VirtualBox

Ticket #19983: VBoxHardening.log

File VBoxHardening.log, 399.6 KB (added by sebibala, 4 years ago)
Line 
141f8.53c: Log file opened: 6.1.14r140239 g_hStartupLog=0000000000000074 g_uNtVerCombined=0xa04a6100
241f8.53c: \SystemRoot\System32\ntdll.dll:
341f8.53c: CreationTime: 2020-10-16T14:29:16.471334100Z
441f8.53c: LastWriteTime: 2020-10-16T14:29:16.554461600Z
541f8.53c: ChangeTime: 2020-10-16T16:42:14.822277800Z
641f8.53c: FileAttributes: 0x20
741f8.53c: Size: 0x1ee338
841f8.53c: NT Headers: 0xe8
941f8.53c: Timestamp: 0x5b56177b
1041f8.53c: Machine: 0x8664 - amd64
1141f8.53c: Timestamp: 0x5b56177b
1241f8.53c: Image Version: 10.0
1341f8.53c: SizeOfImage: 0x1f6000 (2056192)
1441f8.53c: Resource Dir: 0x185000 LB 0x6fd28
1541f8.53c: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
1641f8.53c: [Raw version resource data: 0x1850f0 LB 0x380, codepage 0x0 (reserved 0x0)]
1741f8.53c: ProductName: Microsoft® Windows® Operating System
1841f8.53c: ProductVersion: 10.0.19041.546
1941f8.53c: FileVersion: 10.0.19041.546 (WinBuild.160101.0800)
2041f8.53c: FileDescription: NT Layer DLL
2141f8.53c: \SystemRoot\System32\kernel32.dll:
2241f8.53c: CreationTime: 2020-10-16T14:27:33.731376800Z
2341f8.53c: LastWriteTime: 2020-10-16T14:27:33.794638400Z
2441f8.53c: ChangeTime: 2020-10-16T16:41:28.031858600Z
2541f8.53c: FileAttributes: 0x20
2641f8.53c: Size: 0xbac30
2741f8.53c: NT Headers: 0xe8
2841f8.53c: Timestamp: 0x2f7cc9b6
2941f8.53c: Machine: 0x8664 - amd64
3041f8.53c: Timestamp: 0x2f7cc9b6
3141f8.53c: Image Version: 10.0
3241f8.53c: SizeOfImage: 0xbd000 (774144)
3341f8.53c: Resource Dir: 0xbb000 LB 0x520
3441f8.53c: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
3541f8.53c: [Raw version resource data: 0xbb0b0 LB 0x3a4, codepage 0x0 (reserved 0x0)]
3641f8.53c: ProductName: Microsoft® Windows® Operating System
3741f8.53c: ProductVersion: 10.0.19041.546
3841f8.53c: FileVersion: 10.0.19041.546 (WinBuild.160101.0800)
3941f8.53c: FileDescription: Windows NT BASE API Client DLL
4041f8.53c: \SystemRoot\System32\KernelBase.dll:
4141f8.53c: CreationTime: 2020-10-16T14:29:23.002324100Z
4241f8.53c: LastWriteTime: 2020-10-16T14:29:23.180425500Z
4341f8.53c: ChangeTime: 2020-10-16T16:42:05.853240600Z
4441f8.53c: FileAttributes: 0x20
4541f8.53c: Size: 0x2c8f70
4641f8.53c: NT Headers: 0xf0
4741f8.53c: Timestamp: 0x1183946c
4841f8.53c: Machine: 0x8664 - amd64
4941f8.53c: Timestamp: 0x1183946c
5041f8.53c: Image Version: 10.0
5141f8.53c: SizeOfImage: 0x2c8000 (2916352)
5241f8.53c: Resource Dir: 0x29f000 LB 0x548
5341f8.53c: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
5441f8.53c: [Raw version resource data: 0x29f0b0 LB 0x3bc, codepage 0x0 (reserved 0x0)]
5541f8.53c: ProductName: Microsoft® Windows® Operating System
5641f8.53c: ProductVersion: 10.0.19041.572
5741f8.53c: FileVersion: 10.0.19041.572 (WinBuild.160101.0800)
5841f8.53c: FileDescription: Windows NT BASE API Client DLL
5941f8.53c: \SystemRoot\System32\apisetschema.dll:
6041f8.53c: CreationTime: 2019-12-07T09:08:13.518339400Z
6141f8.53c: LastWriteTime: 2019-12-07T09:08:13.518339400Z
6241f8.53c: ChangeTime: 2020-10-16T14:36:31.648132800Z
6341f8.53c: FileAttributes: 0x20
6441f8.53c: Size: 0x1f538
6541f8.53c: NT Headers: 0xd0
6641f8.53c: Timestamp: 0x31288ce0
6741f8.53c: Machine: 0x8664 - amd64
6841f8.53c: Timestamp: 0x31288ce0
6941f8.53c: Image Version: 10.0
7041f8.53c: SizeOfImage: 0x20000 (131072)
7141f8.53c: Resource Dir: 0x1f000 LB 0x408
7241f8.53c: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
7341f8.53c: [Raw version resource data: 0x1f060 LB 0x3a8, codepage 0x0 (reserved 0x0)]
7441f8.53c: ProductName: Microsoft® Windows® Operating System
7541f8.53c: ProductVersion: 10.0.19041.1
7641f8.53c: FileVersion: 10.0.19041.1 (WinBuild.160101.0800)
7741f8.53c: FileDescription: ApiSet Schema DLL
7841f8.53c: NtOpenDirectoryObject failed on \Driver: 0xc0000022
7941f8.53c: supR3HardenedWinFindAdversaries: 0x20
8041f8.53c: \SystemRoot\System32\drivers\cfwids.sys:
8141f8.53c: CreationTime: 2020-01-16T02:13:34.000000000Z
8241f8.53c: LastWriteTime: 2020-06-09T05:21:26.000000000Z
8341f8.53c: ChangeTime: 2020-10-10T16:02:20.624671800Z
8441f8.53c: FileAttributes: 0x20
8541f8.53c: Size: 0x127b8
8641f8.53c: NT Headers: 0xf0
8741f8.53c: Timestamp: 0x5ed009c1
8841f8.53c: Machine: 0x8664 - amd64
8941f8.53c: Timestamp: 0x5ed009c1
9041f8.53c: Image Version: 0.0
9141f8.53c: SizeOfImage: 0x14000 (81920)
9241f8.53c: Resource Dir: 0x12000 LB 0x550
9341f8.53c: [Version info resource found at 0x80! (ID/Name: 0x1; SubID/SubName: 0x409)]
9441f8.53c: [Raw version resource data: 0x120a0 LB 0x318, codepage 0x0 (reserved 0x0)]
9541f8.53c: ProductName: SYSCORE
9641f8.53c: ProductVersion: 20.6.0.142
9741f8.53c: FileVersion: SYSCORE.20.6.0.142
9841f8.53c: PrivateBuild: SYSCORE.20.6.0.142
9941f8.53c: FileDescription: McAfee Personal Firewall IDS Plugin
10041f8.53c: \SystemRoot\System32\drivers\mfeavfk.sys:
10141f8.53c: CreationTime: 2020-01-16T02:13:34.000000000Z
10241f8.53c: LastWriteTime: 2020-06-09T05:21:28.000000000Z
10341f8.53c: ChangeTime: 2020-10-10T16:02:20.249708600Z
10441f8.53c: FileAttributes: 0x20
10541f8.53c: Size: 0x5d5b8
10641f8.53c: NT Headers: 0xe8
10741f8.53c: Timestamp: 0x5ed00921
10841f8.53c: Machine: 0x8664 - amd64
10941f8.53c: Timestamp: 0x5ed00921
11041f8.53c: Image Version: 0.0
11141f8.53c: SizeOfImage: 0x5e000 (385024)
11241f8.53c: Resource Dir: 0x5c000 LB 0x758
11341f8.53c: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
11441f8.53c: [Raw version resource data: 0x5c110 LB 0x334, codepage 0x0 (reserved 0x0)]
11541f8.53c: ProductName: SYSCORE
11641f8.53c: ProductVersion: 20.6.0.142
11741f8.53c: FileVersion: SYSCORE.20.6.0.142
11841f8.53c: PrivateBuild: SYSCORE.20.6.0.142 F15,F16,F19
11941f8.53c: FileDescription: Anti-Virus File System Filter Driver
12041f8.53c: \SystemRoot\System32\drivers\mfefirek.sys:
12141f8.53c: CreationTime: 2020-01-16T02:13:34.000000000Z
12241f8.53c: LastWriteTime: 2020-06-09T05:21:26.000000000Z
12341f8.53c: ChangeTime: 2020-10-10T16:02:19.249709500Z
12441f8.53c: FileAttributes: 0x20
12541f8.53c: Size: 0x7f5b8
12641f8.53c: NT Headers: 0xe0
12741f8.53c: Timestamp: 0x5ed00994
12841f8.53c: Machine: 0x8664 - amd64
12941f8.53c: Timestamp: 0x5ed00994
13041f8.53c: Image Version: 0.0
13141f8.53c: SizeOfImage: 0x81000 (528384)
13241f8.53c: Resource Dir: 0x7d000 LB 0x388
13341f8.53c: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
13441f8.53c: [Raw version resource data: 0x7d060 LB 0x328, codepage 0x0 (reserved 0x0)]
13541f8.53c: ProductName: SYSCORE
13641f8.53c: ProductVersion: 20.6.0.142
13741f8.53c: FileVersion: SYSCORE.20.6.0.142
13841f8.53c: PrivateBuild: SYSCORE.20.6.0.142 F17,F18
13941f8.53c: FileDescription: McAfee Core Firewall Engine Driver
14041f8.53c: \SystemRoot\System32\drivers\mfehidk.sys:
14141f8.53c: CreationTime: 2020-01-16T02:13:34.000000000Z
14241f8.53c: LastWriteTime: 2020-06-09T05:21:26.000000000Z
14341f8.53c: ChangeTime: 2020-10-10T16:02:10.951327000Z
14441f8.53c: FileAttributes: 0x20
14541f8.53c: Size: 0xf59b8
14641f8.53c: NT Headers: 0x108
14741f8.53c: Timestamp: 0x5ed008d6
14841f8.53c: Machine: 0x8664 - amd64
14941f8.53c: Timestamp: 0x5ed008d6
15041f8.53c: Image Version: 0.0
15141f8.53c: SizeOfImage: 0xff000 (1044480)
15241f8.53c: Resource Dir: 0xfb000 LB 0x758
15341f8.53c: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
15441f8.53c: [Raw version resource data: 0xfb110 LB 0x320, codepage 0x0 (reserved 0x0)]
15541f8.53c: ProductName: SYSCORE
15641f8.53c: ProductVersion: 20.6.0.142
15741f8.53c: FileVersion: SYSCORE.20.6.0.142
15841f8.53c: PrivateBuild: SYSCORE.20.6.0.142 F14,F15,F16,F18,F20
15941f8.53c: FileDescription: McAfee Link Driver
16041f8.53c: \SystemRoot\System32\drivers\mfencbdc.sys:
16141f8.53c: CreationTime: 2020-06-07T18:28:40.000000000Z
16241f8.53c: LastWriteTime: 2020-06-07T18:28:40.000000000Z
16341f8.53c: ChangeTime: 2020-10-10T16:02:52.007548200Z
16441f8.53c: FileAttributes: 0x20
16541f8.53c: Size: 0x917b8
16641f8.53c: NT Headers: 0xe0
16741f8.53c: Timestamp: 0x5ed7c9d8
16841f8.53c: Machine: 0x8664 - amd64
16941f8.53c: Timestamp: 0x5ed7c9d8
17041f8.53c: Image Version: 0.0
17141f8.53c: SizeOfImage: 0x95000 (610304)
17241f8.53c: Resource Dir: 0x93000 LB 0x458
17341f8.53c: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
17441f8.53c: [Raw version resource data: 0x93060 LB 0x3f4, codepage 0x0 (reserved 0x0)]
17541f8.53c: ProductName: Anti-Malware Core
17641f8.53c: ProductVersion: 20.6.0
17741f8.53c: FileVersion: Anti-Malware Core.20.6.0.189.x64
17841f8.53c: PrivateBuild: Anti-Malware Core.20.6.0.189.x64
17941f8.53c: FileDescription: Event Driver
18041f8.53c: \SystemRoot\System32\drivers\mfewfpk.sys:
18141f8.53c: CreationTime: 2020-01-16T02:13:34.000000000Z
18241f8.53c: LastWriteTime: 2020-06-09T05:21:28.000000000Z
18341f8.53c: ChangeTime: 2020-10-10T16:01:10.442385300Z
18441f8.53c: FileAttributes: 0x20
18541f8.53c: Size: 0x3d9b8
18641f8.53c: NT Headers: 0xf0
18741f8.53c: Timestamp: 0x5ed008e8
18841f8.53c: Machine: 0x8664 - amd64
18941f8.53c: Timestamp: 0x5ed008e8
19041f8.53c: Image Version: 0.0
19141f8.53c: SizeOfImage: 0x59000 (364544)
19241f8.53c: Resource Dir: 0x57000 LB 0x380
19341f8.53c: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
19441f8.53c: [Raw version resource data: 0x57060 LB 0x320, codepage 0x0 (reserved 0x0)]
19541f8.53c: ProductName: SYSCORE
19641f8.53c: ProductVersion: 20.6.0.142
19741f8.53c: FileVersion: SYSCORE.20.6.0.142
19841f8.53c: PrivateBuild: SYSCORE.20.6.0.142 F17,F18
19941f8.53c: FileDescription: Anti-Virus Mini-Firewall Driver
20041f8.53c: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume4\virtualbox'
20141f8.53c: Calling main()
20241f8.53c: SUPR3HardenedMain: pszProgName=VirtualBoxVM fFlags=0x2
20341f8.53c: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume4\virtualbox'
20441f8.53c: SUPR3HardenedMain: Respawn #1
20541f8.53c: System32: \Device\HarddiskVolume3\Windows\System32
20641f8.53c: WinSxS: \Device\HarddiskVolume3\Windows\WinSxS
20741f8.53c: KnownDllPath: C:\Windows\System32
20841f8.53c: supR3HardenedWinInit: Performing a limited self purification...
20941f8.53c: supHardNtVpScanVirtualMemory: enmKind=SELF_PURIFICATION
21041f8.53c: *0000000000000000-00000000001fffff 0x0001/0x0000 0x0000000
21141f8.53c: *0000000000200000-0000000000237fff 0x0000/0x0004 0x0020000
21241f8.53c: 0000000000238000-000000000023afff 0x0004/0x0004 0x0020000
21341f8.53c: 000000000023b000-00000000003fffff 0x0000/0x0004 0x0020000
21441f8.53c: *0000000000400000-000000000040ffff 0x0004/0x0004 0x0040000
21541f8.53c: 0000000000410000-000000000041ffff 0x0001/0x0000 0x0000000
21641f8.53c: *0000000000420000-000000000043cfff 0x0002/0x0002 0x0040000
21741f8.53c: 000000000043d000-000000000043ffff 0x0001/0x0000 0x0000000
21841f8.53c: *0000000000440000-00000000004f0fff 0x0000/0x0004 0x0020000
21941f8.53c: 00000000004f1000-00000000004f3fff 0x0104/0x0004 0x0020000
22041f8.53c: 00000000004f4000-000000000053ffff 0x0004/0x0004 0x0020000
22141f8.53c: *0000000000540000-0000000000543fff 0x0002/0x0002 0x0040000
22241f8.53c: 0000000000544000-000000000054ffff 0x0001/0x0000 0x0000000
22341f8.53c: *0000000000550000-0000000000551fff 0x0004/0x0004 0x0020000
22441f8.53c: 0000000000552000-000000000055ffff 0x0001/0x0000 0x0000000
22541f8.53c: *0000000000560000-0000000000561fff 0x0004/0x0004 0x0020000
22641f8.53c: 0000000000562000-0000000000591fff 0x0000/0x0004 0x0020000
22741f8.53c: 0000000000592000-00000000005bffff 0x0001/0x0000 0x0000000
22841f8.53c: *00000000005c0000-00000000005c4fff 0x0004/0x0004 0x0020000
22941f8.53c: 00000000005c5000-00000000006bffff 0x0000/0x0004 0x0020000
23041f8.53c: *00000000006c0000-0000000000788fff 0x0002/0x0002 0x0040000
23141f8.53c: 0000000000789000-000000000083ffff 0x0001/0x0000 0x0000000
23241f8.53c: *0000000000840000-000000000084efff 0x0004/0x0004 0x0020000
23341f8.53c: 000000000084f000-000000000084ffff 0x0000/0x0004 0x0020000
23441f8.53c: *0000000000850000-0000000000859fff 0x0000/0x0004 0x0020000
23541f8.53c: 000000000085a000-0000000000a50fff 0x0004/0x0004 0x0020000
23641f8.53c: 0000000000a51000-0000000000a51fff 0x0000/0x0004 0x0020000
23741f8.53c: 0000000000a52000-0000000000a5ffff 0x0001/0x0000 0x0000000
23841f8.53c: *0000000000a60000-0000000000a7cfff 0x0004/0x0004 0x0020000
23941f8.53c: 0000000000a7d000-0000000000b5ffff 0x0000/0x0004 0x0020000
24041f8.53c: 0000000000b60000-000000007ffdffff 0x0001/0x0000 0x0000000
24141f8.53c: *000000007ffe0000-000000007ffe0fff 0x0002/0x0002 0x0020000
24241f8.53c: 000000007ffe1000-000000007ffe6fff 0x0001/0x0000 0x0000000
24341f8.53c: *000000007ffe7000-000000007ffe7fff 0x0002/0x0002 0x0020000
24441f8.53c: 000000007ffe8000-00007ff4548cffff 0x0001/0x0000 0x0000000
24541f8.53c: *00007ff4548d0000-00007ff4548d4fff 0x0002/0x0002 0x0040000
24641f8.53c: 00007ff4548d5000-00007ff4549cffff 0x0000/0x0002 0x0040000
24741f8.53c: *00007ff4549d0000-00007ff5549effff 0x0000/0x0004 0x0020000
24841f8.53c: *00007ff5549f0000-00007ff5569effff 0x0000/0x0004 0x0020000
24941f8.53c: 00007ff5569f0000-00007ff5569f0fff 0x0004/0x0004 0x0020000
25041f8.53c: 00007ff5569f1000-00007ff5569fffff 0x0001/0x0000 0x0000000
25141f8.53c: *00007ff556a00000-00007ff556a00fff 0x0002/0x0002 0x0040000
25241f8.53c: 00007ff556a01000-00007ff556a0ffff 0x0001/0x0000 0x0000000
25341f8.53c: *00007ff556a10000-00007ff556a32fff 0x0002/0x0002 0x0040000
25441f8.53c: 00007ff556a33000-00007ff655a1ffff 0x0001/0x0000 0x0000000
25541f8.53c: *00007ff655a20000-00007ff655a20fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\virtualbox\VirtualBoxVM.exe
25641f8.53c: 00007ff655a21000-00007ff655a96fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume4\virtualbox\VirtualBoxVM.exe
25741f8.53c: 00007ff655a97000-00007ff655a97fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume4\virtualbox\VirtualBoxVM.exe
25841f8.53c: 00007ff655a98000-00007ff655adffff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\virtualbox\VirtualBoxVM.exe
25941f8.53c: 00007ff655ae0000-00007ff655ae2fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\virtualbox\VirtualBoxVM.exe
26041f8.53c: 00007ff655ae3000-00007ff655ae5fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\virtualbox\VirtualBoxVM.exe
26141f8.53c: 00007ff655ae6000-00007ff655ae8fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\virtualbox\VirtualBoxVM.exe
26241f8.53c: 00007ff655ae9000-00007ff655ae9fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\virtualbox\VirtualBoxVM.exe
26341f8.53c: 00007ff655aea000-00007ff655aebfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\virtualbox\VirtualBoxVM.exe
26441f8.53c: 00007ff655aec000-00007ff655aecfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\virtualbox\VirtualBoxVM.exe
26541f8.53c: 00007ff655aed000-00007ff655b35fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\virtualbox\VirtualBoxVM.exe
26641f8.53c: 00007ff655b36000-00007ffaa9a7ffff 0x0001/0x0000 0x0000000
26741f8.53c: *00007ffaa9a80000-00007ffaa9a80fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\KernelBase.dll
26841f8.53c: 00007ffaa9a81000-00007ffaa9b91fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\KernelBase.dll
26941f8.53c: 00007ffaa9b92000-00007ffaa9d09fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\KernelBase.dll
27041f8.53c: 00007ffaa9d0a000-00007ffaa9d0dfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\KernelBase.dll
27141f8.53c: 00007ffaa9d0e000-00007ffaa9d0efff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\KernelBase.dll
27241f8.53c: 00007ffaa9d0f000-00007ffaa9d47fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\KernelBase.dll
27341f8.53c: 00007ffaa9d48000-00007ffaaab7ffff 0x0001/0x0000 0x0000000
27441f8.53c: *00007ffaaab80000-00007ffaaab80fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\kernel32.dll
27541f8.53c: 00007ffaaab81000-00007ffaaabfefff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\kernel32.dll
27641f8.53c: 00007ffaaabff000-00007ffaaac31fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\kernel32.dll
27741f8.53c: 00007ffaaac32000-00007ffaaac32fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\kernel32.dll
27841f8.53c: 00007ffaaac33000-00007ffaaac33fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\kernel32.dll
27941f8.53c: 00007ffaaac34000-00007ffaaac3cfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\kernel32.dll
28041f8.53c: 00007ffaaac3d000-00007ffaabfaffff 0x0001/0x0000 0x0000000
28141f8.53c: *00007ffaabfb0000-00007ffaabfb0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
28241f8.53c: 00007ffaabfb1000-00007ffaac0cbfff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
28341f8.53c: 00007ffaac0cc000-00007ffaac114fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
28441f8.53c: 00007ffaac115000-00007ffaac115fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
28541f8.53c: 00007ffaac116000-00007ffaac117fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
28641f8.53c: 00007ffaac118000-00007ffaac120fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
28741f8.53c: 00007ffaac121000-00007ffaac1a5fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
28841f8.53c: 00007ffaac1a6000-00007ffffffeffff 0x0001/0x0000 0x0000000
28941f8.53c: kernel32.dll: timestamp 0x2f7cc9b6 (rc=VINF_SUCCESS)
29041f8.53c: kernelbase.dll: timestamp 0x1183946c (rc=VINF_SUCCESS)
29141f8.53c: VirtualBoxVM.exe: timestamp 0x5f51ed66 (rc=VINF_SUCCESS)
29241f8.53c: '\Device\HarddiskVolume4\virtualbox\VirtualBoxVM.exe' has no imports
29341f8.53c: '\Device\HarddiskVolume3\Windows\System32\ntdll.dll' has no imports
29441f8.53c: supR3HardenedWinInit: SUPHARDNTVPKIND_SELF_PURIFICATION_LIMITED -> VINF_SUCCESS, cFixes=0
29541f8.53c: '\Device\HarddiskVolume4\virtualbox\VirtualBoxVM.exe' has no imports
29641f8.53c: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume4\virtualbox\VirtualBoxVM.exe)
29741f8.53c: supR3HardNtEnableThreadCreationEx:
29841f8.53c: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffaac024750 pvNtTerminateThread=00007ffaac04c7e0
29941f8.53c: supR3HardenedWinDoReSpawn(1): New child 2144.38f4 [kernel32].
30041f8.53c: supR3HardNtChildGatherData: PebBaseAddress=0000000000516000 cbPeb=0x388
30141f8.53c: supR3HardNtPuChFindNtdll: uNtDllParentAddr=00007ffaabfb0000 uNtDllChildAddr=00007ffaabfb0000
30241f8.53c: supR3HardenedWinSetupChildInit: uLdrInitThunk=00007ffaac024750
30341f8.53c: supR3HardenedWinSetupChildInit: Initial context:
304 rax=0000000000000000 rbx=0000000000000000 rcx=00007ff655a27900 rdx=0000000000516000
305 rsi=0000000000000000 rdi=0000000000000000 r8 =0000000000000000 r9 =0000000000000000
306 r10=0000000000000000 r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
307 r14=0000000000000000 r15=0000000000000000 P1=0000000000000000 P2=0000000000000000
308 rip=00007ffaabffcea0 rsp=000000000035fc68 rbp=0000000000000000 ctxflags=0010001b
309 cs=0033 ss=002b ds=0000 es=0000 fs=0000 gs=0000 eflags=00000200 mxcrx=00001f80
310 P3=0000000000000000 P4=0000000000000000 P5=0000000000000000 P6=0000000000000000
311 dr0=0000000000000000 dr1=0000000000000000 dr2=0000000000000000 dr3=0000000000000000
312 dr6=0000000000000000 dr7=0000000000000000 vcr=0000000000000000 dcr=0000000000000000
313 lbt=0000000000000000 lbf=0000000000000000 lxt=0000000000000000 lxf=0000000000000000
31441f8.53c: supR3HardenedWinSetupChildInit: Start child.
