdmaud.drv
37336d24.6dc0: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
37346d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff5d540000 'C:\WINDOWS\System32\wdmaud.drv'
37356d24.6dc0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\wdmaud.drv
37366d24.6dc0: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
37376d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff5d540000 'C:\WINDOWS\System32\wdmaud.drv'
37386d24.6dc0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\wdmaud.drv
37396d24.6dc0: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
37406d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff5d540000 'C:\WINDOWS\System32\wdmaud.drv'
37416d24.6dc0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\wdmaud.drv
37426d24.6dc0: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
37436d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff5d540000 'C:\WINDOWS\System32\wdmaud.drv'
37446d24.6dc0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\wdmaud.drv
37456d24.6dc0: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
37466d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff5d540000 'C:\WINDOWS\System32\wdmaud.drv'
37476d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff5d540000 'C:\WINDOWS\System32\wdmaud.drv'
37486d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff5d540000 'C:\WINDOWS\System32\wdmaud.drv'
37496d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff5d540000 'C:\WINDOWS\System32\wdmaud.drv'
37506d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff5d540000 'C:\WINDOWS\System32\wdmaud.drv'
37516d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff5d540000 'C:\WINDOWS\System32\wdmaud.drv'
37526d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff5d540000 'C:\WINDOWS\System32\wdmaud.drv'
37536d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff5d540000 'C:\WINDOWS\System32\wdmaud.drv'
37546d24.6dc0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000016f8 pwszName=\Device\HarddiskVolume8\Windows\System32\msacm32.drv
37556d24.6dc0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000187dd30
37566d24.6dc0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000187dd30
37576d24.6dc0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=763C5E89A8DA653902990733D245B99CC7C40BEA
37586d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
37596d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
37606d24.6dc0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package~31bf3856ad364e35~amd64~~10.0.18362.778.cat'; file='\Device\HarddiskVolume8\Windows\System32\msacm32.drv'
37616d24.6dc0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
37626d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
37636d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'mmdevapi.dll'.
37646d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'msacm32.dll'.
37656d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'winmmbase.dll'.
37666d24.6dc0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\msacm32.drv) WinVerifyTrust
37676d24.6dc0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\msacm32.drv
37686d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmmbase.dll'...
37696d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmmbase.dll' -> '\Device\HarddiskVolume8\Windows\System32\winmmbase.dll' [rcNtRedir=0xc0150008]
37706d24.6dc0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\winmmbase.dll
37716d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msacm32.dll'...
37726d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msacm32.dll' -> '\Device\HarddiskVolume8\Windows\System32\msacm32.dll' [rcNtRedir=0xc0150008]
37736d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
37746d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
37756d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
37766d24.6dc0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\msacm32.dll) WinVerifyTrust
37776d24.6dc0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\msacm32.dll
37786d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mmdevapi.dll'...
37796d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'mmdevapi.dll' -> '\Device\HarddiskVolume8\Windows\System32\mmdevapi.dll' [rcNtRedir=0xc0150008]
37806d24.6dc0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\MMDevAPI.dll
37816d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
37826d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume8\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
37836d24.6dc0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\msvcrt.dll
37846d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
37856d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume8\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
37866d24.6dc0: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
37876d24.6dc0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\msacm32.drv
37886d24.6dc0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\msacm32.dll
37896d24.6dc0: supR3HardenedDllNotificationCallback: load 00007fff7a860000 LB 0x0001c000 C:\WINDOWS\SYSTEM32\MSACM32.dll [fFlags=0x0]
37906d24.6dc0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\msacm32.dll
37916d24.6dc0: supR3HardenedDllNotificationCallback: load 00007fff93de0000 LB 0x0000d000 C:\WINDOWS\System32\msacm32.drv [fFlags=0x0]
37926d24.6dc0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\msacm32.drv
37936d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff93de0000 'C:\WINDOWS\System32\msacm32.drv'
37946d24.6dc0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\msacm32.drv
37956d24.6dc0: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
37966d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff93de0000 'C:\WINDOWS\System32\msacm32.drv'
37976d24.6dc0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\msacm32.drv
37986d24.6dc0: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
37996d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff93de0000 'C:\WINDOWS\System32\msacm32.drv'
38006d24.6dc0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\msacm32.drv
38016d24.6dc0: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
38026d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff93de0000 'C:\WINDOWS\System32\msacm32.drv'
38036d24.6dc0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\msacm32.drv
38046d24.6dc0: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
38056d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff93de0000 'C:\WINDOWS\System32\msacm32.drv'
38066d24.6dc0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\msacm32.drv
38076d24.6dc0: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
38086d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff93de0000 'C:\WINDOWS\System32\msacm32.drv'
38096d24.6dc0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\msacm32.drv
38106d24.6dc0: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
38116d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff93de0000 'C:\WINDOWS\System32\msacm32.drv'
38126d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff93de0000 'C:\WINDOWS\System32\msacm32.drv'
38136d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff93de0000 'C:\WINDOWS\System32\msacm32.drv'
38146d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff93de0000 'C:\WINDOWS\System32\msacm32.drv'
38156d24.6dc0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000170c pwszName=\Device\HarddiskVolume8\Windows\System32\midimap.dll
38166d24.6dc0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000000000187dd30
38176d24.6dc0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000000000187dd30
38186d24.6dc0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=EB34EC166C3F780657AB67E557E6C2E60C398D10
38196d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
38206d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
38216d24.6dc0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package~31bf3856ad364e35~amd64~~10.0.18362.778.cat'; file='\Device\HarddiskVolume8\Windows\System32\midimap.dll'
38226d24.6dc0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
38236d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
38246d24.6dc0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'winmm.dll'.
