VirtualBox

Ticket #14903: VBoxHardening.log

File VBoxHardening.log, 455.7 KB (added by MCon, 9 years ago)

I don't know if this is relevant

Line 
11b6c.84c: Log file opened: 5.0.10r104061 g_hStartupLog=0000000000000014 g_uNtVerCombined=0x611db110
21b6c.84c: \SystemRoot\System32\ntdll.dll:
31b6c.84c: CreationTime: 2015-11-11T09:33:16.213469600Z
41b6c.84c: LastWriteTime: 2015-10-20T01:09:05.164170200Z
51b6c.84c: ChangeTime: 2015-11-12T07:41:52.844818500Z
61b6c.84c: FileAttributes: 0x20
71b6c.84c: Size: 0x1a67c0
81b6c.84c: NT Headers: 0xe0
91b6c.84c: Timestamp: 0x56259295
101b6c.84c: Machine: 0x8664 - amd64
111b6c.84c: Timestamp: 0x56259295
121b6c.84c: Image Version: 6.1
131b6c.84c: SizeOfImage: 0x1a9000 (1740800)
141b6c.84c: Resource Dir: 0x14d000 LB 0x5a028
151b6c.84c: ProductName: Microsoft® Windows® Operating System
161b6c.84c: ProductVersion: 6.1.7601.19045
171b6c.84c: FileVersion: 6.1.7601.19045 (win7sp1_gdr.151019-1254)
181b6c.84c: FileDescription: NT Layer DLL
191b6c.84c: \SystemRoot\System32\kernel32.dll:
201b6c.84c: CreationTime: 2015-11-11T09:33:16.353469800Z
211b6c.84c: LastWriteTime: 2015-10-20T01:05:40.819000000Z
221b6c.84c: ChangeTime: 2015-11-12T07:41:52.954018600Z
231b6c.84c: FileAttributes: 0x20
241b6c.84c: Size: 0x11c600
251b6c.84c: NT Headers: 0xe8
261b6c.84c: Timestamp: 0x56259270
271b6c.84c: Machine: 0x8664 - amd64
281b6c.84c: Timestamp: 0x56259270
291b6c.84c: Image Version: 6.1
301b6c.84c: SizeOfImage: 0x120000 (1179648)
311b6c.84c: Resource Dir: 0x117000 LB 0x528
321b6c.84c: ProductName: Microsoft® Windows® Operating System
331b6c.84c: ProductVersion: 6.1.7601.19045
341b6c.84c: FileVersion: 6.1.7601.19045 (win7sp1_gdr.151019-1254)
351b6c.84c: FileDescription: Windows NT BASE API Client DLL
361b6c.84c: \SystemRoot\System32\KernelBase.dll:
371b6c.84c: CreationTime: 2015-11-11T09:33:16.013469300Z
381b6c.84c: LastWriteTime: 2015-10-20T01:05:40.819000000Z
391b6c.84c: ChangeTime: 2015-11-12T07:41:52.954018600Z
401b6c.84c: FileAttributes: 0x20
411b6c.84c: Size: 0x67c00
421b6c.84c: NT Headers: 0xe8
431b6c.84c: Timestamp: 0x56259271
441b6c.84c: Machine: 0x8664 - amd64
451b6c.84c: Timestamp: 0x56259271
461b6c.84c: Image Version: 6.1
471b6c.84c: SizeOfImage: 0x6c000 (442368)
481b6c.84c: Resource Dir: 0x6a000 LB 0x530
491b6c.84c: ProductName: Microsoft® Windows® Operating System
501b6c.84c: ProductVersion: 6.1.7601.19045
511b6c.84c: FileVersion: 6.1.7601.19045 (win7sp1_gdr.151019-1254)
521b6c.84c: FileDescription: Windows NT BASE API Client DLL
531b6c.84c: \SystemRoot\System32\apisetschema.dll:
541b6c.84c: CreationTime: 2015-11-11T09:33:14.123466700Z
551b6c.84c: LastWriteTime: 2015-10-20T00:53:47.280000000Z
561b6c.84c: ChangeTime: 2015-11-12T07:41:52.829218400Z
571b6c.84c: FileAttributes: 0x20
581b6c.84c: Size: 0x1a00
591b6c.84c: NT Headers: 0xc0
601b6c.84c: Timestamp: 0x562590e2
611b6c.84c: Machine: 0x8664 - amd64
621b6c.84c: Timestamp: 0x562590e2
631b6c.84c: Image Version: 6.1
641b6c.84c: SizeOfImage: 0x50000 (327680)
651b6c.84c: Resource Dir: 0x30000 LB 0x3f8
661b6c.84c: ProductName: Microsoft® Windows® Operating System
671b6c.84c: ProductVersion: 6.1.7601.19045
681b6c.84c: FileVersion: 6.1.7601.19045 (win7sp1_gdr.151019-1254)
691b6c.84c: FileDescription: ApiSet Schema DLL
701b6c.84c: NtOpenDirectoryObject failed on \Driver: 0xc0000022
711b6c.84c: supR3HardenedWinFindAdversaries: 0x400
721b6c.84c: \SystemRoot\System32\drivers\MpFilter.sys:
731b6c.84c: CreationTime: 2015-03-04T17:34:52.000000000Z
741b6c.84c: LastWriteTime: 2015-03-04T17:34:52.000000000Z
751b6c.84c: ChangeTime: 2015-05-13T09:07:56.847024300Z
761b6c.84c: FileAttributes: 0x20
771b6c.84c: Size: 0x44738
781b6c.84c: NT Headers: 0xf0
791b6c.84c: Timestamp: 0x54efb880
801b6c.84c: Machine: 0x8664 - amd64
811b6c.84c: Timestamp: 0x54efb880
821b6c.84c: Image Version: 6.3
831b6c.84c: SizeOfImage: 0x44000 (278528)
841b6c.84c: Resource Dir: 0x42000 LB 0xd50
851b6c.84c: ProductName: Microsoft Malware Protection
861b6c.84c: ProductVersion: 4.8.0200.0
871b6c.84c: FileVersion: 4.8.0200.0
881b6c.84c: FileDescription: Microsoft antimalware file system filter driver
891b6c.84c: \SystemRoot\System32\drivers\NisDrvWFP.sys:
901b6c.84c: CreationTime: 2013-09-27T08:53:06.000000000Z
911b6c.84c: LastWriteTime: 2015-03-04T17:34:52.000000000Z
921b6c.84c: ChangeTime: 2015-05-13T09:07:56.800224300Z
931b6c.84c: FileAttributes: 0x20
941b6c.84c: Size: 0x1e698
951b6c.84c: NT Headers: 0xf0
961b6c.84c: Timestamp: 0x54efb8af
971b6c.84c: Machine: 0x8664 - amd64
981b6c.84c: Timestamp: 0x54efb8af
991b6c.84c: Image Version: 6.3
1001b6c.84c: SizeOfImage: 0x1f000 (126976)
1011b6c.84c: Resource Dir: 0x1c000 LB 0x1b90
1021b6c.84c: ProductName: Microsoft Malware Protection
1031b6c.84c: ProductVersion: 4.8.0200.0
1041b6c.84c: FileVersion: 4.8.0200.0
1051b6c.84c: FileDescription: Microsoft Network Realtime Inspection Driver
1061b6c.84c: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume5\opt\VirtualBox'
1071b6c.84c: Calling main()
1081b6c.84c: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
1091b6c.84c: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume5\opt\VirtualBox'
1101b6c.84c: SUPR3HardenedMain: Respawn #1
1111b6c.84c: System32: \Device\HarddiskVolume3\Windows\System32
1121b6c.84c: WinSxS: \Device\HarddiskVolume3\Windows\winsxs
1131b6c.84c: KnownDllPath: C:\Windows\system32
1141b6c.84c: '\Device\HarddiskVolume5\opt\VirtualBox\VirtualBox.exe' has no imports
1151b6c.84c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\opt\VirtualBox\VirtualBox.exe)
1161b6c.84c: supR3HardNtEnableThreadCreation:
1171b6c.84c: supR3HardNtDisableThreadCreation: pvLdrInitThunk=0000000077b4b630 pvNtTerminateThread=0000000077b6dee0
1181b6c.84c: supR3HardenedWinDoReSpawn(1): New child 1bb8.17e8 [kernel32].
1191b6c.84c: supR3HardNtChildGatherData: PebBaseAddress=000007fffffde000 cbPeb=0x380
1201b6c.84c: supR3HardNtPuChFindNtdll: uNtDllParentAddr=0000000077b20000 uNtDllChildAddr=0000000077b20000
1211b6c.84c: supR3HardenedWinSetupChildInit: uLdrInitThunk=0000000077b4b630
1221b6c.84c: supR3HardenedWinSetupChildInit: Start child.
1231b6c.84c: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
1241b6c.84c: supR3HardNtChildPurify: Startup delay kludge #1/0: 520 ms, 52 sleeps
1251b6c.84c: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
1261b6c.84c: *0000000000000000-fffffffffffeffff 0x0001/0x0000 0x0000000
1271b6c.84c: *0000000000010000-fffffffffffeffff 0x0004/0x0004 0x0020000
1281b6c.84c: *0000000000030000-000000000002bfff 0x0002/0x0002 0x0040000
1291b6c.84c: 0000000000034000-0000000000027fff 0x0001/0x0000 0x0000000
1301b6c.84c: *0000000000040000-000000000003efff 0x0004/0x0004 0x0020000
1311b6c.84c: 0000000000041000-ffffffffffed1fff 0x0001/0x0000 0x0000000
1321b6c.84c: *00000000001b0000-00000000000b3fff 0x0000/0x0004 0x0020000
1331b6c.84c: 00000000002ac000-00000000002a8fff 0x0104/0x0004 0x0020000
1341b6c.84c: 00000000002af000-00000000002adfff 0x0004/0x0004 0x0020000
1351b6c.84c: 00000000002b0000-ffffffff88a3ffff 0x0001/0x0000 0x0000000
1361b6c.84c: *0000000077b20000-0000000077b20fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
1371b6c.84c: 0000000077b21000-0000000077c1efff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
1381b6c.84c: 0000000077c1f000-0000000077c4dfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
1391b6c.84c: 0000000077c4e000-0000000077c55fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
1401b6c.84c: 0000000077c56000-0000000077c56fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
1411b6c.84c: 0000000077c57000-0000000077c59fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
1421b6c.84c: 0000000077c5a000-0000000077cc8fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
1431b6c.84c: 0000000077cc9000-00000000709b1fff 0x0001/0x0000 0x0000000
1441b6c.84c: *000000007efe0000-000000007dfdffff 0x0000/0x0002 0x0020000
1451b6c.84c: *000000007ffe0000-000000007ffdefff 0x0002/0x0002 0x0020000
1461b6c.84c: 000000007ffe1000-000000007ffd1fff 0x0000/0x0002 0x0020000
1471b6c.84c: 000000007fff0000-ffffffffc0bfffff 0x0001/0x0000 0x0000000
1481b6c.84c: *000000013f3e0000-000000013f3e0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\opt\VirtualBox\VirtualBox.exe
1491b6c.84c: 000000013f3e1000-000000013f467fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume5\opt\VirtualBox\VirtualBox.exe
1501b6c.84c: 000000013f468000-000000013f468fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume5\opt\VirtualBox\VirtualBox.exe
1511b6c.84c: 000000013f469000-000000013f4b3fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\opt\VirtualBox\VirtualBox.exe
1521b6c.84c: 000000013f4b4000-000000013f4b4fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume5\opt\VirtualBox\VirtualBox.exe
1531b6c.84c: 000000013f4b5000-000000013f4b5fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume5\opt\VirtualBox\VirtualBox.exe
1541b6c.84c: 000000013f4b6000-000000013f4bafff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume5\opt\VirtualBox\VirtualBox.exe
1551b6c.84c: 000000013f4bb000-000000013f4bbfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume5\opt\VirtualBox\VirtualBox.exe
1561b6c.84c: 000000013f4bc000-000000013f4bcfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume5\opt\VirtualBox\VirtualBox.exe
1571b6c.84c: 000000013f4bd000-000000013f4c0fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume5\opt\VirtualBox\VirtualBox.exe
1581b6c.84c: 000000013f4c1000-000000013f50bfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\opt\VirtualBox\VirtualBox.exe
1591b6c.84c: 000000013f50c000-fffff8037ebd7fff 0x0001/0x0000 0x0000000
1601b6c.84c: *000007feffe40000-000007feffe40fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\apisetschema.dll
1611b6c.84c: 000007feffe41000-000007fdffcd1fff 0x0001/0x0000 0x0000000
1621b6c.84c: *000007fffffb0000-000007fffff8cfff 0x0002/0x0002 0x0040000
1631b6c.84c: 000007fffffd3000-000007fffffc9fff 0x0001/0x0000 0x0000000
1641b6c.84c: *000007fffffdc000-000007fffffd9fff 0x0004/0x0004 0x0020000
1651b6c.84c: *000007fffffde000-000007fffffdcfff 0x0004/0x0004 0x0020000
1661b6c.84c: 000007fffffdf000-000007fffffddfff 0x0001/0x0000 0x0000000
1671b6c.84c: *000007fffffe0000-000007fffffcffff 0x0001/0x0002 0x0020000
1681b6c.84c: apisetschema.dll: timestamp 0x562590e2 (rc=VINF_SUCCESS)
1691b6c.84c: VirtualBox.exe: timestamp 0x564221d3 (rc=VINF_SUCCESS)
1701b6c.84c: '\Device\HarddiskVolume5\opt\VirtualBox\VirtualBox.exe' has no imports
1711b6c.84c: '\Device\HarddiskVolume3\Windows\System32\apisetschema.dll' has no imports
1721b6c.84c: '\Device\HarddiskVolume3\Windows\System32\ntdll.dll' has no imports
1731b6c.84c: supR3HardNtChildPurify: Done after 530 ms and 0 fixes (loop #0).
1741bb8.17e8: Log file opened: 5.0.10r104061 g_hStartupLog=0000000000000004 g_uNtVerCombined=0x611db110
1751bb8.17e8: supR3HardenedVmProcessInit: uNtDllAddr=0000000077b20000
1761b6c.84c: supR3HardNtEnableThreadCreation:
1771bb8.17e8: ntdll.dll: timestamp 0x56259295 (rc=VINF_SUCCESS)
1781bb8.17e8: New simple heap: #1 00000000002b0000 LB 0x400000 (for 1740800 allocation)
1791bb8.17e8: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume5\opt\VirtualBox'
1801bb8.17e8: System32: \Device\HarddiskVolume3\Windows\System32
1811bb8.17e8: WinSxS: \Device\HarddiskVolume3\Windows\winsxs
1821bb8.17e8: KnownDllPath: C:\Windows\system32
1831bb8.17e8: supR3HardenedVmProcessInit: Opening vboxdrv stub...
1841bb8.17e8: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
1851bb8.17e8: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
1861bb8.17e8: Registered Dll notification callback with NTDLL.
1871bb8.17e8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\kernel32.dll)
1881bb8.17e8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\kernel32.dll
1891bb8.17e8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
1901bb8.17e8: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
1911bb8.17e8: supR3HardenedDllNotificationCallback: load 0000000077a00000 LB 0x00120000 C:\Windows\system32\kernel32.dll [fFlags=0x0]
1921bb8.17e8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
1931bb8.17e8: supR3HardenedDllNotificationCallback: load 000007fefdbe0000 LB 0x0006c000 C:\Windows\system32\KERNELBASE.dll [fFlags=0x0]
1941bb8.17e8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\KernelBase.dll)
1951bb8.17e8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\KernelBase.dll
1961bb8.17e8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077a00000 'C:\Windows\system32\kernel32.dll'
1971bb8.17e8: supR3HardNtDisableThreadCreation: pvLdrInitThunk=0000000077b4b630 pvNtTerminateThread=0000000077b6dee0
1981b6c.84c: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 20 ms.
1991bb8.17e8: \SystemRoot\System32\ntdll.dll:
2001bb8.17e8: CreationTime: 2015-11-11T09:33:16.213469600Z
2011bb8.17e8: LastWriteTime: 2015-10-20T01:09:05.164170200Z
2021bb8.17e8: ChangeTime: 2015-11-12T07:41:52.844818500Z
2031bb8.17e8: FileAttributes: 0x20
2041bb8.17e8: Size: 0x1a67c0
2051bb8.17e8: NT Headers: 0xe0
2061bb8.17e8: Timestamp: 0x56259295
2071bb8.17e8: Machine: 0x8664 - amd64
2081bb8.17e8: Timestamp: 0x56259295
2091bb8.17e8: Image Version: 6.1
2101bb8.17e8: SizeOfImage: 0x1a9000 (1740800)
2111bb8.17e8: Resource Dir: 0x14d000 LB 0x5a028
2121bb8.17e8: ProductName: Microsoft® Windows® Operating System
2131bb8.17e8: ProductVersion: 6.1.7601.19045
2141bb8.17e8: FileVersion: 6.1.7601.19045 (win7sp1_gdr.151019-1254)
2151bb8.17e8: FileDescription: NT Layer DLL
2161bb8.17e8: \SystemRoot\System32\kernel32.dll:
2171bb8.17e8: CreationTime: 2015-11-11T09:33:16.353469800Z
2181bb8.17e8: LastWriteTime: 2015-10-20T01:05:40.819000000Z
2191bb8.17e8: ChangeTime: 2015-11-12T07:41:52.954018600Z
2201bb8.17e8: FileAttributes: 0x20
2211bb8.17e8: Size: 0x11c600
2221bb8.17e8: NT Headers: 0xe8
2231bb8.17e8: Timestamp: 0x56259270
2241bb8.17e8: Machine: 0x8664 - amd64
2251bb8.17e8: Timestamp: 0x56259270
2261bb8.17e8: Image Version: 6.1
2271bb8.17e8: SizeOfImage: 0x120000 (1179648)
2281bb8.17e8: Resource Dir: 0x117000 LB 0x528
2291bb8.17e8: ProductName: Microsoft® Windows® Operating System
2301bb8.17e8: ProductVersion: 6.1.7601.19045
2311bb8.17e8: FileVersion: 6.1.7601.19045 (win7sp1_gdr.151019-1254)
2321bb8.17e8: FileDescription: Windows NT BASE API Client DLL
2331bb8.17e8: \SystemRoot\System32\KernelBase.dll:
2341bb8.17e8: CreationTime: 2015-11-11T09:33:16.013469300Z
2351bb8.17e8: LastWriteTime: 2015-10-20T01:05:40.819000000Z
2361bb8.17e8: ChangeTime: 2015-11-12T07:41:52.954018600Z
2371bb8.17e8: FileAttributes: 0x20
2381bb8.17e8: Size: 0x67c00
2391bb8.17e8: NT Headers: 0xe8
2401bb8.17e8: Timestamp: 0x56259271
2411bb8.17e8: Machine: 0x8664 - amd64
2421bb8.17e8: Timestamp: 0x56259271
2431bb8.17e8: Image Version: 6.1
2441bb8.17e8: SizeOfImage: 0x6c000 (442368)
2451bb8.17e8: Resource Dir: 0x6a000 LB 0x530
2461bb8.17e8: ProductName: Microsoft® Windows® Operating System
2471bb8.17e8: ProductVersion: 6.1.7601.19045
2481bb8.17e8: FileVersion: 6.1.7601.19045 (win7sp1_gdr.151019-1254)
2491bb8.17e8: FileDescription: Windows NT BASE API Client DLL
2501bb8.17e8: \SystemRoot\System32\apisetschema.dll:
2511bb8.17e8: CreationTime: 2015-11-11T09:33:14.123466700Z
2521bb8.17e8: LastWriteTime: 2015-10-20T00:53:47.280000000Z
2531bb8.17e8: ChangeTime: 2015-11-12T07:41:52.829218400Z
2541bb8.17e8: FileAttributes: 0x20
2551bb8.17e8: Size: 0x1a00
2561bb8.17e8: NT Headers: 0xc0
2571bb8.17e8: Timestamp: 0x562590e2
2581bb8.17e8: Machine: 0x8664 - amd64
2591bb8.17e8: Timestamp: 0x562590e2
2601bb8.17e8: Image Version: 6.1
2611bb8.17e8: SizeOfImage: 0x50000 (327680)
2621bb8.17e8: Resource Dir: 0x30000 LB 0x3f8
2631bb8.17e8: ProductName: Microsoft® Windows® Operating System
2641bb8.17e8: ProductVersion: 6.1.7601.19045
2651bb8.17e8: FileVersion: 6.1.7601.19045 (win7sp1_gdr.151019-1254)
2661bb8.17e8: FileDescription: ApiSet Schema DLL
2671bb8.17e8: NtOpenDirectoryObject failed on \Driver: 0xc0000022
2681bb8.17e8: supR3HardenedWinFindAdversaries: 0x400
2691bb8.17e8: \SystemRoot\System32\drivers\MpFilter.sys:
2701bb8.17e8: CreationTime: 2015-03-04T17:34:52.000000000Z
2711bb8.17e8: LastWriteTime: 2015-03-04T17:34:52.000000000Z
2721bb8.17e8: ChangeTime: 2015-05-13T09:07:56.847024300Z
2731bb8.17e8: FileAttributes: 0x20
2741bb8.17e8: Size: 0x44738
2751bb8.17e8: NT Headers: 0xf0
2761bb8.17e8: Timestamp: 0x54efb880
2771bb8.17e8: Machine: 0x8664 - amd64
2781bb8.17e8: Timestamp: 0x54efb880
2791bb8.17e8: Image Version: 6.3
2801bb8.17e8: SizeOfImage: 0x44000 (278528)
2811bb8.17e8: Resource Dir: 0x42000 LB 0xd50
2821bb8.17e8: ProductName: Microsoft Malware Protection
2831bb8.17e8: ProductVersion: 4.8.0200.0
2841bb8.17e8: FileVersion: 4.8.0200.0
2851bb8.17e8: FileDescription: Microsoft antimalware file system filter driver
2861bb8.17e8: \SystemRoot\System32\drivers\NisDrvWFP.sys:
2871bb8.17e8: CreationTime: 2013-09-27T08:53:06.000000000Z
2881bb8.17e8: LastWriteTime: 2015-03-04T17:34:52.000000000Z
2891bb8.17e8: ChangeTime: 2015-05-13T09:07:56.800224300Z
2901bb8.17e8: FileAttributes: 0x20
2911bb8.17e8: Size: 0x1e698
2921bb8.17e8: NT Headers: 0xf0
2931bb8.17e8: Timestamp: 0x54efb8af
2941bb8.17e8: Machine: 0x8664 - amd64
2951bb8.17e8: Timestamp: 0x54efb8af
2961bb8.17e8: Image Version: 6.3
2971bb8.17e8: SizeOfImage: 0x1f000 (126976)
2981bb8.17e8: Resource Dir: 0x1c000 LB 0x1b90
2991bb8.17e8: ProductName: Microsoft Malware Protection
3001bb8.17e8: ProductVersion: 4.8.0200.0
3011bb8.17e8: FileVersion: 4.8.0200.0
3021bb8.17e8: FileDescription: Microsoft Network Realtime Inspection Driver
3031bb8.17e8: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume5\opt\VirtualBox'
3041bb8.17e8: Calling main()
3051bb8.17e8: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
3061bb8.17e8: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume5\opt\VirtualBox'
3071bb8.17e8: '\Device\HarddiskVolume5\opt\VirtualBox\VirtualBox.exe' has no imports
3081bb8.17e8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\opt\VirtualBox\VirtualBox.exe)
3091bb8.17e8: SUPR3HardenedMain: Respawn #2
3101bb8.17e8: supR3HardNtEnableThreadCreation:
3111bb8.17e8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\apphelp.dll)
3121bb8.17e8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\apphelp.dll
3131bb8.17e8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\apphelp.dll (rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
3141bb8.17e8: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\apphelp.dll [lacks WinVerifyTrust]
3151bb8.17e8: supR3HardenedDllNotificationCallback: load 000007fefd700000 LB 0x00057000 C:\Windows\system32\apphelp.dll [fFlags=0x0]
3161bb8.17e8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\apphelp.dll [lacks WinVerifyTrust]
3171bb8.17e8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd700000 'C:\Windows\system32\apphelp.dll'
3181bb8.17e8: supR3HardNtDisableThreadCreation: pvLdrInitThunk=0000000077b4b630 pvNtTerminateThread=0000000077b6dee0
3191bb8.17e8: supR3HardenedWinDoReSpawn(2): New child 1428.140c [kernel32].
3201bb8.17e8: supR3HardNtChildGatherData: PebBaseAddress=000007fffffd9000 cbPeb=0x380
3211bb8.17e8: supR3HardNtPuChFindNtdll: uNtDllParentAddr=0000000077b20000 uNtDllChildAddr=0000000077b20000
3221bb8.17e8: supR3HardenedWinSetupChildInit: uLdrInitThunk=0000000077b4b630
3231bb8.17e8: supR3HardenedWinSetupChildInit: Start child.