31541f8.53c: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
31641f8.53c: supR3HardNtChildPurify: Startup delay kludge #1/0: 524 ms, 33 sleeps
31741f8.53c: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
31841f8.53c: *0000000000000000-000000000021ffff 0x0001/0x0000 0x0000000
31941f8.53c: *0000000000220000-000000000023ffff 0x0004/0x0004 0x0020000
32041f8.53c: *0000000000240000-000000000025cfff 0x0002/0x0002 0x0040000
32141f8.53c: 000000000025d000-000000000025ffff 0x0001/0x0000 0x0000000
32241f8.53c: *0000000000260000-000000000035afff 0x0000/0x0004 0x0020000
32341f8.53c: 000000000035b000-000000000035dfff 0x0104/0x0004 0x0020000
32441f8.53c: 000000000035e000-000000000035ffff 0x0004/0x0004 0x0020000
32541f8.53c: *0000000000360000-0000000000363fff 0x0002/0x0002 0x0040000
32641f8.53c: 0000000000364000-000000000036ffff 0x0001/0x0000 0x0000000
32741f8.53c: *0000000000370000-0000000000371fff 0x0004/0x0004 0x0020000
32841f8.53c: 0000000000372000-00000000003fffff 0x0001/0x0000 0x0000000
32941f8.53c: *0000000000400000-0000000000515fff 0x0000/0x0004 0x0020000
33041f8.53c: 0000000000516000-0000000000518fff 0x0004/0x0004 0x0020000
33141f8.53c: 0000000000519000-00000000005fffff 0x0000/0x0004 0x0020000
33241f8.53c: 0000000000600000-000000007ffdffff 0x0001/0x0000 0x0000000
33341f8.53c: *000000007ffe0000-000000007ffe0fff 0x0002/0x0002 0x0020000
33441f8.53c: 000000007ffe1000-000000007ffe6fff 0x0001/0x0000 0x0000000
33541f8.53c: *000000007ffe7000-000000007ffe7fff 0x0002/0x0002 0x0020000
33641f8.53c: 000000007ffe8000-00007ff5bf6fffff 0x0001/0x0000 0x0000000
33741f8.53c: *00007ff5bf700000-00007ff5bf700fff 0x0002/0x0002 0x0040000
33841f8.53c: 00007ff5bf701000-00007ff5bf70ffff 0x0001/0x0000 0x0000000
33941f8.53c: *00007ff5bf710000-00007ff5bf732fff 0x0002/0x0002 0x0040000
34041f8.53c: 00007ff5bf733000-00007ff655a1ffff 0x0001/0x0000 0x0000000
34141f8.53c: *00007ff655a20000-00007ff655a20fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\virtualbox\VirtualBoxVM.exe
34241f8.53c: 00007ff655a21000-00007ff655a96fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume4\virtualbox\VirtualBoxVM.exe
34341f8.53c: 00007ff655a97000-00007ff655a97fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume4\virtualbox\VirtualBoxVM.exe
34441f8.53c: 00007ff655a98000-00007ff655adffff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\virtualbox\VirtualBoxVM.exe
34541f8.53c: 00007ff655ae0000-00007ff655ae0fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\virtualbox\VirtualBoxVM.exe
34641f8.53c: 00007ff655ae1000-00007ff655ae1fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\virtualbox\VirtualBoxVM.exe
34741f8.53c: 00007ff655ae2000-00007ff655ae6fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\virtualbox\VirtualBoxVM.exe
34841f8.53c: 00007ff655ae7000-00007ff655ae7fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\virtualbox\VirtualBoxVM.exe
34941f8.53c: 00007ff655ae8000-00007ff655ae8fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\virtualbox\VirtualBoxVM.exe
35041f8.53c: 00007ff655ae9000-00007ff655aecfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\virtualbox\VirtualBoxVM.exe
35141f8.53c: 00007ff655aed000-00007ff655b35fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\virtualbox\VirtualBoxVM.exe
35241f8.53c: 00007ff655b36000-00007ffaabfaffff 0x0001/0x0000 0x0000000
35341f8.53c: *00007ffaabfb0000-00007ffaabfb0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
35441f8.53c: 00007ffaabfb1000-00007ffaac0cbfff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
35541f8.53c: 00007ffaac0cc000-00007ffaac114fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
35641f8.53c: 00007ffaac115000-00007ffaac120fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
35741f8.53c: 00007ffaac121000-00007ffaac12ffff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
35841f8.53c: 00007ffaac130000-00007ffaac130fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
35941f8.53c: 00007ffaac131000-00007ffaac133fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
36041f8.53c: 00007ffaac134000-00007ffaac1a5fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
36141f8.53c: 00007ffaac1a6000-00007ffffffeffff 0x0001/0x0000 0x0000000
36241f8.53c: supR3HardNtChildPurify: Done after 524 ms and 0 fixes (loop #0).
3632144.38f4: Log file opened: 6.1.14r140239 g_hStartupLog=0000000000000004 g_uNtVerCombined=0xa04a6100
3642144.38f4: supR3HardenedVmProcessInit: uNtDllAddr=00007ffaabfb0000 g_uNtVerCombined=0xa04a6100 (stack ~000000000035f6f8)
3652144.38f4: ntdll.dll: timestamp 0x5b56177b (rc=VINF_SUCCESS)
3662144.38f4: New simple heap: #1 0000000000700000 LB 0x400000 (for 2056192 allocation)
36741f8.53c: supR3HardNtEnableThreadCreationEx:
3682144.38f4: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume4\virtualbox'
3692144.38f4: System32: \Device\HarddiskVolume3\Windows\System32
3702144.38f4: WinSxS: \Device\HarddiskVolume3\Windows\WinSxS
3712144.38f4: KnownDllPath: C:\Windows\System32
3722144.38f4: supR3HardenedVmProcessInit: Opening vboxdrv stub...
3732144.38f4: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
3742144.38f4: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
3752144.38f4: Registered Dll notification callback with NTDLL.
3762144.38f4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\kernel32.dll)
3772144.38f4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\kernel32.dll
3782144.38f4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\KERNEL32.DLL (Input=KERNEL32.DLL, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000004001:<flags> [calling]
3792144.38f4: supR3HardenedDllNotificationCallback: load 00007ffaa9a80000 LB 0x002c8000 C:\Windows\System32\KERNELBASE.dll [fFlags=0x0]
3802144.38f4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\KernelBase.dll)
3812144.38f4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\KernelBase.dll
3822144.38f4: supR3HardenedDllNotificationCallback: load 00007ffaaab80000 LB 0x000bd000 C:\Windows\System32\KERNEL32.DLL [fFlags=0x0]
3832144.38f4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
3842144.38f4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaaab80000 'C:\Windows\System32\KERNEL32.DLL'
3852144.38f4: supR3HardenedDllNotificationCallback: load 00007ff655a20000 LB 0x00116000 F:\virtualbox\VirtualBoxVM.exe [fFlags=0x0]
3862144.38f4: '\Device\HarddiskVolume4\virtualbox\VirtualBoxVM.exe' has no imports
3872144.38f4: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume4\virtualbox\VirtualBoxVM.exe)
3882144.38f4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\virtualbox\VirtualBoxVM.exe
3892144.38f4: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffaac024750 pvNtTerminateThread=00007ffaac04c7e0
39041f8.53c: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 79 ms.
3912144.38f4: \SystemRoot\System32\ntdll.dll:
3922144.38f4: CreationTime: 2020-10-16T14:29:16.471334100Z
3932144.38f4: LastWriteTime: 2020-10-16T14:29:16.554461600Z
3942144.38f4: ChangeTime: 2020-10-16T16:42:14.822277800Z
3952144.38f4: FileAttributes: 0x20
3962144.38f4: Size: 0x1ee338
3972144.38f4: NT Headers: 0xe8
3982144.38f4: Timestamp: 0x5b56177b
3992144.38f4: Machine: 0x8664 - amd64
4002144.38f4: Timestamp: 0x5b56177b
4012144.38f4: Image Version: 10.0
4022144.38f4: SizeOfImage: 0x1f6000 (2056192)
4032144.38f4: Resource Dir: 0x185000 LB 0x6fd28
4042144.38f4: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
4052144.38f4: [Raw version resource data: 0x1850f0 LB 0x380, codepage 0x0 (reserved 0x0)]
4062144.38f4: ProductName: Microsoft® Windows® Operating System
4072144.38f4: ProductVersion: 10.0.19041.546
4082144.38f4: FileVersion: 10.0.19041.546 (WinBuild.160101.0800)
4092144.38f4: FileDescription: NT Layer DLL
4102144.38f4: \SystemRoot\System32\kernel32.dll:
4112144.38f4: CreationTime: 2020-10-16T14:27:33.731376800Z
4122144.38f4: LastWriteTime: 2020-10-16T14:27:33.794638400Z
4132144.38f4: ChangeTime: 2020-10-16T16:41:28.031858600Z
4142144.38f4: FileAttributes: 0x20
4152144.38f4: Size: 0xbac30
4162144.38f4: NT Headers: 0xe8
4172144.38f4: Timestamp: 0x2f7cc9b6
4182144.38f4: Machine: 0x8664 - amd64
4192144.38f4: Timestamp: 0x2f7cc9b6
4202144.38f4: Image Version: 10.0
4212144.38f4: SizeOfImage: 0xbd000 (774144)
4222144.38f4: Resource Dir: 0xbb000 LB 0x520
4232144.38f4: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
4242144.38f4: [Raw version resource data: 0xbb0b0 LB 0x3a4, codepage 0x0 (reserved 0x0)]
4252144.38f4: ProductName: Microsoft® Windows® Operating System
4262144.38f4: ProductVersion: 10.0.19041.546
4272144.38f4: FileVersion: 10.0.19041.546 (WinBuild.160101.0800)
4282144.38f4: FileDescription: Windows NT BASE API Client DLL
4292144.38f4: \SystemRoot\System32\KernelBase.dll:
4302144.38f4: CreationTime: 2020-10-16T14:29:23.002324100Z
4312144.38f4: LastWriteTime: 2020-10-16T14:29:23.180425500Z
4322144.38f4: ChangeTime: 2020-10-16T16:42:05.853240600Z
4332144.38f4: FileAttributes: 0x20
4342144.38f4: Size: 0x2c8f70
4352144.38f4: NT Headers: 0xf0
4362144.38f4: Timestamp: 0x1183946c
4372144.38f4: Machine: 0x8664 - amd64
4382144.38f4: Timestamp: 0x1183946c
4392144.38f4: Image Version: 10.0
4402144.38f4: SizeOfImage: 0x2c8000 (2916352)
4412144.38f4: Resource Dir: 0x29f000 LB 0x548
4422144.38f4: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
4432144.38f4: [Raw version resource data: 0x29f0b0 LB 0x3bc, codepage 0x0 (reserved 0x0)]
4442144.38f4: ProductName: Microsoft® Windows® Operating System
4452144.38f4: ProductVersion: 10.0.19041.572
4462144.38f4: FileVersion: 10.0.19041.572 (WinBuild.160101.0800)
4472144.38f4: FileDescription: Windows NT BASE API Client DLL
4482144.38f4: \SystemRoot\System32\apisetschema.dll:
4492144.38f4: CreationTime: 2019-12-07T09:08:13.518339400Z
4502144.38f4: LastWriteTime: 2019-12-07T09:08:13.518339400Z
4512144.38f4: ChangeTime: 2020-10-16T14:36:31.648132800Z
4522144.38f4: FileAttributes: 0x20
4532144.38f4: Size: 0x1f538
4542144.38f4: NT Headers: 0xd0
4552144.38f4: Timestamp: 0x31288ce0
4562144.38f4: Machine: 0x8664 - amd64
4572144.38f4: Timestamp: 0x31288ce0
4582144.38f4: Image Version: 10.0
4592144.38f4: SizeOfImage: 0x20000 (131072)
4602144.38f4: Resource Dir: 0x1f000 LB 0x408
4612144.38f4: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
4622144.38f4: [Raw version resource data: 0x1f060 LB 0x3a8, codepage 0x0 (reserved 0x0)]
4632144.38f4: ProductName: Microsoft® Windows® Operating System
4642144.38f4: ProductVersion: 10.0.19041.1
4652144.38f4: FileVersion: 10.0.19041.1 (WinBuild.160101.0800)
4662144.38f4: FileDescription: ApiSet Schema DLL
4672144.38f4: NtOpenDirectoryObject failed on \Driver: 0xc0000022
4682144.38f4: supR3HardenedWinFindAdversaries: 0x20
4692144.38f4: \SystemRoot\System32\drivers\cfwids.sys:
4702144.38f4: CreationTime: 2020-01-16T02:13:34.000000000Z
4712144.38f4: LastWriteTime: 2020-06-09T05:21:26.000000000Z
4722144.38f4: ChangeTime: 2020-10-10T16:02:20.624671800Z
4732144.38f4: FileAttributes: 0x20
4742144.38f4: Size: 0x127b8
4752144.38f4: NT Headers: 0xf0
4762144.38f4: Timestamp: 0x5ed009c1
4772144.38f4: Machine: 0x8664 - amd64
4782144.38f4: Timestamp: 0x5ed009c1
4792144.38f4: Image Version: 0.0
4802144.38f4: SizeOfImage: 0x14000 (81920)
4812144.38f4: Resource Dir: 0x12000 LB 0x550
4822144.38f4: [Version info resource found at 0x80! (ID/Name: 0x1; SubID/SubName: 0x409)]
4832144.38f4: [Raw version resource data: 0x120a0 LB 0x318, codepage 0x0 (reserved 0x0)]
4842144.38f4: ProductName: SYSCORE
4852144.38f4: ProductVersion: 20.6.0.142
4862144.38f4: FileVersion: SYSCORE.20.6.0.142
4872144.38f4: PrivateBuild: SYSCORE.20.6.0.142
4882144.38f4: FileDescription: McAfee Personal Firewall IDS Plugin
4892144.38f4: \SystemRoot\System32\drivers\mfeavfk.sys:
4902144.38f4: CreationTime: 2020-01-16T02:13:34.000000000Z
4912144.38f4: LastWriteTime: 2020-06-09T05:21:28.000000000Z
4922144.38f4: ChangeTime: 2020-10-10T16:02:20.249708600Z
4932144.38f4: FileAttributes: 0x20
4942144.38f4: Size: 0x5d5b8
4952144.38f4: NT Headers: 0xe8
4962144.38f4: Timestamp: 0x5ed00921
4972144.38f4: Machine: 0x8664 - amd64
4982144.38f4: Timestamp: 0x5ed00921
4992144.38f4: Image Version: 0.0
5002144.38f4: SizeOfImage: 0x5e000 (385024)
5012144.38f4: Resource Dir: 0x5c000 LB 0x758
5022144.38f4: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
5032144.38f4: [Raw version resource data: 0x5c110 LB 0x334, codepage 0x0 (reserved 0x0)]
5042144.38f4: ProductName: SYSCORE
5052144.38f4: ProductVersion: 20.6.0.142
5062144.38f4: FileVersion: SYSCORE.20.6.0.142
5072144.38f4: PrivateBuild: SYSCORE.20.6.0.142 F15,F16,F19
5082144.38f4: FileDescription: Anti-Virus File System Filter Driver
5092144.38f4: \SystemRoot\System32\drivers\mfefirek.sys:
5102144.38f4: CreationTime: 2020-01-16T02:13:34.000000000Z
5112144.38f4: LastWriteTime: 2020-06-09T05:21:26.000000000Z
5122144.38f4: ChangeTime: 2020-10-10T16:02:19.249709500Z
5132144.38f4: FileAttributes: 0x20
5142144.38f4: Size: 0x7f5b8
5152144.38f4: NT Headers: 0xe0
5162144.38f4: Timestamp: 0x5ed00994
5172144.38f4: Machine: 0x8664 - amd64
5182144.38f4: Timestamp: 0x5ed00994
5192144.38f4: Image Version: 0.0
5202144.38f4: SizeOfImage: 0x81000 (528384)
5212144.38f4: Resource Dir: 0x7d000 LB 0x388
5222144.38f4: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
5232144.38f4: [Raw version resource data: 0x7d060 LB 0x328, codepage 0x0 (reserved 0x0)]
5242144.38f4: ProductName: SYSCORE
5252144.38f4: ProductVersion: 20.6.0.142
5262144.38f4: FileVersion: SYSCORE.20.6.0.142
5272144.38f4: PrivateBuild: SYSCORE.20.6.0.142 F17,F18
5282144.38f4: FileDescription: McAfee Core Firewall Engine Driver
5292144.38f4: \SystemRoot\System32\drivers\mfehidk.sys:
5302144.38f4: CreationTime: 2020-01-16T02:13:34.000000000Z
5312144.38f4: LastWriteTime: 2020-06-09T05:21:26.000000000Z
5322144.38f4: ChangeTime: 2020-10-10T16:02:10.951327000Z
5332144.38f4: FileAttributes: 0x20
5342144.38f4: Size: 0xf59b8
5352144.38f4: NT Headers: 0x108
5362144.38f4: Timestamp: 0x5ed008d6
5372144.38f4: Machine: 0x8664 - amd64
5382144.38f4: Timestamp: 0x5ed008d6
5392144.38f4: Image Version: 0.0
5402144.38f4: SizeOfImage: 0xff000 (1044480)
5412144.38f4: Resource Dir: 0xfb000 LB 0x758
5422144.38f4: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
5432144.38f4: [Raw version resource data: 0xfb110 LB 0x320, codepage 0x0 (reserved 0x0)]
5442144.38f4: ProductName: SYSCORE
5452144.38f4: ProductVersion: 20.6.0.142
5462144.38f4: FileVersion: SYSCORE.20.6.0.142
5472144.38f4: PrivateBuild: SYSCORE.20.6.0.142 F14,F15,F16,F18,F20
5482144.38f4: FileDescription: McAfee Link Driver
5492144.38f4: \SystemRoot\System32\drivers\mfencbdc.sys:
5502144.38f4: CreationTime: 2020-06-07T18:28:40.000000000Z
5512144.38f4: LastWriteTime: 2020-06-07T18:28:40.000000000Z
5522144.38f4: ChangeTime: 2020-10-10T16:02:52.007548200Z
5532144.38f4: FileAttributes: 0x20
5542144.38f4: Size: 0x917b8
5552144.38f4: NT Headers: 0xe0
5562144.38f4: Timestamp: 0x5ed7c9d8
5572144.38f4: Machine: 0x8664 - amd64
5582144.38f4: Timestamp: 0x5ed7c9d8
5592144.38f4: Image Version: 0.0
5602144.38f4: SizeOfImage: 0x95000 (610304)
5612144.38f4: Resource Dir: 0x93000 LB 0x458
5622144.38f4: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
5632144.38f4: [Raw version resource data: 0x93060 LB 0x3f4, codepage 0x0 (reserved 0x0)]
5642144.38f4: ProductName: Anti-Malware Core
5652144.38f4: ProductVersion: 20.6.0
5662144.38f4: FileVersion: Anti-Malware Core.20.6.0.189.x64
5672144.38f4: PrivateBuild: Anti-Malware Core.20.6.0.189.x64
5682144.38f4: FileDescription: Event Driver
5692144.38f4: \SystemRoot\System32\drivers\mfewfpk.sys:
5702144.38f4: CreationTime: 2020-01-16T02:13:34.000000000Z
5712144.38f4: LastWriteTime: 2020-06-09T05:21:28.000000000Z
5722144.38f4: ChangeTime: 2020-10-10T16:01:10.442385300Z
5732144.38f4: FileAttributes: 0x20
5742144.38f4: Size: 0x3d9b8
5752144.38f4: NT Headers: 0xf0
5762144.38f4: Timestamp: 0x5ed008e8
5772144.38f4: Machine: 0x8664 - amd64
5782144.38f4: Timestamp: 0x5ed008e8
5792144.38f4: Image Version: 0.0
5802144.38f4: SizeOfImage: 0x59000 (364544)
5812144.38f4: Resource Dir: 0x57000 LB 0x380
5822144.38f4: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
5832144.38f4: [Raw version resource data: 0x57060 LB 0x320, codepage 0x0 (reserved 0x0)]
5842144.38f4: ProductName: SYSCORE
5852144.38f4: ProductVersion: 20.6.0.142
5862144.38f4: FileVersion: SYSCORE.20.6.0.142
5872144.38f4: PrivateBuild: SYSCORE.20.6.0.142 F17,F18
5882144.38f4: FileDescription: Anti-Virus Mini-Firewall Driver
5892144.38f4: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume4\virtualbox'
5902144.38f4: Calling main()
5912144.38f4: SUPR3HardenedMain: pszProgName=VirtualBoxVM fFlags=0x2
5922144.38f4: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume4\virtualbox'
5932144.38f4: '\Device\HarddiskVolume4\virtualbox\VirtualBoxVM.exe' has no imports
5942144.38f4: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume4\virtualbox\VirtualBoxVM.exe)
5952144.38f4: SUPR3HardenedMain: Respawn #2
5962144.38f4: supR3HardNtEnableThreadCreationEx:
5972144.38f4: supR3HardenedDllNotificationCallback: load 00007ffaaa190000 LB 0x00124000 C:\Windows\System32\RPCRT4.dll [fFlags=0x0]
5982144.38f4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll)
5992144.38f4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll
6002144.38f4: supR3HardenedDllNotificationCallback: load 00007ffaaa0f0000 LB 0x0009b000 C:\Windows\System32\sechost.dll [fFlags=0x0]
6012144.38f4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'rpcrt4.dll'.
6022144.38f4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\sechost.dll)
6032144.38f4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\sechost.dll
6042144.38f4: '\Device\HarddiskVolume3\Windows\System32\ntdll.dll' has no imports
6052144.38f4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\ntdll.dll)
6062144.38f4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\ntdll.dll
6072144.38f4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
6082144.38f4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
6092144.38f4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
6102144.38f4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\ntdll.dll (Input=ntdll.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
6112144.38f4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaabfb0000 'C:\Windows\System32\ntdll.dll'
6122144.38f4: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffaac024750 pvNtTerminateThread=00007ffaac04c7e0
6132144.38f4: supR3HardenedWinDoReSpawn(2): New child 4074.33d4 [kernel32].
6142144.38f4: supR3HardenedWinReSpawn: NtSetInformationThread/ThreadHideFromDebugger failed: 0xc0000022 (harmless)
6152144.38f4: supR3HardNtChildGatherData: PebBaseAddress=0000000000434000 cbPeb=0x388
6162144.38f4: supR3HardNtPuChFindNtdll: uNtDllParentAddr=00007ffaabfb0000 uNtDllChildAddr=00007ffaabfb0000
6172144.38f4: supR3HardenedWinSetupChildInit: uLdrInitThunk=00007ffaac024750
6182144.38f4: supR3HardenedWinSetupChildInit: Initial context:
619 rax=0000000000000000 rbx=0000000000000000 rcx=00007ff655a27900 rdx=0000000000434000
620 rsi=0000000000000000 rdi=0000000000000000 r8 =0000000000000000 r9 =0000000000000000
621 r10=0000000000000000 r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
622 r14=0000000000000000 r15=0000000000000000 P1=0000000000000000 P2=0000000000000000
623 rip=00007ffaabffcea0 rsp=00000000003dfc18 rbp=0000000000000000 ctxflags=0010001b
624 cs=0033 ss=002b ds=0000 es=0000 fs=0000 gs=0000 eflags=00000200 mxcrx=00001f80
625 P3=0000000000000000 P4=0000000000000000 P5=0000000000000000 P6=0000000000000000
626 dr0=0000000000000000 dr1=0000000000000000 dr2=0000000000000000 dr3=0000000000000000
627 dr6=0000000000000000 dr7=0000000000000000 vcr=0000000000000000 dcr=0000000000000000
628 lbt=0000000000000000 lbf=0000000000000000 lxt=0000000000000000 lxf=0000000000000000
6292144.38f4: kernel32.dll: timestamp 0x2f7cc9b6 (rc=VINF_SUCCESS)
6302144.38f4: supR3HardenedWinSetupChildInit: Start child.