38256d24.6dc0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\midimap.dll) WinVerifyTrust
38266d24.6dc0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\midimap.dll
38276d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
38286d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume8\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
38296d24.6dc0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\winmm.dll
38306d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
38316d24.6dc0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume8\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
38326d24.6dc0: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
38336d24.6dc0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\midimap.dll
38346d24.6dc0: supR3HardenedDllNotificationCallback: load 00007fff93530000 LB 0x0000a000 C:\WINDOWS\System32\midimap.dll [fFlags=0x0]
38356d24.6dc0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\midimap.dll
38366d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff93530000 'C:\WINDOWS\System32\midimap.dll'
38376d24.6dc0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\midimap.dll
38386d24.6dc0: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
38396d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff93530000 'C:\WINDOWS\System32\midimap.dll'
38406d24.6dc0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\midimap.dll
38416d24.6dc0: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
38426d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff93530000 'C:\WINDOWS\System32\midimap.dll'
38436d24.6dc0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\midimap.dll
38446d24.6dc0: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
38456d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff93530000 'C:\WINDOWS\System32\midimap.dll'
38466d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa3330000 'C:\WINDOWS\System32\winmm.dll'
38476d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa3330000 'C:\WINDOWS\System32\winmm.dll'
38486d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa3330000 'C:\WINDOWS\System32\winmm.dll'
38496d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa3330000 'C:\WINDOWS\System32\winmm.dll'
38506d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa3330000 'C:\WINDOWS\System32\winmm.dll'
38516d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa3330000 'C:\WINDOWS\System32\winmm.dll'
38526d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa3330000 'C:\WINDOWS\System32\winmm.dll'
38536d24.6dc0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\winmm.dll
38546d24.6dc0: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\winmm.dll (Input=winmm.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
38556d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa3330000 'C:\WINDOWS\System32\winmm.dll'
38566d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa3330000 'C:\WINDOWS\System32\winmm.dll'
38576d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa3330000 'C:\WINDOWS\System32\winmm.dll'
38586d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa3330000 'C:\WINDOWS\System32\winmm.dll'
38596d24.6dc0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\dsound.dll
38606d24.6dc0: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
38616d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff4da10000 'C:\WINDOWS\system32\dsound.dll'
38626d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa3330000 'C:\WINDOWS\System32\winmm.dll'
38636d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa3330000 'C:\WINDOWS\System32\winmm.dll'
38646d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa3330000 'C:\WINDOWS\System32\winmm.dll'
38656d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa3330000 'C:\WINDOWS\System32\winmm.dll'
38666d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa3330000 'C:\WINDOWS\System32\winmm.dll'
38676d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa3330000 'C:\WINDOWS\System32\winmm.dll'
38686d24.6dc0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
38696d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\msctf.dll
38706d24.6d28: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\MSCTF.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
38716d24.6d28: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6b90000 'C:\WINDOWS\System32\MSCTF.dll'
38726d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
38736d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #15 'rpcrt4.dll'.
38746d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #19 'coreuicomponents.dll'.
38756d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #20 'coremessaging.dll'.
38766d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\TextInputFramework.dll)
38776d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\TextInputFramework.dll
38786d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
38796d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #35 'coremessaging.dll'.
38806d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #47 'shcore.dll'.