3241bb8.17e8: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
3251bb8.17e8: supR3HardNtChildPurify: Startup delay kludge #1/0: 520 ms, 52 sleeps
3261bb8.17e8: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
3271bb8.17e8: *0000000000000000-fffffffffffeffff 0x0001/0x0000 0x0000000
3281bb8.17e8: *0000000000010000-fffffffffffeffff 0x0004/0x0004 0x0020000
3291bb8.17e8: *0000000000030000-000000000002bfff 0x0002/0x0002 0x0040000
3301bb8.17e8: 0000000000034000-0000000000027fff 0x0001/0x0000 0x0000000
3311bb8.17e8: *0000000000040000-000000000003efff 0x0004/0x0004 0x0020000
3321bb8.17e8: 0000000000041000-ffffffffffe81fff 0x0001/0x0000 0x0000000
3331bb8.17e8: *0000000000200000-0000000000103fff 0x0000/0x0004 0x0020000
3341bb8.17e8: 00000000002fc000-00000000002f8fff 0x0104/0x0004 0x0020000
3351bb8.17e8: 00000000002ff000-00000000002fdfff 0x0004/0x0004 0x0020000
3361bb8.17e8: 0000000000300000-ffffffff88adffff 0x0001/0x0000 0x0000000
3371bb8.17e8: *0000000077b20000-0000000077b20fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
3381bb8.17e8: 0000000077b21000-0000000077c1efff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
3391bb8.17e8: 0000000077c1f000-0000000077c4dfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
3401bb8.17e8: 0000000077c4e000-0000000077c55fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
3411bb8.17e8: 0000000077c56000-0000000077c56fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
3421bb8.17e8: 0000000077c57000-0000000077c59fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
3431bb8.17e8: 0000000077c5a000-0000000077cc8fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
3441bb8.17e8: 0000000077cc9000-00000000709b1fff 0x0001/0x0000 0x0000000
3451bb8.17e8: *000000007efe0000-000000007dfdffff 0x0000/0x0002 0x0020000
3461bb8.17e8: *000000007ffe0000-000000007ffdefff 0x0002/0x0002 0x0020000
3471bb8.17e8: 000000007ffe1000-000000007ffd1fff 0x0000/0x0002 0x0020000
3481bb8.17e8: 000000007fff0000-ffffffffc0bfffff 0x0001/0x0000 0x0000000
3491bb8.17e8: *000000013f3e0000-000000013f3e0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\opt\VirtualBox\VirtualBox.exe
3501bb8.17e8: 000000013f3e1000-000000013f467fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume5\opt\VirtualBox\VirtualBox.exe
3511bb8.17e8: 000000013f468000-000000013f468fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume5\opt\VirtualBox\VirtualBox.exe
3521bb8.17e8: 000000013f469000-000000013f4b3fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\opt\VirtualBox\VirtualBox.exe
3531bb8.17e8: 000000013f4b4000-000000013f4b4fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume5\opt\VirtualBox\VirtualBox.exe
3541bb8.17e8: 000000013f4b5000-000000013f4b5fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume5\opt\VirtualBox\VirtualBox.exe
3551bb8.17e8: 000000013f4b6000-000000013f4bafff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume5\opt\VirtualBox\VirtualBox.exe
3561bb8.17e8: 000000013f4bb000-000000013f4bbfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume5\opt\VirtualBox\VirtualBox.exe
3571bb8.17e8: 000000013f4bc000-000000013f4bcfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume5\opt\VirtualBox\VirtualBox.exe
3581bb8.17e8: 000000013f4bd000-000000013f4c0fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume5\opt\VirtualBox\VirtualBox.exe
3591bb8.17e8: 000000013f4c1000-000000013f50bfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\opt\VirtualBox\VirtualBox.exe
3601bb8.17e8: 000000013f50c000-fffff8037ebd7fff 0x0001/0x0000 0x0000000
3611bb8.17e8: *000007feffe40000-000007feffe40fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\apisetschema.dll
3621bb8.17e8: 000007feffe41000-000007fdffcd1fff 0x0001/0x0000 0x0000000
3631bb8.17e8: *000007fffffb0000-000007fffff8cfff 0x0002/0x0002 0x0040000
3641bb8.17e8: 000007fffffd3000-000007fffffccfff 0x0001/0x0000 0x0000000
3651bb8.17e8: *000007fffffd9000-000007fffffd7fff 0x0004/0x0004 0x0020000
3661bb8.17e8: 000007fffffda000-000007fffffd5fff 0x0001/0x0000 0x0000000
3671bb8.17e8: *000007fffffde000-000007fffffdbfff 0x0004/0x0004 0x0020000
3681bb8.17e8: *000007fffffe0000-000007fffffcffff 0x0001/0x0002 0x0020000
3691bb8.17e8: apisetschema.dll: timestamp 0x562590e2 (rc=VINF_SUCCESS)
3701bb8.17e8: VirtualBox.exe: timestamp 0x564221d3 (rc=VINF_SUCCESS)
3711bb8.17e8: '\Device\HarddiskVolume5\opt\VirtualBox\VirtualBox.exe' has no imports
3721bb8.17e8: '\Device\HarddiskVolume3\Windows\System32\apisetschema.dll' has no imports
3731bb8.17e8: '\Device\HarddiskVolume3\Windows\System32\ntdll.dll' has no imports
3741bb8.17e8: supR3HardNtChildPurify: Done after 530 ms and 0 fixes (loop #0).
3751428.140c: Log file opened: 5.0.10r104061 g_hStartupLog=0000000000000004 g_uNtVerCombined=0x611db110
3761428.140c: supR3HardenedVmProcessInit: uNtDllAddr=0000000077b20000
3771bb8.17e8: supR3HardenedEarlyCompact: Removed heap 1 (0x000000002b0000 LB 0x400000)
3781428.140c: ntdll.dll: timestamp 0x56259295 (rc=VINF_SUCCESS)
3791428.140c: New simple heap: #1 0000000000300000 LB 0x400000 (for 1740800 allocation)
3801bb8.17e8: supR3HardNtEnableThreadCreation:
3811428.140c: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume5\opt\VirtualBox'
3821428.140c: System32: \Device\HarddiskVolume3\Windows\System32
3831428.140c: WinSxS: \Device\HarddiskVolume3\Windows\winsxs
3841428.140c: KnownDllPath: C:\Windows\system32
3851428.140c: supR3HardenedVmProcessInit: Opening vboxdrv...
3861428.140c: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
3871428.140c: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
3881428.140c: Registered Dll notification callback with NTDLL.
3891428.140c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\kernel32.dll)
3901428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\kernel32.dll
3911428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
3921428.140c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
3931428.140c: supR3HardenedDllNotificationCallback: load 0000000077a00000 LB 0x00120000 C:\Windows\system32\kernel32.dll [fFlags=0x0]
3941428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
3951428.140c: supR3HardenedDllNotificationCallback: load 000007fefdbe0000 LB 0x0006c000 C:\Windows\system32\KERNELBASE.dll [fFlags=0x0]
3961428.140c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\KernelBase.dll)
3971428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\KernelBase.dll
3981428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077a00000 'C:\Windows\system32\kernel32.dll'
3991428.140c: supR3HardNtDisableThreadCreation: pvLdrInitThunk=0000000077b4b630 pvNtTerminateThread=0000000077b6dee0
4001bb8.17e8: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 30 ms.
4011428.140c: \SystemRoot\System32\ntdll.dll:
4021428.140c: CreationTime: 2015-11-11T09:33:16.213469600Z
4031428.140c: LastWriteTime: 2015-10-20T01:09:05.164170200Z
4041428.140c: ChangeTime: 2015-11-12T07:41:52.844818500Z
4051428.140c: FileAttributes: 0x20
4061428.140c: Size: 0x1a67c0
4071428.140c: NT Headers: 0xe0
4081428.140c: Timestamp: 0x56259295
4091428.140c: Machine: 0x8664 - amd64
4101428.140c: Timestamp: 0x56259295
4111428.140c: Image Version: 6.1
4121428.140c: SizeOfImage: 0x1a9000 (1740800)
4131428.140c: Resource Dir: 0x14d000 LB 0x5a028
4141428.140c: ProductName: Microsoft® Windows® Operating System
4151428.140c: ProductVersion: 6.1.7601.19045
4161428.140c: FileVersion: 6.1.7601.19045 (win7sp1_gdr.151019-1254)
4171428.140c: FileDescription: NT Layer DLL
4181428.140c: \SystemRoot\System32\kernel32.dll:
4191428.140c: CreationTime: 2015-11-11T09:33:16.353469800Z
4201428.140c: LastWriteTime: 2015-10-20T01:05:40.819000000Z
4211428.140c: ChangeTime: 2015-11-12T07:41:52.954018600Z
4221428.140c: FileAttributes: 0x20
4231428.140c: Size: 0x11c600
4241428.140c: NT Headers: 0xe8
4251428.140c: Timestamp: 0x56259270
4261428.140c: Machine: 0x8664 - amd64
4271428.140c: Timestamp: 0x56259270
4281428.140c: Image Version: 6.1
4291428.140c: SizeOfImage: 0x120000 (1179648)
4301428.140c: Resource Dir: 0x117000 LB 0x528
4311428.140c: ProductName: Microsoft® Windows® Operating System
4321428.140c: ProductVersion: 6.1.7601.19045
4331428.140c: FileVersion: 6.1.7601.19045 (win7sp1_gdr.151019-1254)
4341428.140c: FileDescription: Windows NT BASE API Client DLL
4351428.140c: \SystemRoot\System32\KernelBase.dll:
4361428.140c: CreationTime: 2015-11-11T09:33:16.013469300Z
4371428.140c: LastWriteTime: 2015-10-20T01:05:40.819000000Z
4381428.140c: ChangeTime: 2015-11-12T07:41:52.954018600Z
4391428.140c: FileAttributes: 0x20
4401428.140c: Size: 0x67c00
4411428.140c: NT Headers: 0xe8
4421428.140c: Timestamp: 0x56259271
4431428.140c: Machine: 0x8664 - amd64
4441428.140c: Timestamp: 0x56259271
4451428.140c: Image Version: 6.1
4461428.140c: SizeOfImage: 0x6c000 (442368)
4471428.140c: Resource Dir: 0x6a000 LB 0x530
4481428.140c: ProductName: Microsoft® Windows® Operating System
4491428.140c: ProductVersion: 6.1.7601.19045
4501428.140c: FileVersion: 6.1.7601.19045 (win7sp1_gdr.151019-1254)
4511428.140c: FileDescription: Windows NT BASE API Client DLL
4521428.140c: \SystemRoot\System32\apisetschema.dll:
4531428.140c: CreationTime: 2015-11-11T09:33:14.123466700Z
4541428.140c: LastWriteTime: 2015-10-20T00:53:47.280000000Z
4551428.140c: ChangeTime: 2015-11-12T07:41:52.829218400Z
4561428.140c: FileAttributes: 0x20
4571428.140c: Size: 0x1a00
4581428.140c: NT Headers: 0xc0
4591428.140c: Timestamp: 0x562590e2
4601428.140c: Machine: 0x8664 - amd64
4611428.140c: Timestamp: 0x562590e2
4621428.140c: Image Version: 6.1
4631428.140c: SizeOfImage: 0x50000 (327680)
4641428.140c: Resource Dir: 0x30000 LB 0x3f8
4651428.140c: ProductName: Microsoft® Windows® Operating System
4661428.140c: ProductVersion: 6.1.7601.19045
4671428.140c: FileVersion: 6.1.7601.19045 (win7sp1_gdr.151019-1254)
4681428.140c: FileDescription: ApiSet Schema DLL
4691428.140c: NtOpenDirectoryObject failed on \Driver: 0xc0000022
4701428.140c: supR3HardenedWinFindAdversaries: 0x400
4711428.140c: \SystemRoot\System32\drivers\MpFilter.sys:
4721428.140c: CreationTime: 2015-03-04T17:34:52.000000000Z
4731428.140c: LastWriteTime: 2015-03-04T17:34:52.000000000Z
4741428.140c: ChangeTime: 2015-05-13T09:07:56.847024300Z
4751428.140c: FileAttributes: 0x20
4761428.140c: Size: 0x44738
4771428.140c: NT Headers: 0xf0
4781428.140c: Timestamp: 0x54efb880
4791428.140c: Machine: 0x8664 - amd64
4801428.140c: Timestamp: 0x54efb880
4811428.140c: Image Version: 6.3
4821428.140c: SizeOfImage: 0x44000 (278528)
4831428.140c: Resource Dir: 0x42000 LB 0xd50
4841428.140c: ProductName: Microsoft Malware Protection
4851428.140c: ProductVersion: 4.8.0200.0
4861428.140c: FileVersion: 4.8.0200.0
4871428.140c: FileDescription: Microsoft antimalware file system filter driver
4881428.140c: \SystemRoot\System32\drivers\NisDrvWFP.sys:
4891428.140c: CreationTime: 2013-09-27T08:53:06.000000000Z
4901428.140c: LastWriteTime: 2015-03-04T17:34:52.000000000Z
4911428.140c: ChangeTime: 2015-05-13T09:07:56.800224300Z
4921428.140c: FileAttributes: 0x20
4931428.140c: Size: 0x1e698
4941428.140c: NT Headers: 0xf0
4951428.140c: Timestamp: 0x54efb8af
4961428.140c: Machine: 0x8664 - amd64
4971428.140c: Timestamp: 0x54efb8af
4981428.140c: Image Version: 6.3
4991428.140c: SizeOfImage: 0x1f000 (126976)
5001428.140c: Resource Dir: 0x1c000 LB 0x1b90
5011428.140c: ProductName: Microsoft Malware Protection
5021428.140c: ProductVersion: 4.8.0200.0
5031428.140c: FileVersion: 4.8.0200.0
5041428.140c: FileDescription: Microsoft Network Realtime Inspection Driver
5051428.140c: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume5\opt\VirtualBox'
5061428.140c: Calling main()
5071428.140c: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
5081428.140c: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume5\opt\VirtualBox'
5091428.140c: '\Device\HarddiskVolume5\opt\VirtualBox\VirtualBox.exe' has no imports
5101428.140c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\opt\VirtualBox\VirtualBox.exe)
5111428.140c: SUPR3HardenedMain: Final process, opening VBoxDrv...
5121428.140c: supR3HardenedEarlyCompact: Removed heap 1 (0x00000000300000 LB 0x400000)
5131428.140c: supR3HardNtEnableThreadCreation:
5141428.140c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\opt\VirtualBox\VBoxSupLib.dll)
5151428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\opt\VirtualBox\VBoxSupLib.dll
5161428.140c: supR3HardenedMonitor_LdrLoadDll: pName=D:\opt\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d4a30:C:\Windows\system32 [calling]
5171428.140c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
5181428.140c: supR3HardenedDllNotificationCallback: load 000007fef9d70000 LB 0x00005000 D:\opt\VirtualBox\VBoxSupLib.DLL [fFlags=0x0]
5191428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
5201428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
5211428.140c: supR3HardenedMonitor_LdrLoadDll: pName=D:\opt\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d5560:D:\opt\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\Common Files\Microsoft Shared\Windows Live;D:\opt\Python27\;D:\opt\Python27\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x64;C:\Program Files\TortoiseSVN\bin;D:\opt\Sync\OpenSSH\bin;D:\opt\perl\c\bin;D:\opt\perl\perl\site\bin;D:\opt\perl\perl\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Skype\Phone\;D:\opt\git\TortoiseGit\bin;C:\Users\mcon\AppData\Roaming\Python\Scripts;D:\opt\cygwin64\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64;D:\opt\Nmap [calling]
5221428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef9d70000 'D:\opt\VirtualBox\VBoxSupLib.DLL'
5231428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
5241428.140c: supR3HardenedMonitor_LdrLoadDll: pName=D:\opt\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d5560:D:\opt\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\Common Files\Microsoft Shared\Windows Live;D:\opt\Python27\;D:\opt\Python27\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x64;C:\Program Files\TortoiseSVN\bin;D:\opt\Sync\OpenSSH\bin;D:\opt\perl\c\bin;D:\opt\perl\perl\site\bin;D:\opt\perl\perl\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Skype\Phone\;D:\opt\git\TortoiseGit\bin;C:\Users\mcon\AppData\Roaming\Python\Scripts;D:\opt\cygwin64\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64;D:\opt\Nmap [calling]
5251428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef9d70000 'D:\opt\VirtualBox\VBoxSupLib.DLL'
5261428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef9d70000 'D:\opt\VirtualBox\VBoxSupLib.DLL'
5271428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
5281428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'crypt32.dll'.
5291428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msasn1.dll'.
5301428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
5311428.140c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\wintrust.dll)
5321428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\wintrust.dll
5331428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
5341428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
5351428.140c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll)
5361428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll
5371428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
5381428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume3\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
5391428.140c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\msasn1.dll)
5401428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\msasn1.dll
5411428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
5421428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume3\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
5431428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
5441428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msasn1.dll'.
5451428.140c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\crypt32.dll)
5461428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\crypt32.dll
5471428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
5481428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
5491428.140c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\msvcrt.dll)
5501428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\msvcrt.dll
5511428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
5521428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume3\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
5531428.140c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
5541428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
5551428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
5561428.140c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
5571428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d4a30:C:\Windows\system32 [calling]
5581428.140c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
5591428.140c: supR3HardenedDllNotificationCallback: load 000007fefd9b0000 LB 0x0003b000 C:\Windows\system32\Wintrust.dll [fFlags=0x0]
5601428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
5611428.140c: supR3HardenedDllNotificationCallback: load 000007feff470000 LB 0x0009f000 C:\Windows\system32\msvcrt.dll [fFlags=0x0]
5621428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
5631428.140c: supR3HardenedDllNotificationCallback: load 000007fefd9f0000 LB 0x0016d000 C:\Windows\system32\CRYPT32.dll [fFlags=0x0]
5641428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
5651428.140c: supR3HardenedDllNotificationCallback: load 000007fefd8d0000 LB 0x0000f000 C:\Windows\system32\MSASN1.dll [fFlags=0x0]
5661428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
5671428.140c: supR3HardenedDllNotificationCallback: load 000007feff7e0000 LB 0x0012d000 C:\Windows\system32\RPCRT4.dll [fFlags=0x0]
5681428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
5691428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd9b0000 'C:\Windows\system32\Wintrust.dll'
5701428.140c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\bcrypt.dll)
5711428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\bcrypt.dll
5721428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\bcrypt.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000084a360:C:\Windows\system32 [calling]
5731428.140c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
5741428.140c: supR3HardenedDllNotificationCallback: load 000007fefd230000 LB 0x00022000 C:\Windows\system32\bcrypt.dll [fFlags=0x0]
5751428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
5761428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd230000 'C:\Windows\system32\bcrypt.dll'
5771428.140c: bcrypt.dll loaded at 000007fefd230000, BCryptOpenAlgorithmProvider at 000007fefd232640, preloading providers:
5781428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'advapi32.dll'.
5791428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'bcrypt.dll'.
5801428.140c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\bcryptprimitives.dll)
5811428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\bcryptprimitives.dll
5821428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
5831428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume3\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
5841428.140c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
5851428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
5861428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
5871428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
5881428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'rpcrt4.dll'.
5891428.140c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\advapi32.dll)
5901428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\advapi32.dll
5911428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
5921428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
5931428.140c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
5941428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
5951428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
5961428.140c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
5971428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\bcryptprimitives.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d5560:D:\opt\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\Common Files\Microsoft Shared\Windows Live;D:\opt\Python27\;D:\opt\Python27\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x64;C:\Program Files\TortoiseSVN\bin;D:\opt\Sync\OpenSSH\bin;D:\opt\perl\c\bin;D:\opt\perl\perl\site\bin;D:\opt\perl\perl\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Skype\Phone\;D:\opt\git\TortoiseGit\bin;C:\Users\mcon\AppData\Roaming\Python\Scripts;D:\opt\cygwin64\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64;D:\opt\Nmap [calling]
5981428.140c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
5991428.140c: supR3HardenedDllNotificationCallback: load 000007fefcd20000 LB 0x0004c000 C:\Windows\system32\bcryptprimitives.dll [fFlags=0x0]
6001428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
6011428.140c: supR3HardenedDllNotificationCallback: load 000007fefdd90000 LB 0x000db000 C:\Windows\system32\ADVAPI32.dll [fFlags=0x0]
6021428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
6031428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msvcrt.dll'.
6041428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'rpcrt4.dll'.
6051428.140c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\sechost.dll)
6061428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\sechost.dll
6071428.140c: supR3HardenedDllNotificationCallback: load 000007fefdcf0000 LB 0x0001f000 C:\Windows\SYSTEM32\sechost.dll [fFlags=0x0]
6081428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\sechost.dll [lacks WinVerifyTrust]
6091428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcd20000 'C:\Windows\system32\bcryptprimitives.dll'
6101428.140c: BCryptOpenAlgorithmProvider(,'MD2',0,0) -> 0x0 (hAlgo=000000000084d0d0)
6111428.140c: BCryptOpenAlgorithmProvider(,'MD4',0,0) -> 0x0 (hAlgo=000000000084d960)
6121428.140c: BCryptOpenAlgorithmProvider(,'MD5',0,0) -> 0x0 (hAlgo=000000000084da80)
6131428.140c: BCryptOpenAlgorithmProvider(,'SHA1',0,0) -> 0x0 (hAlgo=000000000084dc90)
6141428.140c: BCryptOpenAlgorithmProvider(,'SHA256',0,0) -> 0x0 (hAlgo=000000000084ddb0)
6151428.140c: BCryptOpenAlgorithmProvider(,'SHA512',0,0) -> 0x0 (hAlgo=000000000084ded0)
6161428.140c: BCryptOpenAlgorithmProvider(,'RSA',0,0) -> 0x0 (hAlgo=000000000084e110)
6171428.140c: BCryptOpenAlgorithmProvider(,'DSA',0,0) -> 0x0 (hAlgo=000000000084e230)
6181428.140c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\cryptsp.dll)
6191428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\cryptsp.dll
6201428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
6211428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
6221428.140c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
6231428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
6241428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
6251428.140c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
6261428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTSP.dll (Input=CRYPTSP.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d5560:D:\opt\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\Common Files\Microsoft Shared\Windows Live;D:\opt\Python27\;D:\opt\Python27\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x64;C:\Program Files\TortoiseSVN\bin;D:\opt\Sync\OpenSSH\bin;D:\opt\perl\c\bin;D:\opt\perl\perl\site\bin;D:\opt\perl\perl\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Skype\Phone\;D:\opt\git\TortoiseGit\bin;C:\Users\mcon\AppData\Roaming\Python\Scripts;D:\opt\cygwin64\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64;D:\opt\Nmap [calling]
6271428.140c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptsp.dll [lacks WinVerifyTrust]
6281428.140c: supR3HardenedDllNotificationCallback: load 000007fefd260000 LB 0x00018000 C:\Windows\system32\CRYPTSP.dll [fFlags=0x0]
6291428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptsp.dll [lacks WinVerifyTrust]
6301428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd260000 'C:\Windows\system32\CRYPTSP.dll'
6311428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
6321428.140c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\rsaenh.dll)
6331428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\rsaenh.dll
6341428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
6351428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
6361428.140c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
6371428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d5560:D:\opt\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\Common Files\Microsoft Shared\Windows Live;D:\opt\Python27\;D:\opt\Python27\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x64;C:\Program Files\TortoiseSVN\bin;D:\opt\Sync\OpenSSH\bin;D:\opt\perl\c\bin;D:\opt\perl\perl\site\bin;D:\opt\perl\perl\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Skype\Phone\;D:\opt\git\TortoiseGit\bin;C:\Users\mcon\AppData\Roaming\Python\Scripts;D:\opt\cygwin64\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64;D:\opt\Nmap [calling]
6381428.140c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
6391428.140c: supR3HardenedDllNotificationCallback: load 000007fefcde0000 LB 0x00047000 C:\Windows\system32\rsaenh.dll [fFlags=0x0]
6401428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
6411428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcde0000 'C:\Windows\system32\rsaenh.dll'
6421428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
6431428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ADVAPI32.dll (Input=ADVAPI32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d5560:D:\opt\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\Common Files\Microsoft Shared\Windows Live;D:\opt\Python27\;D:\opt\Python27\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x64;C:\Program Files\TortoiseSVN\bin;D:\opt\Sync\OpenSSH\bin;D:\opt\perl\c\bin;D:\opt\perl\perl\site\bin;D:\opt\perl\perl\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Skype\Phone\;D:\opt\git\TortoiseGit\bin;C:\Users\mcon\AppData\Roaming\Python\Scripts;D:\opt\cygwin64\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64;D:\opt\Nmap [calling]
6441428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdd90000 'C:\Windows\system32\ADVAPI32.dll'
6451428.140c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\cryptbase.dll)
6461428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\cryptbase.dll
6471428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTBASE.dll (Input=CRYPTBASE.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d5560:D:\opt\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\Common Files\Microsoft Shared\Windows Live;D:\opt\Python27\;D:\opt\Python27\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x64;C:\Program Files\TortoiseSVN\bin;D:\opt\Sync\OpenSSH\bin;D:\opt\perl\c\bin;D:\opt\perl\perl\site\bin;D:\opt\perl\perl\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Skype\Phone\;D:\opt\git\TortoiseGit\bin;C:\Users\mcon\AppData\Roaming\Python\Scripts;D:\opt\cygwin64\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64;D:\opt\Nmap [calling]
6481428.140c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptbase.dll [lacks WinVerifyTrust]
6491428.140c: supR3HardenedDllNotificationCallback: load 000007fefd760000 LB 0x0000f000 C:\Windows\system32\CRYPTBASE.dll [fFlags=0x0]
6501428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptbase.dll [lacks WinVerifyTrust]
6511428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd760000 'C:\Windows\system32\CRYPTBASE.dll'
6521428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
6531428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d5560:D:\opt\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\Common Files\Microsoft Shared\Windows Live;D:\opt\Python27\;D:\opt\Python27\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x64;C:\Program Files\TortoiseSVN\bin;D:\opt\Sync\OpenSSH\bin;D:\opt\perl\c\bin;D:\opt\perl\perl\site\bin;D:\opt\perl\perl\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Skype\Phone\;D:\opt\git\TortoiseGit\bin;C:\Users\mcon\AppData\Roaming\Python\Scripts;D:\opt\cygwin64\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64;D:\opt\Nmap [calling]
6541428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077a00000 'C:\Windows\system32\kernel32.dll'
6551428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
6561428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\WINTRUST.DLL (Input=WINTRUST.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d5560:D:\opt\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\Common Files\Microsoft Shared\Windows Live;D:\opt\Python27\;D:\opt\Python27\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x64;C:\Program Files\TortoiseSVN\bin;D:\opt\Sync\OpenSSH\bin;D:\opt\perl\c\bin;D:\opt\perl\perl\site\bin;D:\opt\perl\perl\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Skype\Phone\;D:\opt\git\TortoiseGit\bin;C:\Users\mcon\AppData\Roaming\Python\Scripts;D:\opt\cygwin64\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64;D:\opt\Nmap [calling]
6571428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd9b0000 'C:\Windows\system32\WINTRUST.DLL'
6581428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
6591428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPT32.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00000000007d5560:D:\opt\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\Common Files\Microsoft Shared\Windows Live;D:\opt\Python27\;D:\opt\Python27\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x64;C:\Program Files\TortoiseSVN\bin;D:\opt\Sync\OpenSSH\bin;D:\opt\perl\c\bin;D:\opt\perl\perl\site\bin;D:\opt\perl\perl\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Skype\Phone\;D:\opt\git\TortoiseGit\bin;C:\Users\mcon\AppData\Roaming\Python\Scripts;D:\opt\cygwin64\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64;D:\opt\Nmap [calling]
6601428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd9f0000 'C:\Windows\system32\CRYPT32.dll'
6611428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
6621428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'advapi32.dll'.