6312144.38f4: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
6322144.38f4: supR3HardNtChildPurify: Startup delay kludge #1/0: 526 ms, 34 sleeps
6332144.38f4: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
6342144.38f4: *0000000000000000-000000000029ffff 0x0001/0x0000 0x0000000
6352144.38f4: *00000000002a0000-00000000002bffff 0x0004/0x0004 0x0020000
6362144.38f4: *00000000002c0000-00000000002dcfff 0x0002/0x0002 0x0040000
6372144.38f4: 00000000002dd000-00000000002dffff 0x0001/0x0000 0x0000000
6382144.38f4: *00000000002e0000-00000000003dafff 0x0000/0x0004 0x0020000
6392144.38f4: 00000000003db000-00000000003ddfff 0x0104/0x0004 0x0020000
6402144.38f4: 00000000003de000-00000000003dffff 0x0004/0x0004 0x0020000
6412144.38f4: *00000000003e0000-00000000003e3fff 0x0002/0x0002 0x0040000
6422144.38f4: 00000000003e4000-00000000003effff 0x0001/0x0000 0x0000000
6432144.38f4: *00000000003f0000-00000000003f1fff 0x0004/0x0004 0x0020000
6442144.38f4: 00000000003f2000-00000000003fffff 0x0001/0x0000 0x0000000
6452144.38f4: *0000000000400000-0000000000433fff 0x0000/0x0004 0x0020000
6462144.38f4: 0000000000434000-0000000000436fff 0x0004/0x0004 0x0020000
6472144.38f4: 0000000000437000-00000000005fffff 0x0000/0x0004 0x0020000
6482144.38f4: 0000000000600000-000000007ffdffff 0x0001/0x0000 0x0000000
6492144.38f4: *000000007ffe0000-000000007ffe0fff 0x0002/0x0002 0x0020000
6502144.38f4: 000000007ffe1000-000000007ffe6fff 0x0001/0x0000 0x0000000
6512144.38f4: *000000007ffe7000-000000007ffe7fff 0x0002/0x0002 0x0020000
6522144.38f4: 000000007ffe8000-00007ff58d84ffff 0x0001/0x0000 0x0000000
6532144.38f4: *00007ff58d850000-00007ff58d850fff 0x0002/0x0002 0x0040000
6542144.38f4: 00007ff58d851000-00007ff58d85ffff 0x0001/0x0000 0x0000000
6552144.38f4: *00007ff58d860000-00007ff58d882fff 0x0002/0x0002 0x0040000
6562144.38f4: 00007ff58d883000-00007ff655a1ffff 0x0001/0x0000 0x0000000
6572144.38f4: *00007ff655a20000-00007ff655a20fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\virtualbox\VirtualBoxVM.exe
6582144.38f4: 00007ff655a21000-00007ff655a96fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume4\virtualbox\VirtualBoxVM.exe
6592144.38f4: 00007ff655a97000-00007ff655a97fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume4\virtualbox\VirtualBoxVM.exe
6602144.38f4: 00007ff655a98000-00007ff655adffff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\virtualbox\VirtualBoxVM.exe
6612144.38f4: 00007ff655ae0000-00007ff655ae0fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\virtualbox\VirtualBoxVM.exe
6622144.38f4: 00007ff655ae1000-00007ff655ae1fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\virtualbox\VirtualBoxVM.exe
6632144.38f4: 00007ff655ae2000-00007ff655ae6fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\virtualbox\VirtualBoxVM.exe
6642144.38f4: 00007ff655ae7000-00007ff655ae7fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\virtualbox\VirtualBoxVM.exe
6652144.38f4: 00007ff655ae8000-00007ff655ae8fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\virtualbox\VirtualBoxVM.exe
6662144.38f4: 00007ff655ae9000-00007ff655aecfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\virtualbox\VirtualBoxVM.exe
6672144.38f4: 00007ff655aed000-00007ff655b35fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\virtualbox\VirtualBoxVM.exe
6682144.38f4: 00007ff655b36000-00007ffaabfaffff 0x0001/0x0000 0x0000000
6692144.38f4: *00007ffaabfb0000-00007ffaabfb0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
6702144.38f4: 00007ffaabfb1000-00007ffaac0cbfff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
6712144.38f4: 00007ffaac0cc000-00007ffaac114fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
6722144.38f4: 00007ffaac115000-00007ffaac120fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
6732144.38f4: 00007ffaac121000-00007ffaac12ffff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
6742144.38f4: 00007ffaac130000-00007ffaac130fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
6752144.38f4: 00007ffaac131000-00007ffaac133fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
6762144.38f4: 00007ffaac134000-00007ffaac1a5fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
6772144.38f4: 00007ffaac1a6000-00007ffffffeffff 0x0001/0x0000 0x0000000
6782144.38f4: VirtualBoxVM.exe: timestamp 0x5f51ed66 (rc=VINF_SUCCESS)
6792144.38f4: '\Device\HarddiskVolume4\virtualbox\VirtualBoxVM.exe' has no imports
6802144.38f4: '\Device\HarddiskVolume3\Windows\System32\ntdll.dll' has no imports
6812144.38f4: supR3HardNtChildPurify: Done after 557 ms and 0 fixes (loop #0).
6824074.33d4: Log file opened: 6.1.14r140239 g_hStartupLog=0000000000000004 g_uNtVerCombined=0xa04a6100
6834074.33d4: supR3HardenedVmProcessInit: uNtDllAddr=00007ffaabfb0000 g_uNtVerCombined=0xa04a6100 (stack ~00000000003df6a8)
6844074.33d4: ntdll.dll: timestamp 0x5b56177b (rc=VINF_SUCCESS)
6852144.38f4: supR3HardenedEarlyCompact: Removed heap 1 (0x00000000700000 LB 0x400000)
6864074.33d4: New simple heap: #1 0000000000700000 LB 0x400000 (for 2056192 allocation)
6872144.38f4: supR3HardNtEnableThreadCreationEx:
6884074.33d4: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume4\virtualbox'
6894074.33d4: System32: \Device\HarddiskVolume3\Windows\System32
6904074.33d4: WinSxS: \Device\HarddiskVolume3\Windows\WinSxS
6914074.33d4: KnownDllPath: C:\Windows\System32
6924074.33d4: supR3HardenedVmProcessInit: Opening vboxdrv...
6934074.33d4: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
6944074.33d4: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
6954074.33d4: Registered Dll notification callback with NTDLL.
6964074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\kernel32.dll)
6974074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\kernel32.dll
6984074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\KERNEL32.DLL (Input=KERNEL32.DLL, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000004001:<flags> [calling]
6994074.33d4: supR3HardenedDllNotificationCallback: load 00007ffaa9a80000 LB 0x002c8000 C:\Windows\System32\KERNELBASE.dll [fFlags=0x0]
7004074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\KernelBase.dll)
7014074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\KernelBase.dll
7024074.33d4: supR3HardenedDllNotificationCallback: load 00007ffaaab80000 LB 0x000bd000 C:\Windows\System32\KERNEL32.DLL [fFlags=0x0]
7034074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
7044074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaaab80000 'C:\Windows\System32\KERNEL32.DLL'
7054074.33d4: supR3HardenedDllNotificationCallback: load 00007ff655a20000 LB 0x00116000 F:\virtualbox\VirtualBoxVM.exe [fFlags=0x0]
7064074.33d4: '\Device\HarddiskVolume4\virtualbox\VirtualBoxVM.exe' has no imports
7074074.33d4: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume4\virtualbox\VirtualBoxVM.exe)
7084074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\virtualbox\VirtualBoxVM.exe
7094074.33d4: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffaac024750 pvNtTerminateThread=00007ffaac04c7e0
7102144.38f4: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 86 ms.
7114074.33d4: \SystemRoot\System32\ntdll.dll:
7124074.33d4: CreationTime: 2020-10-16T14:29:16.471334100Z
7134074.33d4: LastWriteTime: 2020-10-16T14:29:16.554461600Z
7144074.33d4: ChangeTime: 2020-10-16T16:42:14.822277800Z
7154074.33d4: FileAttributes: 0x20
7164074.33d4: Size: 0x1ee338
7174074.33d4: NT Headers: 0xe8
7184074.33d4: Timestamp: 0x5b56177b
7194074.33d4: Machine: 0x8664 - amd64
7204074.33d4: Timestamp: 0x5b56177b
7214074.33d4: Image Version: 10.0
7224074.33d4: SizeOfImage: 0x1f6000 (2056192)
7234074.33d4: Resource Dir: 0x185000 LB 0x6fd28
7244074.33d4: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
7254074.33d4: [Raw version resource data: 0x1850f0 LB 0x380, codepage 0x0 (reserved 0x0)]
7264074.33d4: ProductName: Microsoft® Windows® Operating System
7274074.33d4: ProductVersion: 10.0.19041.546
7284074.33d4: FileVersion: 10.0.19041.546 (WinBuild.160101.0800)
7294074.33d4: FileDescription: NT Layer DLL
7304074.33d4: \SystemRoot\System32\kernel32.dll:
7314074.33d4: CreationTime: 2020-10-16T14:27:33.731376800Z
7324074.33d4: LastWriteTime: 2020-10-16T14:27:33.794638400Z
7334074.33d4: ChangeTime: 2020-10-16T16:41:28.031858600Z
7344074.33d4: FileAttributes: 0x20
7354074.33d4: Size: 0xbac30
7364074.33d4: NT Headers: 0xe8
7374074.33d4: Timestamp: 0x2f7cc9b6
7384074.33d4: Machine: 0x8664 - amd64
7394074.33d4: Timestamp: 0x2f7cc9b6
7404074.33d4: Image Version: 10.0
7414074.33d4: SizeOfImage: 0xbd000 (774144)
7424074.33d4: Resource Dir: 0xbb000 LB 0x520
7434074.33d4: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
7444074.33d4: [Raw version resource data: 0xbb0b0 LB 0x3a4, codepage 0x0 (reserved 0x0)]
7454074.33d4: ProductName: Microsoft® Windows® Operating System
7464074.33d4: ProductVersion: 10.0.19041.546
7474074.33d4: FileVersion: 10.0.19041.546 (WinBuild.160101.0800)
7484074.33d4: FileDescription: Windows NT BASE API Client DLL
7494074.33d4: \SystemRoot\System32\KernelBase.dll:
7504074.33d4: CreationTime: 2020-10-16T14:29:23.002324100Z
7514074.33d4: LastWriteTime: 2020-10-16T14:29:23.180425500Z
7524074.33d4: ChangeTime: 2020-10-16T16:42:05.853240600Z
7534074.33d4: FileAttributes: 0x20
7544074.33d4: Size: 0x2c8f70
7554074.33d4: NT Headers: 0xf0
7564074.33d4: Timestamp: 0x1183946c
7574074.33d4: Machine: 0x8664 - amd64
7584074.33d4: Timestamp: 0x1183946c
7594074.33d4: Image Version: 10.0
7604074.33d4: SizeOfImage: 0x2c8000 (2916352)
7614074.33d4: Resource Dir: 0x29f000 LB 0x548
7624074.33d4: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
7634074.33d4: [Raw version resource data: 0x29f0b0 LB 0x3bc, codepage 0x0 (reserved 0x0)]
7644074.33d4: ProductName: Microsoft® Windows® Operating System
7654074.33d4: ProductVersion: 10.0.19041.572
7664074.33d4: FileVersion: 10.0.19041.572 (WinBuild.160101.0800)
7674074.33d4: FileDescription: Windows NT BASE API Client DLL
7684074.33d4: \SystemRoot\System32\apisetschema.dll:
7694074.33d4: CreationTime: 2019-12-07T09:08:13.518339400Z
7704074.33d4: LastWriteTime: 2019-12-07T09:08:13.518339400Z
7714074.33d4: ChangeTime: 2020-10-16T14:36:31.648132800Z
7724074.33d4: FileAttributes: 0x20
7734074.33d4: Size: 0x1f538
7744074.33d4: NT Headers: 0xd0
7754074.33d4: Timestamp: 0x31288ce0
7764074.33d4: Machine: 0x8664 - amd64
7774074.33d4: Timestamp: 0x31288ce0
7784074.33d4: Image Version: 10.0
7794074.33d4: SizeOfImage: 0x20000 (131072)
7804074.33d4: Resource Dir: 0x1f000 LB 0x408
7814074.33d4: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
7824074.33d4: [Raw version resource data: 0x1f060 LB 0x3a8, codepage 0x0 (reserved 0x0)]
7834074.33d4: ProductName: Microsoft® Windows® Operating System
7844074.33d4: ProductVersion: 10.0.19041.1
7854074.33d4: FileVersion: 10.0.19041.1 (WinBuild.160101.0800)
7864074.33d4: FileDescription: ApiSet Schema DLL
7874074.33d4: NtOpenDirectoryObject failed on \Driver: 0xc0000022
7884074.33d4: supR3HardenedWinFindAdversaries: 0x20
7894074.33d4: \SystemRoot\System32\drivers\cfwids.sys:
7904074.33d4: CreationTime: 2020-01-16T02:13:34.000000000Z
7914074.33d4: LastWriteTime: 2020-06-09T05:21:26.000000000Z
7924074.33d4: ChangeTime: 2020-10-10T16:02:20.624671800Z
7934074.33d4: FileAttributes: 0x20
7944074.33d4: Size: 0x127b8
7954074.33d4: NT Headers: 0xf0
7964074.33d4: Timestamp: 0x5ed009c1
7974074.33d4: Machine: 0x8664 - amd64
7984074.33d4: Timestamp: 0x5ed009c1
7994074.33d4: Image Version: 0.0
8004074.33d4: SizeOfImage: 0x14000 (81920)
8014074.33d4: Resource Dir: 0x12000 LB 0x550
8024074.33d4: [Version info resource found at 0x80! (ID/Name: 0x1; SubID/SubName: 0x409)]
8034074.33d4: [Raw version resource data: 0x120a0 LB 0x318, codepage 0x0 (reserved 0x0)]
8044074.33d4: ProductName: SYSCORE
8054074.33d4: ProductVersion: 20.6.0.142
8064074.33d4: FileVersion: SYSCORE.20.6.0.142
8074074.33d4: PrivateBuild: SYSCORE.20.6.0.142
8084074.33d4: FileDescription: McAfee Personal Firewall IDS Plugin
8094074.33d4: \SystemRoot\System32\drivers\mfeavfk.sys:
8104074.33d4: CreationTime: 2020-01-16T02:13:34.000000000Z
8114074.33d4: LastWriteTime: 2020-06-09T05:21:28.000000000Z
8124074.33d4: ChangeTime: 2020-10-10T16:02:20.249708600Z
8134074.33d4: FileAttributes: 0x20
8144074.33d4: Size: 0x5d5b8
8154074.33d4: NT Headers: 0xe8
8164074.33d4: Timestamp: 0x5ed00921
8174074.33d4: Machine: 0x8664 - amd64
8184074.33d4: Timestamp: 0x5ed00921
8194074.33d4: Image Version: 0.0
8204074.33d4: SizeOfImage: 0x5e000 (385024)
8214074.33d4: Resource Dir: 0x5c000 LB 0x758
8224074.33d4: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
8234074.33d4: [Raw version resource data: 0x5c110 LB 0x334, codepage 0x0 (reserved 0x0)]
8244074.33d4: ProductName: SYSCORE
8254074.33d4: ProductVersion: 20.6.0.142
8264074.33d4: FileVersion: SYSCORE.20.6.0.142
8274074.33d4: PrivateBuild: SYSCORE.20.6.0.142 F15,F16,F19
8284074.33d4: FileDescription: Anti-Virus File System Filter Driver
8294074.33d4: \SystemRoot\System32\drivers\mfefirek.sys:
8304074.33d4: CreationTime: 2020-01-16T02:13:34.000000000Z
8314074.33d4: LastWriteTime: 2020-06-09T05:21:26.000000000Z
8324074.33d4: ChangeTime: 2020-10-10T16:02:19.249709500Z
8334074.33d4: FileAttributes: 0x20
8344074.33d4: Size: 0x7f5b8
8354074.33d4: NT Headers: 0xe0
8364074.33d4: Timestamp: 0x5ed00994
8374074.33d4: Machine: 0x8664 - amd64
8384074.33d4: Timestamp: 0x5ed00994
8394074.33d4: Image Version: 0.0
8404074.33d4: SizeOfImage: 0x81000 (528384)
8414074.33d4: Resource Dir: 0x7d000 LB 0x388
8424074.33d4: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
8434074.33d4: [Raw version resource data: 0x7d060 LB 0x328, codepage 0x0 (reserved 0x0)]
8444074.33d4: ProductName: SYSCORE
8454074.33d4: ProductVersion: 20.6.0.142
8464074.33d4: FileVersion: SYSCORE.20.6.0.142
8474074.33d4: PrivateBuild: SYSCORE.20.6.0.142 F17,F18
8484074.33d4: FileDescription: McAfee Core Firewall Engine Driver
8494074.33d4: \SystemRoot\System32\drivers\mfehidk.sys:
8504074.33d4: CreationTime: 2020-01-16T02:13:34.000000000Z
8514074.33d4: LastWriteTime: 2020-06-09T05:21:26.000000000Z
8524074.33d4: ChangeTime: 2020-10-10T16:02:10.951327000Z
8534074.33d4: FileAttributes: 0x20
8544074.33d4: Size: 0xf59b8
8554074.33d4: NT Headers: 0x108
8564074.33d4: Timestamp: 0x5ed008d6
8574074.33d4: Machine: 0x8664 - amd64
8584074.33d4: Timestamp: 0x5ed008d6
8594074.33d4: Image Version: 0.0
8604074.33d4: SizeOfImage: 0xff000 (1044480)
8614074.33d4: Resource Dir: 0xfb000 LB 0x758
8624074.33d4: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
8634074.33d4: [Raw version resource data: 0xfb110 LB 0x320, codepage 0x0 (reserved 0x0)]
8644074.33d4: ProductName: SYSCORE
8654074.33d4: ProductVersion: 20.6.0.142
8664074.33d4: FileVersion: SYSCORE.20.6.0.142
8674074.33d4: PrivateBuild: SYSCORE.20.6.0.142 F14,F15,F16,F18,F20
8684074.33d4: FileDescription: McAfee Link Driver
8694074.33d4: \SystemRoot\System32\drivers\mfencbdc.sys:
8704074.33d4: CreationTime: 2020-06-07T18:28:40.000000000Z
8714074.33d4: LastWriteTime: 2020-06-07T18:28:40.000000000Z
8724074.33d4: ChangeTime: 2020-10-10T16:02:52.007548200Z
8734074.33d4: FileAttributes: 0x20
8744074.33d4: Size: 0x917b8
8754074.33d4: NT Headers: 0xe0
8764074.33d4: Timestamp: 0x5ed7c9d8
8774074.33d4: Machine: 0x8664 - amd64
8784074.33d4: Timestamp: 0x5ed7c9d8
8794074.33d4: Image Version: 0.0
8804074.33d4: SizeOfImage: 0x95000 (610304)
8814074.33d4: Resource Dir: 0x93000 LB 0x458
8824074.33d4: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
8834074.33d4: [Raw version resource data: 0x93060 LB 0x3f4, codepage 0x0 (reserved 0x0)]
8844074.33d4: ProductName: Anti-Malware Core
8854074.33d4: ProductVersion: 20.6.0
8864074.33d4: FileVersion: Anti-Malware Core.20.6.0.189.x64
8874074.33d4: PrivateBuild: Anti-Malware Core.20.6.0.189.x64
8884074.33d4: FileDescription: Event Driver
8894074.33d4: \SystemRoot\System32\drivers\mfewfpk.sys:
8904074.33d4: CreationTime: 2020-01-16T02:13:34.000000000Z
8914074.33d4: LastWriteTime: 2020-06-09T05:21:28.000000000Z
8924074.33d4: ChangeTime: 2020-10-10T16:01:10.442385300Z
8934074.33d4: FileAttributes: 0x20
8944074.33d4: Size: 0x3d9b8
8954074.33d4: NT Headers: 0xf0
8964074.33d4: Timestamp: 0x5ed008e8
8974074.33d4: Machine: 0x8664 - amd64
8984074.33d4: Timestamp: 0x5ed008e8
8994074.33d4: Image Version: 0.0
9004074.33d4: SizeOfImage: 0x59000 (364544)
9014074.33d4: Resource Dir: 0x57000 LB 0x380
9024074.33d4: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
9034074.33d4: [Raw version resource data: 0x57060 LB 0x320, codepage 0x0 (reserved 0x0)]
9044074.33d4: ProductName: SYSCORE
9054074.33d4: ProductVersion: 20.6.0.142
9064074.33d4: FileVersion: SYSCORE.20.6.0.142
9074074.33d4: PrivateBuild: SYSCORE.20.6.0.142 F17,F18
9084074.33d4: FileDescription: Anti-Virus Mini-Firewall Driver
9094074.33d4: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume4\virtualbox'
9104074.33d4: Calling main()
9114074.33d4: SUPR3HardenedMain: pszProgName=VirtualBoxVM fFlags=0x2
9124074.33d4: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume4\virtualbox'
9134074.33d4: '\Device\HarddiskVolume4\virtualbox\VirtualBoxVM.exe' has no imports
9144074.33d4: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume4\virtualbox\VirtualBoxVM.exe)
9154074.33d4: SUPR3HardenedMain: Final process, opening VBoxDrv...
9164074.33d4: supR3HardenedEarlyCompact: Removed heap 1 (0x00000000700000 LB 0x400000)
9174074.33d4: supR3HardNtEnableThreadCreationEx:
9184074.33d4: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume4\virtualbox\VBoxSupLib.dll)
9194074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\virtualbox\VBoxSupLib.dll
9204074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=F:\virtualbox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
9214074.33d4: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume4\virtualbox\VBoxSupLib.dll [lacks WinVerifyTrust]
9224074.33d4: supR3HardenedDllNotificationCallback: load 00007ffaa6420000 LB 0x00005000 F:\virtualbox\VBoxSupLib.DLL [fFlags=0x0]
9234074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume4\virtualbox\VBoxSupLib.dll [lacks WinVerifyTrust]
9244074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume4\virtualbox\VBoxSupLib.dll [lacks WinVerifyTrust]
9254074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=F:\virtualbox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
9264074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa6420000 'F:\virtualbox\VBoxSupLib.DLL'
9274074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume4\virtualbox\VBoxSupLib.dll [lacks WinVerifyTrust]
9284074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=F:\virtualbox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
9294074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa6420000 'F:\virtualbox\VBoxSupLib.DLL'
9304074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa6420000 'F:\virtualbox\VBoxSupLib.DLL'
9314074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
9324074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'rpcrt4.dll'.
9334074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\wintrust.dll)
9344074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\wintrust.dll
9354074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
9364074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
9374074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll)
9384074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll
9394074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
9404074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
9414074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\msvcrt.dll)
9424074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\msvcrt.dll
9434074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
9444074.33d4: supR3HardenedDllNotificationCallback: load 00007ffaab8c0000 LB 0x0009e000 C:\Windows\System32\msvcrt.dll [fFlags=0x0]
9454074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
9464074.33d4: supR3HardenedDllNotificationCallback: load 00007ffaaa190000 LB 0x00124000 C:\Windows\System32\RPCRT4.dll [fFlags=0x0]
9474074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
9484074.33d4: supR3HardenedDllNotificationCallback: load 00007ffaa9d80000 LB 0x00060000 C:\Windows\System32\Wintrust.dll [fFlags=0x0]
9494074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
9504074.33d4: supR3HardenedDllNotificationCallback: load 00007ffaa9900000 LB 0x00100000 C:\Windows\System32\ucrtbase.dll [fFlags=0x0]
9514074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\ucrtbase.dll)
9524074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\ucrtbase.dll
9534074.33d4: supR3HardenedDllNotificationCallback: load 00007ffaa97a0000 LB 0x0015d000 C:\Windows\System32\CRYPT32.dll [fFlags=0x0]
9544074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\crypt32.dll)
9554074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\crypt32.dll
9564074.33d4: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
9574074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
9584074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa9a80000 'api-ms-win-core-synch-l1-2-0'
9594074.33d4: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-fibers-l1-1-1) -> 0x0, fPresent=1
9604074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
9614074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa9a80000 'api-ms-win-core-fibers-l1-1-1'
9624074.33d4: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-fibers-l1-1-1) -> 0x0, fPresent=1
9634074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
9644074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa9a80000 'api-ms-win-core-fibers-l1-1-1'
9654074.33d4: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
9664074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
9674074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa9a80000 'api-ms-win-core-synch-l1-2-0'
9684074.33d4: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-l1-2-1) -> 0x0, fPresent=1
9694074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-l1-2-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
9704074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa9a80000 'api-ms-win-core-localization-l1-2-1'
9714074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\msasn1.dll)
9724074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\msasn1.dll
9734074.33d4: supR3HardenedDllNotificationCallback: load 00007ffaa9350000 LB 0x00012000 C:\Windows\SYSTEM32\MSASN1.dll [fFlags=0x0]
9744074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
9754074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa9d80000 'C:\Windows\system32\Wintrust.dll'
9764074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\bcrypt.dll)
9774074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\bcrypt.dll
9784074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\bcrypt.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
9794074.33d4: supR3HardenedDllNotificationCallback: load 00007ffaa9d50000 LB 0x00027000 C:\Windows\System32\bcrypt.dll [fFlags=0x0]
9804074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
9814074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa9d50000 'C:\Windows\system32\bcrypt.dll'
9824074.33d4: bcrypt.dll loaded at 00007ffaa9d50000, BCryptOpenAlgorithmProvider at 00007ffaa9d551e0, preloading providers:
9834074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\bcryptprimitives.dll)
9844074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\bcryptprimitives.dll
9854074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\bcryptprimitives.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
9864074.33d4: supR3HardenedDllNotificationCallback: load 00007ffaa9a00000 LB 0x0007f000 C:\Windows\System32\bcryptprimitives.dll [fFlags=0x0]
9874074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
9884074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa9a00000 'C:\Windows\system32\bcryptprimitives.dll'
9894074.33d4: BCryptOpenAlgorithmProvider(,'MD2',0,0) -> 0x0 (hAlgo=0000000000c48700)
9904074.33d4: BCryptOpenAlgorithmProvider(,'MD4',0,0) -> 0x0 (hAlgo=0000000000c4e160)
9914074.33d4: BCryptOpenAlgorithmProvider(,'MD5',0,0) -> 0x0 (hAlgo=0000000000c4e480)
9924074.33d4: BCryptOpenAlgorithmProvider(,'SHA1',0,0) -> 0x0 (hAlgo=0000000000c4efb0)
9934074.33d4: BCryptOpenAlgorithmProvider(,'SHA256',0,0) -> 0x0 (hAlgo=0000000000c4f2d0)
9944074.33d4: BCryptOpenAlgorithmProvider(,'SHA512',0,0) -> 0x0 (hAlgo=0000000000c4f5f0)
9954074.33d4: BCryptOpenAlgorithmProvider(,'RSA',0,0) -> 0x0 (hAlgo=0000000000c4f910)
9964074.33d4: BCryptOpenAlgorithmProvider(,'DSA',0,0) -> 0x0 (hAlgo=0000000000c4fc30)
9974074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\cryptsp.dll)
9984074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\cryptsp.dll
9994074.33d4: supR3HardenedDllNotificationCallback: load 00007ffaa9160000 LB 0x00018000 C:\Windows\SYSTEM32\CRYPTSP.dll [fFlags=0x0]
10004074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\cryptsp.dll [lacks WinVerifyTrust]
10014074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'bcrypt.dll'.