38816d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\CoreUIComponents.dll)
38826d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\CoreUIComponents.dll
38836d24.6d28: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
38846d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\CoreMessaging.dll)
38856d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\CoreMessaging.dll
38866d24.6d28: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\ntmarta.dll)
38876d24.6d28: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\ntmarta.dll
38886d24.6d28: supR3HardenedDllNotificationCallback: load 00007fffa44a0000 LB 0x00031000 C:\WINDOWS\SYSTEM32\ntmarta.dll [fFlags=0x0]
38896d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\ntmarta.dll [avoiding WinVerifyTrust]
38906d24.6d28: supR3HardenedDllNotificationCallback: load 00007fffa30f0000 LB 0x000d4000 C:\WINDOWS\System32\CoreMessaging.dll [fFlags=0x0]
38916d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\CoreMessaging.dll [avoiding WinVerifyTrust]
38926d24.6d28: supR3HardenedDllNotificationCallback: load 00007fffa1050000 LB 0x0032a000 C:\WINDOWS\System32\CoreUIComponents.dll [fFlags=0x0]
38936d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\CoreUIComponents.dll [avoiding WinVerifyTrust]
38946d24.6d28: supR3HardenedDllNotificationCallback: load 00007fff9cc30000 LB 0x0009e000 C:\WINDOWS\System32\TextInputFramework.dll [fFlags=0x0]
38956d24.6d28: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\TextInputFramework.dll [avoiding WinVerifyTrust]
38966d24.6e10: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
38976d24.6e10: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume8\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
38986d24.6e10: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shcore.dll'...
38996d24.6e10: supR3HardenedWinVerifyCacheProcessImportTodos: 'shcore.dll' -> '\Device\HarddiskVolume8\Windows\System32\shcore.dll' [rcNtRedir=0xc0150008]
39006d24.6e10: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\SHCore.dll
39016d24.6e10: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'coremessaging.dll'...
39026d24.6e10: supR3HardenedWinVerifyCacheProcessImportTodos: 'coremessaging.dll' -> '\Device\HarddiskVolume8\Windows\System32\coremessaging.dll' [rcNtRedir=0xc0150008]
39036d24.6e10: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\CoreMessaging.dll [lacks WinVerifyTrust]
39046d24.6e10: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
39056d24.6e10: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume8\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
39066d24.6e10: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'coremessaging.dll'...
39076d24.6e10: supR3HardenedWinVerifyCacheProcessImportTodos: 'coremessaging.dll' -> '\Device\HarddiskVolume8\Windows\System32\coremessaging.dll' [rcNtRedir=0xc0150008]
39086d24.6e10: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\CoreMessaging.dll [lacks WinVerifyTrust]
39096d24.6e10: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'coreuicomponents.dll'...
39106d24.6e10: supR3HardenedWinVerifyCacheProcessImportTodos: 'coreuicomponents.dll' -> '\Device\HarddiskVolume8\Windows\System32\coreuicomponents.dll' [rcNtRedir=0xc0150008]
39116d24.6e10: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\CoreUIComponents.dll [lacks WinVerifyTrust]
39126d24.6e10: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
39136d24.6e10: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume8\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
39146d24.6e10: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
39156d24.6e10: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume8\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
39166d24.6e10: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
39176d24.6e10: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\wintrust.dll
39186d24.6e10: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\WINTRUST.DLL (Input=WINTRUST.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
39196d24.6e10: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa5600000 'C:\WINDOWS\System32\WINTRUST.DLL'
39206d24.6e10: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\CRYPT32.dll'
39216d24.6e10: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
39226d24.6e10: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff9f4c0000 'C:\Windows\System32\cryptnet.dll'
39236d24.6e10: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume8\Windows\System32\ntmarta.dll'
39246d24.6e10: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
39256d24.6e10: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
39266d24.6e10: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume8\Windows\System32\CoreMessaging.dll'
39276d24.6e10: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
39286d24.6e10: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
39296d24.6e10: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume8\Windows\System32\CoreUIComponents.dll'
39306d24.6e10: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
39316d24.6e10: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
39326d24.6e10: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume8\Windows\System32\TextInputFramework.dll'
39336d24.6e10: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa69f0000 'C:\WINDOWS\system32\User32.dll'
39346d24.6e34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
39356d24.6e34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
39366d24.6e34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
39376d24.6e34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
39386d24.6e34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'win32u.dll'.
39396d24.6e34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'gdi32.dll'.
39406d24.6e34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'dwmapi.dll'.
39416d24.6e34: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\d3d9.dll) WinVerifyTrust
39426d24.6e34: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\d3d9.dll
39436d24.6e34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dwmapi.dll'...
39446d24.6e34: supR3HardenedWinVerifyCacheProcessImportTodos: 'dwmapi.dll' -> '\Device\HarddiskVolume8\Windows\System32\dwmapi.dll' [rcNtRedir=0xc0150008]
39456d24.6e34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
39466d24.6e34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
39476d24.6e34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
39486d24.6e34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #21 'win32u.dll'.
39496d24.6e34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #22 'user32.dll'.
39506d24.6e34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'gdi32.dll'.