6631428.140c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\imagehlp.dll)
6641428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\imagehlp.dll
6651428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
6661428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
6671428.140c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
6681428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
6691428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
6701428.140c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
6711428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\imagehlp.dll (Input=imagehlp.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d5560:D:\opt\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\Common Files\Microsoft Shared\Windows Live;D:\opt\Python27\;D:\opt\Python27\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x64;C:\Program Files\TortoiseSVN\bin;D:\opt\Sync\OpenSSH\bin;D:\opt\perl\c\bin;D:\opt\perl\perl\site\bin;D:\opt\perl\perl\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Skype\Phone\;D:\opt\git\TortoiseGit\bin;C:\Users\mcon\AppData\Roaming\Python\Scripts;D:\opt\cygwin64\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64;D:\opt\Nmap [calling]
6721428.140c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\imagehlp.dll [lacks WinVerifyTrust]
6731428.140c: supR3HardenedDllNotificationCallback: load 000007fefef70000 LB 0x00019000 C:\Windows\system32\imagehlp.dll [fFlags=0x0]
6741428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\imagehlp.dll [lacks WinVerifyTrust]
6751428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefef70000 'C:\Windows\system32\imagehlp.dll'
6761428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptsp.dll [lacks WinVerifyTrust]
6771428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTSP.dll (Input=CRYPTSP.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d5560:D:\opt\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\Common Files\Microsoft Shared\Windows Live;D:\opt\Python27\;D:\opt\Python27\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x64;C:\Program Files\TortoiseSVN\bin;D:\opt\Sync\OpenSSH\bin;D:\opt\perl\c\bin;D:\opt\perl\perl\site\bin;D:\opt\perl\perl\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Skype\Phone\;D:\opt\git\TortoiseGit\bin;C:\Users\mcon\AppData\Roaming\Python\Scripts;D:\opt\cygwin64\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64;D:\opt\Nmap [calling]
6781428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd260000 'C:\Windows\system32\CRYPTSP.dll'
6791428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
6801428.140c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\user32.dll)
6811428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\user32.dll
6821428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
6831428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
6841428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
6851428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'lpk.dll'.
6861428.140c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\gdi32.dll)
6871428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\gdi32.dll
6881428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'lpk.dll'...
6891428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'lpk.dll' -> '\Device\HarddiskVolume3\Windows\System32\lpk.dll' [rcNtRedir=0xc0150008]
6901428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'gdi32.dll'.
6911428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'user32.dll'.
6921428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'usp10.dll'.
6931428.140c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\lpk.dll)
6941428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\lpk.dll
6951428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
6961428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
6971428.140c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\user32.dll [lacks WinVerifyTrust]
6981428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'usp10.dll'...
6991428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'usp10.dll' -> '\Device\HarddiskVolume3\Windows\System32\usp10.dll' [rcNtRedir=0xc0150008]
7001428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
7011428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
7021428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'gdi32.dll'.
7031428.140c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\usp10.dll)
7041428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\usp10.dll
7051428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
7061428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
7071428.140c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\user32.dll [lacks WinVerifyTrust]
7081428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
7091428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
7101428.140c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
7111428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
7121428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
7131428.140c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
7141428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
7151428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
7161428.140c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\user32.dll [lacks WinVerifyTrust]
7171428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
7181428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
7191428.140c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
7201428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\USER32.dll (Input=USER32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d5560:D:\opt\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\Common Files\Microsoft Shared\Windows Live;D:\opt\Python27\;D:\opt\Python27\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x64;C:\Program Files\TortoiseSVN\bin;D:\opt\Sync\OpenSSH\bin;D:\opt\perl\c\bin;D:\opt\perl\perl\site\bin;D:\opt\perl\perl\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Skype\Phone\;D:\opt\git\TortoiseGit\bin;C:\Users\mcon\AppData\Roaming\Python\Scripts;D:\opt\cygwin64\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64;D:\opt\Nmap [calling]
7211428.140c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\user32.dll [lacks WinVerifyTrust]
7221428.140c: supR3HardenedDllNotificationCallback: load 0000000077900000 LB 0x000fa000 C:\Windows\system32\USER32.dll [fFlags=0x0]
7231428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\user32.dll [lacks WinVerifyTrust]
7241428.140c: supR3HardenedDllNotificationCallback: load 000007fefdc80000 LB 0x00067000 C:\Windows\system32\GDI32.dll [fFlags=0x0]
7251428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
7261428.140c: supR3HardenedDllNotificationCallback: load 000007feff2e0000 LB 0x0000e000 C:\Windows\system32\LPK.dll [fFlags=0x0]
7271428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\lpk.dll [lacks WinVerifyTrust]
7281428.140c: supR3HardenedDllNotificationCallback: load 000007feffd60000 LB 0x000c9000 C:\Windows\system32\USP10.dll [fFlags=0x0]
7291428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\usp10.dll [lacks WinVerifyTrust]
7301428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
7311428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\gdi32.dll (Input=gdi32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d5560:D:\opt\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\Common Files\Microsoft Shared\Windows Live;D:\opt\Python27\;D:\opt\Python27\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x64;C:\Program Files\TortoiseSVN\bin;D:\opt\Sync\OpenSSH\bin;D:\opt\perl\c\bin;D:\opt\perl\perl\site\bin;D:\opt\perl\perl\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Skype\Phone\;D:\opt\git\TortoiseGit\bin;C:\Users\mcon\AppData\Roaming\Python\Scripts;D:\opt\cygwin64\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64;D:\opt\Nmap [calling]
7321428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdc80000 'C:\Windows\system32\gdi32.dll'
7331428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'user32.dll'.
7341428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
7351428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msctf.dll'.
7361428.140c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\imm32.dll)
7371428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\imm32.dll
7381428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msctf.dll'...
7391428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msctf.dll' -> '\Device\HarddiskVolume3\Windows\System32\msctf.dll' [rcNtRedir=0xc0150008]
7401428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
7411428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
7421428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'gdi32.dll'.
7431428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'imm32.dll'.
7441428.140c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\msctf.dll)
7451428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\msctf.dll
7461428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
7471428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
7481428.140c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
7491428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
7501428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
7511428.140c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\user32.dll [lacks WinVerifyTrust]
7521428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
7531428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume3\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
7541428.140c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\imm32.dll [lacks WinVerifyTrust]
7551428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
7561428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
7571428.140c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
7581428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
7591428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
7601428.140c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\user32.dll [lacks WinVerifyTrust]
7611428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
7621428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
7631428.140c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
7641428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\IMM32.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d5560:D:\opt\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\Common Files\Microsoft Shared\Windows Live;D:\opt\Python27\;D:\opt\Python27\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x64;C:\Program Files\TortoiseSVN\bin;D:\opt\Sync\OpenSSH\bin;D:\opt\perl\c\bin;D:\opt\perl\perl\site\bin;D:\opt\perl\perl\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Skype\Phone\;D:\opt\git\TortoiseGit\bin;C:\Users\mcon\AppData\Roaming\Python\Scripts;D:\opt\cygwin64\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64;D:\opt\Nmap [calling]
7651428.140c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\imm32.dll [lacks WinVerifyTrust]
7661428.140c: supR3HardenedDllNotificationCallback: load 000007fefed60000 LB 0x0002e000 C:\Windows\system32\IMM32.DLL [fFlags=0x0]
7671428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\imm32.dll [lacks WinVerifyTrust]
7681428.140c: supR3HardenedDllNotificationCallback: load 000007fefec50000 LB 0x00109000 C:\Windows\system32\MSCTF.dll [fFlags=0x0]
7691428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\msctf.dll [lacks WinVerifyTrust]
7701428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefed60000 'C:\Windows\system32\IMM32.DLL'
7711428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077900000 'C:\Windows\system32\USER32.dll'
7721428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'bcrypt.dll'.
7731428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
7741428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msasn1.dll'.
7751428.140c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\ncrypt.dll)
7761428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\ncrypt.dll
7771428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
7781428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume3\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
7791428.140c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
7801428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
7811428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
7821428.140c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
7831428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
7841428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume3\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
7851428.140c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
7861428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ncrypt.dll (Input=ncrypt.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d5560:D:\opt\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\Common Files\Microsoft Shared\Windows Live;D:\opt\Python27\;D:\opt\Python27\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x64;C:\Program Files\TortoiseSVN\bin;D:\opt\Sync\OpenSSH\bin;D:\opt\perl\c\bin;D:\opt\perl\perl\site\bin;D:\opt\perl\perl\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Skype\Phone\;D:\opt\git\TortoiseGit\bin;C:\Users\mcon\AppData\Roaming\Python\Scripts;D:\opt\cygwin64\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64;D:\opt\Nmap [calling]
7871428.140c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\ncrypt.dll [lacks WinVerifyTrust]
7881428.140c: supR3HardenedDllNotificationCallback: load 000007fefd280000 LB 0x00050000 C:\Windows\system32\ncrypt.dll [fFlags=0x0]
7891428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\ncrypt.dll [lacks WinVerifyTrust]
7901428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd280000 'C:\Windows\system32\ncrypt.dll'
7911428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
7921428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\bcrypt.dll (Input=bcrypt.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d5560:D:\opt\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\Common Files\Microsoft Shared\Windows Live;D:\opt\Python27\;D:\opt\Python27\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x64;C:\Program Files\TortoiseSVN\bin;D:\opt\Sync\OpenSSH\bin;D:\opt\perl\c\bin;D:\opt\perl\perl\site\bin;D:\opt\perl\perl\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Skype\Phone\;D:\opt\git\TortoiseGit\bin;C:\Users\mcon\AppData\Roaming\Python\Scripts;D:\opt\cygwin64\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64;D:\opt\Nmap [calling]
7931428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd230000 'C:\Windows\system32\bcrypt.dll'
7941428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
7951428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'rpcrt4.dll'.
7961428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'profapi.dll'.
7971428.140c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\userenv.dll)
7981428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\userenv.dll
7991428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'profapi.dll'...
8001428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'profapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\profapi.dll' [rcNtRedir=0xc0150008]
8011428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
8021428.140c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\profapi.dll)
8031428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\profapi.dll
8041428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
8051428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
8061428.140c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
8071428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
8081428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
8091428.140c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
8101428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
8111428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
8121428.140c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
8131428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\USERENV.dll (Input=USERENV.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d5560:D:\opt\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\Common Files\Microsoft Shared\Windows Live;D:\opt\Python27\;D:\opt\Python27\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x64;C:\Program Files\TortoiseSVN\bin;D:\opt\Sync\OpenSSH\bin;D:\opt\perl\c\bin;D:\opt\perl\perl\site\bin;D:\opt\perl\perl\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Skype\Phone\;D:\opt\git\TortoiseGit\bin;C:\Users\mcon\AppData\Roaming\Python\Scripts;D:\opt\cygwin64\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64;D:\opt\Nmap [calling]
8141428.140c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\userenv.dll [lacks WinVerifyTrust]
8151428.140c: supR3HardenedDllNotificationCallback: load 000007fefdbc0000 LB 0x0001e000 C:\Windows\system32\USERENV.dll [fFlags=0x0]
8161428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\userenv.dll [lacks WinVerifyTrust]
8171428.140c: supR3HardenedDllNotificationCallback: load 000007fefd8c0000 LB 0x0000f000 C:\Windows\system32\profapi.dll [fFlags=0x0]
8181428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\profapi.dll [lacks WinVerifyTrust]
8191428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdbc0000 'C:\Windows\system32\USERENV.dll'
8201428.140c: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007d5560:D:\opt\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\Common Files\Microsoft Shared\Windows Live;D:\opt\Python27\;D:\opt\Python27\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x64;C:\Program Files\TortoiseSVN\bin;D:\opt\Sync\OpenSSH\bin;D:\opt\perl\c\bin;D:\opt\perl\perl\site\bin;D:\opt\perl\perl\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Skype\Phone\;D:\opt\git\TortoiseGit\bin;C:\Users\mcon\AppData\Roaming\Python\Scripts;D:\opt\cygwin64\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64;D:\opt\Nmap [calling]
8211428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdcf0000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
8221428.140c: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007d5560:D:\opt\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\Common Files\Microsoft Shared\Windows Live;D:\opt\Python27\;D:\opt\Python27\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x64;C:\Program Files\TortoiseSVN\bin;D:\opt\Sync\OpenSSH\bin;D:\opt\perl\c\bin;D:\opt\perl\perl\site\bin;D:\opt\perl\perl\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Skype\Phone\;D:\opt\git\TortoiseGit\bin;C:\Users\mcon\AppData\Roaming\Python\Scripts;D:\opt\cygwin64\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64;D:\opt\Nmap [calling]
8231428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdcf0000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
8241428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
8251428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'rpcrt4.dll'.
8261428.140c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\gpapi.dll)
8271428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\gpapi.dll
8281428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
8291428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
8301428.140c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
8311428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
8321428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
8331428.140c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
8341428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\GPAPI.dll (Input=GPAPI.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d5560:D:\opt\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\Common Files\Microsoft Shared\Windows Live;D:\opt\Python27\;D:\opt\Python27\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x64;C:\Program Files\TortoiseSVN\bin;D:\opt\Sync\OpenSSH\bin;D:\opt\perl\c\bin;D:\opt\perl\perl\site\bin;D:\opt\perl\perl\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Skype\Phone\;D:\opt\git\TortoiseGit\bin;C:\Users\mcon\AppData\Roaming\Python\Scripts;D:\opt\cygwin64\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64;D:\opt\Nmap [calling]
8351428.140c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\gpapi.dll [lacks WinVerifyTrust]
8361428.140c: supR3HardenedDllNotificationCallback: load 000007fefcb10000 LB 0x0001b000 C:\Windows\system32\GPAPI.dll [fFlags=0x0]
8371428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\gpapi.dll [lacks WinVerifyTrust]
8381428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcb10000 'C:\Windows\system32\GPAPI.dll'
8391428.140c: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-Management-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007d5560:D:\opt\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\Common Files\Microsoft Shared\Windows Live;D:\opt\Python27\;D:\opt\Python27\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x64;C:\Program Files\TortoiseSVN\bin;D:\opt\Sync\OpenSSH\bin;D:\opt\perl\c\bin;D:\opt\perl\perl\site\bin;D:\opt\perl\perl\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Skype\Phone\;D:\opt\git\TortoiseGit\bin;C:\Users\mcon\AppData\Roaming\Python\Scripts;D:\opt\cygwin64\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64;D:\opt\Nmap [calling]
8401428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdcf0000 'API-MS-WIN-Service-Management-L1-1-0.dll'
8411428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
8421428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rpcrt4.dll (Input=rpcrt4.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d5560:D:\opt\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\Common Files\Microsoft Shared\Windows Live;D:\opt\Python27\;D:\opt\Python27\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x64;C:\Program Files\TortoiseSVN\bin;D:\opt\Sync\OpenSSH\bin;D:\opt\perl\c\bin;D:\opt\perl\perl\site\bin;D:\opt\perl\perl\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Skype\Phone\;D:\opt\git\TortoiseGit\bin;C:\Users\mcon\AppData\Roaming\Python\Scripts;D:\opt\cygwin64\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64;D:\opt\Nmap [calling]
8431428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff7e0000 'C:\Windows\system32\rpcrt4.dll'
8441428.140c: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-Management-L2-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007d5560:D:\opt\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\Common Files\Microsoft Shared\Windows Live;D:\opt\Python27\;D:\opt\Python27\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x64;C:\Program Files\TortoiseSVN\bin;D:\opt\Sync\OpenSSH\bin;D:\opt\perl\c\bin;D:\opt\perl\perl\site\bin;D:\opt\perl\perl\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Skype\Phone\;D:\opt\git\TortoiseGit\bin;C:\Users\mcon\AppData\Roaming\Python\Scripts;D:\opt\cygwin64\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64;D:\opt\Nmap [calling]
8451428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdcf0000 'API-MS-WIN-Service-Management-L2-1-0.dll'
8461428.140c: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007d5560:D:\opt\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\Common Files\Microsoft Shared\Windows Live;D:\opt\Python27\;D:\opt\Python27\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x64;C:\Program Files\TortoiseSVN\bin;D:\opt\Sync\OpenSSH\bin;D:\opt\perl\c\bin;D:\opt\perl\perl\site\bin;D:\opt\perl\perl\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Skype\Phone\;D:\opt\git\TortoiseGit\bin;C:\Users\mcon\AppData\Roaming\Python\Scripts;D:\opt\cygwin64\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64;D:\opt\Nmap [calling]
8471428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdcf0000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
8481428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
8491428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'advapi32.dll'.
8501428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'crypt32.dll'.
8511428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'wldap32.dll'.
8521428.140c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\cryptnet.dll)
8531428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\cryptnet.dll
8541428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wldap32.dll'...
8551428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'wldap32.dll' -> '\Device\HarddiskVolume3\Windows\System32\wldap32.dll' [rcNtRedir=0xc0150008]
8561428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
8571428.140c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\Wldap32.dll)
8581428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\Wldap32.dll
8591428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
8601428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume3\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
8611428.140c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
8621428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
8631428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
8641428.140c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
8651428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
8661428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
8671428.140c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
8681428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
8691428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
8701428.140c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
8711428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (Input=cryptnet.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d5560:D:\opt\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\Common Files\Microsoft Shared\Windows Live;D:\opt\Python27\;D:\opt\Python27\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x64;C:\Program Files\TortoiseSVN\bin;D:\opt\Sync\OpenSSH\bin;D:\opt\perl\c\bin;D:\opt\perl\perl\site\bin;D:\opt\perl\perl\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Skype\Phone\;D:\opt\git\TortoiseGit\bin;C:\Users\mcon\AppData\Roaming\Python\Scripts;D:\opt\cygwin64\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64;D:\opt\Nmap [calling]
8721428.140c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
8731428.140c: supR3HardenedDllNotificationCallback: load 000007fef6250000 LB 0x00027000 C:\Windows\system32\cryptnet.dll [fFlags=0x0]
8741428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
8751428.140c: supR3HardenedDllNotificationCallback: load 000007feff780000 LB 0x00052000 C:\Windows\system32\WLDAP32.dll [fFlags=0x0]
8761428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\Wldap32.dll [lacks WinVerifyTrust]
8771428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
8781428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00000000007d5560:D:\opt\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\Common Files\Microsoft Shared\Windows Live;D:\opt\Python27\;D:\opt\Python27\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x64;C:\Program Files\TortoiseSVN\bin;D:\opt\Sync\OpenSSH\bin;D:\opt\perl\c\bin;D:\opt\perl\perl\site\bin;D:\opt\perl\perl\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Skype\Phone\;D:\opt\git\TortoiseGit\bin;C:\Users\mcon\AppData\Roaming\Python\Scripts;D:\opt\cygwin64\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64;D:\opt\Nmap [calling]
8791428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef6250000 'C:\Windows\system32\cryptnet.dll'
8801428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
8811428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00000000007d5560:D:\opt\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\Common Files\Microsoft Shared\Windows Live;D:\opt\Python27\;D:\opt\Python27\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x64;C:\Program Files\TortoiseSVN\bin;D:\opt\Sync\OpenSSH\bin;D:\opt\perl\c\bin;D:\opt\perl\perl\site\bin;D:\opt\perl\perl\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Skype\Phone\;D:\opt\git\TortoiseGit\bin;C:\Users\mcon\AppData\Roaming\Python\Scripts;D:\opt\cygwin64\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64;D:\opt\Nmap [calling]
8821428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef6250000 'C:\Windows\system32\cryptnet.dll'
8831428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
8841428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00000000007d5560:D:\opt\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\Common Files\Microsoft Shared\Windows Live;D:\opt\Python27\;D:\opt\Python27\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x64;C:\Program Files\TortoiseSVN\bin;D:\opt\Sync\OpenSSH\bin;D:\opt\perl\c\bin;D:\opt\perl\perl\site\bin;D:\opt\perl\perl\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Skype\Phone\;D:\opt\git\TortoiseGit\bin;C:\Users\mcon\AppData\Roaming\Python\Scripts;D:\opt\cygwin64\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64;D:\opt\Nmap [calling]
8851428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef6250000 'C:\Windows\system32\cryptnet.dll'
8861428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
8871428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00000000007d5560:D:\opt\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\Common Files\Microsoft Shared\Windows Live;D:\opt\Python27\;D:\opt\Python27\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x64;C:\Program Files\TortoiseSVN\bin;D:\opt\Sync\OpenSSH\bin;D:\opt\perl\c\bin;D:\opt\perl\perl\site\bin;D:\opt\perl\perl\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Skype\Phone\;D:\opt\git\TortoiseGit\bin;C:\Users\mcon\AppData\Roaming\Python\Scripts;D:\opt\cygwin64\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64;D:\opt\Nmap [calling]
8881428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef6250000 'C:\Windows\system32\cryptnet.dll'
8891428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
8901428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00000000007d5560:D:\opt\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\Common Files\Microsoft Shared\Windows Live;D:\opt\Python27\;D:\opt\Python27\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x64;C:\Program Files\TortoiseSVN\bin;D:\opt\Sync\OpenSSH\bin;D:\opt\perl\c\bin;D:\opt\perl\perl\site\bin;D:\opt\perl\perl\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Skype\Phone\;D:\opt\git\TortoiseGit\bin;C:\Users\mcon\AppData\Roaming\Python\Scripts;D:\opt\cygwin64\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64;D:\opt\Nmap [calling]
8911428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef6250000 'C:\Windows\system32\cryptnet.dll'
8921428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
8931428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=00000000007d5560:D:\opt\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\Common Files\Microsoft Shared\Windows Live;D:\opt\Python27\;D:\opt\Python27\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x64;C:\Program Files\TortoiseSVN\bin;D:\opt\Sync\OpenSSH\bin;D:\opt\perl\c\bin;D:\opt\perl\perl\site\bin;D:\opt\perl\perl\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Skype\Phone\;D:\opt\git\TortoiseGit\bin;C:\Users\mcon\AppData\Roaming\Python\Scripts;D:\opt\cygwin64\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64;D:\opt\Nmap [calling]
8941428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef6250000 'C:\Windows\system32\cryptnet.dll'
8951428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
8961428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef6250000 'C:\Windows\system32\cryptnet.dll'
8971428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
8981428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef6250000 'C:\Windows\system32\cryptnet.dll'
8991428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
9001428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef6250000 'C:\Windows\system32\cryptnet.dll'
9011428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
9021428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef6250000 'C:\Windows\system32\cryptnet.dll'
9031428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
9041428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef6250000 'C:\Windows\system32\cryptnet.dll'
9051428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef6250000 'C:\Windows\system32\cryptnet.dll'
9061428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
9071428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef6250000 'C:\Windows\system32\cryptnet.dll'
9081428.140c: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007d5560:D:\opt\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\Common Files\Microsoft Shared\Windows Live;D:\opt\Python27\;D:\opt\Python27\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x64;C:\Program Files\TortoiseSVN\bin;D:\opt\Sync\OpenSSH\bin;D:\opt\perl\c\bin;D:\opt\perl\perl\site\bin;D:\opt\perl\perl\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Skype\Phone\;D:\opt\git\TortoiseGit\bin;C:\Users\mcon\AppData\Roaming\Python\Scripts;D:\opt\cygwin64\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64;D:\opt\Nmap [calling]
9091428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdcf0000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
9101428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\profapi.dll [lacks WinVerifyTrust]
9111428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\profapi.dll (Input=profapi.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d5560:D:\opt\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\Common Files\Microsoft Shared\Windows Live;D:\opt\Python27\;D:\opt\Python27\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x64;C:\Program Files\TortoiseSVN\bin;D:\opt\Sync\OpenSSH\bin;D:\opt\perl\c\bin;D:\opt\perl\perl\site\bin;D:\opt\perl\perl\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Skype\Phone\;D:\opt\git\TortoiseGit\bin;C:\Users\mcon\AppData\Roaming\Python\Scripts;D:\opt\cygwin64\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64;D:\opt\Nmap [calling]
9121428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd8c0000 'C:\Windows\system32\profapi.dll'
9131428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
9141428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
9151428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msvcrt.dll'.