10024074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\rsaenh.dll)
10034074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\rsaenh.dll
10044074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
10054074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume3\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
10064074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
10074074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
10084074.33d4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
10094074.33d4: supR3HardenedDllNotificationCallback: load 00007ffaa8770000 LB 0x00034000 C:\Windows\system32\rsaenh.dll [fFlags=0x0]
10104074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
10114074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
10124074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\cryptbase.dll)
10134074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\cryptbase.dll
10144074.33d4: supR3HardenedDllNotificationCallback: load 00007ffaa8f40000 LB 0x0000c000 C:\Windows\SYSTEM32\CRYPTBASE.dll [fFlags=0x0]
10154074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\cryptbase.dll [lacks WinVerifyTrust]
10164074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
10174074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
10184074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaaab80000 'C:\Windows\System32\kernel32.dll'
10194074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
10204074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (Input=WINTRUST.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
10214074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa9d80000 'C:\Windows\System32\WINTRUST.DLL'
10224074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
10234074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\CRYPT32.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
10244074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\CRYPT32.dll'
10254074.33d4: supR3HardenedDllNotificationCallback: load 00007ffaabb20000 LB 0x0001d000 C:\Windows\System32\imagehlp.dll [fFlags=0x0]
10264074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\imagehlp.dll)
10274074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\imagehlp.dll
10284074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
10294074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
10304074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
10314074.33d4: supR3HardenedDllNotificationCallback: load 00007ffaaa0f0000 LB 0x0009b000 C:\Windows\System32\sechost.dll [fFlags=0x0]
10324074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'rpcrt4.dll'.
10334074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\sechost.dll)
10344074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\sechost.dll
10354074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
10364074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'rpcrt4.dll'.
10374074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\gpapi.dll)
10384074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\gpapi.dll
10394074.33d4: supR3HardenedDllNotificationCallback: load 00007ffaa7c30000 LB 0x00023000 C:\Windows\SYSTEM32\gpapi.dll [fFlags=0x0]
10404074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gpapi.dll [lacks WinVerifyTrust]
10414074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\profapi.dll)
10424074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\profapi.dll
10434074.33d4: supR3HardenedDllNotificationCallback: load 00007ffaa9630000 LB 0x00026000 C:\Windows\SYSTEM32\profapi.dll [fFlags=0x0]
10444074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\profapi.dll [lacks WinVerifyTrust]
10454074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
10464074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'crypt32.dll'.
10474074.33d4: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\cryptnet.dll)
10484074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\cryptnet.dll
10494074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
10504074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume3\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
10514074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
10524074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
10534074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
10544074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
10554074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
10564074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
10574074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
10584074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
10594074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
10604074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
10614074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
10624074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
10634074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
10644074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\cryptnet.dll (Input=cryptnet.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
10654074.33d4: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
10664074.33d4: supR3HardenedDllNotificationCallback: load 00007ffa924b0000 LB 0x00031000 C:\Windows\System32\cryptnet.dll [fFlags=0x0]
10674074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
10684074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
10694074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
10704074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa924b0000 'C:\Windows\System32\cryptnet.dll'
10714074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
10724074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
10734074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa924b0000 'C:\Windows\System32\cryptnet.dll'
10744074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
10754074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
10764074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa924b0000 'C:\Windows\System32\cryptnet.dll'
10774074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
10784074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
10794074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa924b0000 'C:\Windows\System32\cryptnet.dll'
10804074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
10814074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
10824074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa924b0000 'C:\Windows\System32\cryptnet.dll'
10834074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
10844074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
10854074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa924b0000 'C:\Windows\System32\cryptnet.dll'
10864074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
10874074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa924b0000 'C:\Windows\System32\cryptnet.dll'
10884074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
10894074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa924b0000 'C:\Windows\System32\cryptnet.dll'
10904074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
10914074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa924b0000 'C:\Windows\System32\cryptnet.dll'
10924074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
10934074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa924b0000 'C:\Windows\System32\cryptnet.dll'
10944074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
10954074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa924b0000 'C:\Windows\System32\cryptnet.dll'
10964074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa924b0000 'C:\Windows\System32\cryptnet.dll'
10974074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
10984074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa924b0000 'C:\Windows\System32\cryptnet.dll'
10994074.33d4: supR3HardenedDllNotificationCallback: load 00007ffaaa740000 LB 0x000aa000 C:\Windows\System32\advapi32.dll [fFlags=0x0]
11004074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
11014074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'sechost.dll'.
11024074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #27 'rpcrt4.dll'.
11034074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\advapi32.dll)
11044074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\advapi32.dll
11054074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
11064074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
11074074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
11084074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
11094074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'sechost.dll'...
11104074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'sechost.dll' -> '\Device\HarddiskVolume3\Windows\System32\sechost.dll' [rcNtRedir=0xc0150008]
11114074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\sechost.dll [lacks WinVerifyTrust]
11124074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
11134074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
11144074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
11154074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
11164074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
11174074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
11184074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
11194074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
11204074.33d4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000000 pwszName=\SystemRoot\System32\ntdll.dll
11214074.33d4: supR3HardNtViCallWinVerifyTrustCatFile: New context 0000000000cce4d0
11224074.33d4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000cce4d0
11234074.33d4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=7156C83A907F16145EEEA84ADE6D92E3B0F66BCB
11244074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
11254074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\rpcrt4.dll (Input=rpcrt4.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
11264074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaaa190000 'C:\Windows\System32\rpcrt4.dll'
11274074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
11284074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
11294074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
11304074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
11314074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
11324074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
11334074.33d4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0416~31bf3856ad364e35~amd64~~10.0.19041.572.cat'; file='\SystemRoot\System32\ntdll.dll'
11344074.33d4: g_pfnWinVerifyTrust=00007ffaa9d81da0
11354074.33d4: supR3HardenedScreenImage/preload: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll [redoing WinVerifyTrust]
11364074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
11374074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
11384074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
11394074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
11404074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
11414074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
11424074.33d4: supR3HardenedScreenImage/preload: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\crypt32.dll'
11434074.33d4: supR3HardenedScreenImage/preload: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wintrust.dll [redoing WinVerifyTrust]
11444074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
11454074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
11464074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
11474074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll
11484074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
11494074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
11504074.33d4: supR3HardenedScreenImage/preload: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\wintrust.dll'
11514074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
11524074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
11534074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
11544074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll
11554074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
11564074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
11574074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\advapi32.dll'
11584074.33d4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000380 pwszName=\Device\HarddiskVolume3\Windows\System32\cryptnet.dll
11594074.33d4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000cce4d0
11604074.33d4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000cce4d0
11614074.33d4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=E45ECE98858B46D7A91C9972C8F2F62C2E8A43CC
11624074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
11634074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
11644074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
11654074.33d4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0416~31bf3856ad364e35~amd64~~10.0.19041.572.cat'; file='\Device\HarddiskVolume3\Windows\System32\cryptnet.dll'
11664074.33d4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
11674074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\cryptnet.dll'
11684074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
11694074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
11704074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
11714074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\profapi.dll'
11724074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
11734074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
11744074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
11754074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\gpapi.dll'
11764074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
11774074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
11784074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
11794074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\sechost.dll'
11804074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
11814074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
11824074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
11834074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\imagehlp.dll'
11844074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
11854074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
11864074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
11874074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\cryptbase.dll'
11884074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
11894074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
11904074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
11914074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\rsaenh.dll'
11924074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll
11934074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
11944074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
11954074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll
11964074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
11974074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
11984074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\cryptsp.dll'
11994074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
12004074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
12014074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\bcryptprimitives.dll'
12024074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
12034074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
12044074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\bcrypt.dll'
12054074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
12064074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
12074074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\msasn1.dll'
12084074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
12094074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
12104074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\ucrtbase.dll'
12114074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
12124074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
12134074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll'
12144074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
12154074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
12164074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll'
12174074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
12184074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 24202) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\virtualbox\VBoxSupLib.dll'
12194074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
12204074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 24202) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\virtualbox\VirtualBoxVM.exe'
12214074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
12224074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
12234074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\KernelBase.dll'
12244074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
12254074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
12264074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\kernel32.dll'
12274074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\system32\crypt32.dll'
12284074.33d4: supR3HardenedWinIsDesiredRootCA: Adding 0x5ad46780fa5df300 DC=com, DC=microsoft, CN=Microsoft Root Certificate Authority
12294074.33d4: supR3HardenedWinIsDesiredRootCA: Adding 0xea5386456178582b C=ZA, ST=Western Cape, L=Durbanville, O=Thawte, OU=Thawte Certification, CN=Thawte Timestamping CA
12304074.33d4: supR3HardenedWinIsDesiredRootCA: Adding 0x3be670c1bd02a900 OU=Copyright (c) 1997 Microsoft Corp., OU=Microsoft Corporation, CN=Microsoft Root Authority
12314074.33d4: supR3HardenedWinIsDesiredRootCA: Adding 0xe991ee72b03db500 C=US, O=Symantec Corporation, CN=Symantec Enterprise Mobile Root for Microsoft
12324074.33d4: supR3HardenedWinIsDesiredRootCA: Adding 0x4d3835aa4180b200 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2011
12334074.33d4: supR3HardenedWinIsDesiredRootCA: Adding 0x646e3fe3ba08df00 C=US, O=MSFT, CN=Microsoft Authenticode(tm) Root Authority
12344074.33d4: supR3HardenedWinIsDesiredRootCA: Adding 0xece4e4289e08b900 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010
12354074.33d4: supR3HardenedWinIsDesiredRootCA: Adding 0xf3bb4d7e894b420 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft ECC TS Root Certificate Authority 2018
12364074.33d4: supR3HardenedWinIsDesiredRootCA: Adding 0x43a9cc371ff5385a O=Microsoft Trust Network, OU=Microsoft Corporation, OU=Microsoft Time Stamping Service Root, OU=Copyright (c) 1997 Microsoft Corp.
12374074.33d4: supR3HardenedWinIsDesiredRootCA: Adding 0x2e2d2c7c68f0202e O=VeriSign Trust Network, OU=VeriSign, Inc., OU=VeriSign Time Stamping Service Root, OU=NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.
12384074.33d4: supR3HardenedWinIsDesiredRootCA: Adding 0xcec3d46562b9be8e C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft ECC Product Root Certificate Authority 2018
12394074.33d4: supR3HardenedWinIsDesiredRootCA: Adding 0xca58a05dd401ae00 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Time Stamp Root Certificate Authority 2014
12404074.33d4: supR3HardenedWinIsDesiredRootCA: Adding 0x61a3a33f81aace00 C=US, ST=UT, L=Salt Lake City, O=The USERTRUST Network, OU=http://www.usertrust.com, CN=UTN-USERFirst-Object
12414074.33d4: supR3HardenedWinIsDesiredRootCA: Adding 0x6b7bdc34cd37bb00 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root G2
12424074.33d4: supR3HardenedWinIsDesiredRootCA: Adding 0x57ba5395b561bf00 C=BM, O=QuoVadis Limited, OU=Root Certification Authority, CN=QuoVadis Root Certification Authority
12434074.33d4: supR3HardenedWinIsDesiredRootCA: Adding 0x83085097e9afdf00 O=Digital Signature Trust Co., CN=DST Root CA X3
12444074.33d4: supR3HardenedWinIsDesiredRootCA: Adding 0x780679907625cc00 OU=GlobalSign Root CA - R3, O=GlobalSign, CN=GlobalSign
12454074.33d4: supR3HardenedWinIsDesiredRootCA: Adding 0x3d98ab22bb04a300 C=IE, O=Baltimore, OU=CyberTrust, CN=Baltimore CyberTrust Root
12464074.33d4: supR3HardenedWinIsDesiredRootCA: Adding 0xeae16ef49d40be00 C=GB, ST=Greater Manchester, L=Salford, O=Comodo CA Limited, CN=AAA Certificate Services
12474074.33d4: supR3HardenedWinIsDesiredRootCA: Adding 0x8ff6fc03c1edbd00 C=US, ST=Arizona, L=Scottsdale, O=Starfield Technologies, Inc., CN=Starfield Root Certificate Authority - G2
12484074.33d4: supR3HardenedWinIsDesiredRootCA: Adding 0xc6fa4243b695b600 C=US, O=Entrust, Inc., OU=www.entrust.net/CPS is incorporated by reference, OU=(c) 2006 Entrust, Inc., CN=Entrust Root Certification Authority
12494074.33d4: supR3HardenedWinIsDesiredRootCA: Adding 0xa3ce8d99e60eda00 C=BE, O=GlobalSign nv-sa, OU=Root CA, CN=GlobalSign Root CA
12504074.33d4: supR3HardenedWinIsDesiredRootCA: Adding 0x560ad29254e89100 C=GB, ST=Greater Manchester, L=Salford, O=COMODO CA Limited, CN=COMODO RSA Certification Authority
12514074.33d4: supR3HardenedWinIsDesiredRootCA: Adding 0xa671e9fec832b700 C=US, O=Starfield Technologies, Inc., OU=Starfield Class 2 Certification Authority
12524074.33d4: supR3HardenedWinIsDesiredRootCA: Adding 0xa8de7211e13be200 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root CA
12534074.33d4: supR3HardenedWinIsDesiredRootCA: Adding 0xc9edb72b684ba00 C=US, O=Entrust, Inc., OU=See www.entrust.net/legal-terms, OU=(c) 2009 Entrust, Inc. - for authorized use only, CN=Entrust Root Certification Authority - G2
12544074.33d4: supR3HardenedWinIsDesiredRootCA: Adding 0xf5cd95e581a4ab00 C=US, O=SecureTrust Corporation, CN=SecureTrust CA
12554074.33d4: supR3HardenedWinIsDesiredRootCA: Adding 0x6f2ebe0e24cfa600 OU=GlobalSign Root CA - R2, O=GlobalSign, CN=GlobalSign
12564074.33d4: supR3HardenedWinIsDesiredRootCA: Adding 0x14018a1bf29e595c C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority
12574074.33d4: supR3HardenedWinIsDesiredRootCA: Adding 0x9e5bc2d78b6a3636 C=ZA, ST=Western Cape, L=Cape Town, O=Thawte Consulting cc, OU=Certification Services Division, CN=Thawte Premium Server CA, Email=premium-server@thawte.com
12584074.33d4: supR3HardenedWinIsDesiredRootCA: Adding 0x7c4fd32ec1b1ce00 C=PL, O=Unizeto Sp. z o.o., CN=Certum CA
12594074.33d4: supR3HardenedWinIsDesiredRootCA: Adding 0xd4fbe673e5ccc600 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA
12604074.33d4: supR3HardenedWinIsDesiredRootCA: Adding 0x1b8578514b74ac00 C=US, O=WFA Hotspot 2.0, CN=Hotspot 2.0 Trust Root CA - 03
12614074.33d4: supR3HardenedWinIsDesiredRootCA: Adding 0xb28612a94b4dad00 O=Entrust.net, OU=www.entrust.net/CPS_2048 incorp. by ref. (limits liab.), OU=(c) 1999 Entrust.net Limited, CN=Entrust.net Certification Authority (2048)
12624074.33d4: supR3HardenedWinIsDesiredRootCA: Adding 0x357a29080824af00 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2006 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G5
12634074.33d4: supR3HardenedWinIsDesiredRootCA: Adding 0x59faf1086271bf00 C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com, Inc., CN=Go Daddy Root Certificate Authority - G2
12644074.33d4: supR3HardenedWinIsDesiredRootCA: Adding 0xb16dd37ffeb3b300 C=JP, O=SECOM Trust.net, OU=Security Communication RootCA1
12654074.33d4: supR3HardenedWinIsDesiredRootCA: Adding 0x3401b15e3761c700 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2008 VeriSign, Inc. - For authorized use only, CN=VeriSign Universal Root Certification Authority
12664074.33d4: supR3HardenedWinIsDesiredRootCA: Adding 0xc30e361765128000 C=US, ST=New Jersey, L=Jersey City, O=The USERTRUST Network, CN=USERTrust RSA Certification Authority
12674074.33d4: supR3HardenedWinIsDesiredRootCA: Adding 0x491857ead79dde00 C=US, O=The Go Daddy Group, Inc., OU=Go Daddy Class 2 Certification Authority
12684074.33d4: supR3HardenedWinIsDesiredRootCA: Adding 0xc2ba72a37dfbe300 C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Trusted Network CA
12694074.33d4: supR3HardenedWinIsDesiredRootCA: Adding 0x8043e4ce150ead00 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID Root CA
12704074.33d4: supR3HardenedWinIsDesiredRootCA: Adding 0xf2e6331af7b700 C=SE, O=AddTrust AB, OU=AddTrust External TTP Network, CN=AddTrust External CA Root
12714074.33d4: supR3HardenedWinRetrieveTrustedRootCAs: cAdded=43
12724074.33d4: SUPR3HardenedMain: Load Runtime...
12734074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
12744074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
12754074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
12764074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rpcrt4.dll'.
12774074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ws2_32.dll'.
12784074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\virtualbox\VBoxRT.dll) WinVerifyTrust
12794074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\virtualbox\VBoxRT.dll
12804074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
12814074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
12824074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
12834074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
12844074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'rpcrt4.dll'.
12854074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\ws2_32.dll) WinVerifyTrust
12864074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\ws2_32.dll
12874074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
12884074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
12894074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll
12904074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
12914074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume4\virtualbox\msvcp100.dll' [rcNtRedir=0xc0150008]
12924074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
12934074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
12944074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll
12954074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
12964074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
12974074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\virtualbox\msvcp100.dll) WinVerifyTrust
12984074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\virtualbox\msvcp100.dll
12994074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
13004074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
13014074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
13024074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
13034074.33d4: Detected WinVerifyTrust recursion: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
13044074.33d4: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume4\virtualbox\msvcr100.dll)
13054074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\virtualbox\msvcr100.dll
13064074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
13074074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\virtualbox\msvcr100.dll) WinVerifyTrust
13084074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=F:\virtualbox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000a01:<flags> [calling]
13094074.33d4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\VBoxRT.dll
13104074.33d4: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume4\virtualbox\msvcr100.dll [avoiding WinVerifyTrust]
13114074.33d4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\msvcp100.dll
13124074.33d4: supR3HardenedDllNotificationCallback: load 0000000075140000 LB 0x000d2000 F:\virtualbox\MSVCR100.dll [fFlags=0x0]
13134074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume4\virtualbox\msvcr100.dll [avoiding WinVerifyTrust]
13144074.33d4: supR3HardenedDllNotificationCallback: load 0000000075350000 LB 0x00098000 F:\virtualbox\MSVCP100.dll [fFlags=0x0]
13154074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\msvcp100.dll
13164074.33d4: supR3HardenedDllNotificationCallback: load 00007ffaabc70000 LB 0x0006b000 C:\Windows\System32\WS2_32.dll [fFlags=0x0]
13174074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ws2_32.dll
13184074.33d4: supR3HardenedDllNotificationCallback: load 00007ffa2c760000 LB 0x005e0000 F:\virtualbox\VBoxRT.dll [fFlags=0x0]
13194074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\VBoxRT.dll
13204074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
13214074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
13224074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\VBoxRT.dll
13234074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=F:\virtualbox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
13244074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa2c760000 'F:\virtualbox\VBoxRT.dll'
13254074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
13264074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
13274074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
13284074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
13294074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\VBoxRT.dll
13304074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=F:\virtualbox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
13314074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa2c760000 'F:\virtualbox\VBoxRT.dll'
13324074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
13334074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
13344074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
13354074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
13364074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\VBoxRT.dll
13374074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=F:\virtualbox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
13384074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa2c760000 'F:\virtualbox\VBoxRT.dll'
13394074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
13404074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
13414074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
13424074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
13434074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\VBoxRT.dll
13444074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=F:\virtualbox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
13454074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa2c760000 'F:\virtualbox\VBoxRT.dll'
13464074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
13474074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
13484074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
13494074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
13504074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\VBoxRT.dll
13514074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=F:\virtualbox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
13524074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa2c760000 'F:\virtualbox\VBoxRT.dll'
13534074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
13544074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
13554074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
13564074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
13574074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\VBoxRT.dll
13584074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=F:\virtualbox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
13594074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa2c760000 'F:\virtualbox\VBoxRT.dll'
13604074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
13614074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
13624074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
13634074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
13644074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa2c760000 'F:\virtualbox\VBoxRT.dll'
13654074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
13664074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
13674074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
13684074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
13694074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa2c760000 'F:\virtualbox\VBoxRT.dll'
13704074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
13714074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
13724074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
13734074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
13744074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa2c760000 'F:\virtualbox\VBoxRT.dll'
13754074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
13764074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
13774074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
13784074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
13794074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa2c760000 'F:\virtualbox\VBoxRT.dll'
13804074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
13814074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
13824074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
13834074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
13844074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa2c760000 'F:\virtualbox\VBoxRT.dll'
13854074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
13864074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
13874074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
13884074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
13894074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa2c760000 'F:\virtualbox\VBoxRT.dll'
13904074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
13914074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
13924074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
13934074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
13944074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa2c760000 'F:\virtualbox\VBoxRT.dll'
13954074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
13964074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
13974074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
13984074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
13994074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\VBoxRT.dll
14004074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=F:\virtualbox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
14014074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa2c760000 'F:\virtualbox\VBoxRT.dll'
14024074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
14034074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
14044074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
14054074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
14064074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa2c760000 'F:\virtualbox\VBoxRT.dll'
14074074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
14084074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
14094074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
14104074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
14114074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa2c760000 'F:\virtualbox\VBoxRT.dll'
14124074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
14134074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
14144074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
14154074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
14164074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa2c760000 'F:\virtualbox\VBoxRT.dll'
14174074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
14184074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
14194074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
14204074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
14214074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa2c760000 'F:\virtualbox\VBoxRT.dll'
14224074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
14234074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
14244074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
14254074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
14264074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa2c760000 'F:\virtualbox\VBoxRT.dll'
14274074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
14284074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
14294074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
14304074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
14314074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa2c760000 'F:\virtualbox\VBoxRT.dll'
14324074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
14334074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
14344074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
14354074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
14364074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa2c760000 'F:\virtualbox\VBoxRT.dll'
14374074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
14384074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
14394074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
14404074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
14414074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa2c760000 'F:\virtualbox\VBoxRT.dll'
14424074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
14434074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
14444074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
14454074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
14464074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa2c760000 'F:\virtualbox\VBoxRT.dll'
14474074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
14484074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
14494074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
14504074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
14514074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa2c760000 'F:\virtualbox\VBoxRT.dll'
14524074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
14534074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
14544074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
14554074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
14564074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa2c760000 'F:\virtualbox\VBoxRT.dll'
14574074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
14584074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
14594074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
14604074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
14614074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa2c760000 'F:\virtualbox\VBoxRT.dll'
14624074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
14634074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
14644074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
14654074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
14664074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa2c760000 'F:\virtualbox\VBoxRT.dll'
14674074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
14684074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
14694074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
14704074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
14714074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa2c760000 'F:\virtualbox\VBoxRT.dll'
14724074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
14734074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
14744074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
14754074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
14764074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa2c760000 'F:\virtualbox\VBoxRT.dll'
14774074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
14784074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
14794074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
14804074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
14814074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\VBoxRT.dll
14824074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=F:\virtualbox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
14834074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa2c760000 'F:\virtualbox\VBoxRT.dll'
14844074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
14854074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
14864074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
14874074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
14884074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa2c760000 'F:\virtualbox\VBoxRT.dll'
14894074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
14904074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
14914074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
14924074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
14934074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa2c760000 'F:\virtualbox\VBoxRT.dll'
14944074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'.
14954074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rescheduled]
14964074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa2c760000 'F:\virtualbox\VBoxRT.dll'
14974074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
14984074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 24202) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\virtualbox\msvcr100.dll'
14994074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wintrust.dll
15004074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
15014074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa9d80000 'C:\Windows\system32\Wintrust.dll'
15024074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll
15034074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
15044074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
15054074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
15064074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
15074074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
15084074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\system32\crypt32.dll'
15094074.33d4: SUPR3HardenedMain: Load TrustedMain...
15104074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
15114074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'opengl32.dll'.
15124074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'uicommon.dll'.
15134074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
15144074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcp100.dll'.
15154074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msvcr100.dll'.
15164074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'qt5corevbox.dll'.
15174074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'qt5guivbox.dll'.
15184074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'qt5widgetsvbox.dll'.
15194074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'qt5openglvbox.dll'.
15204074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'user32.dll'.
15214074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'ole32.dll'.
15224074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'oleaut32.dll'.
15234074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'winmm.dll'.
15244074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\virtualbox\VirtualBoxVM.dll) WinVerifyTrust
15254074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\virtualbox\VirtualBoxVM.dll
15264074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
15274074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume3\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
15284074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
15294074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
15304074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
15314074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\winmm.dll) WinVerifyTrust
15324074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\winmm.dll
15334074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
15344074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume3\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
15354074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
15364074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
15374074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll
15384074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
15394074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
15404074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
15414074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'combase.dll'.
15424074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #21 'rpcrt4.dll'.