39516d24.6e34: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\dwmapi.dll) WinVerifyTrust
39526d24.6e34: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\dwmapi.dll
39536d24.6e34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
39546d24.6e34: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume8\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
39556d24.6e34: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\gdi32.dll
39566d24.6e34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
39576d24.6e34: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume8\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
39586d24.6e34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
39596d24.6e34: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume8\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
39606d24.6e34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
39616d24.6e34: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume8\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
39626d24.6e34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
39636d24.6e34: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume8\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
39646d24.6e34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
39656d24.6e34: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume8\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
39666d24.6e34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
39676d24.6e34: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume8\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
39686d24.6e34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
39696d24.6e34: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume8\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
39706d24.6e34: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\d3d9.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
39716d24.6e34: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\d3d9.dll
39726d24.6e34: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\dwmapi.dll
39736d24.6e34: supR3HardenedDllNotificationCallback: load 00007fffa3a30000 LB 0x0002d000 C:\WINDOWS\SYSTEM32\dwmapi.dll [fFlags=0x0]
39746d24.6e34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\dwmapi.dll
39756d24.6e34: supR3HardenedDllNotificationCallback: load 00007fff987a0000 LB 0x001c7000 C:\WINDOWS\system32\d3d9.dll [fFlags=0x0]
39766d24.6e34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\d3d9.dll
39776d24.6e34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff987a0000 'C:\WINDOWS\system32\d3d9.dll'
39786d24.6e34: \Device\HarddiskVolume8\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_93eff437a314841a\nvldumdx.dll: Owner is administrators group.
39796d24.6e34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
39806d24.6e34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
39816d24.6e34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #30 'version.dll'.
39826d24.6e34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #31 'user32.dll'.
39836d24.6e34: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_93eff437a314841a\nvldumdx.dll) WinVerifyTrust
39846d24.6e34: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_93eff437a314841a\nvldumdx.dll
39856d24.6e34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
39866d24.6e34: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume8\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
39876d24.6e34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'version.dll'...
39886d24.6e34: supR3HardenedWinVerifyCacheProcessImportTodos: 'version.dll' -> '\Device\HarddiskVolume8\Windows\System32\version.dll' [rcNtRedir=0xc0150008]
39896d24.6e34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
39906d24.6e34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
39916d24.6e34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
39926d24.6e34: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\version.dll) WinVerifyTrust
39936d24.6e34: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\version.dll
39946d24.6e34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
39956d24.6e34: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume8\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
39966d24.6e34: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_93eff437a314841a\nvldumdx.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
39976d24.6e34: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_93eff437a314841a\nvldumdx.dll
39986d24.6e34: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\version.dll
39996d24.6e34: supR3HardenedDllNotificationCallback: load 00007fffa3fb0000 LB 0x0000a000 C:\WINDOWS\SYSTEM32\VERSION.dll [fFlags=0x0]
40006d24.6e34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\version.dll
40016d24.6e34: supR3HardenedDllNotificationCallback: load 00007fff9d240000 LB 0x000ef000 C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_93eff437a314841a\nvldumdx.dll [fFlags=0x0]
40026d24.6e34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_93eff437a314841a\nvldumdx.dll
40036d24.6e34: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
40046d24.6e34: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
40056d24.6e34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa5710000 'api-ms-win-core-synch-l1-2-0'
40066d24.6e34: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-fibers-l1-1-1) -> 0x0, fPresent=1
40076d24.6e34: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
40086d24.6e34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa5710000 'api-ms-win-core-fibers-l1-1-1'
40096d24.6e34: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
40106d24.6e34: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
40116d24.6e34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa5710000 'api-ms-win-core-synch-l1-2-0'
40126d24.6e34: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-fibers-l1-1-1) -> 0x0, fPresent=1
40136d24.6e34: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
40146d24.6e34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa5710000 'api-ms-win-core-fibers-l1-1-1'
40156d24.6e34: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-l1-2-1) -> 0x0, fPresent=1
40166d24.6e34: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-l1-2-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
40176d24.6e34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa5710000 'api-ms-win-core-localization-l1-2-1'
40186d24.6e34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff9d240000 'C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_93eff437a314841a\nvldumdx.dll'
40196d24.6e34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
40206d24.6e34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\wintrust.dll
40216d24.6e34: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\wintrust.dll (Input=wintrust.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
40226d24.6e34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa5600000 'C:\WINDOWS\System32\wintrust.dll'
40236d24.6e34: \Device\HarddiskVolume8\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_93eff437a314841a\nvd3dumx.dll: Owner is administrators group.
40246d24.6e34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
40256d24.6e34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
40266d24.6e34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'version.dll'.
40276d24.6e34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
40286d24.6e34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
40296d24.6e34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'gdi32.dll'.
40306d24.6e34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'winmm.dll'.
40316d24.6e34: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_93eff437a314841a\nvd3dumx.dll) WinVerifyTrust
40326d24.6e34: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_93eff437a314841a\nvd3dumx.dll
40336d24.6e34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
40346d24.6e34: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume8\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
40356d24.6e34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
40366d24.6e34: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume8\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
40376d24.6e34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
40386d24.6e34: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume8\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
40396d24.6e34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
40406d24.6e34: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume8\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
40416d24.6e34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'version.dll'...