9161428.140c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\shlwapi.dll)
9171428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\shlwapi.dll
9181428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
9191428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
9201428.140c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
9211428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
9221428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
9231428.140c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\user32.dll [lacks WinVerifyTrust]
9241428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
9251428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
9261428.140c: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
9271428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\SHLWAPI.dll (Input=SHLWAPI.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d5560:D:\opt\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\Common Files\Microsoft Shared\Windows Live;D:\opt\Python27\;D:\opt\Python27\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x64;C:\Program Files\TortoiseSVN\bin;D:\opt\Sync\OpenSSH\bin;D:\opt\perl\c\bin;D:\opt\perl\perl\site\bin;D:\opt\perl\perl\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Skype\Phone\;D:\opt\git\TortoiseGit\bin;C:\Users\mcon\AppData\Roaming\Python\Scripts;D:\opt\cygwin64\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64;D:\opt\Nmap [calling]
9281428.140c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\shlwapi.dll [lacks WinVerifyTrust]
9291428.140c: supR3HardenedDllNotificationCallback: load 000007fefdd10000 LB 0x00071000 C:\Windows\system32\SHLWAPI.dll [fFlags=0x0]
9301428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\shlwapi.dll [lacks WinVerifyTrust]
9311428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdd10000 'C:\Windows\system32\SHLWAPI.dll'
9321428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000000 pwszName=\SystemRoot\System32\ntdll.dll
9331428.140c: supR3HardNtViCallWinVerifyTrustCatFile: New context 00000000008b9e60
9341428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
9351428.140c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=9B1D637739FC6B271ED989F7454A98D5A76C1B7A
9361428.140c: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007d5560:D:\opt\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\Common Files\Microsoft Shared\Windows Live;D:\opt\Python27\;D:\opt\Python27\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x64;C:\Program Files\TortoiseSVN\bin;D:\opt\Sync\OpenSSH\bin;D:\opt\perl\c\bin;D:\opt\perl\perl\site\bin;D:\opt\perl\perl\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Skype\Phone\;D:\opt\git\TortoiseGit\bin;C:\Users\mcon\AppData\Roaming\Python\Scripts;D:\opt\cygwin64\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64;D:\opt\Nmap [calling]
9371428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdcf0000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
9381428.140c: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-Management-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007d5560:D:\opt\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\Common Files\Microsoft Shared\Windows Live;D:\opt\Python27\;D:\opt\Python27\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x64;C:\Program Files\TortoiseSVN\bin;D:\opt\Sync\OpenSSH\bin;D:\opt\perl\c\bin;D:\opt\perl\perl\site\bin;D:\opt\perl\perl\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Skype\Phone\;D:\opt\git\TortoiseGit\bin;C:\Users\mcon\AppData\Roaming\Python\Scripts;D:\opt\cygwin64\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64;D:\opt\Nmap [calling]
9391428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdcf0000 'API-MS-WIN-Service-Management-L1-1-0.dll'
9401428.140c: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-winsvc-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007d5560:D:\opt\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\Common Files\Microsoft Shared\Windows Live;D:\opt\Python27\;D:\opt\Python27\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x64;C:\Program Files\TortoiseSVN\bin;D:\opt\Sync\OpenSSH\bin;D:\opt\perl\c\bin;D:\opt\perl\perl\site\bin;D:\opt\perl\perl\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Skype\Phone\;D:\opt\git\TortoiseGit\bin;C:\Users\mcon\AppData\Roaming\Python\Scripts;D:\opt\cygwin64\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64;D:\opt\Nmap [calling]
9411428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdcf0000 'API-MS-WIN-Service-winsvc-L1-1-0.dll'
9421428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
9431428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ADVAPI32.dll (Input=ADVAPI32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d5560:D:\opt\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\Common Files\Microsoft Shared\Windows Live;D:\opt\Python27\;D:\opt\Python27\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x64;C:\Program Files\TortoiseSVN\bin;D:\opt\Sync\OpenSSH\bin;D:\opt\perl\c\bin;D:\opt\perl\perl\site\bin;D:\opt\perl\perl\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Skype\Phone\;D:\opt\git\TortoiseGit\bin;C:\Users\mcon\AppData\Roaming\Python\Scripts;D:\opt\cygwin64\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64;D:\opt\Nmap [calling]
9441428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdd90000 'C:\Windows\system32\ADVAPI32.dll'
9451428.140c: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-LSALookup-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007d5560:D:\opt\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\Common Files\Microsoft Shared\Windows Live;D:\opt\Python27\;D:\opt\Python27\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x64;C:\Program Files\TortoiseSVN\bin;D:\opt\Sync\OpenSSH\bin;D:\opt\perl\c\bin;D:\opt\perl\perl\site\bin;D:\opt\perl\perl\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Skype\Phone\;D:\opt\git\TortoiseGit\bin;C:\Users\mcon\AppData\Roaming\Python\Scripts;D:\opt\cygwin64\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64;D:\opt\Nmap [calling]
9461428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdcf0000 'API-MS-Win-Security-LSALookup-L1-1-0.dll'
9471428.140c: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-LSALookup-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000007d5560:D:\opt\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\Common Files\Microsoft Shared\Windows Live;D:\opt\Python27\;D:\opt\Python27\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x64;C:\Program Files\TortoiseSVN\bin;D:\opt\Sync\OpenSSH\bin;D:\opt\perl\c\bin;D:\opt\perl\perl\site\bin;D:\opt\perl\perl\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Skype\Phone\;D:\opt\git\TortoiseGit\bin;C:\Users\mcon\AppData\Roaming\Python\Scripts;D:\opt\cygwin64\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64;D:\opt\Nmap [calling]
9481428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdcf0000 'API-MS-Win-Security-LSALookup-L1-1-0.dll'
9491428.140c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_60_for_KB3101746~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\SystemRoot\System32\ntdll.dll'
9501428.140c: g_pfnWinVerifyTrust=000007fefd9b1010
9511428.140c: supR3HardenedScreenImage/preload: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll [redoing WinVerifyTrust]
9521428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000e0 pwszName=\Device\HarddiskVolume3\Windows\System32\crypt32.dll
9531428.140c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
9541428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
9551428.140c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=BFD41401EDEBD4D914977D62B588ECABEE60CFD3
9561428.140c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_112_for_KB3040272~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume3\Windows\System32\crypt32.dll'
9571428.140c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
9581428.140c: supR3HardenedScreenImage/preload: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\crypt32.dll'
9591428.140c: supR3HardenedScreenImage/preload: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\wintrust.dll [redoing WinVerifyTrust]
9601428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000d4 pwszName=\Device\HarddiskVolume3\Windows\System32\wintrust.dll
9611428.140c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
9621428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
9631428.140c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=E1BBE4EB6D114F50142F24E2E2749EFD81021486
9641428.140c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_75_for_KB3040272~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume3\Windows\System32\wintrust.dll'
9651428.140c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
9661428.140c: supR3HardenedScreenImage/preload: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\wintrust.dll'
9671428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000003b8 pwszName=\Device\HarddiskVolume3\Windows\System32\shlwapi.dll
9681428.140c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
9691428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
9701428.140c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=0AB8D9C9D3E1FC95D01F9A984B16ED031BB40CD8
9711428.140c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume3\Windows\System32\shlwapi.dll'
9721428.140c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
9731428.140c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\shlwapi.dll'
9741428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000003b0 pwszName=\Device\HarddiskVolume3\Windows\System32\Wldap32.dll
9751428.140c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
9761428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
9771428.140c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=87E73086F2528CF31D3AD5F0D71E04F8B942D5D8
9781428.140c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume3\Windows\System32\Wldap32.dll'
9791428.140c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
9801428.140c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\Wldap32.dll'
9811428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000003ac pwszName=\Device\HarddiskVolume3\Windows\System32\cryptnet.dll
9821428.140c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
9831428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
9841428.140c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=756DC088EE40CF9369C990D71B200F3CB59FC35D
9851428.140c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_75_for_KB3040272~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume3\Windows\System32\cryptnet.dll'
9861428.140c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
9871428.140c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\cryptnet.dll'
9881428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000268 pwszName=\Device\HarddiskVolume3\Windows\System32\gpapi.dll
9891428.140c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
9901428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
9911428.140c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=470795C189226F7BDB8E50F42104CC34488B9340
9921428.140c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume3\Windows\System32\gpapi.dll'
9931428.140c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
9941428.140c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\gpapi.dll'
9951428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000001d4 pwszName=\Device\HarddiskVolume3\Windows\System32\profapi.dll
9961428.140c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
9971428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
9981428.140c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2449672745D9BA339420451D13FA0380AA768231
9991428.140c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume3\Windows\System32\profapi.dll'
10001428.140c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
10011428.140c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\profapi.dll'
10021428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000001d0 pwszName=\Device\HarddiskVolume3\Windows\System32\userenv.dll
10031428.140c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
10041428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
10051428.140c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=D3E1A2CC7367F751C19EBF4E6EDF5E9A10E47313
10061428.140c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume3\Windows\System32\userenv.dll'
10071428.140c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
10081428.140c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\userenv.dll'
10091428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000001bc pwszName=\Device\HarddiskVolume3\Windows\System32\ncrypt.dll
10101428.140c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
10111428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
10121428.140c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=DE8C9B0409BB6DC8348383C722B4EC4291BB2193
10131428.140c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_60_for_KB3101746~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume3\Windows\System32\ncrypt.dll'
10141428.140c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
10151428.140c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\ncrypt.dll'
10161428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000001a4 pwszName=\Device\HarddiskVolume3\Windows\System32\msctf.dll
10171428.140c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
10181428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
10191428.140c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=03916BC73EE5A0E312E3D3100D0ACE1B78E93BB1
10201428.140c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3033889~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume3\Windows\System32\msctf.dll'
10211428.140c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
10221428.140c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\msctf.dll'
10231428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000001a0 pwszName=\Device\HarddiskVolume3\Windows\System32\imm32.dll
10241428.140c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
10251428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
10261428.140c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=6EEE1AB3B6D79AFF857940FF5F51ED27698153EC
10271428.140c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume3\Windows\System32\imm32.dll'
10281428.140c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
10291428.140c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\imm32.dll'
10301428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000019c pwszName=\Device\HarddiskVolume3\Windows\System32\usp10.dll
10311428.140c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
10321428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
10331428.140c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=1F1AA8340DE02FC1B6341EE2706E55D56EDF63B8
10341428.140c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB2957509~31bf3856ad364e35~amd64~~6.1.1.2.cat'; file='\Device\HarddiskVolume3\Windows\System32\usp10.dll'
10351428.140c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
10361428.140c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\usp10.dll'
10371428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000198 pwszName=\Device\HarddiskVolume3\Windows\System32\lpk.dll
10381428.140c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
10391428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
10401428.140c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=FDBA63132AE4F561C5CFC5478222E40A2DAA2ACC
10411428.140c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3087039~31bf3856ad364e35~amd64~~6.1.1.4.cat'; file='\Device\HarddiskVolume3\Windows\System32\lpk.dll'
10421428.140c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
10431428.140c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\lpk.dll'
10441428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000194 pwszName=\Device\HarddiskVolume3\Windows\System32\gdi32.dll
10451428.140c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
10461428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
10471428.140c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=EB178841F5FFC6B05E668168217B0AC222A62955
10481428.140c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3069392~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume3\Windows\System32\gdi32.dll'
10491428.140c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
10501428.140c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\gdi32.dll'
10511428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000190 pwszName=\Device\HarddiskVolume3\Windows\System32\user32.dll
10521428.140c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
10531428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
10541428.140c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B723D1B8AD72750B0CF5F6BEC66171B1254ED879
10551428.140c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume3\Windows\System32\user32.dll'
10561428.140c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
10571428.140c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\user32.dll'
10581428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000018c pwszName=\Device\HarddiskVolume3\Windows\System32\imagehlp.dll
10591428.140c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
10601428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
10611428.140c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2702EE05F1B717B0F2CE0FBE32784A47B8419DCA
10621428.140c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_2_for_KB2893294~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume3\Windows\System32\imagehlp.dll'
10631428.140c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
10641428.140c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\imagehlp.dll'
10651428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000130 pwszName=\Device\HarddiskVolume3\Windows\System32\cryptbase.dll
10661428.140c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
10671428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
10681428.140c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=DD41E47CDA7ECDD58265F0739B9BC23E0761082B
10691428.140c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_60_for_KB3101746~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume3\Windows\System32\cryptbase.dll'
10701428.140c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
10711428.140c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\cryptbase.dll'
10721428.140c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\rsaenh.dll'
10731428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000012c pwszName=\Device\HarddiskVolume3\Windows\System32\cryptsp.dll
10741428.140c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
10751428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
10761428.140c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=BA7AC4A7E8ADDFEA90AC951ECB6D6546E4873613
10771428.140c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_115_for_KB3033929~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume3\Windows\System32\cryptsp.dll'
10781428.140c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
10791428.140c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\cryptsp.dll'
10801428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000120 pwszName=\Device\HarddiskVolume3\Windows\System32\sechost.dll
10811428.140c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
10821428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
10831428.140c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=CB669FA8DB80F8E50A29D055BB8D558E10E5E6B4
10841428.140c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_85_for_KB3068708~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume3\Windows\System32\sechost.dll'
10851428.140c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
10861428.140c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\sechost.dll'
10871428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000011c pwszName=\Device\HarddiskVolume3\Windows\System32\advapi32.dll
10881428.140c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
10891428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
10901428.140c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=D58A667BECF67ECC76D4BEEDB96E9F1960013145
10911428.140c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_60_for_KB3080149~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume3\Windows\System32\advapi32.dll'
10921428.140c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
10931428.140c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\advapi32.dll'
10941428.140c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\bcryptprimitives.dll'
10951428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000104 pwszName=\Device\HarddiskVolume3\Windows\System32\bcrypt.dll
10961428.140c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
10971428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
10981428.140c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=62E377A1F0AD0C2EDC0A73CB3EFF841FF18D00D2
10991428.140c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume3\Windows\System32\bcrypt.dll'
11001428.140c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
11011428.140c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\bcrypt.dll'
11021428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000e4 pwszName=\Device\HarddiskVolume3\Windows\System32\msvcrt.dll
11031428.140c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
11041428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
11051428.140c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2CA2FD632B264C063162F71474266E3615B6420C
11061428.140c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB2654428~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume3\Windows\System32\msvcrt.dll'
11071428.140c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
11081428.140c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll'
11091428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000dc pwszName=\Device\HarddiskVolume3\Windows\System32\msasn1.dll
11101428.140c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
11111428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
11121428.140c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=F2FF57DC30D774F93061607060DAA0DD15E39CCE
11131428.140c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume3\Windows\System32\msasn1.dll'
11141428.140c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
11151428.140c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\msasn1.dll'
11161428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000d8 pwszName=\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll
11171428.140c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
11181428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
11191428.140c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=35EB15A32FF6A8320A28B76654C7C05F183C0649
11201428.140c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_60_for_KB3101746~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll'
11211428.140c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
11221428.140c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll'
11231428.140c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\opt\VirtualBox\VBoxSupLib.dll'
11241428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000028 pwszName=\Device\HarddiskVolume3\Windows\System32\KernelBase.dll
11251428.140c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
11261428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
11271428.140c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=D187E2BFBA7ED9D015FB710000144445CAD8B2DE
11281428.140c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_60_for_KB3101746~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume3\Windows\System32\KernelBase.dll'
11291428.140c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
11301428.140c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\KernelBase.dll'
11311428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000020 pwszName=\Device\HarddiskVolume3\Windows\System32\kernel32.dll
11321428.140c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
11331428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
11341428.140c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=3ABD4E7598BD11C4FA1AD66BF1B854BCC2A7C5DD
11351428.140c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_60_for_KB3101746~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume3\Windows\System32\kernel32.dll'
11361428.140c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
11371428.140c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\kernel32.dll'
11381428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll
11391428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\crypt32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000004f5140:C:\Windows\system32 [calling]
11401428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd9f0000 'C:\Windows\system32\crypt32.dll'
11411428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x5ad46780fa5df300 DC=com, DC=microsoft, CN=Microsoft Root Certificate Authority
11421428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xea5386456178582b C=ZA, ST=Western Cape, L=Durbanville, O=Thawte, OU=Thawte Certification, CN=Thawte Timestamping CA
11431428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x3be670c1bd02a900 OU=Copyright (c) 1997 Microsoft Corp., OU=Microsoft Corporation, CN=Microsoft Root Authority
11441428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x4d3835aa4180b200 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2011
11451428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x646e3fe3ba08df00 C=US, O=MSFT, CN=Microsoft Authenticode(tm) Root Authority
11461428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xece4e4289e08b900 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010
11471428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x43a9cc371ff5385a O=Microsoft Trust Network, OU=Microsoft Corporation, OU=Microsoft Time Stamping Service Root, OU=Copyright (c) 1997 Microsoft Corp.
11481428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x2e2d2c7c68f0202e O=VeriSign Trust Network, OU=VeriSign, Inc., OU=VeriSign Time Stamping Service Root, OU=NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.
11491428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xe0249b57ec7fbc00 C=JP, O=SECOM Trust Systems CO.,LTD., OU=Security Communication EV RootCA1
11501428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xee325335cd8dba00 C=DE, O=D-Trust GmbH, CN=D-TRUST Root Class 3 CA 2007
11511428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x4a25c87eb933b700 C=RO, O=certSIGN, OU=certSIGN ROOT CA
11521428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x3703c8da1585b000 C=FI, ST=Finland, O=Vaestorekisterikeskus CA, OU=Certification Authority Services, OU=Varmennepalvelut, CN=VRK Gov. Root CA
11531428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x8b062bb556fcc300 C=FR, O=Certeurope, OU=0002 434202180, CN=Certeurope Root CA 2
11541428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x977025a7d23db100 C=UY, O=ADMINISTRACION NACIONAL DE CORREOS, OU=SERVICIOS ELECTRONICOS, CN=Correo Uruguayo - Root CA
11551428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x15941d5f68b5c600 CN=ComSign Secured CA, O=ComSign, C=IL
11561428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x75a2ccecb8259a00 C=TW, O=Government Root Certification Authority
11571428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x3c0043239a65bd00 C=FR, O=Certplus, CN=Class 3TS Primary CA
11581428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xd8dbfb2c27bfb200 C=US, O=thawte, Inc., OU=Certification Services Division, OU=(c) 2008 thawte, Inc. - For authorized use only, CN=thawte Primary Root CA - G3
11591428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xa5c88c0a3eb7ab00 CN=TÜRKTRUST Elektronik Sertifika Hizmet Sağlayıcısı, C=TR, L=Ankara, O=TÜRKTRUST Bilgi İletişim ve Bilişim Güvenliği Hizmetleri A.Ş. (c) Aralık 2007
11601428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x49dccfc3945cd200 C=GB, O=Trustis Limited, OU=Trustis EVS Root CA
11611428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xeb7a1ac4eef2cd00 C=HU, L=Budapest, O=NetLock Kft., OU=Tanúsítványkiadók (Certification Services), CN=NetLock Platina (Class Platinum) Főtanúsítvány
11621428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x8fe279bdb46fee00 C=US, O=Wells Fargo WellsSecure, OU=Wells Fargo Bank NA, CN=WellsSecure Public Root Certificate Authority
11631428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xe0c6a3a05515a600 C=US, O=GeoTrust Inc., CN=GeoTrust Universal CA
11641428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xc7d32b6954e4f000 CN=ComSign CA, O=ComSign, C=IL
11651428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x61a3a33f81aace00 C=US, ST=UT, L=Salt Lake City, O=The USERTRUST Network, OU=http://www.usertrust.com, CN=UTN-USERFirst-Object
11661428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x760668e19592ff00 CN=ACEDICOM Root, OU=PKI, O=EDICOM, C=ES
11671428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x50bb81640c01cb00 C=TW, O=TAIWAN-CA, OU=Root CA, CN=TWCA Root Certification Authority
11681428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xaafa7abb99ab000 O=Cisco Systems, CN=Cisco Root CA 2048
11691428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x57ba5395b561bf00 C=BM, O=QuoVadis Limited, OU=Root Certification Authority, CN=QuoVadis Root Certification Authority
11701428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xf4fd306318ccda00 C=US, O=GeoTrust Inc., CN=GeoTrust Global CA
11711428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x5eb09e2012c300 C=TR, O=Elektronik Bilgi Guvenligi A.S., CN=e-Guven Kok Elektronik Sertifika Hizmet Saglayicisi
11721428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x83085097e9afdf00 O=Digital Signature Trust Co., CN=DST Root CA X3
11731428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xe248b7eeee4af00 C=CH, O=SwissSign AG, CN=SwissSign Gold CA - G2
11741428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x266e9b638ffac00 C=HK, O=Hongkong Post, CN=Hongkong Post Root CA 1
11751428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xafc0be88bdf2a800 DC=rs, DC=posta, DC=ca, CN=Configuration, CN=Services, CN=Public Key Services, CN=AIA, CN=Posta CA Root
11761428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x780679907625cc00 OU=GlobalSign Root CA - R3, O=GlobalSign, CN=GlobalSign
11771428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x3d98ab22bb04a300 C=IE, O=Baltimore, OU=CyberTrust, CN=Baltimore CyberTrust Root
11781428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xd94cd06e3094b700 C=FR, O=Certplus, CN=Class 3 Primary CA
11791428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xa0ee62086758b15d C=US, O=Equifax, OU=Equifax Secure Certificate Authority
11801428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xeae16ef49d40be00 C=GB, ST=Greater Manchester, L=Salford, O=Comodo CA Limited, CN=AAA Certificate Services
11811428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x9403a4b8727eb000 C=TW, O=TAIWAN-CA, OU=Root CA, CN=TWCA Root Certification Authority
11821428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x48cc53a3896bab00 C=CO, O=Sociedad Cameral de Certificación Digital - Certicámara S.A., CN=AC Raíz Certicámara S.A.
11831428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xd71519e43fd5ba00 C=CA, ST=Ontario, L=Toronto, O=Echoworx Corporation, OU=Certification Services, CN=Echoworx Root CA2
11841428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xade42733bd8d9700 C=us, O=U.S. Government, OU=FBCA, CN=Common Policy
11851428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x1c29714b0c909400 C=JP, O=Japan Certification Services, Inc., CN=SecureSign RootCA1
11861428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xd944bca189a00 C=BM, O=QuoVadis Limited, CN=QuoVadis Root CA 2
11871428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xe0b0c3006b04c400 C=LV, OU=Sertifikacijas pakalpojumu dala, CN=E-ME SSI (RCA)
11881428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xd8240de4137fd600 C=IE, O=An Post, OU=Post.Trust Ltd., CN=Post.Trust Root CA
11891428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x5295db258780a400 C=CL, ST=Region Metropolitana, L=Santiago, O=E-CERTCHILE, OU=Autoridad Certificadora, Email=sclientes@ccs.cl, CN=E-CERT ROOT CA
11901428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xd38f027573ffd300 CN=TÜRKTRUST Elektronik İşlem Hizmetleri, C=TR, L=Ankara, O=TÜRKTRUST Bilgi İletişim ve Bilişim Güvenliği Hizmetleri A.Ş. (c) Kasım 2005
11911428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x292d67d00f91f000 C=ES, O=Agencia Notarial de Certificacion S.L. Unipersonal - CIF B83395988, CN=ANCERT Certificados Notariales
11921428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xea33d3c14ab5d900 C=DE, ST=Baden-Wuerttemberg (BW), L=Stuttgart, O=Deutscher Sparkassen Verlag GmbH, CN=S-TRUST Authentication and Encryption Root CA 2005:PN
11931428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xea5386456178582b C=ZA, ST=Western Cape, L=Durbanville, O=Thawte, OU=Thawte Certification, CN=Thawte Timestamping CA
11941428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x6e864c7a8071ba00 C=ES, O=FNMT-RCM, OU=AC RAIZ FNMT-RCM
11951428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xbab415bd1e249800 C=US, OU=www.xrampsecurity.com, O=XRamp Security Services Inc, CN=XRamp Global Certification Authority
11961428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x8ff6fc03c1edbd00 C=US, ST=Arizona, L=Scottsdale, O=Starfield Technologies, Inc., CN=Starfield Root Certificate Authority - G2
11971428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x4c4391c37e36a900 CN=TÜRKTRUST Elektronik Sertifika Hizmet Sağlayıcısı, C=TR, L=Ankara, O=TÜRKTRUST Bilgi İletişim ve Bilişim Güvenliği Hizmetleri A.Ş. (c) Kasım 2005
11981428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x20a3c30cad008000 C=ES, O=DIRECCION GENERAL DE LA POLICIA, OU=DNIE, CN=AC RAIZ DNIE
11991428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xc6fa4243b695b600 C=US, O=Entrust, Inc., OU=www.entrust.net/CPS is incorporated by reference, OU=(c) 2006 Entrust, Inc., CN=Entrust Root Certification Authority
12001428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xf7c33b7ebfec9b00 C=SI, O=POSTA, OU=POSTArCA
12011428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xa3ce8d99e60eda00 C=BE, O=GlobalSign nv-sa, OU=Root CA, CN=GlobalSign Root CA
12021428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xab7df2a48539b200 C=US, ST=UT, L=Salt Lake City, O=The USERTRUST Network, OU=http://www.usertrust.com, CN=UTN-USERFirst-Client Authentication and Email
12031428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xb3d6d6c9f168c800 C=FR, O=Dhimyotis, CN=Certigna
12041428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xa671e9fec832b700 C=US, O=Starfield Technologies, Inc., OU=Starfield Class 2 Certification Authority
12051428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xf44cbb0f8c74bc00 C=HU, ST=Hungary, L=Budapest, O=NetLock Halozatbiztonsagi Kft., OU=Tanusitvanykiadok, CN=NetLock Kozjegyzoi (Class A) Tanusitvanykiado
12061428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x6a4c39c4152dd100 C=CZ, CN=I.CA - Standard root certificate, O=Prvni certifikacni autorita a.s.