15434074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\oleaut32.dll) WinVerifyTrust
15444074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\oleaut32.dll
15454074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
15464074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
15474074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
15484074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
15494074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll
15504074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
15514074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume3\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
15524074.33d4: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\combase.dll'.
15534074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rpcrt4.dll'.
15544074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\combase.dll)
15554074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\combase.dll
15564074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
15574074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
15584074.33d4: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll'.
15594074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll)
15604074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\msvcp_win.dll
15614074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
15624074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
15634074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
15644074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll
15654074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
15664074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
15674074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #21 'rpcrt4.dll'.
15684074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #49 'gdi32.dll'.
15694074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #50 'user32.dll'.
15704074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #51 'combase.dll'.
15714074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\ole32.dll) WinVerifyTrust
15724074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\ole32.dll
15734074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
15744074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
15754074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
15764074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume3\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
15774074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\combase.dll [lacks WinVerifyTrust]
15784074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
15794074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
15804074.33d4: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\user32.dll'.
15814074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'win32u.dll'.
15824074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #37 'gdi32.dll'.
15834074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\user32.dll)
15844074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\user32.dll
15854074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
15864074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
15874074.33d4: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32.dll'.
15884074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'win32u.dll'.
15894074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\gdi32.dll)
15904074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\gdi32.dll
15914074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
15924074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
15934074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
15944074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
15954074.33d4: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\win32u.dll'.
15964074.33d4: '\Device\HarddiskVolume3\Windows\System32\win32u.dll' has no imports
15974074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\win32u.dll)
15984074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\win32u.dll
15994074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
16004074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
16014074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
16024074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
16034074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
16044074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\win32u.dll [lacks WinVerifyTrust]
16054074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
16064074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
16074074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'win32u.dll'.
16084074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #37 'gdi32.dll'.
16094074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\user32.dll) WinVerifyTrust
16104074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5openglvbox.dll'...
16114074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5openglvbox.dll' -> '\Device\HarddiskVolume4\virtualbox\qt5openglvbox.dll' [rcNtRedir=0xc0150008]
16124074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
16134074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
16144074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
16154074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
16164074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
16174074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\win32u.dll [lacks WinVerifyTrust]
16184074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
16194074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'qt5widgetsvbox.dll'.
16204074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'qt5guivbox.dll'.
16214074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5corevbox.dll'.
16224074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcr100.dll'.
16234074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\virtualbox\Qt5OpenGLVBox.dll) WinVerifyTrust
16244074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\virtualbox\Qt5OpenGLVBox.dll
16254074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
16264074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume4\virtualbox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
16274074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
16284074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
16294074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\msvcr100.dll
16304074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
16314074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume4\virtualbox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
16324074.33d4: Detected WinVerifyTrust recursion: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\Qt5CoreVBox.dll'.
16334074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
16344074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'shell32.dll'.
16354074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ole32.dll'.
16364074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
16374074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ws2_32.dll'.
16384074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'mpr.dll'.
16394074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'msvcp100.dll'.
16404074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'msvcr100.dll'.
16414074.33d4: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume4\virtualbox\Qt5CoreVBox.dll)
16424074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\virtualbox\Qt5CoreVBox.dll
16434074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
16444074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume4\virtualbox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
16454074.33d4: Detected WinVerifyTrust recursion: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\Qt5GuiVBox.dll'.
16464074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ole32.dll'.
16474074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'opengl32.dll'.
16484074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
16494074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
16504074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qt5corevbox.dll'.
16514074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcp100.dll'.
16524074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msvcr100.dll'.
16534074.33d4: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume4\virtualbox\Qt5GuiVBox.dll)
16544074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\virtualbox\Qt5GuiVBox.dll
16554074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
16564074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume4\virtualbox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
16574074.33d4: Detected WinVerifyTrust recursion: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\Qt5WidgetsVBox.dll'.
16584074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
16594074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
16604074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5guivbox.dll'.
16614074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qt5corevbox.dll'.
16624074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'shell32.dll'.
16634074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcp100.dll'.
16644074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msvcr100.dll'.
16654074.33d4: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume4\virtualbox\Qt5WidgetsVBox.dll)
16664074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\virtualbox\Qt5WidgetsVBox.dll
16674074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
16684074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
16694074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\msvcr100.dll
16704074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
16714074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume4\virtualbox\msvcp100.dll' [rcNtRedir=0xc0150008]
16724074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\msvcp100.dll
16734074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
16744074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume3\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
16754074.33d4: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\shell32.dll'.
16764074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
16774074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #72 'user32.dll'.
16784074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #74 'gdi32.dll'.
16794074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\shell32.dll)
16804074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\shell32.dll
16814074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
16824074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume4\virtualbox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
16834074.33d4: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume4\virtualbox\Qt5CoreVBox.dll [lacks WinVerifyTrust]
16844074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
16854074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume4\virtualbox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
16864074.33d4: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume4\virtualbox\Qt5GuiVBox.dll [lacks WinVerifyTrust]
16874074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
16884074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
16894074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\user32.dll [lacks WinVerifyTrust]
16904074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
16914074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
16924074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
16934074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
16944074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
16954074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\msvcr100.dll
16964074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
16974074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume4\virtualbox\msvcp100.dll' [rcNtRedir=0xc0150008]
16984074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\msvcp100.dll
16994074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
17004074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume4\virtualbox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
17014074.33d4: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume4\virtualbox\Qt5CoreVBox.dll [lacks WinVerifyTrust]
17024074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
17034074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
17044074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\user32.dll [lacks WinVerifyTrust]
17054074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
17064074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
17074074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
17084074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
17094074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume3\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
17104074.33d4: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume3\Windows\System32\opengl32.dll'.
17114074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
17124074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'advapi32.dll'.
17134074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
17144074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'gdi32.dll'.
17154074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'glu32.dll'.
17164074.33d4: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\opengl32.dll)
17174074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\opengl32.dll
17184074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
17194074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
17204074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ole32.dll
17214074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
17224074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
17234074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\msvcr100.dll
17244074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
17254074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume4\virtualbox\msvcp100.dll' [rcNtRedir=0xc0150008]
17264074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\msvcp100.dll
17274074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mpr.dll'...
17284074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'mpr.dll' -> '\Device\HarddiskVolume3\Windows\System32\mpr.dll' [rcNtRedir=0xc0150008]
17294074.33d4: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\mpr.dll'.
17304074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\mpr.dll)
17314074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\mpr.dll
17324074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
17334074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
17344074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ws2_32.dll
17354074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
17364074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
17374074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\advapi32.dll
17384074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
17394074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
17404074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ole32.dll
17414074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
17424074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume3\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
17434074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\shell32.dll [lacks WinVerifyTrust]
17444074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
17454074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
17464074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\user32.dll [lacks WinVerifyTrust]
17474074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'glu32.dll'...
17484074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'glu32.dll' -> '\Device\HarddiskVolume3\Windows\System32\glu32.dll' [rcNtRedir=0xc0150008]
17494074.33d4: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume3\Windows\System32\glu32.dll'.
17504074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
17514074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
17524074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'opengl32.dll'.
17534074.33d4: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\glu32.dll)
17544074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\glu32.dll
17554074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
17564074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
17574074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
17584074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
17594074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
17604074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\user32.dll [lacks WinVerifyTrust]
17614074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
17624074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
17634074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\advapi32.dll
17644074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
17654074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
17664074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll
17674074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
17684074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
17694074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
17704074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
17714074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
17724074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\user32.dll [lacks WinVerifyTrust]
17734074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
17744074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
17754074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcp_win.dll [lacks WinVerifyTrust]
17764074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
17774074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume3\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
17784074.33d4: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\opengl32.dll [lacks WinVerifyTrust]
17794074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
17804074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
17814074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\user32.dll [lacks WinVerifyTrust]
17824074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
17834074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
17844074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll
17854074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
17864074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
17874074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
17884074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5guivbox.dll'.
17894074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qt5corevbox.dll'.
17904074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'shell32.dll'.
17914074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcp100.dll'.
17924074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msvcr100.dll'.
17934074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\virtualbox\Qt5WidgetsVBox.dll) WinVerifyTrust
17944074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
17954074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume4\virtualbox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
17964074.33d4: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume4\virtualbox\Qt5GuiVBox.dll [redoing WinVerifyTrust]
17974074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
17984074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
17994074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\msvcr100.dll
18004074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
18014074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume4\virtualbox\msvcp100.dll' [rcNtRedir=0xc0150008]
18024074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\msvcp100.dll
18034074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
18044074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume3\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
18054074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\shell32.dll [lacks WinVerifyTrust]
18064074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
18074074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume4\virtualbox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
18084074.33d4: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume4\virtualbox\Qt5CoreVBox.dll [lacks WinVerifyTrust]
18094074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
18104074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume4\virtualbox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
18114074.33d4: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume4\virtualbox\Qt5GuiVBox.dll [lacks WinVerifyTrust]
18124074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
18134074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
18144074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\user32.dll [lacks WinVerifyTrust]
18154074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
18164074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
18174074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
18184074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
18194074.33d4: supR3HardenedScreenImage/Imports: 0 (was 24202) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\virtualbox\Qt5GuiVBox.dll'
18204074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
18214074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume4\virtualbox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
18224074.33d4: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume4\virtualbox\Qt5CoreVBox.dll [redoing WinVerifyTrust]
18234074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
18244074.33d4: supR3HardenedScreenImage/Imports: 0 (was 24202) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\virtualbox\Qt5CoreVBox.dll'
18254074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
18264074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
18274074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\msvcr100.dll
18284074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
18294074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume4\virtualbox\msvcp100.dll' [rcNtRedir=0xc0150008]
18304074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\msvcp100.dll
18314074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
18324074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\virtualbox\vboxrt.dll' [rcNtRedir=0xc0150008]
18334074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'uicommon.dll'...
18344074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'uicommon.dll' -> '\Device\HarddiskVolume4\virtualbox\uicommon.dll' [rcNtRedir=0xc0150008]
18354074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
18364074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'vboxrt.dll'.
18374074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcr100.dll'.
18384074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5corevbox.dll'.
18394074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qt5guivbox.dll'.
18404074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qt5widgetsvbox.dll'.
18414074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
18424074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'advapi32.dll'.
18434074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'ole32.dll'.
18444074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'oleaut32.dll'.
18454074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'rpcrt4.dll'.
18464074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\virtualbox\UICommon.dll) WinVerifyTrust
18474074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\virtualbox\UICommon.dll
18484074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
18494074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume3\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
18504074.33d4: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\opengl32.dll [redoing WinVerifyTrust]
18514074.33d4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000464 pwszName=\Device\HarddiskVolume3\Windows\System32\opengl32.dll
18524074.33d4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000cce4d0
18534074.33d4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000cce4d0
18544074.33d4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=F14F1B7D8729223C0DB5ABA6EC95E5C5A3D6D1EC
18554074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
18564074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
18574074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
18584074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume3\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
18594074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\oleaut32.dll
18604074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
18614074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
18624074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ole32.dll
18634074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
18644074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
18654074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\advapi32.dll
18664074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
18674074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
18684074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\user32.dll [lacks WinVerifyTrust]
18694074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
18704074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume4\virtualbox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
18714074.33d4: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume4\virtualbox\Qt5WidgetsVBox.dll [lacks WinVerifyTrust]
18724074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
18734074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume4\virtualbox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
18744074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\Qt5GuiVBox.dll
18754074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
18764074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume4\virtualbox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
18774074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\Qt5CoreVBox.dll
18784074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
18794074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
18804074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
18814074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\virtualbox\vboxrt.dll' [rcNtRedir=0xc0150008]
18824074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
18834074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
18844074.33d4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0212~31bf3856ad364e35~amd64~~10.0.19041.572.cat'; file='\Device\HarddiskVolume3\Windows\System32\opengl32.dll'
18854074.33d4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
18864074.33d4: supR3HardenedScreenImage/Imports: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\opengl32.dll'
18874074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=F:\virtualbox\VirtualBoxVM.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000a01:<flags> [calling]
18884074.33d4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\VirtualBoxVM.dll
18894074.33d4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\opengl32.dll
18904074.33d4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\UICommon.dll
18914074.33d4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\Qt5CoreVBox.dll
18924074.33d4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\Qt5GuiVBox.dll
18934074.33d4: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume4\virtualbox\Qt5WidgetsVBox.dll [avoiding WinVerifyTrust]
18944074.33d4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\Qt5OpenGLVBox.dll
18954074.33d4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winmm.dll
18964074.33d4: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\glu32.dll [avoiding WinVerifyTrust]
18974074.33d4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\mpr.dll [avoiding WinVerifyTrust]
18984074.33d4: supR3HardenedDllNotificationCallback: load 00007ffaa9ff0000 LB 0x00022000 C:\Windows\System32\win32u.dll [fFlags=0x0]
18994074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\win32u.dll [avoiding WinVerifyTrust]
19004074.33d4: supR3HardenedDllNotificationCallback: load 00007ffaa9700000 LB 0x0009d000 C:\Windows\System32\msvcp_win.dll [fFlags=0x0]
19014074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcp_win.dll [avoiding WinVerifyTrust]
19024074.33d4: supR3HardenedDllNotificationCallback: load 00007ffaa9e30000 LB 0x00109000 C:\Windows\System32\gdi32full.dll [fFlags=0x0]
19034074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
19044074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #33 'gdi32.dll'.
19054074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #35 'user32.dll'.
19064074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #36 'win32u.dll'.
19074074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\gdi32full.dll)
19084074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\gdi32full.dll
19094074.33d4: supR3HardenedDllNotificationCallback: load 00007ffaaa8d0000 LB 0x0002a000 C:\Windows\System32\GDI32.dll [fFlags=0x0]
19104074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [avoiding WinVerifyTrust]
19114074.33d4: supR3HardenedDllNotificationCallback: load 00007ffaaa970000 LB 0x001a0000 C:\Windows\System32\USER32.dll [fFlags=0x0]
19124074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\user32.dll [avoiding WinVerifyTrust]
19134074.33d4: supR3HardenedDllNotificationCallback: load 00007ffaab560000 LB 0x00355000 C:\Windows\System32\combase.dll [fFlags=0x0]
19144074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\combase.dll [avoiding WinVerifyTrust]
19154074.33d4: supR3HardenedDllNotificationCallback: load 00007ffaa0470000 LB 0x0002c000 C:\Windows\SYSTEM32\GLU32.dll [fFlags=0x0]
19164074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\glu32.dll [avoiding WinVerifyTrust]
19174074.33d4: supR3HardenedDllNotificationCallback: load 00007ffa981c0000 LB 0x00125000 C:\Windows\SYSTEM32\OPENGL32.dll [fFlags=0x0]
19184074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\opengl32.dll
19194074.33d4: supR3HardenedDllNotificationCallback: load 00007ffaaae20000 LB 0x00740000 C:\Windows\System32\SHELL32.dll [fFlags=0x0]
19204074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\shell32.dll [avoiding WinVerifyTrust]
19214074.33d4: supR3HardenedDllNotificationCallback: load 00007ffaabb40000 LB 0x0012a000 C:\Windows\System32\ole32.dll [fFlags=0x0]
19224074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ole32.dll
19234074.33d4: supR3HardenedDllNotificationCallback: load 00007ffa8c1b0000 LB 0x0001d000 C:\Windows\SYSTEM32\MPR.dll [fFlags=0x0]
19244074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\mpr.dll [avoiding WinVerifyTrust]
19254074.33d4: supR3HardenedDllNotificationCallback: load 0000000074b00000 LB 0x00565000 F:\virtualbox\Qt5CoreVBox.dll [fFlags=0x0]
19264074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\Qt5CoreVBox.dll
19274074.33d4: supR3HardenedDllNotificationCallback: load 00007ffa2c160000 LB 0x005f7000 F:\virtualbox\Qt5GuiVBox.dll [fFlags=0x0]
19284074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\Qt5GuiVBox.dll
19294074.33d4: supR3HardenedDllNotificationCallback: load 0000000074590000 LB 0x00561000 F:\virtualbox\Qt5WidgetsVBox.dll [fFlags=0x0]
19304074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume4\virtualbox\Qt5WidgetsVBox.dll [avoiding WinVerifyTrust]
19314074.33d4: supR3HardenedDllNotificationCallback: load 00007ffaaa020000 LB 0x000cd000 C:\Windows\System32\OLEAUT32.dll [fFlags=0x0]
19324074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\oleaut32.dll
19334074.33d4: supR3HardenedDllNotificationCallback: load 00007ffa2cd40000 LB 0x02317000 F:\virtualbox\UICommon.dll [fFlags=0x0]
19344074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\UICommon.dll
19354074.33d4: supR3HardenedDllNotificationCallback: load 0000000075840000 LB 0x00054000 F:\virtualbox\Qt5OpenGLVBox.dll [fFlags=0x0]
19364074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\Qt5OpenGLVBox.dll
19374074.33d4: supR3HardenedDllNotificationCallback: load 00007ffa8ecb0000 LB 0x00027000 C:\Windows\SYSTEM32\WINMM.dll [fFlags=0x0]
19384074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winmm.dll
19394074.33d4: supR3HardenedDllNotificationCallback: load 00007ffa674f0000 LB 0x001c8000 F:\virtualbox\VirtualBoxVM.dll [fFlags=0x0]
19404074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\VirtualBoxVM.dll
19414074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll'.
19424074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll' [rescheduled]
19434074.33d4: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume3\Windows\System32\glu32.dll'.
19444074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\glu32.dll' [rescheduled]
19454074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\mpr.dll'.
19464074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\mpr.dll' [rescheduled]
19474074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\shell32.dll'.
19484074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\shell32.dll' [rescheduled]
19494074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\Qt5WidgetsVBox.dll'.
19504074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\Qt5WidgetsVBox.dll' [rescheduled]
19514074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\win32u.dll'.
19524074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rescheduled]
19534074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32.dll'.
19544074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rescheduled]
19554074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\user32.dll'.
19564074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rescheduled]
19574074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll'.
19584074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rescheduled]
19594074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\combase.dll'.
19604074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\combase.dll' [rescheduled]
19614074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\kernel32.dll
19624074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
19634074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
19644074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\win32u.dll [redoing WinVerifyTrust]
19654074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\win32u.dll'.
19664074.33d4: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume3\Windows\System32\win32u.dll
19674074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
19684074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
19694074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\user32.dll [redoing WinVerifyTrust]
19704074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\user32.dll'.
19714074.33d4: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume3\Windows\System32\user32.dll
19724074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
19734074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
19744074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [redoing WinVerifyTrust]
19754074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32.dll'.
19764074.33d4: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume3\Windows\System32\gdi32.dll
19774074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
19784074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
19794074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcp_win.dll [redoing WinVerifyTrust]
19804074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll'.
19814074.33d4: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume3\Windows\System32\msvcp_win.dll
19824074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\kernel32.dll (Input=kernel32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
19834074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaaab80000 'C:\Windows\System32\kernel32.dll'
19844074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll'.
19854074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll' [rescheduled]
19864074.33d4: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume3\Windows\System32\glu32.dll'.
19874074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\glu32.dll' [rescheduled]
19884074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\mpr.dll'.
19894074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\mpr.dll' [rescheduled]
19904074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\shell32.dll'.
19914074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\shell32.dll' [rescheduled]
19924074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\Qt5WidgetsVBox.dll'.
19934074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\Qt5WidgetsVBox.dll' [rescheduled]
19944074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\win32u.dll'.
19954074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rescheduled]
19964074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32.dll'.
19974074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rescheduled]
19984074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\user32.dll'.
19994074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rescheduled]
20004074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll'.
20014074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rescheduled]
20024074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\combase.dll'.
20034074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\combase.dll' [rescheduled]
20044074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll'.
20054074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll' [rescheduled]
20064074.33d4: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume3\Windows\System32\glu32.dll'.
20074074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\glu32.dll' [rescheduled]
20084074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\mpr.dll'.
20094074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\mpr.dll' [rescheduled]
20104074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\shell32.dll'.
20114074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\shell32.dll' [rescheduled]
20124074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\Qt5WidgetsVBox.dll'.
20134074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\Qt5WidgetsVBox.dll' [rescheduled]
20144074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\win32u.dll'.
20154074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rescheduled]
20164074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32.dll'.
20174074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rescheduled]
20184074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\user32.dll'.
20194074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rescheduled]
20204074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll'.
20214074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rescheduled]
20224074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\combase.dll'.
20234074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\combase.dll' [rescheduled]
20244074.33d4: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-string-l1-1-0) -> 0x0, fPresent=1
20254074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-string-l1-1-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
20264074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa9a80000 'api-ms-win-core-string-l1-1-0'
20274074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll'.
20284074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll' [rescheduled]
20294074.33d4: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume3\Windows\System32\glu32.dll'.
20304074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\glu32.dll' [rescheduled]
20314074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\mpr.dll'.
20324074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\mpr.dll' [rescheduled]
20334074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\shell32.dll'.
20344074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\shell32.dll' [rescheduled]
20354074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\Qt5WidgetsVBox.dll'.
20364074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\Qt5WidgetsVBox.dll' [rescheduled]
20374074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\win32u.dll'.
20384074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rescheduled]
20394074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32.dll'.
20404074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rescheduled]
20414074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\user32.dll'.
20424074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rescheduled]
20434074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll'.
20444074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rescheduled]
20454074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\combase.dll'.
20464074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\combase.dll' [rescheduled]
20474074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll'.
20484074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll' [rescheduled]
20494074.33d4: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume3\Windows\System32\glu32.dll'.
20504074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\glu32.dll' [rescheduled]
20514074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\mpr.dll'.
20524074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\mpr.dll' [rescheduled]
20534074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\shell32.dll'.
20544074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\shell32.dll' [rescheduled]
20554074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\Qt5WidgetsVBox.dll'.
20564074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\Qt5WidgetsVBox.dll' [rescheduled]
20574074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\win32u.dll'.
20584074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rescheduled]
20594074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32.dll'.
20604074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rescheduled]
20614074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\user32.dll'.
20624074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rescheduled]
20634074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll'.
20644074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rescheduled]
20654074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\combase.dll'.
20664074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\combase.dll' [rescheduled]
20674074.33d4: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-datetime-l1-1-1) -> 0x0, fPresent=1
20684074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-datetime-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
20694074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa9a80000 'api-ms-win-core-datetime-l1-1-1'
20704074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll'.
20714074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll' [rescheduled]
20724074.33d4: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume3\Windows\System32\glu32.dll'.
20734074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\glu32.dll' [rescheduled]
20744074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\mpr.dll'.
20754074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\mpr.dll' [rescheduled]
20764074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\shell32.dll'.
20774074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\shell32.dll' [rescheduled]
20784074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\Qt5WidgetsVBox.dll'.
20794074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\Qt5WidgetsVBox.dll' [rescheduled]
20804074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\win32u.dll'.
20814074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rescheduled]
20824074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32.dll'.
20834074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rescheduled]
20844074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\user32.dll'.
20854074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rescheduled]
20864074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll'.
20874074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rescheduled]
20884074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\combase.dll'.
20894074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\combase.dll' [rescheduled]
20904074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll'.
20914074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll' [rescheduled]
20924074.33d4: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume3\Windows\System32\glu32.dll'.
20934074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\glu32.dll' [rescheduled]
20944074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\mpr.dll'.
20954074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\mpr.dll' [rescheduled]
20964074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\shell32.dll'.
20974074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\shell32.dll' [rescheduled]
20984074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\Qt5WidgetsVBox.dll'.
20994074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\Qt5WidgetsVBox.dll' [rescheduled]
21004074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\win32u.dll'.
21014074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rescheduled]
21024074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32.dll'.
21034074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rescheduled]
21044074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\user32.dll'.
21054074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rescheduled]
21064074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll'.
21074074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rescheduled]
21084074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\combase.dll'.
21094074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\combase.dll' [rescheduled]
21104074.33d4: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-obsolete-l1-2-0) -> 0x0, fPresent=1
21114074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-obsolete-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
21124074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa9a80000 'api-ms-win-core-localization-obsolete-l1-2-0'
21134074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll'.
21144074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll' [rescheduled]
21154074.33d4: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume3\Windows\System32\glu32.dll'.
21164074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\glu32.dll' [rescheduled]
21174074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\mpr.dll'.
21184074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\mpr.dll' [rescheduled]
21194074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\shell32.dll'.
21204074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\shell32.dll' [rescheduled]
21214074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\Qt5WidgetsVBox.dll'.
21224074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\Qt5WidgetsVBox.dll' [rescheduled]
21234074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\win32u.dll'.
21244074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rescheduled]
21254074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32.dll'.
21264074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rescheduled]
21274074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\user32.dll'.
21284074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rescheduled]
21294074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll'.
21304074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rescheduled]
21314074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\combase.dll'.
21324074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\combase.dll' [rescheduled]
21334074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll'.
21344074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll' [rescheduled]
21354074.33d4: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume3\Windows\System32\glu32.dll'.
21364074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\glu32.dll' [rescheduled]
21374074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\mpr.dll'.
21384074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\mpr.dll' [rescheduled]
21394074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\shell32.dll'.
21404074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\shell32.dll' [rescheduled]
21414074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\Qt5WidgetsVBox.dll'.
21424074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\Qt5WidgetsVBox.dll' [rescheduled]
21434074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\win32u.dll'.
21444074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rescheduled]
21454074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32.dll'.
21464074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rescheduled]
21474074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\user32.dll'.