40426d24.6e34: supR3HardenedWinVerifyCacheProcessImportTodos: 'version.dll' -> '\Device\HarddiskVolume8\Windows\System32\version.dll' [rcNtRedir=0xc0150008]
40436d24.6e34: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\version.dll
40446d24.6e34: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_93eff437a314841a\nvd3dumx.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
40456d24.6e34: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_93eff437a314841a\nvd3dumx.dll
40466d24.6e34: supR3HardenedDllNotificationCallback: load 00007fff33e00000 LB 0x01503000 C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_93eff437a314841a\nvd3dumx.dll [fFlags=0x0]
40476d24.6e34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_93eff437a314841a\nvd3dumx.dll
40486d24.6e34: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
40496d24.6e34: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
40506d24.6e34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa5710000 'api-ms-win-core-synch-l1-2-0'
40516d24.6e34: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-fibers-l1-1-1) -> 0x0, fPresent=1
40526d24.6e34: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
40536d24.6e34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa5710000 'api-ms-win-core-fibers-l1-1-1'
40546d24.6e34: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
40556d24.6e34: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
40566d24.6e34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa5710000 'api-ms-win-core-synch-l1-2-0'
40576d24.6e34: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-fibers-l1-1-1) -> 0x0, fPresent=1
40586d24.6e34: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
40596d24.6e34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa5710000 'api-ms-win-core-fibers-l1-1-1'
40606d24.6e34: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-l1-2-1) -> 0x0, fPresent=1
40616d24.6e34: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-l1-2-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
40626d24.6e34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa5710000 'api-ms-win-core-localization-l1-2-1'
40636d24.6e34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff33e00000 'C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_93eff437a314841a\nvd3dumx.dll'
40646d24.6e34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6d90000 'C:\WINDOWS\System32\gdi32.dll'
40656d24.6e34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_93eff437a314841a\nvldumdx.dll
40666d24.6e34: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_93eff437a314841a\nvldumdx.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
40676d24.6e34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff9d240000 'C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_93eff437a314841a\nvldumdx.dll'
40686d24.6e34: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(ext-ms-win-core-resourcepolicy-l1-1-0.dll) -> 0x0, fPresent=1
40696d24.6e34: supR3HardenedMonitor_LdrLoadDll: pName=ext-ms-win-core-resourcepolicy-l1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
40706d24.6e34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa3940000 'ext-ms-win-core-resourcepolicy-l1-1-0.dll'
40716d24.6e34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_93eff437a314841a\nvldumdx.dll
40726d24.6e34: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_93eff437a314841a\nvldumdx.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
40736d24.6e34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff9d240000 'C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_93eff437a314841a\nvldumdx.dll'
40746d24.6e34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa69f0000 'C:\WINDOWS\system32\user32.dll'
40756d24.6e34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\kernel32.dll
40766d24.6e34: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\kernel32.dll (Input=kernel32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
40776d24.6e34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa70c0000 'C:\WINDOWS\System32\kernel32.dll'
40786d24.6e34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\powrprof.dll
40796d24.6e34: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\powrprof.dll (Input=powrprof.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
40806d24.6e34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa5490000 'C:\WINDOWS\System32\powrprof.dll'
40816d24.6e34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa7ac0000 'C:\WINDOWS\System32\Shell32.dll'
40826d24.6e34: \Device\HarddiskVolume8\Windows\System32\nvspcap64.dll: Owner is administrators group.
40836d24.6e34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
40846d24.6e34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'shell32.dll'.
40856d24.6e34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'ole32.dll'.
40866d24.6e34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'advapi32.dll'.
40876d24.6e34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
40886d24.6e34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'shlwapi.dll'.
40896d24.6e34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'version.dll'.
40906d24.6e34: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\nvspcap64.dll) WinVerifyTrust
40916d24.6e34: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\nvspcap64.dll
40926d24.6e34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'version.dll'...