12071428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xbf168afe877852f1 C=US, O=thawte, Inc., OU=(c) 2007 thawte, Inc. - For authorized use only, CN=thawte Primary Root CA - G2
12081428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xdf103d404d3cef00 C=US, O=GeoTrust Inc., CN=GeoTrust Global CA 2
12091428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xa8de7211e13be200 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root CA
12101428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xbeb3e8b6dcbbd000 C=BR, O=Serasa S.A., OU=Serasa CA I, CN=Serasa Certificate Authority I
12111428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x177a8452aab3d500 C=BE, O=Certipost s.a./n.v., CN=Certipost E-Trust Primary Normalised CA
12121428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xdff6d845073c8b00 C=NO, O=Buypass AS-983163327, CN=Buypass Class 2 CA 1
12131428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x2f371157ab2ac600 C=ES, O=Generalitat Valenciana, OU=PKIGVA, CN=Root CA Generalitat Valenciana
12141428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xd41691e475fb8515 C=GB, ST=Greater Manchester, L=Salford, O=COMODO CA Limited, CN=COMODO ECC Certification Authority
12151428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x1a1ea800c447f200 C=BR, O=Serasa S.A., OU=Serasa CA III, CN=Serasa Certificate Authority III
12161428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x3178d37f87f1c400 C=CH, O=SwissSign AG, CN=SwissSign Silver CA - G2
12171428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x7ae89c50f0b6a00f C=US, O=GTE Corporation, OU=GTE CyberTrust Solutions, Inc., CN=GTE CyberTrust Global Root
12181428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x68dbf810c635b900 C=JP, O=LGPKI, OU=Application CA G2
12191428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xd45980fbf0a0ac00 C=US, O=thawte, Inc., OU=Certification Services Division, OU=(c) 2006 thawte, Inc. - For authorized use only, CN=thawte Primary Root CA
12201428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x52273f34861cc300 C=IT, L=Milano, O=Actalis S.p.A./03358520967, CN=Actalis Authentication CA G1
12211428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x4d3835aa4180b200 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2011
12221428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x236696801e5e9900 C=JP, O=Japan Certification Services, Inc., CN=SecureSign RootCA3
12231428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xef62113787ebace5 C=US, O=GeoTrust Inc., OU=(c) 2007 GeoTrust Inc. - For authorized use only, CN=GeoTrust Primary Certification Authority - G2
12241428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xc9edb72b684ba00 C=US, O=Entrust, Inc., OU=See www.entrust.net/legal-terms, OU=(c) 2009 Entrust, Inc. - for authorized use only, CN=Entrust Root Certification Authority - G2
12251428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x6a3ad06184a0ee00 CN=EBG Elektronik Sertifika Hizmet Sağlayıcısı, O=EBG Bilişim Teknolojileri ve Hizmetleri A.Ş., C=TR
12261428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xad77733ff735d300 C=CN, O=CNNIC, CN=CNNIC ROOT
12271428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xf5cd95e581a4ab00 C=US, O=SecureTrust Corporation, CN=SecureTrust CA
12281428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xcfb22061f662ac00 C=DK, O=TDC, CN=TDC OCES CA
12291428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x298be035a30bab00 C=DE, O=Deutsche Telekom AG, OU=T-TeleSec Trust Center, CN=Deutsche Telekom Root CA 2
12301428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xabd0695c5d11d15e C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority - G2, OU=(c) 1998 VeriSign, Inc. - For authorized use only, OU=VeriSign Trust Network
12311428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x7d2686ca075db300 C=CN, O=UniTrust, CN=UCA Root
12321428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x5784013b5c9c9d00 CN=ComSign Advanced Security CA
12331428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x5c39bb51bbe0b400 C=DE, O=TC TrustCenter GmbH, OU=TC TrustCenter Class 3 CA, CN=TC TrustCenter Class 3 CA II
12341428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x80932303749f217 C=SI, O=Halcom, CN=Halcom CA PO 2
12351428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x8b7607cf260bd500 C=si, O=state-institutions, OU=sigov-ca
12361428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x8f874e74e06da700 C=JP, O=Japanese Government, OU=ApplicationCA
12371428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x23f085ee57b2b400 C=ES, O=Consejo General de la Abogacia NIF:Q-2863006I, CN=Autoridad de Certificacion de la Abogacia
12381428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x5534b165029017e7 C=US, O=Equifax Secure Inc., CN=Equifax Secure Global eBusiness CA-1
12391428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x7052e7f4a064c100 ˜H?
12401428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xd80363d60552ca00 CN=TÜRKTRUST Elektronik Sertifika Hizmet Sağlayıcısı, C=TR, L=ANKARA, O=(c) 2005 TÜRKTRUST Bilgi İletişim ve Bilişim Güvenliği Hizmetleri A.Ş.
12411428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x802b3770cb00af00 C=EU, L=Madrid (see current address at www.camerfirma.com/address)
12421428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x6f2ebe0e24cfa600 OU=GlobalSign Root CA - R2, O=GlobalSign, CN=GlobalSign
12431428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xff91db7d3f31b300 CN=TÜRKTRUST Elektronik İşlem Hizmetleri, C=TR, L=ANKARA, O=(c) 2005 TÜRKTRUST Bilgi İletişim ve Bilişim Güvenliği Hizmetleri A.Ş.
12441428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xa09adb78d220ae00 C=BE, O=Certipost s.a./n.v., CN=Certipost E-Trust Primary Qualified CA
12451428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x14018a1bf29e595c C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority
12461428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x35f812d09650dc00 C=FR, O=Certplus, CN=Class 2 Primary CA
12471428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xa16e1e56de57af00 C=US, O=VISA, OU=Visa International Service Association, CN=Visa eCommerce Root
12481428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x185da5e55536b700 C=EU, O=AC Camerfirma SA CIF A82743287, OU=http://www.chambersign.org, CN=Chambers of Commerce Root
12491428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x2ca999312534d200 C=CH, O=admin, OU=Services, OU=Certification Authorities, CN=AdminCA-CD-T01
12501428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xaec72ec8296bc300 C=FR, O=Certplus, CN=Class 1 Primary CA
12511428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x88db8dee0f25e100 C=TW, O=Chunghwa Telecom Co., Ltd., OU=ePKI Root Certification Authority
12521428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xf274f0a48808ab00 C=CZ, CN=I.CA - Qualified root certificate, O=První certifikační autorita, a.s.
12531428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x9e5bc2d78b6a3636 C=ZA, ST=Western Cape, L=Cape Town, O=Thawte Consulting cc, OU=Certification Services Division, CN=Thawte Premium Server CA, Email=premium-server@thawte.com
12541428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x7c4fd32ec1b1ce00 C=PL, O=Unizeto Sp. z o.o., CN=Certum CA
12551428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xdb2cd5c20d0aaf00 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 1999 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 2 Public Primary Certification Authority - G3
12561428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x6429d974d78ea400 C=NO, O=Buypass AS-983163327, CN=Buypass Class 3 CA 1
12571428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x33c562d0d11fb200 C=FR, ST=France, L=Paris, O=PM/SGDN, OU=DCSSI, CN=IGC/A, Email=igca@sgdn.pm.gouv.fr
12581428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xd4fbe673e5ccc600 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA
12591428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x665014bdbcc8f800 O=Cybertrust, Inc, CN=Cybertrust Global Root
12601428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xbbd90ca8b0b9d000 C=ch, O=Swisscom, OU=Digital Certificate Services, CN=Swisscom Root CA 1
12611428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x5536e4a191fbb300 C=US, ST=UT, L=Salt Lake City, O=The USERTRUST Network, OU=http://www.usertrust.com, CN=UTN-USERFirst-Network Applications
12621428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x16e64d2a56ccf200 C=US, ST=Arizona, L=Scottsdale, O=Starfield Technologies, Inc., OU=http://certificates.starfieldtech.com/repository/, CN=Starfield Services Root Certificate Authority
12631428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x19c084be4feaba00 C=LT, O=Skaitmeninio sertifikavimo centras, OU=Certification Authority, CN=SSC Root CA A
12641428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x92d01fe10011c900 C=US, O=VISA, OU=Visa International Service Association, CN=Visa Information Delivery Root CA
12651428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x3eaa756fe759c500 C=NL, O=Staat der Nederlanden, CN=Staat der Nederlanden Root CA - G2
12661428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x363d9b00b34fcb00 C=CH, O=WISeKey, OU=Copyright (c) 2005, OU=OISTE Foundation Endorsed, CN=OISTE WISeKey Global Root GA CA
12671428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xf8dae202a2dfca00 C=CH, O=SwissSign AG, CN=SwissSign Platinum CA - G2
12681428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x7637cbb5cf9ce200 C=SG, O=Netrust Certificate Authority 1, OU=Netrust CA1
12691428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xb28612a94b4dad00 O=Entrust.net, OU=www.entrust.net/CPS_2048 incorp. by ref. (limits liab.), OU=(c) 1999 Entrust.net Limited, CN=Entrust.net Certification Authority (2048)
12701428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x357a29080824af00 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2006 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G5
12711428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x9b3ae4d356dfc000 C=EU, L=Madrid (see current address at www.camerfirma.com/address)
12721428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x69785d02da6eb500 C=ES, O=IZENPE S.A. - CIF A-01337260-RMerc.Vitoria-Gasteiz T1055 F62 S8, L=Avda del Mediterraneo Etorbidea 3 - 01010 Vitoria-Gasteiz, CN=Izenpe.com, Email=Info@izenpe.com
12731428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xf8491584e4cdb300 C=DE, O=D-Trust GmbH, CN=D-TRUST Root Class 2 CA 2007
12741428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x59faf1086271bf00 C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com, Inc., CN=Go Daddy Root Certificate Authority - G2
12751428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xfe3e3d933619ad3f C=ES, O=FNMT, OU=FNMT Clase 2 CA
12761428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xcfd21c88249eb300 C=AT, O=A-Trust Ges. f. Sicherheitssysteme im elektr. Datenverkehr GmbH, OU=A-Trust-Qual-03, CN=A-Trust-Qual-03
12771428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xd607333e36718100 Email=pki@sk.ee, C=EE, O=AS Sertifitseerimiskeskus, CN=Juur-SK
12781428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xdc94c92cf53db900 C=US, O=Digital Signature Trust, OU=DST ACES, CN=DST ACES CA X6
12791428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x4e5147f555f3c100 C=LT, O=Skaitmeninio sertifikavimo centras, OU=Certification Authority, CN=SSC Root CA B
12801428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x64acc0b265e5b000 C=si, O=state-institutions, OU=sigen-ca
12811428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x466cbc09db88c100 C=IL, O=StartCom Ltd., OU=Secure Digital Certificate Signing, CN=StartCom Certification Authority
12821428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x5901ca5aa77fd00 C=JP, O=Japan Certification Services, Inc., CN=SecureSign RootCA11
12831428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xd0353b9e7b50c500 C=GB, O=Trustis Limited, OU=Trustis FPS Root CA
12841428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x556cacd82e35af00 C=US, O=SecureTrust Corporation, CN=Secure Global CA
12851428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x30669a4e82fa800 C=US, O=America Online Inc., CN=America Online Root Certification Authority 1
12861428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xa9c86e43a2efdb00 C=PT, O=SCEE, CN=ECRaizEstado
12871428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xf0ca9d354a179000 C=FI, O=Sonera, CN=Sonera Class2 CA
12881428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xf23ec9c15254b300 C=US, O=GeoTrust Inc., CN=GeoTrust Universal CA 2
12891428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xb16dd37ffeb3b300 C=JP, O=SECOM Trust.net, OU=Security Communication RootCA1
12901428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x3401b15e3761c700 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2008 VeriSign, Inc. - For authorized use only, CN=VeriSign Universal Root Certification Authority
12911428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x7052e7f4a064c100 L=Alvaro Obregon, ST=Distrito Federal, C=MX?
12921428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xe8985fec4712d200 C=AT, L=Vienna, ST=Austria, O=ARGE DATEN - Austrian Society for Data Protection, OU=GLOBALTRUST Certification Service, CN=GLOBALTRUST, Email=info@globaltrust.info
12931428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xae429fd0a270a200 C=EU, O=AC Camerfirma SA CIF A82743287, OU=http://www.chambersign.org, CN=Global Chambersign Root
12941428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x7cd4ff7b15b8be00 C=US, O=GeoTrust Inc., CN=GeoTrust Primary Certification Authority
12951428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x5b9d66b2891fad00 C=BR, O=Serasa S.A., OU=Serasa CA II, CN=Serasa Certificate Authority II
12961428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xac1e0fca7ad3c900 C=ES, O=IZENPE S.A., CN=Izenpe.com
12971428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xfd887dc131f69200 C=SK, L=Bratislava, O=Disig a.s., CN=CA Disig
12981428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x4297e24fc722b300 C=ES, O=Agencia Catalana de Certificacio (NIF Q-0801176-I), OU=Serveis Publics de Certificacio, OU=Vegeu https://www.catcert.net/verarrel (c)03, OU=Jerarquia Entitats de Certificacio Catalanes, CN=EC-ACC
12991428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x491857ead79dde00 C=US, O=The Go Daddy Group, Inc., OU=Go Daddy Class 2 Certification Authority
13001428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xfe221444afe0cb00 C=ch, O=admin, OU=Services, OU=Certification Authorities, CN=Admin-Root-CA
13011428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xdd80d271558fb700 O=RSA Security Inc, OU=RSA Security 2048 V3
13021428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xab549401526569d3 L=Internet, O=VeriSign, Inc., OU=VeriSign Commercial Software Publishers CA
13031428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xa9cc8cfa2245a100 C=LT, O=Skaitmeninio sertifikavimo centras, OU=Certification Authority, CN=SSC Root CA C
13041428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xe66b56ffc86e50a4 C=ZA, ST=Western Cape, L=Cape Town, O=Thawte Consulting cc, OU=Certification Services Division, CN=Thawte Server CA, Email=server-certs@thawte.com
13051428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xcd7b81d500c8ed00 C=HU, L=Budapest, O=Microsec Ltd., OU=e-Szigno CA, CN=Microsec e-Szigno Root CA
13061428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x92ac5ed85c2d0e9b C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2007 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G4
13071428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x419b60ebff37ab00 C=FR, O=Certplus, CN=Class 3P Primary CA
13081428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x2676db9b15412b5a C=KR, O=Government of Korea, OU=GPKI, CN=GPKIRootCA
13091428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xa7f9b4b9d484dd00 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 1999 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 1 Public Primary Certification Authority - G3
13101428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xe69c54164257cc00 C=BM, O=QuoVadis Limited, CN=QuoVadis Root CA 3
13111428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x3a8810ff4b6d8a00 C=TR, L=Gebze - Kocaeli, O=Türkiye Bilimsel ve Teknolojik Araştırma Kurumu - TÜBİTAK, OU=Ulusal Elektronik ve Kriptoloji Araştırma Enstitüsü - UEKAE, OU=Kamu Sertifikasyon Merkezi, CN=TÜBİTAK UEKAE Kök Sertifika Hizmet Sağlayıcısı - Sürüm 3
13121428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x1f78fc529cbacb00 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 1999 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G3
13131428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xcaac0c3f3f759000 C=ES, O=Agencia Notarial de Certificacion S.L. Unipersonal - CIF B83395988, CN=ANCERT Certificados CGN
13141428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x817a1151b5d29800 C=NL, O=Staat der Nederlanden, CN=Staat der Nederlanden Root CA
13151428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xeb8adc879521a200 C=ES, O=Agencia Notarial de Certificacion S.L. Unipersonal - CIF B83395988, CN=ANCERT Corporaciones de Derecho Publico
13161428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xf63f5006e5b3da00 C=CN, O=UniTrust, CN=UCA Global Root
13171428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x2f5561fdf9b89b00 C=LV, O=VAS Latvijas Pasts - Vien.reg.Nr.40003052790, OU=Sertifikacijas pakalpojumi, CN=VAS Latvijas Pasts SSI(RCA)
13181428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xc2ba72a37dfbe300 C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Trusted Network CA
13191428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xa674f2b1f89b500 C=FI, O=Sonera, CN=Sonera Class1 CA
13201428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x6d4bbe735e24c400 C=HU, L=Budapest, O=NetLock Kft., OU=Tanúsítványkiadók (Certification Services), CN=NetLock Arany (Class Gold) Főtanúsítvány
13211428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x8043e4ce150ead00 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID Root CA
13221428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xf1fbd6404bd4a500 C=BE, O=Certipost s.a./n.v., CN=Certipost E-Trust TOP Root CA
13231428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xa8b43f38c3f7b100 C=US, ST=UT, L=Salt Lake City, O=The USERTRUST Network, OU=http://www.usertrust.com, CN=UTN-USERFirst-Hardware
13241428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x407c0c3d7576bf00 C=SI, O=ACNLB
13251428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x9de5960126a3bc00 C=SI, O=Halcom, CN=Halcom CA FO
13261428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0x331d58625ee2dc00 C=US, O=GeoTrust Inc., OU=(c) 2008 GeoTrust Inc. - For authorized use only, CN=GeoTrust Primary Certification Authority - G3
13271428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xf2e6331af7b700 C=SE, O=AddTrust AB, OU=AddTrust External TTP Network, CN=AddTrust External CA Root
13281428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xf03913fae404bc00 C=KR, O=KISA, OU=Korea Certification Authority Central, CN=KISA RootCA 1
13291428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xd43dd8b22552c700 C=HU, L=Budapest, O=NetLock Halozatbiztonsagi Kft., OU=Tanusitvanykiadok, CN=NetLock Minositett Kozjegyzoi (Class QA) Tanusitvanykiado, Email=info@netlock.hu
13301428.140c: supR3HardenedWinIsDesiredRootCA: Adding 0xdf603f23927b9600 C=JP, O=Japan Certification Services, Inc., CN=SecureSign RootCA2
13311428.140c: supR3HardenedWinRetrieveTrustedRootCAs: cAdded=190
13321428.140c: SUPR3HardenedMain: Load Runtime...
13331428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
13341428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
13351428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ws2_32.dll'.
13361428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'rpcrt4.dll'.
13371428.140c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\opt\VirtualBox\VBoxRT.dll) WinVerifyTrust
13381428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\opt\VirtualBox\VBoxRT.dll
13391428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
13401428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
13411428.140c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll
13421428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
13431428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
13441428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000045c pwszName=\Device\HarddiskVolume3\Windows\System32\ws2_32.dll
13451428.140c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
13461428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
13471428.140c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=3EF3BDC1E84DFA17EA056313214EE88EC3E66F79
13481428.140c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume3\Windows\System32\ws2_32.dll'
13491428.140c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
13501428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
13511428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'rpcrt4.dll'.
13521428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'nsi.dll'.