21484074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rescheduled]
21494074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll'.
21504074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rescheduled]
21514074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\combase.dll'.
21524074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\combase.dll' [rescheduled]
21534074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\imm32.dll'.
21544074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'user32.dll'.
21554074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'win32u.dll'.
21564074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\imm32.dll)
21574074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\imm32.dll
21584074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
21594074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
21604074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\win32u.dll [redoing WinVerifyTrust]
21614074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\win32u.dll'.
21624074.33d4: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume3\Windows\System32\win32u.dll
21634074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
21644074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
21654074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\user32.dll [redoing WinVerifyTrust]
21664074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\user32.dll'.
21674074.33d4: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume3\Windows\System32\user32.dll
21684074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\IMM32.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
21694074.33d4: supR3HardenedDllNotificationCallback: load 00007ffaaadf0000 LB 0x00030000 C:\Windows\System32\IMM32.DLL [fFlags=0x0]
21704074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\imm32.dll [avoiding WinVerifyTrust]
21714074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaaadf0000 'C:\Windows\system32\IMM32.DLL'
21724074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\imm32.dll'.
21734074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\imm32.dll' [rescheduled]
21744074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll'.
21754074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll' [rescheduled]
21764074.33d4: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume3\Windows\System32\glu32.dll'.
21774074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\glu32.dll' [rescheduled]
21784074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\mpr.dll'.
21794074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\mpr.dll' [rescheduled]
21804074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\shell32.dll'.
21814074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\shell32.dll' [rescheduled]
21824074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\Qt5WidgetsVBox.dll'.
21834074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\Qt5WidgetsVBox.dll' [rescheduled]
21844074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\win32u.dll'.
21854074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rescheduled]
21864074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32.dll'.
21874074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rescheduled]
21884074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\user32.dll'.
21894074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rescheduled]
21904074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll'.
21914074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rescheduled]
21924074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\combase.dll'.
21934074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\combase.dll' [rescheduled]
21944074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\imm32.dll'.
21954074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\imm32.dll' [rescheduled]
21964074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll'.
21974074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll' [rescheduled]
21984074.33d4: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume3\Windows\System32\glu32.dll'.
21994074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\glu32.dll' [rescheduled]
22004074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\mpr.dll'.
22014074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\mpr.dll' [rescheduled]
22024074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\shell32.dll'.
22034074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\shell32.dll' [rescheduled]
22044074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\Qt5WidgetsVBox.dll'.
22054074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\Qt5WidgetsVBox.dll' [rescheduled]
22064074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\win32u.dll'.
22074074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rescheduled]
22084074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32.dll'.
22094074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rescheduled]
22104074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\user32.dll'.
22114074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rescheduled]
22124074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll'.
22134074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rescheduled]
22144074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\combase.dll'.
22154074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\combase.dll' [rescheduled]
22164074.33d4: supR3HardenedMonitor_LdrLoadDll: error opening 'C:\Windows\System32\edgegdi.dll': 0 (NtPath=\??\C:\Windows\System32\edgegdi.dll; Input=edgegdi.dll; rcNtGetDll=0xc0000135
22174074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000034 'C:\Windows\System32\edgegdi.dll'
22184074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\imm32.dll'.
22194074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\imm32.dll' [rescheduled]
22204074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll'.
22214074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll' [rescheduled]
22224074.33d4: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume3\Windows\System32\glu32.dll'.
22234074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\glu32.dll' [rescheduled]
22244074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\mpr.dll'.
22254074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\mpr.dll' [rescheduled]
22264074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\shell32.dll'.
22274074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\shell32.dll' [rescheduled]
22284074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\Qt5WidgetsVBox.dll'.
22294074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\Qt5WidgetsVBox.dll' [rescheduled]
22304074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\win32u.dll'.
22314074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rescheduled]
22324074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32.dll'.
22334074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rescheduled]
22344074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\user32.dll'.
22354074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rescheduled]
22364074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll'.
22374074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rescheduled]
22384074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\combase.dll'.
22394074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\combase.dll' [rescheduled]
22404074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\advapi32.dll
22414074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\ADVAPI32.DLL (Input=ADVAPI32.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
22424074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaaa740000 'C:\Windows\System32\ADVAPI32.DLL'
22434074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\imm32.dll'.
22444074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\imm32.dll' [rescheduled]
22454074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll'.
22464074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll' [rescheduled]
22474074.33d4: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume3\Windows\System32\glu32.dll'.
22484074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\glu32.dll' [rescheduled]
22494074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\mpr.dll'.
22504074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\mpr.dll' [rescheduled]
22514074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\shell32.dll'.
22524074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\shell32.dll' [rescheduled]
22534074.33d4: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume4\virtualbox\Qt5WidgetsVBox.dll'.
22544074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\virtualbox\Qt5WidgetsVBox.dll' [rescheduled]
22554074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\win32u.dll'.
22564074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rescheduled]
22574074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32.dll'.
22584074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rescheduled]
22594074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\user32.dll'.
22604074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rescheduled]
22614074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll'.
22624074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rescheduled]
22634074.33d4: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\combase.dll'.
22644074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\combase.dll' [rescheduled]
22654074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa674f0000 'F:\virtualbox\VirtualBoxVM.dll'
22664074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
22674074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
22684074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\imm32.dll'
22694074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
22704074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
22714074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll'
22724074.33d4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000468 pwszName=\Device\HarddiskVolume3\Windows\System32\glu32.dll
22734074.33d4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000cce4d0
22744074.33d4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000cce4d0
22754074.33d4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=087A92E70231A784DB8F333F449EAE73CA72A5AC
22764074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
22774074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
22784074.33d4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0212~31bf3856ad364e35~amd64~~10.0.19041.572.cat'; file='\Device\HarddiskVolume3\Windows\System32\glu32.dll'
22794074.33d4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
22804074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\glu32.dll'
22814074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
22824074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
22834074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\mpr.dll'
22844074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
22854074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
22864074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\shell32.dll'
22874074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
22884074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 24202) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\virtualbox\Qt5WidgetsVBox.dll'
22894074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
22904074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
22914074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\win32u.dll'
22924074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
22934074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
22944074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\gdi32.dll'
22954074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
22964074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
22974074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\user32.dll'
22984074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
22994074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
23004074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll'
23014074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
23024074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
23034074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\combase.dll'
23044074.33d4: SUPR3HardenedMain: Calling TrustedMain (00007ffa674f16c0)...
23054074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #31 'combase.dll'.
23064074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #32 'msvcp_win.dll'.
23074074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #34 'wldp.dll'.
23084074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\windows.storage.dll)
23094074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\windows.storage.dll
23104074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
23114074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\wldp.dll)
23124074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\wldp.dll
23134074.33d4: supR3HardenedDllNotificationCallback: load 00007ffaa8fd0000 LB 0x0002c000 C:\Windows\SYSTEM32\Wldp.dll [fFlags=0x0]
23144074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wldp.dll [avoiding WinVerifyTrust]
23154074.33d4: supR3HardenedDllNotificationCallback: load 00007ffaa7280000 LB 0x00794000 C:\Windows\SYSTEM32\windows.storage.dll [fFlags=0x0]
23164074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\windows.storage.dll [avoiding WinVerifyTrust]
23174074.33d4: supR3HardenedDllNotificationCallback: load 00007ffaaba70000 LB 0x000ae000 C:\Windows\System32\SHCORE.dll [fFlags=0x0]
23184074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
23194074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #42 'combase.dll'.
23204074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\SHCore.dll)
23214074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\SHCore.dll
23224074.33d4: supR3HardenedDllNotificationCallback: load 00007ffaaab10000 LB 0x00055000 C:\Windows\System32\shlwapi.dll [fFlags=0x0]
23234074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
23244074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\shlwapi.dll)
23254074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\shlwapi.dll
23264074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
23274074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
23284074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll
23294074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
23304074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume3\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
23314074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\combase.dll
23324074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
23334074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
23344074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
23354074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
23364074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wldp.dll'...
23374074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'wldp.dll' -> '\Device\HarddiskVolume3\Windows\System32\wldp.dll' [rcNtRedir=0xc0150008]
23384074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wldp.dll [lacks WinVerifyTrust]
23394074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
23404074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
23414074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcp_win.dll
23424074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
23434074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume3\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
23444074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\combase.dll
23454074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
23464074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
23474074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\shlwapi.dll'
23484074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
23494074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
23504074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\SHCore.dll'
23514074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
23524074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
23534074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\wldp.dll'
23544074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
23554074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
23564074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\windows.storage.dll'
23574074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
23584074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
23594074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'ole32.dll'.
23604074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
23614074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'imm32.dll'.
23624074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'winmm.dll'.
23634074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'oleaut32.dll'.
23644074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'shell32.dll'.
23654074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'advapi32.dll'.
23664074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'qt5guivbox.dll'.
23674074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'qt5corevbox.dll'.
23684074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'msvcr100.dll'.
23694074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\virtualbox\platforms\qwindows.dll) WinVerifyTrust
23704074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\virtualbox\platforms\qwindows.dll
23714074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
23724074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
23734074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
23744074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume4\virtualbox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
23754074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\Qt5CoreVBox.dll
23764074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
23774074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume4\virtualbox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
23784074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\Qt5GuiVBox.dll
23794074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
23804074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
23814074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\advapi32.dll
23824074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
23834074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume3\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
23844074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\shell32.dll
23854074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
23864074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume3\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
23874074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\oleaut32.dll
23884074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
23894074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume3\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
23904074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winmm.dll
23914074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
23924074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume3\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
23934074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\imm32.dll
23944074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
23954074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
23964074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
23974074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
23984074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ole32.dll
23994074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
24004074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
24014074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=F:\virtualbox\platforms\qwindows.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
24024074.33d4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\platforms\qwindows.dll
24034074.33d4: supR3HardenedDllNotificationCallback: load 00007ffa541d0000 LB 0x0012e000 F:\virtualbox\platforms\qwindows.dll [fFlags=0x0]
24044074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\platforms\qwindows.dll
24054074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa541d0000 'F:\virtualbox\platforms\qwindows.dll'
24064074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'msvcrt.dll'.
24074074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'rpcrt4.dll'.
24084074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\kernel.appcore.dll)
24094074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\kernel.appcore.dll
24104074.33d4: supR3HardenedDllNotificationCallback: load 00007ffaa83b0000 LB 0x00012000 C:\Windows\SYSTEM32\kernel.appcore.dll [fFlags=0x0]
24114074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\kernel.appcore.dll [avoiding WinVerifyTrust]
24124074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
24134074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
24144074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
24154074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
24164074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
24174074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
24184074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\kernel.appcore.dll'
24194074.33d4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000005c8 pwszName=\Device\HarddiskVolume3\Windows\System32\uxtheme.dll
24204074.33d4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000cce4d0
24214074.33d4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000cce4d0
24224074.33d4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=24C36BDDBF70FC15AF1BBA02DB55AE15854E94AD
24234074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
24244074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
24254074.33d4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0419~31bf3856ad364e35~amd64~~10.0.19041.572.cat'; file='\Device\HarddiskVolume3\Windows\System32\uxtheme.dll'
24264074.33d4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
24274074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
24284074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #33 'gdi32.dll'.
24294074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #34 'user32.dll'.
24304074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\uxtheme.dll) WinVerifyTrust
24314074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\uxtheme.dll
24324074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
24334074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
24344074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
24354074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
24364074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
24374074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
24384074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
24394074.33d4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\uxtheme.dll
24404074.33d4: supR3HardenedDllNotificationCallback: load 00007ffaa6c50000 LB 0x0009f000 C:\Windows\system32\uxtheme.dll [fFlags=0x0]
24414074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\uxtheme.dll
24424074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa6c50000 'C:\Windows\system32\uxtheme.dll'
24434074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaaa970000 'C:\Windows\system32\user32.dll'
24444074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\shell32.dll
24454074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
24464074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaaae20000 'C:\Windows\system32\shell32.dll'
24474074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\SHCore.dll
24484074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\SHCore.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
24494074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaaba70000 'C:\Windows\system32\SHCore.dll'
24504074.33d4: supR3HardenedMonitor_LdrLoadDll: error opening 'C:\Windows\system32\wintab32.dll': 0 (NtPath=\??\C:\Windows\system32\wintab32.dll; Input=C:\Windows\system32\wintab32.dll; rcNtGetDll=0x0
24514074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000034 'C:\Windows\system32\wintab32.dll'
24524074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winmm.dll
24534074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\winmm.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
24544074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa8ecb0000 'C:\Windows\system32\winmm.dll'
24554074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winmm.dll
24564074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\winmm.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
24574074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa8ecb0000 'C:\Windows\system32\winmm.dll'
24584074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\shell32.dll
24594074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
24604074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaaae20000 'C:\Windows\system32\shell32.dll'
24614074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\uxtheme.dll
24624074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
24634074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa6c50000 'C:\Windows\system32\uxtheme.dll'
24644074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\advapi32.dll
24654074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\advapi32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
24664074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaaa740000 'C:\Windows\system32\advapi32.dll'
24674074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
24684074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
24694074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'rpcrt4.dll'.
24704074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\userenv.dll) WinVerifyTrust
24714074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\userenv.dll
24724074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
24734074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
24744074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\userenv.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
24754074.33d4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\userenv.dll
24764074.33d4: supR3HardenedDllNotificationCallback: load 00007ffaa95f0000 LB 0x0002e000 C:\Windows\system32\userenv.dll [fFlags=0x0]
24774074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\userenv.dll
24784074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa95f0000 'C:\Windows\system32\userenv.dll'
24794074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\kernel32.dll
24804074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\kernel32.dll (Input=kernel32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
24814074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaaab80000 'C:\Windows\System32\kernel32.dll'
24824074.33d4: supR3HardenedDllNotificationCallback: load 00007ffaabec0000 LB 0x000a9000 C:\Windows\System32\clbcatq.dll [fFlags=0x0]
24834074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
24844074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #30 'rpcrt4.dll'.
24854074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\clbcatq.dll)
24864074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\clbcatq.dll
24874074.40fc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll
24884074.40fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
24894074.40fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
24904074.40fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
24914074.40fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
24924074.40fc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
24934074.40fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
24944074.40fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
24954074.40fc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\clbcatq.dll'
24964074.40fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
24974074.40fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
24984074.40fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
24994074.40fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
25004074.40fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
25014074.40fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ole32.dll'.
25024074.40fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'oleaut32.dll'.
25034074.40fc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\virtualbox\VBoxC.dll) WinVerifyTrust
25044074.40fc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\virtualbox\VBoxC.dll
25054074.40fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
25064074.40fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume3\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
25074074.40fc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\oleaut32.dll
25084074.40fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
25094074.40fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
25104074.40fc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ole32.dll
25114074.40fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
25124074.40fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
25134074.40fc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\advapi32.dll
25144074.40fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
25154074.40fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\virtualbox\vboxrt.dll' [rcNtRedir=0xc0150008]
25164074.40fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
25174074.40fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume4\virtualbox\msvcp100.dll' [rcNtRedir=0xc0150008]
25184074.40fc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\msvcp100.dll
25194074.40fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
25204074.40fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
25214074.40fc: supR3HardenedMonitor_LdrLoadDll: pName=F:\virtualbox\VBoxC.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
25224074.40fc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\VBoxC.dll
25234074.40fc: supR3HardenedDllNotificationCallback: load 00007ffa45330000 LB 0x003c0000 F:\virtualbox\VBoxC.dll [fFlags=0x0]
25244074.40fc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\VBoxC.dll
25254074.40fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa45330000 'F:\virtualbox\VBoxC.dll'
25264074.40fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
25274074.40fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
25284074.40fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
25294074.40fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
25304074.40fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'shlwapi.dll'.
25314074.40fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ole32.dll'.
25324074.40fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'oleaut32.dll'.
25334074.40fc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
25344074.40fc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\virtualbox\VBoxProxyStub.dll) WinVerifyTrust
25354074.40fc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\virtualbox\VBoxProxyStub.dll
25364074.40fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
25374074.40fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
25384074.40fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
25394074.40fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume3\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
25404074.40fc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\oleaut32.dll
25414074.40fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
25424074.40fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
25434074.40fc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ole32.dll
25444074.40fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
25454074.40fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
25464074.40fc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\shlwapi.dll
25474074.40fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
25484074.40fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
25494074.40fc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\advapi32.dll
25504074.40fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
25514074.40fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\virtualbox\vboxrt.dll' [rcNtRedir=0xc0150008]
25524074.40fc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
25534074.40fc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
25544074.40fc: supR3HardenedMonitor_LdrLoadDll: pName=F:\virtualbox\VBoxProxyStub.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
25554074.40fc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\VBoxProxyStub.dll
25564074.40fc: supR3HardenedDllNotificationCallback: load 00007ffa540e0000 LB 0x000ef000 F:\virtualbox\VBoxProxyStub.dll [fFlags=0x0]
25574074.40fc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\VBoxProxyStub.dll
25584074.40fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa540e0000 'F:\virtualbox\VBoxProxyStub.dll'
25594074.40fc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\oleaut32.dll
25604074.40fc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\oleaut32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
25614074.40fc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaaa020000 'C:\Windows\System32\oleaut32.dll'
25624074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaaa8d0000 'C:\Windows\system32\gdi32.dll'
25634074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\shell32.dll
25644074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
25654074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaaae20000 'C:\Windows\system32\shell32.dll'
25664074.33d4: supR3HardenedDllNotificationCallback: load 00007ffaabce0000 LB 0x00115000 C:\Windows\System32\MSCTF.dll [fFlags=0x0]
25674074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
25684074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'oleaut32.dll'.
25694074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #36 'user32.dll'.
25704074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #37 'gdi32.dll'.
25714074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #38 'imm32.dll'.
25724074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\msctf.dll)
25734074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\msctf.dll
25744074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
25754074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume3\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
25764074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\imm32.dll
25774074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
25784074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
25794074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
25804074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
25814074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
25824074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume3\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
25834074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\oleaut32.dll
25844074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
25854074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
25864074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
25874074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
25884074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\msctf.dll'
25894074.33d4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000960 pwszName=\Device\HarddiskVolume3\Windows\System32\DataExchange.dll
25904074.33d4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000cce4d0
25914074.33d4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000cce4d0
25924074.33d4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=783F5D82A4B979F1AE8853415E4264F3E2314DE6
25934074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
25944074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
25954074.33d4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0410~31bf3856ad364e35~amd64~~10.0.19041.572.cat'; file='\Device\HarddiskVolume3\Windows\System32\DataExchange.dll'
25964074.33d4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
25974074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
25984074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'd3d11.dll'.
25994074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #27 'dcomp.dll'.
26004074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\DataExchange.dll) WinVerifyTrust
26014074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\DataExchange.dll
26024074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dcomp.dll'...
26034074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'dcomp.dll' -> '\Device\HarddiskVolume3\Windows\System32\dcomp.dll' [rcNtRedir=0xc0150008]
26044074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
26054074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
26064074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'win32u.dll'.
26074074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp_win.dll'.
26084074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\dcomp.dll) WinVerifyTrust
26094074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\dcomp.dll
26104074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'd3d11.dll'...
26114074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'd3d11.dll' -> '\Device\HarddiskVolume3\Windows\System32\d3d11.dll' [rcNtRedir=0xc0150008]
26124074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
26134074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
26144074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcp_win.dll
26154074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
26164074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
26174074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\win32u.dll
26184074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
26194074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
26204074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
26214074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'dxgi.dll'.
26224074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #28 'win32u.dll'.
26234074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\d3d11.dll) WinVerifyTrust
26244074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\d3d11.dll
26254074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
26264074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
26274074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
26284074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
26294074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\win32u.dll
26304074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dxgi.dll'...
26314074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'dxgi.dll' -> '\Device\HarddiskVolume3\Windows\System32\dxgi.dll' [rcNtRedir=0xc0150008]
26324074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
26334074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
26344074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
26354074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'win32u.dll'.
26364074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\dxgi.dll) WinVerifyTrust
26374074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\dxgi.dll
26384074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
26394074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
26404074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll
26414074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
26424074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
26434074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\win32u.dll
26444074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
26454074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
26464074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\dataexchange.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
26474074.33d4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\DataExchange.dll
26484074.33d4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\d3d11.dll
26494074.33d4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\dcomp.dll
26504074.33d4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\dxgi.dll
26514074.33d4: supR3HardenedDllNotificationCallback: load 00007ffaa7da0000 LB 0x000f3000 C:\Windows\system32\dxgi.dll [fFlags=0x0]
26524074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\dxgi.dll
26534074.33d4: supR3HardenedDllNotificationCallback: load 00007ffaa5980000 LB 0x00264000 C:\Windows\system32\d3d11.dll [fFlags=0x0]
26544074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\d3d11.dll
26554074.33d4: supR3HardenedDllNotificationCallback: load 00007ffaa5bf0000 LB 0x001e5000 C:\Windows\system32\dcomp.dll [fFlags=0x0]
26564074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\dcomp.dll
26574074.33d4: supR3HardenedDllNotificationCallback: load 00007ffa96880000 LB 0x0003e000 C:\Windows\system32\dataexchange.dll [fFlags=0x0]
26584074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\DataExchange.dll
26594074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaaa8d0000 'C:\Windows\System32\gdi32.dll'
26604074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa96880000 'C:\Windows\system32\dataexchange.dll'
26614074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #30 'rpcrt4.dll'.
26624074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #43 'combase.dll'.
26634074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #45 'msvcp_win.dll'.
26644074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\twinapi.appcore.dll)
26654074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\twinapi.appcore.dll
26664074.33d4: supR3HardenedDllNotificationCallback: load 00007ffaa2400000 LB 0x00208000 C:\Windows\system32\twinapi.appcore.dll [fFlags=0x0]
26674074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\twinapi.appcore.dll [avoiding WinVerifyTrust]
26684074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
26694074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
26704074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcp_win.dll
26714074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
26724074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume3\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
26734074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\combase.dll
26744074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
26754074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
26764074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll
26774074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
26784074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
26794074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\twinapi.appcore.dll'
26804074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\SHCore.dll
26814074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\Shcore.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
26824074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaaba70000 'C:\Windows\system32\Shcore.dll'
26834074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
26844074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #15 'oleaut32.dll'.
26854074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'rpcrt4.dll'.
26864074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #20 'coreuicomponents.dll'.
26874074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #21 'coremessaging.dll'.
26884074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\TextInputFramework.dll)
26894074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\TextInputFramework.dll
26904074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
26914074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #35 'coremessaging.dll'.
26924074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #40 'rpcrt4.dll'.
26934074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #48 'shcore.dll'.
26944074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\CoreUIComponents.dll)
26954074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\CoreUIComponents.dll
26964074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
26974074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #20 'ws2_32.dll'.
26984074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\CoreMessaging.dll)
26994074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\CoreMessaging.dll
27004074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\ntmarta.dll)
27014074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\ntmarta.dll
27024074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'combase.dll'.
27034074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #24 'rpcrt4.dll'.
27044074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #32 'bcryptprimitives.dll'.
27054074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\WinTypes.dll)
27064074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\WinTypes.dll
27074074.33d4: supR3HardenedDllNotificationCallback: load 00007ffaa8400000 LB 0x00033000 C:\Windows\SYSTEM32\ntmarta.dll [fFlags=0x0]
27084074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ntmarta.dll [avoiding WinVerifyTrust]
27094074.33d4: supR3HardenedDllNotificationCallback: load 00007ffaa6140000 LB 0x000f2000 C:\Windows\System32\CoreMessaging.dll [fFlags=0x0]
27104074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\CoreMessaging.dll [avoiding WinVerifyTrust]
27114074.33d4: supR3HardenedDllNotificationCallback: load 00007ffaa4dd0000 LB 0x00156000 C:\Windows\SYSTEM32\wintypes.dll [fFlags=0x0]
27124074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\WinTypes.dll [avoiding WinVerifyTrust]
27134074.33d4: supR3HardenedDllNotificationCallback: load 00007ffaa5de0000 LB 0x0035e000 C:\Windows\System32\CoreUIComponents.dll [fFlags=0x0]
27144074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\CoreUIComponents.dll [avoiding WinVerifyTrust]
27154074.33d4: supR3HardenedDllNotificationCallback: load 00007ffa99270000 LB 0x000fc000 C:\Windows\SYSTEM32\textinputframework.dll [fFlags=0x0]
27164074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\TextInputFramework.dll [avoiding WinVerifyTrust]
27174074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcryptprimitives.dll'...
27184074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcryptprimitives.dll' -> '\Device\HarddiskVolume3\Windows\System32\bcryptprimitives.dll' [rcNtRedir=0xc0150008]
27194074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\bcryptprimitives.dll
27204074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
27214074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
27224074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
27234074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume3\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
27244074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\combase.dll
27254074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
27264074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
27274074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ws2_32.dll
27284074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
27294074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
27304074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shcore.dll'...
27314074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'shcore.dll' -> '\Device\HarddiskVolume3\Windows\System32\shcore.dll' [rcNtRedir=0xc0150008]
27324074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\SHCore.dll
27334074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
27344074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
27354074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'coremessaging.dll'...
27364074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'coremessaging.dll' -> '\Device\HarddiskVolume3\Windows\System32\coremessaging.dll' [rcNtRedir=0xc0150008]
27374074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\CoreMessaging.dll [lacks WinVerifyTrust]
27384074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
27394074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
27404074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'coremessaging.dll'...