40936d24.6e34: supR3HardenedWinVerifyCacheProcessImportTodos: 'version.dll' -> '\Device\HarddiskVolume8\Windows\System32\version.dll' [rcNtRedir=0xc0150008]
40946d24.6e34: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\version.dll
40956d24.6e34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
40966d24.6e34: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume8\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
40976d24.6e34: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\shlwapi.dll
40986d24.6e34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
40996d24.6e34: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume8\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
41006d24.6e34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
41016d24.6e34: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume8\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
41026d24.6e34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
41036d24.6e34: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume8\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
41046d24.6e34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
41056d24.6e34: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume8\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
41066d24.6e34: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\nvspcap64.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
41076d24.6e34: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\nvspcap64.dll
41086d24.6e34: supR3HardenedDllNotificationCallback: load 00007fff66c50000 LB 0x002c2000 C:\WINDOWS\system32\nvspcap64.dll [fFlags=0x0]
41096d24.6e34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\nvspcap64.dll
41106d24.6e34: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
41116d24.6e34: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
41126d24.6e34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa5710000 'api-ms-win-core-synch-l1-2-0'
41136d24.6e34: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-fibers-l1-1-1) -> 0x0, fPresent=1
41146d24.6e34: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
41156d24.6e34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa5710000 'api-ms-win-core-fibers-l1-1-1'
41166d24.6e34: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
41176d24.6e34: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
41186d24.6e34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa5710000 'api-ms-win-core-synch-l1-2-0'
41196d24.6e34: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-fibers-l1-1-1) -> 0x0, fPresent=1
41206d24.6e34: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
41216d24.6e34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa5710000 'api-ms-win-core-fibers-l1-1-1'
41226d24.6e34: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-l1-2-1) -> 0x0, fPresent=1
41236d24.6e34: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-l1-2-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
41246d24.6e34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa5710000 'api-ms-win-core-localization-l1-2-1'
41256d24.6e34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff66c50000 'C:\WINDOWS\system32\nvspcap64.dll'
41266d24.6e34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa69f0000 'C:\WINDOWS\System32\User32.dll'
41276d24.6e34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
41286d24.6e34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\cryptnet.dll
41296d24.6e34: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptnet.dll (Input=cryptnet.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
41306d24.6e34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff9f4c0000 'C:\WINDOWS\System32\cryptnet.dll'
41316d24.6e34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\cryptbase.dll
41326d24.6e34: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\cryptbase.dll (Input=cryptbase.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
41336d24.6e34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4ea0000 'C:\WINDOWS\System32\cryptbase.dll'
41346d24.6e34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\wintrust.dll
41356d24.6e34: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\wintrust.dll (Input=wintrust.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
41366d24.6e34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa5600000 'C:\WINDOWS\System32\wintrust.dll'
41376d24.6e34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
41386d24.6e34: \Device\HarddiskVolume8\Program Files\NVIDIA Corporation\Ansel\NvCameraWhitelisting64.dll: Owner is administrators group.
41396d24.6e34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
41406d24.6e34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'advapi32.dll'.
41416d24.6e34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'shell32.dll'.
41426d24.6e34: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'version.dll'.
41436d24.6e34: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Program Files\NVIDIA Corporation\Ansel\NvCameraWhitelisting64.dll) WinVerifyTrust
41446d24.6e34: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Program Files\NVIDIA Corporation\Ansel\NvCameraWhitelisting64.dll
41456d24.6e34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'version.dll'...
41466d24.6e34: supR3HardenedWinVerifyCacheProcessImportTodos: 'version.dll' -> '\Device\HarddiskVolume8\Windows\System32\version.dll' [rcNtRedir=0xc0150008]
41476d24.6e34: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\version.dll
41486d24.6e34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
41496d24.6e34: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume8\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
41506d24.6e34: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
41516d24.6e34: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume8\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
41526d24.6e34: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\NVIDIA Corporation\Ansel\NvCameraWhitelisting64.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
41536d24.6e34: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\NVIDIA Corporation\Ansel\NvCameraWhitelisting64.dll
41546d24.6e34: supR3HardenedDllNotificationCallback: load 00007fff6e790000 LB 0x0009e000 C:\Program Files\NVIDIA Corporation\Ansel\NvCameraWhitelisting64.dll [fFlags=0x0]
41556d24.6e34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Program Files\NVIDIA Corporation\Ansel\NvCameraWhitelisting64.dll
41566d24.6e34: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
41576d24.6e34: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
41586d24.6e34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa5710000 'api-ms-win-core-synch-l1-2-0'
41596d24.6e34: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-fibers-l1-1-1) -> 0x0, fPresent=1
41606d24.6e34: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
41616d24.6e34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa5710000 'api-ms-win-core-fibers-l1-1-1'
41626d24.6e34: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
41636d24.6e34: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
41646d24.6e34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa5710000 'api-ms-win-core-synch-l1-2-0'
41656d24.6e34: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-fibers-l1-1-1) -> 0x0, fPresent=1
41666d24.6e34: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
41676d24.6e34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa5710000 'api-ms-win-core-fibers-l1-1-1'