13531428.140c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\ws2_32.dll) WinVerifyTrust
13541428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\ws2_32.dll
13551428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
13561428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
13571428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
13581428.140c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\opt\VirtualBox\msvcp100.dll) WinVerifyTrust
13591428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\opt\VirtualBox\msvcp100.dll
13601428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
13611428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
13621428.140c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\opt\VirtualBox\msvcr100.dll) WinVerifyTrust
13631428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\opt\VirtualBox\msvcr100.dll
13641428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
13651428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
13661428.140c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\msvcr100.dll
13671428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
13681428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume3\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
13691428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000460 pwszName=\Device\HarddiskVolume3\Windows\System32\nsi.dll
13701428.140c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
13711428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
13721428.140c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=7AFD8538945F2D05BC1AF949B9B19B7D2D9FBBF8
13731428.140c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume3\Windows\System32\nsi.dll'
13741428.140c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
13751428.140c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\nsi.dll) WinVerifyTrust
13761428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\nsi.dll
13771428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
13781428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
13791428.140c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll
13801428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
13811428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
13821428.140c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll
13831428.140c: supR3HardenedMonitor_LdrLoadDll: pName=D:\opt\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000448520:D:\opt\VirtualBox;C:\Windows\system32 [calling]
13841428.140c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\VBoxRT.dll
13851428.140c: supR3HardenedDllNotificationCallback: load 000007fee7e00000 LB 0x0055f000 D:\opt\VirtualBox\VBoxRT.dll [fFlags=0x0]
13861428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\VBoxRT.dll
13871428.140c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\msvcr100.dll
13881428.140c: supR3HardenedDllNotificationCallback: load 0000000071010000 LB 0x000d2000 D:\opt\VirtualBox\MSVCR100.dll [fFlags=0x0]
13891428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\msvcr100.dll
13901428.140c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\msvcp100.dll
13911428.140c: supR3HardenedDllNotificationCallback: load 0000000070f70000 LB 0x00098000 D:\opt\VirtualBox\MSVCP100.dll [fFlags=0x0]
13921428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\msvcp100.dll
13931428.140c: supR3HardenedDllNotificationCallback: load 000007fefde70000 LB 0x0004d000 C:\Windows\system32\WS2_32.dll [fFlags=0x0]
13941428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ws2_32.dll
13951428.140c: supR3HardenedDllNotificationCallback: load 000007feffbc0000 LB 0x00008000 C:\Windows\system32\NSI.dll [fFlags=0x0]
13961428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\nsi.dll
13971428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\VBoxRT.dll
13981428.140c: supR3HardenedMonitor_LdrLoadDll: pName=D:\opt\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d5560:D:\opt\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\Common Files\Microsoft Shared\Windows Live;D:\opt\Python27\;D:\opt\Python27\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x64;C:\Program Files\TortoiseSVN\bin;D:\opt\Sync\OpenSSH\bin;D:\opt\perl\c\bin;D:\opt\perl\perl\site\bin;D:\opt\perl\perl\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Skype\Phone\;D:\opt\git\TortoiseGit\bin;C:\Users\mcon\AppData\Roaming\Python\Scripts;D:\opt\cygwin64\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64;D:\opt\Nmap [calling]
13991428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7e00000 'D:\opt\VirtualBox\VBoxRT.dll'
14001428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\VBoxRT.dll
14011428.140c: supR3HardenedMonitor_LdrLoadDll: pName=D:\opt\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d5560:D:\opt\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\Common Files\Microsoft Shared\Windows Live;D:\opt\Python27\;D:\opt\Python27\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x64;C:\Program Files\TortoiseSVN\bin;D:\opt\Sync\OpenSSH\bin;D:\opt\perl\c\bin;D:\opt\perl\perl\site\bin;D:\opt\perl\perl\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Skype\Phone\;D:\opt\git\TortoiseGit\bin;C:\Users\mcon\AppData\Roaming\Python\Scripts;D:\opt\cygwin64\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64;D:\opt\Nmap [calling]
14021428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7e00000 'D:\opt\VirtualBox\VBoxRT.dll'
14031428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\VBoxRT.dll
14041428.140c: supR3HardenedMonitor_LdrLoadDll: pName=D:\opt\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d5560:D:\opt\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\Common Files\Microsoft Shared\Windows Live;D:\opt\Python27\;D:\opt\Python27\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x64;C:\Program Files\TortoiseSVN\bin;D:\opt\Sync\OpenSSH\bin;D:\opt\perl\c\bin;D:\opt\perl\perl\site\bin;D:\opt\perl\perl\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Skype\Phone\;D:\opt\git\TortoiseGit\bin;C:\Users\mcon\AppData\Roaming\Python\Scripts;D:\opt\cygwin64\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64;D:\opt\Nmap [calling]
14051428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7e00000 'D:\opt\VirtualBox\VBoxRT.dll'
14061428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\VBoxRT.dll
14071428.140c: supR3HardenedMonitor_LdrLoadDll: pName=D:\opt\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d5560:D:\opt\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\Common Files\Microsoft Shared\Windows Live;D:\opt\Python27\;D:\opt\Python27\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x64;C:\Program Files\TortoiseSVN\bin;D:\opt\Sync\OpenSSH\bin;D:\opt\perl\c\bin;D:\opt\perl\perl\site\bin;D:\opt\perl\perl\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Skype\Phone\;D:\opt\git\TortoiseGit\bin;C:\Users\mcon\AppData\Roaming\Python\Scripts;D:\opt\cygwin64\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64;D:\opt\Nmap [calling]
14081428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7e00000 'D:\opt\VirtualBox\VBoxRT.dll'
14091428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\VBoxRT.dll
14101428.140c: supR3HardenedMonitor_LdrLoadDll: pName=D:\opt\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d5560:D:\opt\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\Common Files\Microsoft Shared\Windows Live;D:\opt\Python27\;D:\opt\Python27\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x64;C:\Program Files\TortoiseSVN\bin;D:\opt\Sync\OpenSSH\bin;D:\opt\perl\c\bin;D:\opt\perl\perl\site\bin;D:\opt\perl\perl\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Skype\Phone\;D:\opt\git\TortoiseGit\bin;C:\Users\mcon\AppData\Roaming\Python\Scripts;D:\opt\cygwin64\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64;D:\opt\Nmap [calling]
14111428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7e00000 'D:\opt\VirtualBox\VBoxRT.dll'
14121428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\VBoxRT.dll
14131428.140c: supR3HardenedMonitor_LdrLoadDll: pName=D:\opt\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d5560:D:\opt\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\Common Files\Microsoft Shared\Windows Live;D:\opt\Python27\;D:\opt\Python27\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x64;C:\Program Files\TortoiseSVN\bin;D:\opt\Sync\OpenSSH\bin;D:\opt\perl\c\bin;D:\opt\perl\perl\site\bin;D:\opt\perl\perl\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Skype\Phone\;D:\opt\git\TortoiseGit\bin;C:\Users\mcon\AppData\Roaming\Python\Scripts;D:\opt\cygwin64\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64;D:\opt\Nmap [calling]
14141428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7e00000 'D:\opt\VirtualBox\VBoxRT.dll'
14151428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7e00000 'D:\opt\VirtualBox\VBoxRT.dll'
14161428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7e00000 'D:\opt\VirtualBox\VBoxRT.dll'
14171428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7e00000 'D:\opt\VirtualBox\VBoxRT.dll'
14181428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7e00000 'D:\opt\VirtualBox\VBoxRT.dll'
14191428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7e00000 'D:\opt\VirtualBox\VBoxRT.dll'
14201428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7e00000 'D:\opt\VirtualBox\VBoxRT.dll'
14211428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7e00000 'D:\opt\VirtualBox\VBoxRT.dll'
14221428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\VBoxRT.dll
14231428.140c: supR3HardenedMonitor_LdrLoadDll: pName=D:\opt\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d5560:D:\opt\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\Common Files\Microsoft Shared\Windows Live;D:\opt\Python27\;D:\opt\Python27\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x64;C:\Program Files\TortoiseSVN\bin;D:\opt\Sync\OpenSSH\bin;D:\opt\perl\c\bin;D:\opt\perl\perl\site\bin;D:\opt\perl\perl\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Skype\Phone\;D:\opt\git\TortoiseGit\bin;C:\Users\mcon\AppData\Roaming\Python\Scripts;D:\opt\cygwin64\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64;D:\opt\Nmap [calling]
14241428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7e00000 'D:\opt\VirtualBox\VBoxRT.dll'
14251428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7e00000 'D:\opt\VirtualBox\VBoxRT.dll'
14261428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7e00000 'D:\opt\VirtualBox\VBoxRT.dll'
14271428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7e00000 'D:\opt\VirtualBox\VBoxRT.dll'
14281428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7e00000 'D:\opt\VirtualBox\VBoxRT.dll'
14291428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7e00000 'D:\opt\VirtualBox\VBoxRT.dll'
14301428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7e00000 'D:\opt\VirtualBox\VBoxRT.dll'
14311428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7e00000 'D:\opt\VirtualBox\VBoxRT.dll'
14321428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7e00000 'D:\opt\VirtualBox\VBoxRT.dll'
14331428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7e00000 'D:\opt\VirtualBox\VBoxRT.dll'
14341428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7e00000 'D:\opt\VirtualBox\VBoxRT.dll'
14351428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7e00000 'D:\opt\VirtualBox\VBoxRT.dll'
14361428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7e00000 'D:\opt\VirtualBox\VBoxRT.dll'
14371428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7e00000 'D:\opt\VirtualBox\VBoxRT.dll'
14381428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7e00000 'D:\opt\VirtualBox\VBoxRT.dll'
14391428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7e00000 'D:\opt\VirtualBox\VBoxRT.dll'
14401428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\VBoxRT.dll
14411428.140c: supR3HardenedMonitor_LdrLoadDll: pName=D:\opt\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007d5560:D:\opt\VirtualBox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\Common Files\Microsoft Shared\Windows Live;D:\opt\Python27\;D:\opt\Python27\Scripts;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\3.0\bin\x64;C:\Program Files\TortoiseSVN\bin;D:\opt\Sync\OpenSSH\bin;D:\opt\perl\c\bin;D:\opt\perl\perl\site\bin;D:\opt\perl\perl\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Skype\Phone\;D:\opt\git\TortoiseGit\bin;C:\Users\mcon\AppData\Roaming\Python\Scripts;D:\opt\cygwin64\bin;D:\opt\MiKTeX 2.9\miktex\bin\x64;D:\opt\Nmap [calling]
14421428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7e00000 'D:\opt\VirtualBox\VBoxRT.dll'
14431428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7e00000 'D:\opt\VirtualBox\VBoxRT.dll'
14441428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7e00000 'D:\opt\VirtualBox\VBoxRT.dll'
14451428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7e00000 'D:\opt\VirtualBox\VBoxRT.dll'
14461428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wintrust.dll
14471428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000002c72920:C:\Windows\system32 [calling]
14481428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd9b0000 'C:\Windows\system32\Wintrust.dll'
14491428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll
14501428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\crypt32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000002c72920:C:\Windows\system32 [calling]
14511428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd9f0000 'C:\Windows\system32\crypt32.dll'
14521428.140c: SUPR3HardenedMain: Load TrustedMain...
14531428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'opengl32.dll'.
14541428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
14551428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msvcp100.dll'.
14561428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcr100.dll'.
14571428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qtcorevbox4.dll'.
14581428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'qtguivbox4.dll'.
14591428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'qtopenglvbox4.dll'.
14601428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'user32.dll'.
14611428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'gdi32.dll'.
14621428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'advapi32.dll'.
14631428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'shell32.dll'.
14641428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'ole32.dll'.
14651428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'oleaut32.dll'.
14661428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'comdlg32.dll'.
14671428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #15 'winmm.dll'.
14681428.140c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\opt\VirtualBox\VirtualBox.dll) WinVerifyTrust
14691428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\opt\VirtualBox\VirtualBox.dll
14701428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
14711428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume3\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
14721428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004c0 pwszName=\Device\HarddiskVolume3\Windows\System32\winmm.dll
14731428.140c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
14741428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
14751428.140c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=82E2B2A7826F88BEB98FFF0540C9BDB0A12F001A
14761428.140c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume3\Windows\System32\winmm.dll'
14771428.140c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
14781428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
14791428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
14801428.140c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\winmm.dll) WinVerifyTrust
14811428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\winmm.dll
14821428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comdlg32.dll'...
14831428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'comdlg32.dll' -> '\Device\HarddiskVolume3\Windows\System32\comdlg32.dll' [rcNtRedir=0xc0150008]
14841428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004a8 pwszName=\Device\HarddiskVolume3\Windows\System32\comdlg32.dll
14851428.140c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
14861428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
14871428.140c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=66EE5BDFFA413AEA9E1FE7838A08646E94136DA5
14881428.140c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume3\Windows\System32\comdlg32.dll'
14891428.140c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
14901428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
14911428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'shlwapi.dll'.
14921428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
14931428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'gdi32.dll'.
14941428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'comctl32.dll'.
14951428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'shell32.dll'.
14961428.140c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\comdlg32.dll) WinVerifyTrust
14971428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\comdlg32.dll
14981428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
14991428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume3\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
15001428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004cc pwszName=\Device\HarddiskVolume3\Windows\System32\oleaut32.dll
15011428.140c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
15021428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
15031428.140c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=8A837B0D823EB506C6A4C447C1962174D27ED954
15041428.140c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3020338~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume3\Windows\System32\oleaut32.dll'
15051428.140c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
15061428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ole32.dll'.
15071428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
15081428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
15091428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'user32.dll'.
15101428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'gdi32.dll'.
15111428.140c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\oleaut32.dll) WinVerifyTrust
15121428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\oleaut32.dll
15131428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
15141428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
15151428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004c4 pwszName=\Device\HarddiskVolume3\Windows\System32\ole32.dll
15161428.140c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
15171428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
15181428.140c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2E93C1851E5754D607F55581B4DE2A30B711C830
15191428.140c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_2_for_KB3072633~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume3\Windows\System32\ole32.dll'
15201428.140c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
15211428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
15221428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
15231428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'user32.dll'.
15241428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'rpcrt4.dll'.
15251428.140c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\ole32.dll) WinVerifyTrust
15261428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\ole32.dll
15271428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
15281428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume3\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
15291428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004bc pwszName=\Device\HarddiskVolume3\Windows\System32\shell32.dll
15301428.140c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
15311428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
15321428.140c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=FB4A0D952E568C1E85DCE662F9A066FFB2E6CE84
15331428.140c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3080446~31bf3856ad364e35~amd64~~6.1.1.2.cat'; file='\Device\HarddiskVolume3\Windows\System32\shell32.dll'
15341428.140c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
15351428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
15361428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #21 'shlwapi.dll'.
15371428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'user32.dll'.
15381428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #24 'gdi32.dll'.
15391428.140c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\shell32.dll) WinVerifyTrust
15401428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\shell32.dll
15411428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
15421428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
15431428.140c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\advapi32.dll
15441428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
15451428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
15461428.140c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll
15471428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
15481428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
15491428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtopenglvbox4.dll'...
15501428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtopenglvbox4.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\qtopenglvbox4.dll' [rcNtRedir=0xc0150008]
15511428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'opengl32.dll'.
15521428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
15531428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
15541428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qtguivbox4.dll'.
15551428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qtcorevbox4.dll'.
15561428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcr100.dll'.
15571428.140c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\opt\VirtualBox\QtOpenGLVBox4.dll) WinVerifyTrust
15581428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\opt\VirtualBox\QtOpenGLVBox4.dll
15591428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtguivbox4.dll'...
15601428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtguivbox4.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\qtguivbox4.dll' [rcNtRedir=0xc0150008]
15611428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
15621428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'comdlg32.dll'.
15631428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'oleaut32.dll'.
15641428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'imm32.dll'.
15651428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'winmm.dll'.
15661428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'winspool.drv'.
15671428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'ole32.dll'.
15681428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'user32.dll'.
15691428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'advapi32.dll'.
15701428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'shell32.dll'.
15711428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'qtcorevbox4.dll'.
15721428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'msvcp100.dll'.
15731428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'msvcr100.dll'.
15741428.140c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\opt\VirtualBox\QtGuiVBox4.dll) WinVerifyTrust
15751428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\opt\VirtualBox\QtGuiVBox4.dll
15761428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtcorevbox4.dll'...
15771428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtcorevbox4.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\qtcorevbox4.dll' [rcNtRedir=0xc0150008]
15781428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
15791428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'ole32.dll'.
15801428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
15811428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ws2_32.dll'.
15821428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcp100.dll'.
15831428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msvcr100.dll'.
15841428.140c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\opt\VirtualBox\QtCoreVBox4.dll) WinVerifyTrust
15851428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\opt\VirtualBox\QtCoreVBox4.dll
15861428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
15871428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
15881428.140c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\msvcr100.dll
15891428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
15901428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
15911428.140c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\msvcp100.dll
15921428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
15931428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
15941428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
15951428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume3\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
15961428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004ec pwszName=\Device\HarddiskVolume3\Windows\System32\opengl32.dll
15971428.140c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
15981428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
15991428.140c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=608AC397FCC42B9FBAE25CB8C25EAF4C19AA384D
16001428.140c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume3\Windows\System32\opengl32.dll'
16011428.140c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
16021428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
16031428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
16041428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'gdi32.dll'.
16051428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'glu32.dll'.
16061428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'ddraw.dll'.
16071428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'user32.dll'.
16081428.140c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\opengl32.dll) WinVerifyTrust
16091428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\opengl32.dll
16101428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
16111428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
16121428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ddraw.dll'...
16131428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ddraw.dll' -> '\Device\HarddiskVolume3\Windows\System32\ddraw.dll' [rcNtRedir=0xc0150008]
16141428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000508 pwszName=\Device\HarddiskVolume3\Windows\System32\ddraw.dll
16151428.140c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
16161428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
16171428.140c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=24C763EA54CD792A0F1618411061DC356EE31FF6
16181428.140c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume3\Windows\System32\ddraw.dll'
16191428.140c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
16201428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
16211428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
16221428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'dciman32.dll'.
16231428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
16241428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'setupapi.dll'.
16251428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'dwmapi.dll'.
16261428.140c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\ddraw.dll) WinVerifyTrust
16271428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\ddraw.dll
16281428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'glu32.dll'...
16291428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'glu32.dll' -> '\Device\HarddiskVolume3\Windows\System32\glu32.dll' [rcNtRedir=0xc0150008]
16301428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004f0 pwszName=\Device\HarddiskVolume3\Windows\System32\glu32.dll
16311428.140c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
16321428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
16331428.140c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=60E45AB914E06A11F44EA76C6EF750AF892F9EA2
16341428.140c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume3\Windows\System32\glu32.dll'
16351428.140c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
16361428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
16371428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'opengl32.dll'.
16381428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
16391428.140c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\glu32.dll) WinVerifyTrust
16401428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\glu32.dll
16411428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
16421428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
16431428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
16441428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
16451428.140c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\advapi32.dll
16461428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
16471428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
16481428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
16491428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
16501428.140c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\msvcr100.dll
16511428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
16521428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
16531428.140c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\msvcp100.dll
16541428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
16551428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
16561428.140c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ws2_32.dll
16571428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
16581428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
16591428.140c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\advapi32.dll
16601428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
16611428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
16621428.140c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ole32.dll
16631428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
16641428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
16651428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
16661428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
16671428.140c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\msvcr100.dll
16681428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
16691428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
16701428.140c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\msvcp100.dll
16711428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtcorevbox4.dll'...
16721428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtcorevbox4.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\qtcorevbox4.dll' [rcNtRedir=0xc0150008]
16731428.140c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\QtCoreVBox4.dll
16741428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
16751428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume3\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
16761428.140c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\shell32.dll
16771428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
16781428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
16791428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
16801428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
16811428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
16821428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
16831428.140c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ole32.dll
16841428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winspool.drv'...
16851428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'winspool.drv' -> '\Device\HarddiskVolume3\Windows\System32\winspool.drv' [rcNtRedir=0xc0150008]
16861428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000504 pwszName=\Device\HarddiskVolume3\Windows\System32\winspool.drv
16871428.140c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
16881428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
16891428.140c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=C89A2ED7B99A056D78CA6BAC9CCAB8B1FF119A14
16901428.140c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume3\Windows\System32\winspool.drv'
16911428.140c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
16921428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
16931428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
16941428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
16951428.140c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\winspool.drv) WinVerifyTrust
16961428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\winspool.drv
16971428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
16981428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume3\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
16991428.140c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winmm.dll
17001428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
17011428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume3\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
17021428.140c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\imm32.dll
17031428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
17041428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume3\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
17051428.140c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\oleaut32.dll
17061428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comdlg32.dll'...
17071428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'comdlg32.dll' -> '\Device\HarddiskVolume3\Windows\System32\comdlg32.dll' [rcNtRedir=0xc0150008]
17081428.140c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\comdlg32.dll
17091428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
17101428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
17111428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
17121428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
17131428.140c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\msvcr100.dll
17141428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtcorevbox4.dll'...
17151428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtcorevbox4.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\qtcorevbox4.dll' [rcNtRedir=0xc0150008]
17161428.140c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\QtCoreVBox4.dll
17171428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtguivbox4.dll'...
17181428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtguivbox4.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\qtguivbox4.dll' [rcNtRedir=0xc0150008]
17191428.140c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\QtGuiVBox4.dll
17201428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
17211428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
17221428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
17231428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
17241428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
17251428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume3\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
17261428.140c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\opengl32.dll
17271428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
17281428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
17291428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
17301428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
17311428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
17321428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
17331428.140c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\shlwapi.dll
17341428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
17351428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
17361428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
17371428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
17381428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
17391428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
17401428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
17411428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
17421428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
17431428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
17441428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
17451428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
17461428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
17471428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
17481428.140c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\user32.dll
17491428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
17501428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
17511428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
17521428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
17531428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
17541428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
17551428.140c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ole32.dll
17561428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
17571428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume3\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
17581428.140c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\shell32.dll
17591428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comctl32.dll'...
17601428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'comctl32.dll' -> '\Device\HarddiskVolume3\Windows\System32\comctl32.dll' [rcNtRedir=0x0]
17611428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004c8 pwszName=\Device\HarddiskVolume3\Windows\System32\comctl32.dll
17621428.140c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
17631428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
17641428.140c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=761964761EE466757E306124E042F4C2ACBEA092
17651428.140c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3059317~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume3\Windows\System32\comctl32.dll'
17661428.140c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
17671428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'advapi32.dll'.
17681428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
17691428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
17701428.140c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\comctl32.dll) WinVerifyTrust
17711428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\comctl32.dll
17721428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
17731428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
17741428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
17751428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
17761428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
17771428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
17781428.140c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\shlwapi.dll
17791428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
17801428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
17811428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
17821428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
17831428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
17841428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
17851428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
17861428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
17871428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
17881428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
17891428.140c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll
17901428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
17911428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
17921428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
17931428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
17941428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
17951428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
17961428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
17971428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
17981428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
17991428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
18001428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
18011428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume3\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
18021428.140c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\opengl32.dll
18031428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
18041428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
18051428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dwmapi.dll'...
18061428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'dwmapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\dwmapi.dll' [rcNtRedir=0xc0150008]
18071428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000510 pwszName=\Device\HarddiskVolume3\Windows\System32\dwmapi.dll
18081428.140c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
18091428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
18101428.140c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=F3F3D4867E9140896E0742D7EE8AE1D01FE85ECE
18111428.140c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3078667~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume3\Windows\System32\dwmapi.dll'
18121428.140c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
18131428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
18141428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
18151428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
18161428.140c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\dwmapi.dll) WinVerifyTrust
18171428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\dwmapi.dll
18181428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
18191428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
18201428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000518 pwszName=\Device\HarddiskVolume3\Windows\System32\setupapi.dll
18211428.140c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
18221428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
18231428.140c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=1499C4FEA6E143F9BEC35B4FFA098917D3A6EBF2
18241428.140c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume3\Windows\System32\setupapi.dll'
18251428.140c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
18261428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'cfgmgr32.dll'.
18271428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msvcrt.dll'.
18281428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'gdi32.dll'.
18291428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
18301428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'user32.dll'.
18311428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'oleaut32.dll'.
18321428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'devobj.dll'.
18331428.140c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\setupapi.dll) WinVerifyTrust
18341428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\setupapi.dll
18351428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
18361428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
18371428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dciman32.dll'...
18381428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'dciman32.dll' -> '\Device\HarddiskVolume3\Windows\System32\dciman32.dll' [rcNtRedir=0xc0150008]
18391428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000051c pwszName=\Device\HarddiskVolume3\Windows\System32\dciman32.dll
18401428.140c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
18411428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
18421428.140c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=779E327CA47BE9830D08A18EEDE8A70C3A978A3B
18431428.140c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3087039~31bf3856ad364e35~amd64~~6.1.1.4.cat'; file='\Device\HarddiskVolume3\Windows\System32\dciman32.dll'
18441428.140c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
18451428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
18461428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'gdi32.dll'.
18471428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
18481428.140c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\dciman32.dll) WinVerifyTrust
18491428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\dciman32.dll
18501428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
18511428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
18521428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
18531428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
18541428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
18551428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
18561428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
18571428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
18581428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
18591428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
18601428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'devobj.dll'...
18611428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'devobj.dll' -> '\Device\HarddiskVolume3\Windows\System32\devobj.dll' [rcNtRedir=0xc0150008]
18621428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000528 pwszName=\Device\HarddiskVolume3\Windows\System32\devobj.dll
18631428.140c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
18641428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
18651428.140c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B410A095222E69F0ECE7D66E4AC27A7125D2EB5A
18661428.140c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume3\Windows\System32\devobj.dll'
18671428.140c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
18681428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
18691428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'cfgmgr32.dll'.
18701428.140c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\devobj.dll) WinVerifyTrust
18711428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\devobj.dll
18721428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
18731428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume3\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
18741428.140c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\oleaut32.dll
18751428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
18761428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
18771428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
18781428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
18791428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
18801428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
18811428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
18821428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
18831428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
18841428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume3\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
18851428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000534 pwszName=\Device\HarddiskVolume3\Windows\System32\cfgmgr32.dll
18861428.140c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
18871428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
18881428.140c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=8F731777EFC4BC982C1E1467FBF29A74CC14D93A
18891428.140c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume3\Windows\System32\cfgmgr32.dll'
18901428.140c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
18911428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
18921428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'rpcrt4.dll'.
18931428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
18941428.140c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\cfgmgr32.dll) WinVerifyTrust
18951428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\cfgmgr32.dll
18961428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
18971428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
18981428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
18991428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
19001428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
19011428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
19021428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
19031428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
19041428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
19051428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
19061428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
19071428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
19081428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
19091428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume3\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
19101428.140c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\cfgmgr32.dll
19111428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
19121428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
19131428.140c: supR3HardenedMonitor_LdrLoadDll: pName=D:\opt\VirtualBox\VirtualBox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000448520:D:\opt\VirtualBox;C:\Windows\system32 [calling]
19141428.140c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\VirtualBox.dll
19151428.140c: supR3HardenedDllNotificationCallback: load 000007fee7340000 LB 0x00abb000 D:\opt\VirtualBox\VirtualBox.dll [fFlags=0x0]
19161428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\VirtualBox.dll
19171428.140c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\opengl32.dll
19181428.140c: supR3HardenedDllNotificationCallback: load 000007feec880000 LB 0x0011d000 C:\Windows\system32\OPENGL32.dll [fFlags=0x0]
19191428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\opengl32.dll
19201428.140c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\glu32.dll
19211428.140c: supR3HardenedDllNotificationCallback: load 000007feee900000 LB 0x0002d000 C:\Windows\system32\GLU32.dll [fFlags=0x0]
19221428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\glu32.dll
19231428.140c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ddraw.dll
19241428.140c: supR3HardenedDllNotificationCallback: load 000007feec780000 LB 0x000f1000 C:\Windows\system32\DDRAW.dll [fFlags=0x0]
19251428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ddraw.dll
19261428.140c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\dciman32.dll
19271428.140c: supR3HardenedDllNotificationCallback: load 000007fef0cf0000 LB 0x00008000 C:\Windows\system32\DCIMAN32.dll [fFlags=0x0]
19281428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\dciman32.dll
19291428.140c: supR3HardenedDllNotificationCallback: load 000007fefed90000 LB 0x001d7000 C:\Windows\system32\SETUPAPI.dll [fFlags=0x0]
19301428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\setupapi.dll
19311428.140c: supR3HardenedDllNotificationCallback: load 000007fefdb80000 LB 0x00036000 C:\Windows\system32\CFGMGR32.dll [fFlags=0x0]
19321428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\cfgmgr32.dll
19331428.140c: supR3HardenedDllNotificationCallback: load 000007feff390000 LB 0x000d7000 C:\Windows\system32\OLEAUT32.dll [fFlags=0x0]
19341428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\oleaut32.dll
19351428.140c: supR3HardenedDllNotificationCallback: load 000007feff9b0000 LB 0x00203000 C:\Windows\system32\ole32.dll [fFlags=0x0]
19361428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ole32.dll
19371428.140c: supR3HardenedDllNotificationCallback: load 000007fefdb60000 LB 0x0001a000 C:\Windows\system32\DEVOBJ.dll [fFlags=0x0]
19381428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\devobj.dll
19391428.140c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\dwmapi.dll
19401428.140c: supR3HardenedDllNotificationCallback: load 000007fefabd0000 LB 0x00018000 C:\Windows\system32\dwmapi.dll [fFlags=0x0]
19411428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\dwmapi.dll
19421428.140c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\QtCoreVBox4.dll
19431428.140c: supR3HardenedDllNotificationCallback: load 000000005d8e0000 LB 0x002de000 D:\opt\VirtualBox\QtCoreVBox4.dll [fFlags=0x0]
19441428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\QtCoreVBox4.dll
19451428.140c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\QtGuiVBox4.dll
19461428.140c: supR3HardenedDllNotificationCallback: load 0000000064510000 LB 0x0096c000 D:\opt\VirtualBox\QtGuiVBox4.dll [fFlags=0x0]
19471428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\QtGuiVBox4.dll
19481428.140c: supR3HardenedDllNotificationCallback: load 000007feff910000 LB 0x00097000 C:\Windows\system32\COMDLG32.dll [fFlags=0x0]
19491428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\comdlg32.dll
19501428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'advapi32.dll'.