27414074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'coremessaging.dll' -> '\Device\HarddiskVolume3\Windows\System32\coremessaging.dll' [rcNtRedir=0xc0150008]
27424074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\CoreMessaging.dll [lacks WinVerifyTrust]
27434074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'coreuicomponents.dll'...
27444074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'coreuicomponents.dll' -> '\Device\HarddiskVolume3\Windows\System32\coreuicomponents.dll' [rcNtRedir=0xc0150008]
27454074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\CoreUIComponents.dll [lacks WinVerifyTrust]
27464074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
27474074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
27484074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
27494074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume3\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
27504074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\oleaut32.dll
27514074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
27524074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
27534074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
27544074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
27554074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\WinTypes.dll'
27564074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
27574074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
27584074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\ntmarta.dll'
27594074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
27604074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
27614074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\CoreMessaging.dll'
27624074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
27634074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
27644074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\CoreUIComponents.dll'
27654074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
27664074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
27674074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\TextInputFramework.dll'
27684074.33d4: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(ext-ms-win-rtcore-ntuser-window-ext-l1-1-0.dll) -> 0x0, fPresent=1
27694074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=ext-ms-win-rtcore-ntuser-window-ext-l1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
27704074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaaa970000 'ext-ms-win-rtcore-ntuser-window-ext-l1-1-0.dll'
27714074.33d4: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(ext-ms-win-rtcore-ntuser-integration-l1-1-0.dll) -> 0x0, fPresent=1
27724074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=ext-ms-win-rtcore-ntuser-integration-l1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
27734074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaaa970000 'ext-ms-win-rtcore-ntuser-integration-l1-1-0.dll'
27744074.33d4: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-com-l1-1-0.dll) -> 0x0, fPresent=1
27754074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-com-l1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
27764074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaab560000 'api-ms-win-core-com-l1-1-0.dll'
27774074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msctf.dll
27784074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\MSCTF.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
27794074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaabce0000 'C:\Windows\System32\MSCTF.dll'
27804074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
27814074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll
27824074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
27834074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
27844074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
27854074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #20 'win32u.dll'.
27864074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #21 'user32.dll'.
27874074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #22 'gdi32.dll'.
27884074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\dwmapi.dll) WinVerifyTrust
27894074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\dwmapi.dll
27904074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
27914074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
27924074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
27934074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
27944074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\user32.dll
27954074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
27964074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
27974074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
27984074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
27994074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\dwmapi.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
28004074.33d4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\dwmapi.dll
28014074.33d4: supR3HardenedDllNotificationCallback: load 00007ffaa6e30000 LB 0x0002f000 C:\Windows\system32\dwmapi.dll [fFlags=0x0]
28024074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\dwmapi.dll
28034074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa6e30000 'C:\Windows\system32\dwmapi.dll'
28044074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\uxtheme.dll
28054074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
28064074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa6c50000 'C:\Windows\system32\uxtheme.dll'
28074074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
28084074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\TextShaping.dll)
28094074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\TextShaping.dll
28104074.33d4: supR3HardenedDllNotificationCallback: load 00007ffa93ec0000 LB 0x000ac000 C:\Windows\SYSTEM32\TextShaping.dll [fFlags=0x0]
28114074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\TextShaping.dll [avoiding WinVerifyTrust]
28124074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
28134074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
28144074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
28154074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
28164074.33d4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\TextShaping.dll'
28174074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\dwmapi.dll
28184074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\dwmapi.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
28194074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa6e30000 'C:\Windows\System32\dwmapi.dll'
28204074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ole32.dll
28214074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\ole32.dll (Input=ole32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
28224074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaabb40000 'C:\Windows\System32\ole32.dll'
28234074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaaa020000 'C:\Windows\System32\OLEAUT32.dll'
28244074.33d4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000aac pwszName=\Device\HarddiskVolume3\Windows\System32\wbem\wbemprox.dll
28254074.33d4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000cce4d0
28264074.33d4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000cce4d0
28274074.33d4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=707DD50B09AF532CC60D811EEEFB525036D0EC3B
28284074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
28294074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
28304074.33d4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package03~31bf3856ad364e35~amd64~~10.0.19041.572.cat'; file='\Device\HarddiskVolume3\Windows\System32\wbem\wbemprox.dll'
28314074.33d4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
28324074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
28334074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ws2_32.dll'.
28344074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'wbemcomn.dll'.
28354074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\wbem\wbemprox.dll) WinVerifyTrust
28364074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\wbem\wbemprox.dll
28374074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wbemcomn.dll'...
28384074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'wbemcomn.dll' -> '\Device\HarddiskVolume3\Windows\System32\wbemcomn.dll' [rcNtRedir=0xc0150008]
28394074.33d4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000ab4 pwszName=\Device\HarddiskVolume3\Windows\System32\wbemcomn.dll
28404074.33d4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000cce4d0
28414074.33d4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000cce4d0
28424074.33d4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=C300CB1A203662154729906A10B05CEE85D4742B
28434074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
28444074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
28454074.33d4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package03~31bf3856ad364e35~amd64~~10.0.19041.572.cat'; file='\Device\HarddiskVolume3\Windows\System32\wbemcomn.dll'
28464074.33d4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
28474074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
28484074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\wbemcomn.dll) WinVerifyTrust
28494074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\wbemcomn.dll
28504074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
28514074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
28524074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ws2_32.dll
28534074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
28544074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
28554074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
28564074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
28574074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wbem\wbemprox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
28584074.33d4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wbem\wbemprox.dll
28594074.33d4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wbemcomn.dll
28604074.33d4: supR3HardenedDllNotificationCallback: load 00007ffa93cd0000 LB 0x00086000 C:\Windows\SYSTEM32\wbemcomn.dll [fFlags=0x0]
28614074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wbemcomn.dll
28624074.33d4: supR3HardenedDllNotificationCallback: load 00007ffa89df0000 LB 0x00011000 C:\Windows\system32\wbem\wbemprox.dll [fFlags=0x0]
28634074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wbem\wbemprox.dll
28644074.33d4: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(API-MS-Win-Core-LocalRegistry-L1-1-0.dll) -> 0x0, fPresent=1
28654074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Core-LocalRegistry-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
28664074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa9a80000 'API-MS-Win-Core-LocalRegistry-L1-1-0.dll'
28674074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa89df0000 'C:\Windows\system32\wbem\wbemprox.dll'
28684074.33d4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000a9c pwszName=\Device\HarddiskVolume3\Windows\System32\wbem\wbemsvc.dll
28694074.33d4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000cce4d0
28704074.33d4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000cce4d0
28714074.33d4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=3CFF11F3C684911C4E61C8117C8CEB7CBDC749CB
28724074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
28734074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
28744074.33d4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package03~31bf3856ad364e35~amd64~~10.0.19041.572.cat'; file='\Device\HarddiskVolume3\Windows\System32\wbem\wbemsvc.dll'
28754074.33d4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
28764074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
28774074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'rpcrt4.dll'.
28784074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\wbem\wbemsvc.dll) WinVerifyTrust
28794074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\wbem\wbemsvc.dll
28804074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
28814074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
28824074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
28834074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
28844074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wbem\wbemsvc.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
28854074.33d4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wbem\wbemsvc.dll
28864074.33d4: supR3HardenedDllNotificationCallback: load 00007ffa89e40000 LB 0x00014000 C:\Windows\system32\wbem\wbemsvc.dll [fFlags=0x0]
28874074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wbem\wbemsvc.dll
28884074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa89e40000 'C:\Windows\system32\wbem\wbemsvc.dll'
28894074.33d4: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-l1-2-0.dll) -> 0x0, fPresent=1
28904074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-l1-2-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
28914074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa9a80000 'api-ms-win-core-localization-l1-2-0.dll'
28924074.33d4: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-obsolete-l1-1-0.dll) -> 0x0, fPresent=1
28934074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-obsolete-l1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
28944074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa9a80000 'api-ms-win-core-localization-obsolete-l1-1-0.dll'
28954074.33d4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000aa8 pwszName=\Device\HarddiskVolume3\Windows\System32\wbem\fastprox.dll
28964074.33d4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000cce4d0
28974074.33d4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000cce4d0
28984074.33d4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=184DC69A17259EC62BC6A74793DCE28D7CC5A1AC
28994074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
29004074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
29014074.33d4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package03~31bf3856ad364e35~amd64~~10.0.19041.572.cat'; file='\Device\HarddiskVolume3\Windows\System32\wbem\fastprox.dll'
29024074.33d4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
29034074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
29044074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #20 'wbemcomn.dll'.
29054074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\wbem\fastprox.dll) WinVerifyTrust
29064074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\wbem\fastprox.dll
29074074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wbemcomn.dll'...
29084074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'wbemcomn.dll' -> '\Device\HarddiskVolume3\Windows\System32\wbemcomn.dll' [rcNtRedir=0xc0150008]
29094074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wbemcomn.dll
29104074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
29114074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
29124074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wbem\fastprox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
29134074.33d4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wbem\fastprox.dll
29144074.33d4: supR3HardenedDllNotificationCallback: load 00007ffa88ee0000 LB 0x0010b000 C:\Windows\system32\wbem\fastprox.dll [fFlags=0x0]
29154074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wbem\fastprox.dll
29164074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa88ee0000 'C:\Windows\system32\wbem\fastprox.dll'
29174074.33d4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000ad0 pwszName=\Device\HarddiskVolume3\Windows\System32\amsi.dll
29184074.33d4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000cce4d0
29194074.33d4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000cce4d0
29204074.33d4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=97764CBC54D020522D3ED8BD2BBA1282B13A6320
29214074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
29224074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
29234074.33d4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package04~31bf3856ad364e35~amd64~~10.0.19041.572.cat'; file='\Device\HarddiskVolume3\Windows\System32\amsi.dll'
29244074.33d4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
29254074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
29264074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'rpcrt4.dll'.
29274074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\amsi.dll) WinVerifyTrust
29284074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\amsi.dll
29294074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
29304074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
29314074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
29324074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
29334074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\amsi.dll (Input=amsi.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
29344074.33d4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\amsi.dll
29354074.33d4: supR3HardenedDllNotificationCallback: load 00007ffa87970000 LB 0x00017000 C:\Windows\System32\amsi.dll [fFlags=0x0]
29364074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\amsi.dll
29374074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa87970000 'C:\Windows\System32\amsi.dll'
29384074.33d4: \Device\HarddiskVolume3\Program Files\McAfee\MfeAV\AMSIExt.dll: Owner is administrators group.
29394074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
29404074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
29414074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'psapi.dll'.
29424074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'wintrust.dll'.
29434074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'crypt32.dll'.
29444074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'version.dll'.
29454074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'user32.dll'.
29464074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'advapi32.dll'.
29474074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'shell32.dll'.
29484074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'ole32.dll'.
29494074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'oleaut32.dll'.
29504074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'shlwapi.dll'.
29514074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\McAfee\MfeAV\AMSIExt.dll) WinVerifyTrust
29524074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\McAfee\MfeAV\AMSIExt.dll
29534074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
29544074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
29554074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\shlwapi.dll
29564074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
29574074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume3\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
29584074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
29594074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
29604074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
29614074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume3\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
29624074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\shell32.dll
29634074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
29644074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
29654074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
29664074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
29674074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'version.dll'...
29684074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'version.dll' -> '\Device\HarddiskVolume3\Windows\System32\version.dll' [rcNtRedir=0xc0150008]
29694074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
29704074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
29714074.33d4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
29724074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\version.dll) WinVerifyTrust
29734074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\version.dll
29744074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
29754074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume3\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
29764074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wintrust.dll'...
29774074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'wintrust.dll' -> '\Device\HarddiskVolume3\Windows\System32\wintrust.dll' [rcNtRedir=0xc0150008]
29784074.33d4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wintrust.dll
29794074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'psapi.dll'...
29804074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'psapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\psapi.dll' [rcNtRedir=0xc0150008]
29814074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
29824074.33d4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
29834074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
29844074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
29854074.33d4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\psapi.dll) WinVerifyTrust
29864074.33d4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\psapi.dll
29874074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\McAfee\MfeAV\AMSIExt.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
29884074.33d4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\McAfee\MfeAV\AMSIExt.dll
29894074.33d4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\version.dll
29904074.33d4: supR3HardenedDllNotificationCallback: load 00007ffaaa730000 LB 0x00008000 C:\Windows\System32\PSAPI.DLL [fFlags=0x0]
29914074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\psapi.dll
29924074.33d4: supR3HardenedDllNotificationCallback: load 00007ffaa1fb0000 LB 0x0000a000 C:\Windows\SYSTEM32\VERSION.dll [fFlags=0x0]
29934074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\version.dll
29944074.33d4: supR3HardenedDllNotificationCallback: load 00007ffa878d0000 LB 0x0009b000 C:\Program Files\McAfee\MfeAV\AMSIExt.dll [fFlags=0x0]
29954074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\McAfee\MfeAV\AMSIExt.dll
29964074.33d4: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
29974074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
29984074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa9a80000 'api-ms-win-core-synch-l1-2-0'
29994074.33d4: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-fibers-l1-1-1) -> 0x0, fPresent=1
30004074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
30014074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa9a80000 'api-ms-win-core-fibers-l1-1-1'
30024074.33d4: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
30034074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
30044074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa9a80000 'api-ms-win-core-synch-l1-2-0'
30054074.33d4: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-fibers-l1-1-1) -> 0x0, fPresent=1
30064074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
30074074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa9a80000 'api-ms-win-core-fibers-l1-1-1'
30084074.33d4: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-l1-2-1) -> 0x0, fPresent=1
30094074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-l1-2-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
30104074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa9a80000 'api-ms-win-core-localization-l1-2-1'
30114074.33d4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\kernel32.dll
30124074.33d4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\kernel32.dll (Input=kernel32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
30134074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaaab80000 'C:\Windows\System32\kernel32.dll'
30144074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa878d0000 'C:\Program Files\McAfee\MfeAV\AMSIExt.dll'
30154074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaaa740000 'C:\Windows\System32\ADVAPI32.dll'
30164074.450: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
30174074.450: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
30184074.450: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
30194074.450: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\virtualbox\VBoxVMM.dll) WinVerifyTrust
30204074.450: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\virtualbox\VBoxVMM.dll
30214074.450: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
30224074.450: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\virtualbox\vboxrt.dll' [rcNtRedir=0xc0150008]
30234074.450: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
30244074.450: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
30254074.450: supR3HardenedMonitor_LdrLoadDll: pName=F:\virtualbox\VBoxVMM.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
30264074.450: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\VBoxVMM.dll
30274074.450: supR3HardenedDllNotificationCallback: load 00007ffa286b0000 LB 0x0037e000 F:\virtualbox\VBoxVMM.DLL [fFlags=0x0]
30284074.450: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\VBoxVMM.dll
30294074.450: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa286b0000 'F:\virtualbox\VBoxVMM.DLL'
30304074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
30314074.333c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000c8c pwszName=\Device\HarddiskVolume3\Windows\System32\NetSetupShim.dll
30324074.333c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000cce4d0
30334074.333c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000cce4d0
30344074.333c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=C55CF6F88F96953426D647BA94686B330A7EFFC1
30354074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
30364074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
30374074.333c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package04111~31bf3856ad364e35~amd64~~10.0.19041.329.cat'; file='\Device\HarddiskVolume3\Windows\System32\NetSetupShim.dll'
30384074.333c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
30394074.333c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
30404074.333c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #31 'rpcrt4.dll'.
30414074.333c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #32 'oleaut32.dll'.
30424074.333c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #34 'ws2_32.dll'.
30434074.333c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #35 'netsetupapi.dll'.
30444074.333c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #36 'setupapi.dll'.
30454074.333c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #37 'devrtl.dll'.
30464074.333c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\NetSetupShim.dll) WinVerifyTrust
30474074.333c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\NetSetupShim.dll
30484074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'devrtl.dll'...
30494074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: 'devrtl.dll' -> '\Device\HarddiskVolume3\Windows\System32\devrtl.dll' [rcNtRedir=0xc0150008]
30504074.333c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000c78 pwszName=\Device\HarddiskVolume3\Windows\System32\devrtl.dll
30514074.333c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000cce4d0
30524074.333c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000cce4d0
30534074.333c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=33BBF6397EB75AA0F0A1F00943D02D98D1F9C5BA
30544074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
30554074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
30564074.333c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0416~31bf3856ad364e35~amd64~~10.0.19041.572.cat'; file='\Device\HarddiskVolume3\Windows\System32\devrtl.dll'
30574074.333c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
30584074.333c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\devrtl.dll) WinVerifyTrust
30594074.333c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\devrtl.dll
30604074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
30614074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
30624074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
30634074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
30644074.333c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
30654074.333c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #28 'rpcrt4.dll'.
30664074.333c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #35 'cfgmgr32.dll'.
30674074.333c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #40 'bcrypt.dll'.
30684074.333c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\setupapi.dll) WinVerifyTrust
30694074.333c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\setupapi.dll
30704074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'netsetupapi.dll'...
30714074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: 'netsetupapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\netsetupapi.dll' [rcNtRedir=0xc0150008]
30724074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
30734074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume3\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
30744074.333c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\bcrypt.dll
30754074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
30764074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume3\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
30774074.333c: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\cfgmgr32.dll'.
30784074.333c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\cfgmgr32.dll)
30794074.333c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\cfgmgr32.dll
30804074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
30814074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
30824074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
30834074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
30844074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
30854074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
30864074.333c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
30874074.333c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'rpcrt4.dll'.
30884074.333c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\NetSetupApi.dll) WinVerifyTrust
30894074.333c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\NetSetupApi.dll
30904074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
30914074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
30924074.333c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ws2_32.dll
30934074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
30944074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume3\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
30954074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
30964074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
30974074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
30984074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
30994074.333c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcp_win.dll
31004074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
31014074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
31024074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
31034074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
31044074.333c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\NetSetupShim.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
31054074.333c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\NetSetupShim.dll
31064074.333c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\NetSetupApi.dll
31074074.333c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\devrtl.dll
31084074.333c: supR3HardenedDllNotificationCallback: load 00007ffaa9de0000 LB 0x0004e000 C:\Windows\System32\cfgmgr32.dll [fFlags=0x0]
31094074.333c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\cfgmgr32.dll [avoiding WinVerifyTrust]
31104074.333c: supR3HardenedDllNotificationCallback: load 00007ffa98440000 LB 0x00026000 C:\Windows\System32\NetSetupApi.dll [fFlags=0x0]
31114074.333c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\NetSetupApi.dll
31124074.333c: supR3HardenedDllNotificationCallback: load 00007ffaaa2c0000 LB 0x00467000 C:\Windows\System32\setupapi.dll [fFlags=0x0]
31134074.333c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\setupapi.dll
31144074.333c: supR3HardenedDllNotificationCallback: load 00007ffa93cb0000 LB 0x00014000 C:\Windows\System32\DEVRTL.dll [fFlags=0x0]
31154074.333c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\devrtl.dll
31164074.333c: supR3HardenedDllNotificationCallback: load 00007ffa93e10000 LB 0x00078000 C:\Windows\System32\NetSetupShim.dll [fFlags=0x0]
31174074.333c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\NetSetupShim.dll
31184074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa93e10000 'C:\Windows\System32\NetSetupShim.dll'
31194074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
31204074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
31214074.333c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\cfgmgr32.dll'
31224074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
31234074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
31244074.333c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
31254074.333c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'rpcrt4.dll'.
31264074.333c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #24 'nsi.dll'.
31274074.333c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'winnsi.dll'.
31284074.333c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\NetSetupEngine.dll) WinVerifyTrust
31294074.333c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\NetSetupEngine.dll
31304074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winnsi.dll'...
31314074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: 'winnsi.dll' -> '\Device\HarddiskVolume3\Windows\System32\winnsi.dll' [rcNtRedir=0xc0150008]
31324074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
31334074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
31344074.333c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rpcrt4.dll'.
31354074.333c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'nsi.dll'.
31364074.333c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\winnsi.dll) WinVerifyTrust
31374074.333c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\winnsi.dll
31384074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
31394074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume3\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
31404074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
31414074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume3\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
31424074.333c: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\nsi.dll'.
31434074.333c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\nsi.dll)
31444074.333c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\nsi.dll
31454074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
31464074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
31474074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
31484074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
31494074.333c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\nsi.dll) WinVerifyTrust
31504074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
31514074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
31524074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
31534074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
31544074.333c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\NetSetupEngine.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
31554074.333c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\NetSetupEngine.dll
31564074.333c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winnsi.dll
31574074.333c: supR3HardenedDllNotificationCallback: load 00007ffaaa960000 LB 0x00009000 C:\Windows\System32\NSI.dll [fFlags=0x0]
31584074.333c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\nsi.dll [avoiding WinVerifyTrust]
31594074.333c: supR3HardenedDllNotificationCallback: load 00007ffaa1f80000 LB 0x0000b000 C:\Windows\SYSTEM32\WINNSI.DLL [fFlags=0x0]
31604074.333c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winnsi.dll
31614074.333c: supR3HardenedDllNotificationCallback: load 00007ffa798c0000 LB 0x000ca000 C:\Windows\System32\NetSetupEngine.dll [fFlags=0x0]
31624074.333c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\NetSetupEngine.dll
31634074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa798c0000 'C:\Windows\System32\NetSetupEngine.dll'
31644074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
31654074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
31664074.333c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\nsi.dll'
31674074.2a08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
31684074.2a08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
31694074.2a08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
31704074.2a08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxvmm.dll'.
31714074.2a08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vboxrt.dll'.
31724074.2a08: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'user32.dll'.
31734074.2a08: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\virtualbox\VBoxSharedClipboard.dll) WinVerifyTrust
31744074.2a08: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\virtualbox\VBoxSharedClipboard.dll
31754074.2a08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
31764074.2a08: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
31774074.2a08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
31784074.2a08: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\virtualbox\vboxrt.dll' [rcNtRedir=0xc0150008]
31794074.2a08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
31804074.2a08: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume4\virtualbox\vboxvmm.dll' [rcNtRedir=0xc0150008]
31814074.2a08: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\VBoxVMM.dll
31824074.2a08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
31834074.2a08: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume4\virtualbox\msvcp100.dll' [rcNtRedir=0xc0150008]
31844074.2a08: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
31854074.2a08: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
31864074.2a08: supR3HardenedMonitor_LdrLoadDll: pName=F:\virtualbox\VBoxSharedClipboard.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
31874074.2a08: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\VBoxSharedClipboard.dll
31884074.2a08: supR3HardenedDllNotificationCallback: load 00007ffaa4c60000 LB 0x00010000 F:\virtualbox\VBoxSharedClipboard.DLL [fFlags=0x0]
31894074.2a08: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\VBoxSharedClipboard.dll
31904074.2a08: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa4c60000 'F:\virtualbox\VBoxSharedClipboard.DLL'
31914074.2e54: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
31924074.2e54: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
31934074.2e54: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
31944074.2e54: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
31954074.2e54: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\virtualbox\VBoxDragAndDropSvc.dll) WinVerifyTrust
31964074.2e54: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\virtualbox\VBoxDragAndDropSvc.dll
31974074.2e54: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
31984074.2e54: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\virtualbox\vboxrt.dll' [rcNtRedir=0xc0150008]
31994074.2e54: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
32004074.2e54: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume4\virtualbox\msvcp100.dll' [rcNtRedir=0xc0150008]
32014074.2e54: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
32024074.2e54: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
32034074.2e54: supR3HardenedMonitor_LdrLoadDll: pName=F:\virtualbox\VBoxDragAndDropSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
32044074.2e54: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\VBoxDragAndDropSvc.dll
32054074.2e54: supR3HardenedDllNotificationCallback: load 00007ffaa3610000 LB 0x0000d000 F:\virtualbox\VBoxDragAndDropSvc.DLL [fFlags=0x0]
32064074.2e54: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\VBoxDragAndDropSvc.dll
32074074.2e54: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa3610000 'F:\virtualbox\VBoxDragAndDropSvc.DLL'
32084074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaaae20000 'C:\Windows\system32\Shell32.dll'
32094074.333c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000d34 pwszName=\Device\HarddiskVolume3\Windows\System32\WinHvPlatform.dll
32104074.333c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000cce4d0
32114074.333c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000cce4d0
32124074.333c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=E4C882F4212D993AB8CD1218452ADE578B4E8723
32134074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
32144074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
32154074.333c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package02~31bf3856ad364e35~amd64~~10.0.19041.329.cat'; file='\Device\HarddiskVolume3\Windows\System32\WinHvPlatform.dll'
32164074.333c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
32174074.333c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'vid.dll'.
32184074.333c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\WinHvPlatform.dll) WinVerifyTrust
32194074.333c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\WinHvPlatform.dll
32204074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vid.dll'...