41686d24.6e34: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-l1-2-1) -> 0x0, fPresent=1
41696d24.6e34: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-l1-2-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
41706d24.6e34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa5710000 'api-ms-win-core-localization-l1-2-1'
41716d24.6e34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff6e790000 'C:\Program Files\NVIDIA Corporation\Ansel\NvCameraWhitelisting64.dll'
41726d24.6e34: supR3HardenedDllNotificationCallback: Unload 00007fff6e790000 LB 0x0009e000 C:\Program Files\NVIDIA Corporation\Ansel\NvCameraWhitelisting64.dll [flags=0x0]
41736d24.6e34: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\d3d9.dll
41746d24.6e34: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\d3d9.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
41756d24.6e34: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff987a0000 'C:\WINDOWS\system32\d3d9.dll'
41766d24.6dcc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\dsound.dll
41776d24.6dcc: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
41786d24.6dcc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff4da10000 'C:\WINDOWS\system32\dsound.dll'
41796d24.6dcc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\dsound.dll
41806d24.6dcc: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
41816d24.6dcc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff4da10000 'C:\WINDOWS\System32\dsound.dll'
41826d24.6dcc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa3330000 'C:\WINDOWS\System32\winmm.dll'
41836d24.6dcc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa3330000 'C:\WINDOWS\System32\winmm.dll'
41846d24.6dcc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa3330000 'C:\WINDOWS\System32\winmm.dll'
41856d24.6dcc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa3330000 'C:\WINDOWS\System32\winmm.dll'
41866d24.6dcc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa3330000 'C:\WINDOWS\System32\winmm.dll'
41876d24.6dcc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\winmm.dll
41886d24.6dcc: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\winmm.dll (Input=winmm.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
41896d24.6dcc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa3330000 'C:\WINDOWS\System32\winmm.dll'
41906d24.6dd8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
41916d24.6dd8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa5600000 'C:\WINDOWS\System32\WINTRUST.DLL'
41926d24.6dd8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\CRYPT32.dll'
41936d24.6dd8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
41946d24.6dd8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff9f4c0000 'C:\Windows\System32\cryptnet.dll'
41956d24.6dd8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
41966d24.6dd8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'rpcrt4.dll'.
41976d24.6dd8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'combase.dll'.
41986d24.6dd8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #21 'shcore.dll'.
41996d24.6dd8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #22 'textinputframework.dll'.
42006d24.6dd8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'inputhost.dll'.
42016d24.6dd8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #42 'user32.dll'.
42026d24.6dd8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\Windows.UI.dll) WinVerifyTrust
42036d24.6dd8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\Windows.UI.dll
42046d24.6dd8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
42056d24.6dd8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume8\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
42066d24.6dd8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'inputhost.dll'...
42076d24.6dd8: supR3HardenedWinVerifyCacheProcessImportTodos: 'inputhost.dll' -> '\Device\HarddiskVolume8\Windows\System32\inputhost.dll' [rcNtRedir=0xc0150008]
42086d24.6dd8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
42096d24.6dd8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
42106d24.6dd8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
42116d24.6dd8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'coremessaging.dll'.
42126d24.6dd8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #40 'coreuicomponents.dll'.
42136d24.6dd8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #44 'propsys.dll'.
42146d24.6dd8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #46 'shcore.dll'.
42156d24.6dd8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #47 'win32u.dll'.
42166d24.6dd8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #50 'combase.dll'.
42176d24.6dd8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\InputHost.dll) WinVerifyTrust
42186d24.6dd8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\InputHost.dll
42196d24.6dd8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'textinputframework.dll'...
42206d24.6dd8: supR3HardenedWinVerifyCacheProcessImportTodos: 'textinputframework.dll' -> '\Device\HarddiskVolume8\Windows\System32\textinputframework.dll' [rcNtRedir=0xc0150008]
42216d24.6dd8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\TextInputFramework.dll
42226d24.6dd8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shcore.dll'...
42236d24.6dd8: supR3HardenedWinVerifyCacheProcessImportTodos: 'shcore.dll' -> '\Device\HarddiskVolume8\Windows\System32\shcore.dll' [rcNtRedir=0xc0150008]
42246d24.6dd8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\SHCore.dll
42256d24.6dd8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
42266d24.6dd8: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume8\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
42276d24.6dd8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\combase.dll
42286d24.6dd8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
42296d24.6dd8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume8\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
42306d24.6dd8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
42316d24.6dd8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume8\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
42326d24.6dd8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
42336d24.6dd8: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume8\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
42346d24.6dd8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
42356d24.6dd8: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume8\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
42366d24.6dd8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shcore.dll'...
42376d24.6dd8: supR3HardenedWinVerifyCacheProcessImportTodos: 'shcore.dll' -> '\Device\HarddiskVolume8\Windows\System32\shcore.dll' [rcNtRedir=0xc0150008]
42386d24.6dd8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\SHCore.dll
42396d24.6dd8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'propsys.dll'...
42406d24.6dd8: supR3HardenedWinVerifyCacheProcessImportTodos: 'propsys.dll' -> '\Device\HarddiskVolume8\Windows\System32\propsys.dll' [rcNtRedir=0xc0150008]
42416d24.6dd8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa4840000 'C:\WINDOWS\system32\rsaenh.dll'
42426d24.6dd8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa6500000 'C:\WINDOWS\System32\crypt32.dll'
42436d24.6dd8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'oleaut32.dll'.
42446d24.6dd8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #33 'rpcrt4.dll'.