19511428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
19521428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
19531428.140c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll)
19541428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll
19551428.140c: supR3HardenedDllNotificationCallback: load 000007fef8b90000 LB 0x000a0000 C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\COMCTL32.dll [fFlags=0x0]
19561428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll [avoiding WinVerifyTrust]
19571428.140c: supR3HardenedDllNotificationCallback: load 000007fefdec0000 LB 0x00d89000 C:\Windows\system32\SHELL32.dll [fFlags=0x0]
19581428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\shell32.dll
19591428.140c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winmm.dll
19601428.140c: supR3HardenedDllNotificationCallback: load 000007fefa8a0000 LB 0x0003b000 C:\Windows\system32\WINMM.dll [fFlags=0x0]
19611428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winmm.dll
19621428.140c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winspool.drv
19631428.140c: supR3HardenedDllNotificationCallback: load 000007fef87a0000 LB 0x00071000 C:\Windows\system32\WINSPOOL.DRV [fFlags=0x0]
19641428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winspool.drv
19651428.140c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\QtOpenGLVBox4.dll
19661428.140c: supR3HardenedDllNotificationCallback: load 0000000070e90000 LB 0x000dc000 D:\opt\VirtualBox\QtOpenGLVBox4.dll [fFlags=0x0]
19671428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\QtOpenGLVBox4.dll
19681428.140c: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume3\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll'.
19691428.140c: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll' [rescheduled]
19701428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\imm32.dll
19711428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
19721428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
19731428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
19741428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
19751428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
19761428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
19771428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\imm32.dll (Input=imm32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000448750:D:\opt\VirtualBox;C:\Windows\system32 [calling]
19781428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefed60000 'C:\Windows\system32\imm32.dll'
19791428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7340000 'D:\opt\VirtualBox\VirtualBox.dll'
19801428.140c: SUPR3HardenedMain: Calling TrustedMain (000007fee73410d0)...
19811428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winmm.dll
19821428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\winmm.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000448520:D:\opt\VirtualBox;C:\Windows\system32 [calling]
19831428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa8a0000 'C:\Windows\system32\winmm.dll'
19841428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000005c4 pwszName=\Device\HarddiskVolume3\Windows\System32\uxtheme.dll
19851428.140c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
19861428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
19871428.140c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=936D45CC7026757A151F62882B557DD75D5FCB21
19881428.140c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume3\Windows\System32\uxtheme.dll'
19891428.140c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
19901428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
19911428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
19921428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'gdi32.dll'.
19931428.140c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\uxtheme.dll) WinVerifyTrust
19941428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\uxtheme.dll
19951428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
19961428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
19971428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
19981428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
19991428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
20001428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
20011428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000878c30:C:\Windows\system32;D:\opt\VirtualBox;C:\Windows\system32 [calling]
20021428.140c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\uxtheme.dll
20031428.140c: supR3HardenedDllNotificationCallback: load 000007fefbc80000 LB 0x00056000 C:\Windows\system32\uxtheme.dll [fFlags=0x0]
20041428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\uxtheme.dll
20051428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbc80000 'C:\Windows\system32\uxtheme.dll'
20061428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\uxtheme.dll
20071428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000878c30:C:\Windows\system32;D:\opt\VirtualBox;C:\Windows\system32 [calling]
20081428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbc80000 'C:\Windows\system32\uxtheme.dll'
20091428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\uxtheme.dll
20101428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000878c30:C:\Windows\system32;D:\opt\VirtualBox;C:\Windows\system32 [calling]
20111428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbc80000 'C:\Windows\system32\uxtheme.dll'
20121428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\uxtheme.dll
20131428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000878c30:C:\Windows\system32;D:\opt\VirtualBox;C:\Windows\system32 [calling]
20141428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbc80000 'C:\Windows\system32\uxtheme.dll'
20151428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\dwmapi.dll
20161428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\dwmapi.dll (Input=dwmapi.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000448a60:D:\opt\VirtualBox;C:\Windows\system32 [calling]
20171428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefabd0000 'C:\Windows\system32\dwmapi.dll'
20181428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\cryptbase.dll
20191428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTBASE.dll (Input=CRYPTBASE.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000448a60:D:\opt\VirtualBox;C:\Windows\system32 [calling]
20201428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd760000 'C:\Windows\system32\CRYPTBASE.dll'
20211428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\shell32.dll
20221428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000448a60:D:\opt\VirtualBox;C:\Windows\system32 [calling]
20231428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdec0000 'C:\Windows\system32\shell32.dll'
20241428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\kernel32.dll
20251428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000448a60:D:\opt\VirtualBox;C:\Windows\system32 [calling]
20261428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077a00000 'C:\Windows\system32\kernel32.dll'
20271428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\uxtheme.dll
20281428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000448a60:D:\opt\VirtualBox;C:\Windows\system32 [calling]
20291428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbc80000 'C:\Windows\system32\uxtheme.dll'
20301428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\uxtheme.dll
20311428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000448a60:D:\opt\VirtualBox;C:\Windows\system32 [calling]
20321428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbc80000 'C:\Windows\system32\uxtheme.dll'
20331428.140c: supR3HardenedMonitor_LdrLoadDll: error opening 'C:\Windows\system32\wintab32.dll': 0 (NtPath=\??\C:\Windows\system32\wintab32.dll; Input=C:\Windows\system32\wintab32.dll; rcNtGetDll=0x0
20341428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wintab32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000448a60:D:\opt\VirtualBox;C:\Windows\system32 [calling]
20351428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000135 'C:\Windows\system32\wintab32.dll'
20361428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077900000 'C:\Windows\system32\user32.dll'
20371428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\uxtheme.dll
20381428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000448a60:D:\opt\VirtualBox;C:\Windows\system32 [calling]
20391428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbc80000 'C:\Windows\system32\uxtheme.dll'
20401428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077900000 'C:\Windows\system32\user32.dll'
20411428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdd90000 'C:\Windows\system32\advapi32.dll'
20421428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\userenv.dll
20431428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\userenv.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000448a60:D:\opt\VirtualBox;C:\Windows\system32 [calling]
20441428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdbc0000 'C:\Windows\system32\userenv.dll'
20451428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\kernel32.dll
20461428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000448a60:D:\opt\VirtualBox;C:\Windows\system32 [calling]
20471428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077a00000 'C:\Windows\system32\kernel32.dll'
20481428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000624 pwszName=\Device\HarddiskVolume3\Windows\System32\clbcatq.dll
20491428.140c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
20501428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
20511428.140c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B01469787CE9D8C6FEE98FB207652B88B8494526
20521428.140c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume3\Windows\System32\clbcatq.dll'
20531428.140c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
20541428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
20551428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'ole32.dll'.
20561428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
20571428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
20581428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'oleaut32.dll'.
20591428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'rpcrt4.dll'.
20601428.140c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\clbcatq.dll) WinVerifyTrust
20611428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\clbcatq.dll
20621428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
20631428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
20641428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
20651428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume3\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
20661428.140c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\oleaut32.dll
20671428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
20681428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
20691428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
20701428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
20711428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
20721428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
20731428.140c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ole32.dll
20741428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
20751428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
20761428.140c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll
20771428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CLBCatQ.DLL (Input=CLBCatQ.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000448a60:D:\opt\VirtualBox;C:\Windows\system32 [calling]
20781428.140c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\clbcatq.dll
20791428.140c: supR3HardenedDllNotificationCallback: load 000007feff2f0000 LB 0x00099000 C:\Windows\system32\CLBCatQ.DLL [fFlags=0x0]
20801428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\clbcatq.dll
20811428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff2f0000 'C:\Windows\system32\CLBCatQ.DLL'
20821428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdd90000 'C:\Windows\system32\ADVAPI32.dll'
20831428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\cryptsp.dll
20841428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTSP.dll (Input=CRYPTSP.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000002dca160:D:\opt\VirtualBox;C:\Windows\system32 [calling]
20851428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd260000 'C:\Windows\system32\CRYPTSP.dll'
20861428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000064c pwszName=\Device\HarddiskVolume3\Windows\System32\RpcRtRemote.dll
20871428.140c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
20881428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
20891428.140c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=DFC4A7C7E103D324218E6EF5D219B953746D6EC1
20901428.140c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume3\Windows\System32\RpcRtRemote.dll'
20911428.140c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
20921428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'rpcrt4.dll'.
20931428.140c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\RpcRtRemote.dll) WinVerifyTrust
20941428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\RpcRtRemote.dll
20951428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
20961428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
20971428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\RpcRtRemote.dll (Input=RpcRtRemote.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000002dca1d0:D:\opt\VirtualBox;C:\Windows\system32 [calling]
20981428.140c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\RpcRtRemote.dll
20991428.140c: supR3HardenedDllNotificationCallback: load 000007fefd810000 LB 0x00014000 C:\Windows\system32\RpcRtRemote.dll [fFlags=0x0]
21001428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\RpcRtRemote.dll
21011428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd810000 'C:\Windows\system32\RpcRtRemote.dll'
21021428.1ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
21031428.1ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
21041428.1ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'psapi.dll'.
21051428.1ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vboxrt.dll'.
21061428.1ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'advapi32.dll'.
21071428.1ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'version.dll'.
21081428.1ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'ws2_32.dll'.
21091428.1ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'ole32.dll'.
21101428.1ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'oleaut32.dll'.
21111428.1ba8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\opt\VirtualBox\VBoxC.dll) WinVerifyTrust
21121428.1ba8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\opt\VirtualBox\VBoxC.dll
21131428.1ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
21141428.1ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume3\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
21151428.1ba8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\oleaut32.dll
21161428.1ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
21171428.1ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
21181428.1ba8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ole32.dll
21191428.1ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
21201428.1ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
21211428.1ba8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ws2_32.dll
21221428.1ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'version.dll'...
21231428.1ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'version.dll' -> '\Device\HarddiskVolume3\Windows\System32\version.dll' [rcNtRedir=0xc0150008]
21241428.1ba8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000006a0 pwszName=\Device\HarddiskVolume3\Windows\System32\version.dll
21251428.1ba8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
21261428.1ba8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
21271428.1ba8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=A3AB94A028D0330A3DBCAE54C04C648532198DB9
21281428.1ba8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume3\Windows\System32\version.dll'
21291428.1ba8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
21301428.1ba8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
21311428.1ba8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\version.dll) WinVerifyTrust
21321428.1ba8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\version.dll
21331428.1ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
21341428.1ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
21351428.1ba8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\advapi32.dll
21361428.1ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
21371428.1ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
21381428.1ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'psapi.dll'...
21391428.1ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'psapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\psapi.dll' [rcNtRedir=0xc0150008]
21401428.1ba8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000006a4 pwszName=\Device\HarddiskVolume3\Windows\System32\psapi.dll
21411428.1ba8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
21421428.1ba8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
21431428.1ba8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=561BAAB249C395B66D294444DF251EDB701DB607
21441428.1ba8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume3\Windows\System32\psapi.dll'
21451428.1ba8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
21461428.1ba8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\psapi.dll) WinVerifyTrust
21471428.1ba8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\psapi.dll
21481428.1ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
21491428.1ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
21501428.1ba8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\msvcp100.dll
21511428.1ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
21521428.1ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
21531428.1ba8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\msvcr100.dll
21541428.1ba8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
21551428.1ba8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
21561428.1ba8: supR3HardenedMonitor_LdrLoadDll: pName=D:\opt\VirtualBox\VBoxC.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000879260:D:\opt\VirtualBox;D:\opt\VirtualBox;C:\Windows\system32 [calling]
21571428.1ba8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\VBoxC.dll
21581428.1ba8: supR3HardenedDllNotificationCallback: load 000007fee6d60000 LB 0x005d7000 D:\opt\VirtualBox\VBoxC.dll [fFlags=0x0]
21591428.1ba8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\VBoxC.dll
21601428.1ba8: supR3HardenedDllNotificationCallback: load 0000000077ce0000 LB 0x00007000 C:\Windows\system32\PSAPI.DLL [fFlags=0x0]
21611428.1ba8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\psapi.dll
21621428.1ba8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\version.dll
21631428.1ba8: supR3HardenedDllNotificationCallback: load 000007fefc940000 LB 0x0000c000 C:\Windows\system32\VERSION.dll [fFlags=0x0]
21641428.1ba8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\version.dll
21651428.1ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee6d60000 'D:\opt\VirtualBox\VBoxC.dll'
21661428.1ba8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\oleaut32.dll
21671428.1ba8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\oleaut32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000879530:C:\Windows\system32;D:\opt\VirtualBox;C:\Windows\system32 [calling]
21681428.1ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff390000 'C:\Windows\system32\oleaut32.dll'
21691428.1ba8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000694 pwszName=\Device\HarddiskVolume3\Windows\System32\sxs.dll
21701428.1ba8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
21711428.1ba8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
21721428.1ba8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=FCAC019C19F878C2B628662A84ECE75A01818BC9
21731428.1ba8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume3\Windows\System32\sxs.dll'
21741428.1ba8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
21751428.1ba8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\sxs.dll) WinVerifyTrust
21761428.1ba8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\sxs.dll
21771428.1ba8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\SXS.DLL (Input=SXS.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000002dca630:D:\opt\VirtualBox;C:\Windows\system32 [calling]
21781428.1ba8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\sxs.dll
21791428.1ba8: supR3HardenedDllNotificationCallback: load 000007fefd770000 LB 0x00091000 C:\Windows\system32\SXS.DLL [fFlags=0x0]
21801428.1ba8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\sxs.dll
21811428.1ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd770000 'C:\Windows\system32\SXS.DLL'
21821428.1ba8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdd90000 'C:\Windows\system32\ADVAPI32.dll'
21831428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\oleaut32.dll
21841428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\OLEAUT32.dll (Input=OLEAUT32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000002de39e0:D:\opt\VirtualBox;C:\Windows\system32 [calling]
21851428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff390000 'C:\Windows\system32\OLEAUT32.dll'
21861428.140c: supR3HardenedMonitor_LdrLoadDll: error opening 'C:\Windows\system32\wintab32.dll': 0 (NtPath=\??\C:\Windows\system32\wintab32.dll; Input=C:\Windows\system32\wintab32.dll; rcNtGetDll=0x0
21871428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wintab32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000037c6160:D:\opt\VirtualBox;C:\Windows\system32 [calling]
21881428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000135 'C:\Windows\system32\wintab32.dll'
21891428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdc80000 'C:\Windows\system32\gdi32.dll'
21901428.1a10: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
21911428.1a10: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
21921428.1a10: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\opt\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMain.dll) WinVerifyTrust
21931428.1a10: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\opt\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMain.dll
21941428.1a10: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
21951428.1a10: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
21961428.1a10: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
21971428.1a10: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
21981428.1a10: supR3HardenedMonitor_LdrLoadDll: pName=D:\opt\VirtualBox/ExtensionPacks/Oracle_VM_VirtualBox_Extension_Pack/win.amd64/VBoxPuelMain.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000037c5130:D:\opt\VirtualBox;C:\Windows\system32 [calling]
21991428.1a10: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMain.dll
22001428.1a10: supR3HardenedDllNotificationCallback: load 000007fef4150000 LB 0x0000d000 D:\opt\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMain.DLL [fFlags=0x0]
22011428.1a10: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMain.dll
22021428.1a10: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef4150000 'D:\opt\VirtualBox/ExtensionPacks/Oracle_VM_VirtualBox_Extension_Pack/win.amd64/VBoxPuelMain.DLL'
22031428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077900000 'C:\Windows\system32\user32.dll'
22041428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'vboxoglhostcrutil.dll'.
22051428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
22061428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msvcr100.dll'.
22071428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qtcorevbox4.dll'.
22081428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qtguivbox4.dll'.
22091428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'qtopenglvbox4.dll'.
22101428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'opengl32.dll'.
22111428.140c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\opt\VirtualBox\VBoxTestOGL.exe)
22121428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\opt\VirtualBox\VBoxTestOGL.exe
22131428.140c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\opt\VirtualBox\VBoxTestOGL.exe'
22141428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000ac8 pwszName=\Device\HarddiskVolume3\Windows\System32\apphelp.dll
22151428.140c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
22161428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
22171428.140c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=8FFB8CDACDC5C9C6D9256E97FB0710E2753FFAA1
22181428.140c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3045645~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume3\Windows\System32\apphelp.dll'
22191428.140c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
22201428.140c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\apphelp.dll) WinVerifyTrust
22211428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\apphelp.dll
22221428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
22231428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume3\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
22241428.140c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\opengl32.dll
22251428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtopenglvbox4.dll'...
22261428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtopenglvbox4.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\qtopenglvbox4.dll' [rcNtRedir=0xc0150008]
22271428.140c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\QtOpenGLVBox4.dll
22281428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtguivbox4.dll'...
22291428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtguivbox4.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\qtguivbox4.dll' [rcNtRedir=0xc0150008]
22301428.140c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\QtGuiVBox4.dll
22311428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtcorevbox4.dll'...
22321428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtcorevbox4.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\qtcorevbox4.dll' [rcNtRedir=0xc0150008]
22331428.140c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\QtCoreVBox4.dll
22341428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
22351428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
22361428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
22371428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
22381428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxoglhostcrutil.dll'...
22391428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxoglhostcrutil.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\vboxoglhostcrutil.dll' [rcNtRedir=0xc0150008]
22401428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
22411428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
22421428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'shlwapi.dll'.
22431428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ws2_32.dll'.
22441428.140c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\opt\VirtualBox\VBoxOGLhostcrutil.dll) WinVerifyTrust
22451428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\opt\VirtualBox\VBoxOGLhostcrutil.dll
22461428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
22471428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
22481428.140c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ws2_32.dll
22491428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
22501428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
22511428.140c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\shlwapi.dll
22521428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
22531428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
22541428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
22551428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
22561428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\apphelp.dll (rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
22571428.140c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\apphelp.dll
22581428.140c: supR3HardenedDllNotificationCallback: load 000007fefd700000 LB 0x00057000 C:\Windows\system32\apphelp.dll [fFlags=0x0]
22591428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\apphelp.dll
22601428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd700000 'C:\Windows\system32\apphelp.dll'
22611428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\shell32.dll
22621428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000038884c0:D:\opt\VirtualBox;C:\Windows\system32 [calling]
22631428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdec0000 'C:\Windows\system32\shell32.dll'
22641428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ole32.dll
22651428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ole32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000038884c0:D:\opt\VirtualBox;C:\Windows\system32 [calling]
22661428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff9b0000 'C:\Windows\system32\ole32.dll'
22671428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\shell32.dll
22681428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000036f5c80:D:\opt\VirtualBox;C:\Windows\system32 [calling]
22691428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdec0000 'C:\Windows\system32\shell32.dll'
22701428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ole32.dll
22711428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ole32.dll (Input=ole32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000389d1f0:D:\opt\VirtualBox;C:\Windows\system32 [calling]
22721428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff9b0000 'C:\Windows\system32\ole32.dll'
22731428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\oleaut32.dll
22741428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\OLEAUT32.dll (Input=OLEAUT32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000389d1f0:D:\opt\VirtualBox;C:\Windows\system32 [calling]
22751428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff390000 'C:\Windows\system32\OLEAUT32.dll'
22761428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000b0c pwszName=\Device\HarddiskVolume3\Windows\System32\wbem\wbemprox.dll
22771428.140c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
22781428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
22791428.140c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=41D7AA7A9ECA84ABF6801478BA3134174B21C472
22801428.140c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume3\Windows\System32\wbem\wbemprox.dll'
22811428.140c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
22821428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
22831428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'wbemcomn.dll'.
22841428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
22851428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'oleaut32.dll'.
22861428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'ole32.dll'.
22871428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'ws2_32.dll'.
22881428.140c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\wbem\wbemprox.dll) WinVerifyTrust
22891428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\wbem\wbemprox.dll
22901428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
22911428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
22921428.140c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ws2_32.dll
22931428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
22941428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
22951428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
22961428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume3\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
22971428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
22981428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
22991428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wbemcomn.dll'...
23001428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'wbemcomn.dll' -> '\Device\HarddiskVolume3\Windows\System32\wbemcomn.dll' [rcNtRedir=0xc0150008]
23011428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000b24 pwszName=\Device\HarddiskVolume3\Windows\System32\wbemcomn.dll
23021428.140c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
23031428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
23041428.140c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=03D0A77E5195AA70198FDE6C2FAC2C76FF200674
23051428.140c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume3\Windows\System32\wbemcomn.dll'
23061428.140c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
23071428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
23081428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'oleaut32.dll'.
23091428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'ole32.dll'.
23101428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
23111428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'ws2_32.dll'.
23121428.140c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\wbemcomn.dll) WinVerifyTrust
23131428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\wbemcomn.dll
23141428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
23151428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
23161428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
23171428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
23181428.140c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ws2_32.dll
23191428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
23201428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
23211428.140c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\user32.dll
23221428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
23231428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
23241428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
23251428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume3\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
23261428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
23271428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
23281428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wbem\wbemprox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000037ec4c0:C:\Windows\system32\wbem;D:\opt\VirtualBox;C:\Windows\system32 [calling]
23291428.140c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wbem\wbemprox.dll
23301428.140c: supR3HardenedDllNotificationCallback: load 000007fef4c10000 LB 0x0000f000 C:\Windows\system32\wbem\wbemprox.dll [fFlags=0x0]
23311428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wbem\wbemprox.dll
23321428.140c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wbemcomn.dll
23331428.140c: supR3HardenedDllNotificationCallback: load 000007fef4e50000 LB 0x00086000 C:\Windows\system32\wbemcomn.dll [fFlags=0x0]
23341428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wbemcomn.dll
23351428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef4c10000 'C:\Windows\system32\wbem\wbemprox.dll'
23361428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000b4c pwszName=\Device\HarddiskVolume3\Windows\System32\wbem\wbemsvc.dll
23371428.140c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
23381428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
23391428.140c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=83AB88529BF28CFF670EA617E0B9C376CFE28B0F
23401428.140c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume3\Windows\System32\wbem\wbemsvc.dll'
23411428.140c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
23421428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
23431428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'rpcrt4.dll'.
23441428.140c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\wbem\wbemsvc.dll) WinVerifyTrust
23451428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\wbem\wbemsvc.dll
23461428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
23471428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
23481428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
23491428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
23501428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wbem\wbemsvc.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000037ec380:C:\Windows\system32\wbem;D:\opt\VirtualBox;C:\Windows\system32 [calling]
23511428.140c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wbem\wbemsvc.dll
23521428.140c: supR3HardenedDllNotificationCallback: load 000007fef4870000 LB 0x00014000 C:\Windows\system32\wbem\wbemsvc.dll [fFlags=0x0]
23531428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wbem\wbemsvc.dll
23541428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef4870000 'C:\Windows\system32\wbem\wbemsvc.dll'
23551428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000b58 pwszName=\Device\HarddiskVolume3\Windows\System32\wbem\fastprox.dll
23561428.140c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
23571428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
23581428.140c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=391AD7580DBA8EA6A4190F5A010E834B8C320D79
23591428.140c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume3\Windows\System32\wbem\fastprox.dll'
23601428.140c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
23611428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
23621428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'wbemcomn.dll'.
23631428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'advapi32.dll'.
23641428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'oleaut32.dll'.
23651428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ole32.dll'.
23661428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ntdsapi.dll'.
23671428.140c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\wbem\fastprox.dll) WinVerifyTrust
23681428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\wbem\fastprox.dll
23691428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntdsapi.dll'...
23701428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntdsapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\ntdsapi.dll' [rcNtRedir=0xc0150008]
23711428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000b40 pwszName=\Device\HarddiskVolume3\Windows\System32\ntdsapi.dll
23721428.140c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
23731428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
23741428.140c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=67C74E045820FCAB3FC8AD5C180928A20C1F11CE
23751428.140c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume3\Windows\System32\ntdsapi.dll'
23761428.140c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
23771428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
23781428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'rpcrt4.dll'.
23791428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'ws2_32.dll'.
23801428.140c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\ntdsapi.dll) WinVerifyTrust
23811428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\ntdsapi.dll
23821428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
23831428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
23841428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
23851428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume3\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
23861428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
23871428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
23881428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wbemcomn.dll'...