32214074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vid.dll' -> '\Device\HarddiskVolume3\Windows\System32\vid.dll' [rcNtRedir=0xc0150008]
32224074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
32234074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
32244074.333c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\vid.dll) WinVerifyTrust
32254074.333c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\vid.dll
32264074.333c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\WinHvPlatform.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
32274074.333c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\WinHvPlatform.dll
32284074.333c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\vid.dll
32294074.333c: supR3HardenedDllNotificationCallback: load 00007ffa993a0000 LB 0x0001b000 C:\Windows\SYSTEM32\vid.dll [fFlags=0x0]
32304074.333c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\vid.dll
32314074.333c: supR3HardenedDllNotificationCallback: load 00007ffa993c0000 LB 0x00026000 C:\Windows\system32\WinHvPlatform.dll [fFlags=0x0]
32324074.333c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\WinHvPlatform.dll
32334074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa993c0000 'C:\Windows\system32\WinHvPlatform.dll'
32344074.333c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\vid.dll
32354074.333c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\vid.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
32364074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa993a0000 'C:\Windows\system32\vid.dll'
32374074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
32384074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
32394074.333c: '\Device\HarddiskVolume3\Windows\System32\ntdll.dll' has no imports
32404074.333c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\ntdll.dll) WinVerifyTrust
32414074.333c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\ntdll.dll
32424074.333c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\NTDLL.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
32434074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaabfb0000 'C:\Windows\system32\NTDLL.DLL'
32444074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
32454074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
32464074.333c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
32474074.333c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
32484074.333c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
32494074.333c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vboxddu.dll'.
32504074.333c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'vboxdd2.dll'.
32514074.333c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
32524074.333c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'setupapi.dll'.
32534074.333c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'ws2_32.dll'.
32544074.333c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'ole32.dll'.
32554074.333c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'iphlpapi.dll'.
32564074.333c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\virtualbox\VBoxDD.dll) WinVerifyTrust
32574074.333c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\virtualbox\VBoxDD.dll
32584074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'iphlpapi.dll'...
32594074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: 'iphlpapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\iphlpapi.dll' [rcNtRedir=0xc0150008]
32604074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
32614074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
32624074.333c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\IPHLPAPI.DLL) WinVerifyTrust
32634074.333c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\IPHLPAPI.DLL
32644074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
32654074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
32664074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
32674074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
32684074.333c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ws2_32.dll
32694074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
32704074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
32714074.333c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\setupapi.dll
32724074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
32734074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
32744074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxdd2.dll'...
32754074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxdd2.dll' -> '\Device\HarddiskVolume4\virtualbox\vboxdd2.dll' [rcNtRedir=0xc0150008]
32764074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
32774074.333c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
32784074.333c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
32794074.333c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\virtualbox\VBoxDD2.dll) WinVerifyTrust
32804074.333c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\virtualbox\VBoxDD2.dll
32814074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxddu.dll'...
32824074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxddu.dll' -> '\Device\HarddiskVolume4\virtualbox\vboxddu.dll' [rcNtRedir=0xc0150008]
32834074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
32844074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\virtualbox\vboxrt.dll' [rcNtRedir=0xc0150008]
32854074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
32864074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
32874074.333c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\msvcr100.dll
32884074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
32894074.333c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
32904074.333c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
32914074.333c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
32924074.333c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'setupapi.dll'.
32934074.333c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'advapi32.dll'.
32944074.333c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\virtualbox\VBoxDDU.dll) WinVerifyTrust
32954074.333c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\virtualbox\VBoxDDU.dll
32964074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
32974074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\virtualbox\vboxrt.dll' [rcNtRedir=0xc0150008]
32984074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
32994074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume4\virtualbox\vboxvmm.dll' [rcNtRedir=0xc0150008]
33004074.333c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\VBoxVMM.dll
33014074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
33024074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
33034074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
33044074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
33054074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
33064074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
33074074.333c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\setupapi.dll
33084074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
33094074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
33104074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
33114074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\virtualbox\vboxrt.dll' [rcNtRedir=0xc0150008]
33124074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
33134074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
33144074.333c: supR3HardenedMonitor_LdrLoadDll: pName=F:\virtualbox\VBoxDD.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
33154074.333c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\VBoxDD.dll
33164074.333c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\VBoxDDU.dll
33174074.333c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\VBoxDD2.dll
33184074.333c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\IPHLPAPI.DLL
33194074.333c: supR3HardenedDllNotificationCallback: load 00007ffa8c110000 LB 0x00067000 F:\virtualbox\VBoxDDU.dll [fFlags=0x0]
33204074.333c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\VBoxDDU.dll
33214074.333c: supR3HardenedDllNotificationCallback: load 00007ffa27460000 LB 0x0085c000 F:\virtualbox\VBoxDD2.dll [fFlags=0x0]
33224074.333c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\VBoxDD2.dll
33234074.333c: supR3HardenedDllNotificationCallback: load 00007ffaa8ad0000 LB 0x0003b000 C:\Windows\SYSTEM32\IPHLPAPI.DLL [fFlags=0x0]
33244074.333c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\IPHLPAPI.DLL
33254074.333c: supR3HardenedDllNotificationCallback: load 00007ffa27cc0000 LB 0x009e6000 F:\virtualbox\VBoxDD.DLL [fFlags=0x0]
33264074.333c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\VBoxDD.dll
33274074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa27cc0000 'F:\virtualbox\VBoxDD.DLL'
33284074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
33294074.333c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\VBoxC.dll
33304074.333c: supR3HardenedMonitor_LdrLoadDll: pName=F:\virtualbox\VBoxC.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
33314074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa45330000 'F:\virtualbox\VBoxC.DLL'
33324074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
33334074.333c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\VBoxDD2.dll
33344074.333c: supR3HardenedMonitor_LdrLoadDll: pName=F:\virtualbox\VBoxDD2.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
33354074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa27460000 'F:\virtualbox\VBoxDD2.DLL'
33364074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
33374074.21a8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
33384074.21a8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
33394074.21a8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
33404074.21a8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
33414074.21a8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\virtualbox\VBoxSharedFolders.dll) WinVerifyTrust
33424074.21a8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\virtualbox\VBoxSharedFolders.dll
33434074.21a8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
33444074.21a8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\virtualbox\vboxrt.dll' [rcNtRedir=0xc0150008]
33454074.21a8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
33464074.21a8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume4\virtualbox\vboxvmm.dll' [rcNtRedir=0xc0150008]
33474074.21a8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\VBoxVMM.dll
33484074.21a8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
33494074.21a8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
33504074.21a8: supR3HardenedMonitor_LdrLoadDll: pName=F:\virtualbox\VBoxSharedFolders.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
33514074.21a8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\VBoxSharedFolders.dll
33524074.21a8: supR3HardenedDllNotificationCallback: load 00007ffa967d0000 LB 0x00014000 F:\virtualbox\VBoxSharedFolders.DLL [fFlags=0x0]
33534074.21a8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\VBoxSharedFolders.dll
33544074.21a8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa967d0000 'F:\virtualbox\VBoxSharedFolders.DLL'
33554074.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
33564074.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
33574074.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
33584074.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxvmm.dll'.
33594074.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vboxrt.dll'.
33604074.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\virtualbox\VBoxGuestControlSvc.dll) WinVerifyTrust
33614074.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\virtualbox\VBoxGuestControlSvc.dll
33624074.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
33634074.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\virtualbox\vboxrt.dll' [rcNtRedir=0xc0150008]
33644074.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
33654074.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume4\virtualbox\vboxvmm.dll' [rcNtRedir=0xc0150008]
33664074.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\VBoxVMM.dll
33674074.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
33684074.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume4\virtualbox\msvcp100.dll' [rcNtRedir=0xc0150008]
33694074.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
33704074.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
33714074.31ac: supR3HardenedMonitor_LdrLoadDll: pName=F:\virtualbox\VBoxGuestControlSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
33724074.31ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\VBoxGuestControlSvc.dll
33734074.31ac: supR3HardenedDllNotificationCallback: load 00007ffa967c0000 LB 0x0000c000 F:\virtualbox\VBoxGuestControlSvc.DLL [fFlags=0x0]
33744074.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\VBoxGuestControlSvc.dll
33754074.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa967c0000 'F:\virtualbox\VBoxGuestControlSvc.DLL'
33764074.2134: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
33774074.2134: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
33784074.2134: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
33794074.2134: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
33804074.2134: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\virtualbox\VBoxGuestPropSvc.dll) WinVerifyTrust
33814074.2134: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\virtualbox\VBoxGuestPropSvc.dll
33824074.2134: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
33834074.2134: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\virtualbox\vboxrt.dll' [rcNtRedir=0xc0150008]
33844074.2134: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
33854074.2134: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume4\virtualbox\msvcp100.dll' [rcNtRedir=0xc0150008]
33864074.2134: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
33874074.2134: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
33884074.2134: supR3HardenedMonitor_LdrLoadDll: pName=F:\virtualbox\VBoxGuestPropSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
33894074.2134: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\VBoxGuestPropSvc.dll
33904074.2134: supR3HardenedDllNotificationCallback: load 00007ffa94140000 LB 0x0000d000 F:\virtualbox\VBoxGuestPropSvc.DLL [fFlags=0x0]
33914074.2134: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\virtualbox\VBoxGuestPropSvc.dll
33924074.2134: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa94140000 'F:\virtualbox\VBoxGuestPropSvc.DLL'
33934074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
33944074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
33954074.333c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
33964074.333c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'rpcrt4.dll'.
33974074.333c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #28 'devobj.dll'.
33984074.333c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\MMDevAPI.dll) WinVerifyTrust
33994074.333c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\MMDevAPI.dll
34004074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'devobj.dll'...
34014074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: 'devobj.dll' -> '\Device\HarddiskVolume3\Windows\System32\devobj.dll' [rcNtRedir=0xc0150008]
34024074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
34034074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
34044074.333c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'cfgmgr32.dll'.
34054074.333c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\devobj.dll) WinVerifyTrust
34064074.333c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\devobj.dll
34074074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
34084074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
34094074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
34104074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
34114074.333c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcp_win.dll
34124074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
34134074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume3\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
34144074.333c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\cfgmgr32.dll
34154074.333c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\MMDevApi.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
34164074.333c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\MMDevAPI.dll
34174074.333c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\devobj.dll
34184074.333c: supR3HardenedDllNotificationCallback: load 00007ffaa93e0000 LB 0x0002c000 C:\Windows\System32\DEVOBJ.dll [fFlags=0x0]
34194074.333c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\devobj.dll
34204074.333c: supR3HardenedDllNotificationCallback: load 00007ffaa1820000 LB 0x00085000 C:\Windows\System32\MMDevApi.dll [fFlags=0x0]
34214074.333c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\MMDevAPI.dll
34224074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa1820000 'C:\Windows\System32\MMDevApi.dll'
34234074.333c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000109c pwszName=\Device\HarddiskVolume3\Windows\System32\dsound.dll
34244074.333c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000cce4d0
34254074.333c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000cce4d0
34264074.333c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=52FFFB4153FE3DAE37A0C896FAC0D39F6841832F
34274074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
34284074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
34294074.333c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package~31bf3856ad364e35~amd64~~10.0.19041.508.cat'; file='\Device\HarddiskVolume3\Windows\System32\dsound.dll'
34304074.333c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
34314074.333c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
34324074.333c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\dsound.dll) WinVerifyTrust
34334074.333c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\dsound.dll
34344074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
34354074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
34364074.333c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll
34374074.333c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
34384074.333c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\dsound.dll
34394074.333c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'rpcrt4.dll'.
34404074.333c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\powrprof.dll)
34414074.333c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\powrprof.dll
34424074.333c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
34434074.333c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\winmmbase.dll)
34444074.333c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\winmmbase.dll
34454074.333c: supR3HardenedDllNotificationCallback: load 00007ffaa9560000 LB 0x0004b000 C:\Windows\SYSTEM32\powrprof.dll [fFlags=0x0]
34464074.333c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\powrprof.dll [avoiding WinVerifyTrust]
34474074.333c: supR3HardenedDllNotificationCallback: load 00007ffa95a90000 LB 0x00026000 C:\Windows\SYSTEM32\winmmbase.dll [fFlags=0x0]
34484074.333c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winmmbase.dll [avoiding WinVerifyTrust]
34494074.333c: supR3HardenedDllNotificationCallback: load 00007ffa68b80000 LB 0x0009c000 C:\Windows\System32\dsound.dll [fFlags=0x0]
34504074.333c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\dsound.dll
34514074.333c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\umpdc.dll)
34524074.333c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\umpdc.dll
34534074.333c: supR3HardenedDllNotificationCallback: load 00007ffaa9540000 LB 0x00012000 C:\Windows\SYSTEM32\UMPDC.dll [fFlags=0x0]
34544074.333c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\umpdc.dll [avoiding WinVerifyTrust]
34554074.333c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\umpdc.dll'.
34564074.333c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\umpdc.dll' [rescheduled]
34574074.333c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\winmmbase.dll'.
34584074.333c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\winmmbase.dll' [rescheduled]
34594074.333c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\powrprof.dll'.
34604074.333c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\powrprof.dll' [rescheduled]
34614074.333c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\dsound.dll
34624074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
34634074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
34644074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
34654074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
34664074.333c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
34674074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa68b80000 'C:\Windows\System32\dsound.dll'
34684074.333c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\umpdc.dll'.
34694074.333c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\umpdc.dll' [rescheduled]
34704074.333c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\winmmbase.dll'.
34714074.333c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\winmmbase.dll' [rescheduled]
34724074.333c: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\powrprof.dll'.
34734074.333c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\powrprof.dll' [rescheduled]
34744074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa68b80000 'C:\Windows\System32\dsound.dll'
34754074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
34764074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
34774074.333c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\umpdc.dll'
34784074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
34794074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
34804074.333c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\winmmbase.dll'
34814074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
34824074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
34834074.333c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\powrprof.dll'
34844074.333c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\dsound.dll
34854074.333c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
34864074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa68b80000 'C:\Windows\system32\dsound.dll'
34874074.333c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\MMDevAPI.dll
34884074.333c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\MMDEVAPI.DLL (Input=MMDEVAPI.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
34894074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa1820000 'C:\Windows\System32\MMDEVAPI.DLL'
34904074.33ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
34914074.33ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
34924074.33ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
34934074.33ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'rpcrt4.dll'.
34944074.33ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'oleaut32.dll'.
34954074.33ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #29 'mmdevapi.dll'.
34964074.33ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\AudioSes.dll) WinVerifyTrust
34974074.33ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\AudioSes.dll
34984074.33ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mmdevapi.dll'...
34994074.33ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'mmdevapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\mmdevapi.dll' [rcNtRedir=0xc0150008]
35004074.33ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\MMDevAPI.dll
35014074.33ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
35024074.33ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume3\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
35034074.33ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
35044074.33ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
35054074.33ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
35064074.33ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
35074074.33ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\AUDIOSES.DLL (Input=AUDIOSES.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
35084074.33ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\AudioSes.dll
35094074.33ac: supR3HardenedDllNotificationCallback: load 00007ffaa19b0000 LB 0x00181000 C:\Windows\System32\AUDIOSES.DLL [fFlags=0x0]
35104074.33ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\AudioSes.dll
35114074.33ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa19b0000 'C:\Windows\System32\AUDIOSES.DLL'
35124074.33ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
35134074.33ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'rpcrt4.dll'.
35144074.33ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\ResourcePolicyClient.dll)
35154074.33ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\ResourcePolicyClient.dll
35164074.33ac: supR3HardenedDllNotificationCallback: load 00007ffaa69d0000 LB 0x00014000 C:\Windows\SYSTEM32\resourcepolicyclient.dll [fFlags=0x0]
35174074.33ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ResourcePolicyClient.dll [avoiding WinVerifyTrust]
35184074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
35194074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
35204074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
35214074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
35224074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
35234074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
35244074.333c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\ResourcePolicyClient.dll'
35254074.333c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winmm.dll
35264074.333c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\winmm.dll (Input=winmm.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
35274074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa8ecb0000 'C:\Windows\System32\winmm.dll'
35284074.333c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000001118 pwszName=\Device\HarddiskVolume3\Windows\System32\wdmaud.drv
35294074.333c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000cce4d0
35304074.333c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000cce4d0
35314074.333c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=7F7F29B63FBFB61F7E4F361F4C3593442D614D77
35324074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
35334074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
35344074.333c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package~31bf3856ad364e35~amd64~~10.0.19041.508.cat'; file='\Device\HarddiskVolume3\Windows\System32\wdmaud.drv'
35354074.333c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
35364074.333c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
35374074.333c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'mmdevapi.dll'.
35384074.333c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'ksuser.dll'.
35394074.333c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #30 'avrt.dll'.
35404074.333c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\wdmaud.drv) WinVerifyTrust
35414074.333c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\wdmaud.drv
35424074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'avrt.dll'...
35434074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: 'avrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\avrt.dll' [rcNtRedir=0xc0150008]
35444074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
35454074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
35464074.333c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\avrt.dll) WinVerifyTrust
35474074.333c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\avrt.dll
35484074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ksuser.dll'...
35494074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ksuser.dll' -> '\Device\HarddiskVolume3\Windows\System32\ksuser.dll' [rcNtRedir=0xc0150008]
35504074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
35514074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
35524074.333c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
35534074.333c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\ksuser.dll) WinVerifyTrust
35544074.333c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\ksuser.dll
35554074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mmdevapi.dll'...
35564074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: 'mmdevapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\mmdevapi.dll' [rcNtRedir=0xc0150008]
35574074.333c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\MMDevAPI.dll
35584074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
35594074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
35604074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
35614074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
35624074.333c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
35634074.333c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wdmaud.drv
35644074.333c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ksuser.dll
35654074.333c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\avrt.dll
35664074.333c: supR3HardenedDllNotificationCallback: load 00007ffaa23b0000 LB 0x00009000 C:\Windows\SYSTEM32\ksuser.dll [fFlags=0x0]
35674074.333c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ksuser.dll
35684074.333c: supR3HardenedDllNotificationCallback: load 00007ffaa3bb0000 LB 0x0000a000 C:\Windows\SYSTEM32\AVRT.dll [fFlags=0x0]
35694074.333c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\avrt.dll
35704074.333c: supR3HardenedDllNotificationCallback: load 00007ffa7c7f0000 LB 0x00046000 C:\Windows\System32\wdmaud.drv [fFlags=0x0]
35714074.333c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wdmaud.drv
35724074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa7c7f0000 'C:\Windows\System32\wdmaud.drv'
35734074.333c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wdmaud.drv
35744074.333c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
35754074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa7c7f0000 'C:\Windows\System32\wdmaud.drv'
35764074.333c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wdmaud.drv
35774074.333c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
35784074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa7c7f0000 'C:\Windows\System32\wdmaud.drv'
35794074.333c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wdmaud.drv
35804074.333c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
35814074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa7c7f0000 'C:\Windows\System32\wdmaud.drv'
35824074.333c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wdmaud.drv
35834074.333c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
35844074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa7c7f0000 'C:\Windows\System32\wdmaud.drv'
35854074.333c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wdmaud.drv
35864074.333c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
35874074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa7c7f0000 'C:\Windows\System32\wdmaud.drv'
35884074.333c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wdmaud.drv
35894074.333c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
35904074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa7c7f0000 'C:\Windows\System32\wdmaud.drv'
35914074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa7c7f0000 'C:\Windows\System32\wdmaud.drv'
35924074.333c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000001078 pwszName=\Device\HarddiskVolume3\Windows\System32\msacm32.drv
35934074.333c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000cce4d0
35944074.333c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000cce4d0
35954074.333c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=F871EA11D693E9807F8DF13D54497BA0E40D30AB
35964074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
35974074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
35984074.333c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package~31bf3856ad364e35~amd64~~10.0.19041.508.cat'; file='\Device\HarddiskVolume3\Windows\System32\msacm32.drv'
35994074.333c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
36004074.333c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
36014074.333c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'mmdevapi.dll'.
36024074.333c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'msacm32.dll'.
36034074.333c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\msacm32.drv) WinVerifyTrust
36044074.333c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\msacm32.drv
36054074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msacm32.dll'...
36064074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msacm32.dll' -> '\Device\HarddiskVolume3\Windows\System32\msacm32.dll' [rcNtRedir=0xc0150008]
36074074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
36084074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
36094074.333c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
36104074.333c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\msacm32.dll) WinVerifyTrust
36114074.333c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\msacm32.dll
36124074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mmdevapi.dll'...
36134074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: 'mmdevapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\mmdevapi.dll' [rcNtRedir=0xc0150008]
36144074.333c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\MMDevAPI.dll
36154074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
36164074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
36174074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
36184074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
36194074.333c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
36204074.333c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msacm32.drv
36214074.333c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msacm32.dll
36224074.333c: supR3HardenedDllNotificationCallback: load 00007ffa96690000 LB 0x0001e000 C:\Windows\SYSTEM32\MSACM32.dll [fFlags=0x0]
36234074.333c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msacm32.dll
36244074.333c: supR3HardenedDllNotificationCallback: load 00007ffaa4f40000 LB 0x0000d000 C:\Windows\System32\msacm32.drv [fFlags=0x0]
36254074.333c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msacm32.drv
36264074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa4f40000 'C:\Windows\System32\msacm32.drv'
36274074.333c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msacm32.drv
36284074.333c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
36294074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa4f40000 'C:\Windows\System32\msacm32.drv'
36304074.333c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msacm32.drv
36314074.333c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
36324074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa4f40000 'C:\Windows\System32\msacm32.drv'
36334074.333c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msacm32.drv
36344074.333c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
36354074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa4f40000 'C:\Windows\System32\msacm32.drv'
36364074.333c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msacm32.drv
36374074.333c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
36384074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa4f40000 'C:\Windows\System32\msacm32.drv'
36394074.333c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msacm32.drv
36404074.333c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
36414074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa4f40000 'C:\Windows\System32\msacm32.drv'
36424074.333c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msacm32.drv
36434074.333c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
36444074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa4f40000 'C:\Windows\System32\msacm32.drv'
36454074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa4f40000 'C:\Windows\System32\msacm32.drv'
36464074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa4f40000 'C:\Windows\System32\msacm32.drv'
36474074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa4f40000 'C:\Windows\System32\msacm32.drv'
36484074.333c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000107c pwszName=\Device\HarddiskVolume3\Windows\System32\midimap.dll
36494074.333c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000000cce4d0
36504074.333c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000000cce4d0
36514074.333c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=3B1E0F68F4DF584853FE4112795D7092EFE15F7D
36524074.333c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll
36534074.333c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
36544074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8770000 'C:\Windows\system32\rsaenh.dll'
36554074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa97a0000 'C:\Windows\System32\crypt32.dll'
36564074.333c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package~31bf3856ad364e35~amd64~~10.0.19041.508.cat'; file='\Device\HarddiskVolume3\Windows\System32\midimap.dll'
36574074.333c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
36584074.333c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
36594074.333c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'winmmbase.dll'.
36604074.333c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\midimap.dll) WinVerifyTrust
36614074.333c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\midimap.dll
36624074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmmbase.dll'...
36634074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmmbase.dll' -> '\Device\HarddiskVolume3\Windows\System32\winmmbase.dll' [rcNtRedir=0xc0150008]
36644074.333c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winmmbase.dll
36654074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
36664074.333c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
36674074.333c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
36684074.333c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\midimap.dll
36694074.333c: supR3HardenedDllNotificationCallback: load 00007ffaa4f30000 LB 0x0000b000 C:\Windows\System32\midimap.dll [fFlags=0x0]
36704074.333c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\midimap.dll
36714074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa4f30000 'C:\Windows\System32\midimap.dll'
36724074.333c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\midimap.dll
36734074.333c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
36744074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa4f30000 'C:\Windows\System32\midimap.dll'
36754074.333c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\midimap.dll
36764074.333c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
36774074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa4f30000 'C:\Windows\System32\midimap.dll'
36784074.333c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\midimap.dll
36794074.333c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
36804074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa4f30000 'C:\Windows\System32\midimap.dll'
36814074.333c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winmm.dll
36824074.333c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\winmm.dll (Input=winmm.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
36834074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa8ecb0000 'C:\Windows\System32\winmm.dll'
36844074.333c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winmm.dll
36854074.333c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\winmm.dll (Input=winmm.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
36864074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa8ecb0000 'C:\Windows\System32\winmm.dll'
36874074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa8ecb0000 'C:\Windows\System32\winmm.dll'
36884074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa8ecb0000 'C:\Windows\System32\winmm.dll'
36894074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa8ecb0000 'C:\Windows\System32\winmm.dll'
36904074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa8ecb0000 'C:\Windows\System32\winmm.dll'
36914074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa8ecb0000 'C:\Windows\System32\winmm.dll'
36924074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa8ecb0000 'C:\Windows\System32\winmm.dll'
36934074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa8ecb0000 'C:\Windows\System32\winmm.dll'
36944074.333c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winmm.dll
36954074.333c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\winmm.dll (Input=winmm.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
36964074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa8ecb0000 'C:\Windows\System32\winmm.dll'
36974074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa8ecb0000 'C:\Windows\System32\winmm.dll'
36984074.333c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\dsound.dll
36994074.333c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
37004074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa68b80000 'C:\Windows\system32\dsound.dll'
37014074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa8ecb0000 'C:\Windows\System32\winmm.dll'
37024074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa8ecb0000 'C:\Windows\System32\winmm.dll'
37034074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa8ecb0000 'C:\Windows\System32\winmm.dll'
37044074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa8ecb0000 'C:\Windows\System32\winmm.dll'
37054074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa8ecb0000 'C:\Windows\System32\winmm.dll'
37064074.333c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa8ecb0000 'C:\Windows\System32\winmm.dll'
37074074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaaae20000 'C:\Windows\system32\shell32.dll'
37084074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaaae20000 'C:\Windows\system32\shell32.dll'
37094074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaaae20000 'C:\Windows\system32\shell32.dll'
37104074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaaae20000 'C:\Windows\system32\shell32.dll'
37114074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaaae20000 'C:\Windows\system32\shell32.dll'
37124074.33d4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaaae20000 'C:\Windows\system32\shell32.dll'

© 2024 Oracle Support Privacy / Do Not Sell My Info Terms of Use Trademark Policy Automated Access Etiquette