42456d24.6dd8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume8\Windows\System32\propsys.dll) WinVerifyTrust
42466d24.6dd8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume8\Windows\System32\propsys.dll
42476d24.6dd8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'coreuicomponents.dll'...
42486d24.6dd8: supR3HardenedWinVerifyCacheProcessImportTodos: 'coreuicomponents.dll' -> '\Device\HarddiskVolume8\Windows\System32\coreuicomponents.dll' [rcNtRedir=0xc0150008]
42496d24.6dd8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\CoreUIComponents.dll
42506d24.6dd8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'coremessaging.dll'...
42516d24.6dd8: supR3HardenedWinVerifyCacheProcessImportTodos: 'coremessaging.dll' -> '\Device\HarddiskVolume8\Windows\System32\coremessaging.dll' [rcNtRedir=0xc0150008]
42526d24.6dd8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\CoreMessaging.dll
42536d24.6dd8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
42546d24.6dd8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume8\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
42556d24.6dd8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
42566d24.6dd8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume8\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
42576d24.6dd8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
42586d24.6dd8: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume8\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
42596d24.6dd8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\Windows.UI.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
42606d24.6dd8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\Windows.UI.dll
42616d24.6dd8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\InputHost.dll
42626d24.6dd8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\propsys.dll
42636d24.6dd8: supR3HardenedDllNotificationCallback: load 00007fffa1a00000 LB 0x000f0000 C:\Windows\System32\PROPSYS.dll [fFlags=0x0]
42646d24.6dd8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\propsys.dll
42656d24.6dd8: supR3HardenedDllNotificationCallback: load 00007fff9caf0000 LB 0x0011a000 C:\Windows\System32\InputHost.dll [fFlags=0x0]
42666d24.6dd8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\InputHost.dll
42676d24.6dd8: supR3HardenedDllNotificationCallback: load 00007fff9ccd0000 LB 0x00151000 C:\Windows\System32\Windows.UI.dll [fFlags=0x0]
42686d24.6dd8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\Windows.UI.dll
42696d24.6dd8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fff9ccd0000 'C:\Windows\System32\Windows.UI.dll'
42706d24.bb70: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume8\Windows\System32\avrt.dll
42716d24.bb70: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\avrt.dll (Input=avrt.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
42726d24.bb70: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa17b0000 'C:\WINDOWS\System32\avrt.dll'
42736d24.a950: supR3HardenedDllNotificationCallback: Unload 00007fff9ccd0000 LB 0x00151000 C:\Windows\System32\Windows.UI.dll [flags=0x0]
42746d24.a950: supR3HardenedDllNotificationCallback: Unload 00007fff9caf0000 LB 0x0011a000 C:\Windows\System32\InputHost.dll [flags=0x0]
42756d24.6e38: KiUserExceptionDispatcher: 0x80000003 (0000000000000000) @ 00007fff3a25d544 (flags=0x0)
4276 rax=0000000000000001 rbx=00000000fffffffe rcx=a70afc6ec3eb0000 rdx=0000000000000000
4277 rsi=00000000094dec18 rdi=000000000b3671f0 r8 =0000000002176220 r9 =7efefefefefeff52
4278 r10=0000000000000015 r11=0000000002cf6f40 r12=00000000094debf0 r13=0000000000000000
4279 r14=0000000008b3396c r15=0000000000000000 P1=0000000000000000 P2=00007fff366d4050
4280 rip=00007fff3a25d544 rsp=000000002152fb70 rbp=0000000000000000 ctxflags=0010005f
4281 cs=0033 ss=002b ds=002b es=002b fs=0053 gs=002b eflags=00000202 mxcrx=00001f80
4282 P3=000025de153c2d8d P4=00007fff366e6b99 P5=000000002152f5e0 P6=0000000000000022
4283 dr0=0000000000000000 dr1=0000000000000000 dr2=0000000000000000 dr3=0000000000000000
4284 dr6=0000000000000000 dr7=0000000000000000 vcr=000000000000000b dcr=000000000000e000
4285 lbt=0000000000000000 lbf=0000000000000000 lxt=0000000000000000 lxf=0000000000000000
42866d24.6e38: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(ext-ms-win-kernel32-errorhandling-l1-1-0.dll) -> 0x0, fPresent=1
42876d24.6e38: supR3HardenedMonitor_LdrLoadDll: pName=ext-ms-win-kernel32-errorhandling-l1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
42886d24.6e38: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007fffa70c0000 'ext-ms-win-kernel32-errorhandling-l1-1-0.dll'
42896d10.6d14: supR3HardNtChildWaitFor[2]: Quitting: ExitCode=0x80000003 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 129182724 ms, the end);
42906cec.6cf0: supR3HardNtChildWaitFor[1]: Quitting: ExitCode=0x80000003 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 129183452 ms, the end);

© 2024 Oracle Support Privacy / Do Not Sell My Info Terms of Use Trademark Policy Automated Access Etiquette