23891428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'wbemcomn.dll' -> '\Device\HarddiskVolume3\Windows\System32\wbemcomn.dll' [rcNtRedir=0xc0150008]
23901428.140c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wbemcomn.dll
23911428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
23921428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
23931428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
23941428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
23951428.140c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ws2_32.dll
23961428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
23971428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
23981428.140c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll
23991428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
24001428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
24011428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wbem\fastprox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000037ec420:C:\Windows\system32\wbem;D:\opt\VirtualBox;C:\Windows\system32 [calling]
24021428.140c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wbem\fastprox.dll
24031428.140c: supR3HardenedDllNotificationCallback: load 000007fef4c50000 LB 0x000e2000 C:\Windows\system32\wbem\fastprox.dll [fFlags=0x0]
24041428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wbem\fastprox.dll
24051428.140c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ntdsapi.dll
24061428.140c: supR3HardenedDllNotificationCallback: load 000007fef4c20000 LB 0x00027000 C:\Windows\system32\NTDSAPI.dll [fFlags=0x0]
24071428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ntdsapi.dll
24081428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef4c50000 'C:\Windows\system32\wbem\fastprox.dll'
24091428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff390000 'C:\Windows\system32\OLEAUT32.dll'
24101428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msctf.dll
24111428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\MSCTF.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000037b3de0:C:\Windows\system32;D:\opt\VirtualBox;C:\Windows\system32 [calling]
24121428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefec50000 'C:\Windows\system32\MSCTF.dll'
24131428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff390000 'C:\Windows\system32\OLEAUT32.DLL'
24141428.16b8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
24151428.16b8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrem.dll'.
24161428.16b8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
24171428.16b8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\opt\VirtualBox\VBoxVMM.dll) WinVerifyTrust
24181428.16b8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\opt\VirtualBox\VBoxVMM.dll
24191428.16b8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
24201428.16b8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
24211428.16b8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrem.dll'...
24221428.16b8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrem.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\vboxrem.dll' [rcNtRedir=0xc0150008]
24231428.16b8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'vboxrt.dll'.
24241428.16b8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
24251428.16b8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcrt.dll'.
24261428.16b8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\opt\VirtualBox\VBoxREM.dll) WinVerifyTrust
24271428.16b8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\opt\VirtualBox\VBoxREM.dll
24281428.16b8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
24291428.16b8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
24301428.16b8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
24311428.16b8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
24321428.16b8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
24331428.16b8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
24341428.16b8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\VBoxVMM.dll
24351428.16b8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
24361428.16b8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
24371428.16b8: supR3HardenedMonitor_LdrLoadDll: pName=D:\opt\VirtualBox\VBoxVMM.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000389e6a0:D:\opt\VirtualBox;C:\Windows\system32 [calling]
24381428.16b8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\VBoxVMM.dll
24391428.16b8: supR3HardenedDllNotificationCallback: load 000007fee8620000 LB 0x0029c000 D:\opt\VirtualBox\VBoxVMM.DLL [fFlags=0x0]
24401428.16b8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\VBoxVMM.dll
24411428.16b8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\VBoxREM.dll
24421428.16b8: supR3HardenedDllNotificationCallback: load 000000005d7d0000 LB 0x0010a000 D:\opt\VirtualBox\VBoxREM.dll [fFlags=0x0]
24431428.16b8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\VBoxREM.dll
24441428.16b8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee8620000 'D:\opt\VirtualBox\VBoxVMM.DLL'
24451428.1a7c: \Device\HarddiskVolume3\Windows\System32\drivers\VBoxNetAdp6.sys: Owner is administrators group.
24461428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ndis.sys'.
24471428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'ntoskrnl.exe'.
24481428.1a7c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\drivers\VBoxNetAdp6.sys)
24491428.1a7c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\drivers\VBoxNetAdp6.sys
24501428.1a7c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\drivers\VBoxNetAdp6.sys [avoiding WinVerifyTrust]
24511428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
24521428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'ndis.sys'.
24531428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'netio.sys'.
24541428.1a7c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\drivers\VBoxNetLwf.sys)
24551428.1a7c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\drivers\VBoxNetLwf.sys
24561428.1a7c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\drivers\VBoxNetLwf.sys [avoiding WinVerifyTrust]
24571428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
24581428.1a7c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\drivers\VBoxUSBMon.sys)
24591428.1a7c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\drivers\VBoxUSBMon.sys
24601428.1a7c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\drivers\VBoxUSBMon.sys [avoiding WinVerifyTrust]
24611428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
24621428.1a7c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\drivers\VBoxDrv.sys)
24631428.1a7c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\drivers\VBoxDrv.sys
24641428.1a7c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\drivers\VBoxDrv.sys [avoiding WinVerifyTrust]
24651428.16cc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\drivers\VBoxDrv.sys'
24661428.16cc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\drivers\VBoxUSBMon.sys'
24671428.16cc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\drivers\VBoxNetLwf.sys'
24681428.16cc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\drivers\VBoxNetAdp6.sys'
24691428.16cc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
24701428.16cc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
24711428.16cc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
24721428.16cc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
24731428.16cc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\opt\VirtualBox\VBoxSharedClipboard.dll) WinVerifyTrust
24741428.16cc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\opt\VirtualBox\VBoxSharedClipboard.dll
24751428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
24761428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
24771428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
24781428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
24791428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
24801428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
24811428.16cc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\VBoxVMM.dll
24821428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
24831428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
24841428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
24851428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume3\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
24861428.16cc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'pshed.dll'.
24871428.16cc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'hal.dll'.
24881428.16cc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'kdcom.dll'.
24891428.16cc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'clfs.sys'.
24901428.16cc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ci.dll'.
24911428.16cc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\ntoskrnl.exe) WinVerifyTrust
24921428.16cc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\ntoskrnl.exe
24931428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
24941428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume3\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
24951428.16cc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ntoskrnl.exe
24961428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'netio.sys'...
24971428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: 'netio.sys' -> '\Device\HarddiskVolume3\Windows\System32\drivers\netio.sys' [rcNtRedir=0xc0150008]
24981428.16cc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
24991428.16cc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'ndis.sys'.
25001428.16cc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msrpc.sys'.
25011428.16cc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\drivers\netio.sys) WinVerifyTrust
25021428.16cc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\drivers\netio.sys
25031428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ndis.sys'...
25041428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: 'ndis.sys' -> '\Device\HarddiskVolume3\Windows\System32\drivers\ndis.sys' [rcNtRedir=0xc0150008]
25051428.16cc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
25061428.16cc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'hal.dll'.
25071428.16cc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'netio.sys'.
25081428.16cc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\drivers\ndis.sys) WinVerifyTrust
25091428.16cc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\drivers\ndis.sys
25101428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
25111428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume3\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
25121428.16cc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ntoskrnl.exe
25131428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
25141428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume3\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
25151428.16cc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ntoskrnl.exe
25161428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ndis.sys'...
25171428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: 'ndis.sys' -> '\Device\HarddiskVolume3\Windows\System32\drivers\ndis.sys' [rcNtRedir=0xc0150008]
25181428.16cc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\drivers\ndis.sys
25191428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'netio.sys'...
25201428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: 'netio.sys' -> '\Device\HarddiskVolume3\Windows\System32\drivers\netio.sys' [rcNtRedir=0xc0150008]
25211428.16cc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\drivers\netio.sys
25221428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'hal.dll'...
25231428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: 'hal.dll' -> '\Device\HarddiskVolume3\Windows\System32\hal.dll' [rcNtRedir=0xc0150008]
25241428.16cc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
25251428.16cc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'kdcom.dll'.
25261428.16cc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'pshed.dll'.
25271428.16cc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\hal.dll) WinVerifyTrust
25281428.16cc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\hal.dll
25291428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
25301428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume3\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
25311428.16cc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ntoskrnl.exe
25321428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msrpc.sys'...
25331428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msrpc.sys' -> '\Device\HarddiskVolume3\Windows\System32\drivers\msrpc.sys' [rcNtRedir=0xc0150008]
25341428.16cc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
25351428.16cc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\drivers\msrpc.sys) WinVerifyTrust
25361428.16cc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\drivers\msrpc.sys
25371428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ndis.sys'...
25381428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: 'ndis.sys' -> '\Device\HarddiskVolume3\Windows\System32\drivers\ndis.sys' [rcNtRedir=0xc0150008]
25391428.16cc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\drivers\ndis.sys
25401428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
25411428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume3\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
25421428.16cc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ntoskrnl.exe
25431428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ci.dll'...
25441428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: 'ci.dll' -> '\Device\HarddiskVolume3\Windows\System32\ci.dll' [rcNtRedir=0xc0150008]
25451428.16cc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
25461428.16cc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\ci.dll) WinVerifyTrust
25471428.16cc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\ci.dll
25481428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'clfs.sys'...
25491428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: 'clfs.sys' -> '\Device\HarddiskVolume3\Windows\System32\clfs.sys' [rcNtRedir=0xc0150008]
25501428.16cc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
25511428.16cc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\clfs.sys) WinVerifyTrust
25521428.16cc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\clfs.sys
25531428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'kdcom.dll'...
25541428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: 'kdcom.dll' -> '\Device\HarddiskVolume3\Windows\System32\kdcom.dll' [rcNtRedir=0xc0150008]
25551428.16cc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
25561428.16cc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'hal.dll'.
25571428.16cc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\kdcom.dll) WinVerifyTrust
25581428.16cc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\kdcom.dll
25591428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'hal.dll'...
25601428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: 'hal.dll' -> '\Device\HarddiskVolume3\Windows\System32\hal.dll' [rcNtRedir=0xc0150008]
25611428.16cc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\hal.dll
25621428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'pshed.dll'...
25631428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: 'pshed.dll' -> '\Device\HarddiskVolume3\Windows\System32\pshed.dll' [rcNtRedir=0xc0150008]
25641428.16cc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ntoskrnl.exe'.
25651428.16cc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'hal.dll'.
25661428.16cc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\PSHED.DLL) WinVerifyTrust
25671428.16cc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\PSHED.DLL
25681428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'hal.dll'...
25691428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: 'hal.dll' -> '\Device\HarddiskVolume3\Windows\System32\hal.dll' [rcNtRedir=0xc0150008]
25701428.16cc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\hal.dll
25711428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
25721428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume3\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
25731428.16cc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ntoskrnl.exe
25741428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'hal.dll'...
25751428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: 'hal.dll' -> '\Device\HarddiskVolume3\Windows\System32\hal.dll' [rcNtRedir=0xc0150008]
25761428.16cc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\hal.dll
25771428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
25781428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume3\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
25791428.16cc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ntoskrnl.exe
25801428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
25811428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume3\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
25821428.16cc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ntoskrnl.exe
25831428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
25841428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume3\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
25851428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
25861428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume3\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
25871428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'pshed.dll'...
25881428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: 'pshed.dll' -> '\Device\HarddiskVolume3\Windows\System32\pshed.dll' [rcNtRedir=0xc0150008]
25891428.16cc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\PSHED.DLL
25901428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'kdcom.dll'...
25911428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: 'kdcom.dll' -> '\Device\HarddiskVolume3\Windows\System32\kdcom.dll' [rcNtRedir=0xc0150008]
25921428.16cc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\kdcom.dll
25931428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntoskrnl.exe'...
25941428.16cc: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntoskrnl.exe' -> '\Device\HarddiskVolume3\Windows\System32\ntoskrnl.exe' [rcNtRedir=0xc0150008]
25951428.16cc: supR3HardenedMonitor_LdrLoadDll: pName=D:\opt\VirtualBox\VBoxSharedClipboard.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000389e6a0:D:\opt\VirtualBox;C:\Windows\system32 [calling]
25961428.16cc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\VBoxSharedClipboard.dll
25971428.16cc: supR3HardenedDllNotificationCallback: load 000007fef3720000 LB 0x0000a000 D:\opt\VirtualBox\VBoxSharedClipboard.DLL [fFlags=0x0]
25981428.16cc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\VBoxSharedClipboard.dll
25991428.16cc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef3720000 'D:\opt\VirtualBox\VBoxSharedClipboard.DLL'
26001428.1898: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
26011428.1898: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
26021428.1898: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
26031428.1898: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\opt\VirtualBox\VBoxDragAndDropSvc.dll) WinVerifyTrust
26041428.1898: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\opt\VirtualBox\VBoxDragAndDropSvc.dll
26051428.1898: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
26061428.1898: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
26071428.1898: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
26081428.1898: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
26091428.1898: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\msvcp100.dll
26101428.1898: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
26111428.1898: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
26121428.1898: supR3HardenedMonitor_LdrLoadDll: pName=D:\opt\VirtualBox\VBoxDragAndDropSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000389e6a0:D:\opt\VirtualBox;C:\Windows\system32 [calling]
26131428.1898: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\VBoxDragAndDropSvc.dll
26141428.1898: supR3HardenedDllNotificationCallback: load 000007fef3710000 LB 0x0000d000 D:\opt\VirtualBox\VBoxDragAndDropSvc.DLL [fFlags=0x0]
26151428.1898: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\VBoxDragAndDropSvc.dll
26161428.1898: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef3710000 'D:\opt\VirtualBox\VBoxDragAndDropSvc.DLL'
26171428.1a7c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\VBoxTestOGL.exe
26181428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winmm.dll
26191428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\WINMM.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000389d340:D:\opt\VirtualBox;C:\Windows\system32 [calling]
26201428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa8a0000 'C:\Windows\system32\WINMM.dll'
26211428.12e0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
26221428.12e0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxoglhostcrutil.dll'.
26231428.12e0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
26241428.12e0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vboxvmm.dll'.
26251428.12e0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'vboxoglrenderspu.dll'.
26261428.12e0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'advapi32.dll'.
26271428.12e0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'ole32.dll'.
26281428.12e0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'oleaut32.dll'.
26291428.12e0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\opt\VirtualBox\VBoxSharedCrOpenGL.dll) WinVerifyTrust
26301428.12e0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\opt\VirtualBox\VBoxSharedCrOpenGL.dll
26311428.12e0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
26321428.12e0: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume3\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
26331428.12e0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
26341428.12e0: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
26351428.12e0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
26361428.12e0: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
26371428.12e0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxoglrenderspu.dll'...
26381428.12e0: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxoglrenderspu.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\vboxoglrenderspu.dll' [rcNtRedir=0xc0150008]
26391428.12e0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
26401428.12e0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxoglhostcrutil.dll'.
26411428.12e0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
26421428.12e0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
26431428.12e0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
26441428.12e0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'advapi32.dll'.
26451428.12e0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\opt\VirtualBox\VBoxOGLrenderspu.dll) WinVerifyTrust
26461428.12e0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\opt\VirtualBox\VBoxOGLrenderspu.dll
26471428.12e0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
26481428.12e0: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
26491428.12e0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\VBoxVMM.dll
26501428.12e0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
26511428.12e0: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
26521428.12e0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxoglhostcrutil.dll'...
26531428.12e0: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxoglhostcrutil.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\vboxoglhostcrutil.dll' [rcNtRedir=0xc0150008]
26541428.12e0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\VBoxOGLhostcrutil.dll
26551428.12e0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
26561428.12e0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
26571428.12e0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
26581428.12e0: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
26591428.12e0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
26601428.12e0: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
26611428.12e0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
26621428.12e0: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
26631428.12e0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
26641428.12e0: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
26651428.12e0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxoglhostcrutil.dll'...
26661428.12e0: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxoglhostcrutil.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\vboxoglhostcrutil.dll' [rcNtRedir=0xc0150008]
26671428.12e0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\VBoxOGLhostcrutil.dll
26681428.12e0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
26691428.12e0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
26701428.12e0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\msvcr100.dll
26711428.12e0: supR3HardenedMonitor_LdrLoadDll: pName=D:\opt\VirtualBox\VBoxSharedCrOpenGL.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000389e6a0:D:\opt\VirtualBox;C:\Windows\system32 [calling]
26721428.12e0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\VBoxSharedCrOpenGL.dll
26731428.12e0: supR3HardenedDllNotificationCallback: load 000007fee8bf0000 LB 0x0012c000 D:\opt\VirtualBox\VBoxSharedCrOpenGL.DLL [fFlags=0x0]
26741428.12e0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\VBoxSharedCrOpenGL.dll
26751428.12e0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\VBoxOGLhostcrutil.dll
26761428.12e0: supR3HardenedDllNotificationCallback: load 000007feeb0c0000 LB 0x00034000 D:\opt\VirtualBox\VBoxOGLhostcrutil.dll [fFlags=0x0]
26771428.12e0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\VBoxOGLhostcrutil.dll
26781428.12e0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\VBoxOGLrenderspu.dll
26791428.12e0: supR3HardenedDllNotificationCallback: load 000007fef1420000 LB 0x00028000 D:\opt\VirtualBox\VBoxOGLrenderspu.dll [fFlags=0x0]
26801428.12e0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\VBoxOGLrenderspu.dll
26811428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee8bf0000 'D:\opt\VirtualBox\VBoxSharedCrOpenGL.DLL'
26821428.12e0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\VBoxOGLrenderspu.dll
26831428.12e0: supR3HardenedMonitor_LdrLoadDll: pName=D:\opt\VirtualBox\VBoxOGLrenderspu.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000389e6a0:D:\opt\VirtualBox;C:\Windows\system32 [calling]
26841428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef1420000 'D:\opt\VirtualBox\VBoxOGLrenderspu.dll'
26851428.12e0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
26861428.12e0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxoglhostcrutil.dll'.
26871428.12e0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\opt\VirtualBox\VBoxOGLhosterrorspu.dll) WinVerifyTrust
26881428.12e0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\opt\VirtualBox\VBoxOGLhosterrorspu.dll
26891428.12e0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxoglhostcrutil.dll'...
26901428.12e0: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxoglhostcrutil.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\vboxoglhostcrutil.dll' [rcNtRedir=0xc0150008]
26911428.12e0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\VBoxOGLhostcrutil.dll
26921428.12e0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
26931428.12e0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
26941428.12e0: supR3HardenedMonitor_LdrLoadDll: pName=D:\opt\VirtualBox\VBoxOGLhosterrorspu.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000389e6a0:D:\opt\VirtualBox;C:\Windows\system32 [calling]
26951428.12e0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\VBoxOGLhosterrorspu.dll
26961428.12e0: supR3HardenedDllNotificationCallback: load 000007feeb0a0000 LB 0x0001a000 D:\opt\VirtualBox\VBoxOGLhosterrorspu.dll [fFlags=0x0]
26971428.12e0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\VBoxOGLhosterrorspu.dll
26981428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeb0a0000 'D:\opt\VirtualBox\VBoxOGLhosterrorspu.dll'
26991428.12e0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\opengl32.dll
27001428.12e0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32/opengl32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000037b2150:D:\opt\VirtualBox;C:\Windows\system32 [calling]
27011428.12e0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\opengl32.dll
27021428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32/opengl32.dll'
27031428.12e0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\opengl32.dll
27041428.12e0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\OPENGL32.dll (Input=OPENGL32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000037b2150:D:\opt\VirtualBox;C:\Windows\system32 [calling]
27051428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
27061428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdc80000 'C:\Windows\system32\gdi32.dll'
27071428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdc80000 'C:\Windows\system32\gdi32.dll'
27081428.12e0: \Device\HarddiskVolume3\Windows\System32\nvoglv64.dll: Owner is administrators group.
27091428.12e0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
27101428.12e0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
27111428.12e0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'shell32.dll'.
27121428.12e0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
27131428.12e0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'setupapi.dll'.
27141428.12e0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'wtsapi32.dll'.
27151428.12e0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'version.dll'.
27161428.12e0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\nvoglv64.dll) WinVerifyTrust
27171428.12e0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\nvoglv64.dll
27181428.12e0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'version.dll'...
27191428.12e0: supR3HardenedWinVerifyCacheProcessImportTodos: 'version.dll' -> '\Device\HarddiskVolume3\Windows\System32\version.dll' [rcNtRedir=0xc0150008]
27201428.12e0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\version.dll
27211428.12e0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wtsapi32.dll'...
27221428.12e0: supR3HardenedWinVerifyCacheProcessImportTodos: 'wtsapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\wtsapi32.dll' [rcNtRedir=0xc0150008]
27231428.12e0: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000d4c pwszName=\Device\HarddiskVolume3\Windows\System32\wtsapi32.dll
27241428.12e0: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
27251428.12e0: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
27261428.12e0: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=E653B4F2F82EC27E9205DC90EBEB7A5AAB37A8B0
27271428.12e0: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume3\Windows\System32\wtsapi32.dll'
27281428.12e0: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
27291428.12e0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
27301428.12e0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\wtsapi32.dll) WinVerifyTrust
27311428.12e0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\wtsapi32.dll
27321428.12e0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
27331428.12e0: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
27341428.12e0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\setupapi.dll
27351428.12e0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
27361428.12e0: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
27371428.12e0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
27381428.12e0: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume3\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
27391428.12e0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\shell32.dll
27401428.12e0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
27411428.12e0: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
27421428.12e0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
27431428.12e0: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
27441428.12e0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
27451428.12e0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
27461428.12e0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\nvoglv64.dll (Input=nvoglv64, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000037b2150:D:\opt\VirtualBox;C:\Windows\system32 [calling]
27471428.12e0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\nvoglv64.dll
27481428.12e0: supR3HardenedDllNotificationCallback: load 0000000068b70000 LB 0x01d42000 C:\Windows\system32\nvoglv64.dll [fFlags=0x0]
27491428.12e0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\nvoglv64.dll
27501428.12e0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wtsapi32.dll
27511428.12e0: supR3HardenedDllNotificationCallback: load 000007fefcac0000 LB 0x00011000 C:\Windows\system32\WTSAPI32.dll [fFlags=0x0]
27521428.12e0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wtsapi32.dll
27531428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdc80000 'C:\Windows\system32\gdi32.dll'
27541428.12e0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wintrust.dll
27551428.12e0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\WINTRUST.dll (Input=WINTRUST.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000037b21c0:D:\opt\VirtualBox;C:\Windows\system32 [calling]
27561428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd9b0000 'C:\Windows\system32\WINTRUST.dll'
27571428.12e0: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume3\Windows\System32\ntmarta.dll'.
27581428.12e0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
27591428.12e0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'advapi32.dll'.
27601428.12e0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'wldap32.dll'.
27611428.12e0: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\ntmarta.dll)
27621428.12e0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\ntmarta.dll
27631428.12e0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wldap32.dll'...
27641428.12e0: supR3HardenedWinVerifyCacheProcessImportTodos: 'wldap32.dll' -> '\Device\HarddiskVolume3\Windows\System32\wldap32.dll' [rcNtRedir=0xc0150008]
27651428.12e0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\Wldap32.dll
27661428.12e0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
27671428.12e0: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
27681428.12e0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
27691428.12e0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
27701428.12e0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ntmarta.dll (Input=ntmarta.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000037b21c0:D:\opt\VirtualBox;C:\Windows\system32 [calling]
27711428.12e0: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\ntmarta.dll [avoiding WinVerifyTrust]
27721428.12e0: supR3HardenedDllNotificationCallback: load 000007fefc680000 LB 0x0002d000 C:\Windows\system32\ntmarta.dll [fFlags=0x0]
27731428.12e0: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\ntmarta.dll [avoiding WinVerifyTrust]
27741428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc680000 'C:\Windows\system32\ntmarta.dll'
27751428.12e0: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume3\Windows\System32\ntmarta.dll'.
27761428.12e0: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\ntmarta.dll' [rescheduled]
27771428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000068b70000 'C:\Windows\system32\nvoglv64.dll'
27781428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdc80000 'C:\Windows\system32\gdi32.dll'
27791428.12b8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000dac pwszName=\Device\HarddiskVolume3\Windows\System32\powrprof.dll
27801428.12b8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
27811428.12b8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
27821428.12b8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=E0B7DE18787DB24DAD3580634869A9A8FF4AB48F
27831428.12b8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume3\Windows\System32\powrprof.dll'
27841428.12b8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
27851428.12b8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
27861428.12b8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'rpcrt4.dll'.
27871428.12b8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'setupapi.dll'.
27881428.12b8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\powrprof.dll) WinVerifyTrust
27891428.12b8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\powrprof.dll
27901428.12b8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
27911428.12b8: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
27921428.12b8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\setupapi.dll
27931428.12b8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
27941428.12b8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
27951428.12b8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
27961428.12b8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
27971428.12b8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\POWRPROF.DLL (Input=POWRPROF.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000037b2150:D:\opt\VirtualBox;C:\Windows\system32 [calling]
27981428.12b8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\powrprof.dll
27991428.12b8: supR3HardenedDllNotificationCallback: load 000007fefc4b0000 LB 0x0002c000 C:\Windows\system32\POWRPROF.DLL [fFlags=0x0]
28001428.12b8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\powrprof.dll
28011428.12b8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc4b0000 'C:\Windows\system32\POWRPROF.DLL'
28021428.12b8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077900000 'C:\Windows\system32\USER32.dll'
28031428.12b8: supR3HardenedDllNotificationCallback: Unload 000007fefc4b0000 LB 0x0002c000 C:\Windows\system32\POWRPROF.DLL [flags=0x0]
28041428.12b8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077900000 'C:\Windows\system32\USER32.dll'
28051428.12b8: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000db0 pwszName=\Device\HarddiskVolume3\Windows\System32\winsta.dll
28061428.12b8: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
28071428.12b8: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
28081428.12b8: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=1784FF9CB91ACF5CDF00DE84F778DD4A67C759FA
28091428.12b8: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_51_for_KB2984972~31bf3856ad364e35~amd64~~6.1.1.4.cat'; file='\Device\HarddiskVolume3\Windows\System32\winsta.dll'
28101428.12b8: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
28111428.12b8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
28121428.12b8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\winsta.dll) WinVerifyTrust
28131428.12b8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\winsta.dll
28141428.12b8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
28151428.12b8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
28161428.12b8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\WINSTA.dll (Input=WINSTA.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000037b2150:D:\opt\VirtualBox;C:\Windows\system32 [calling]
28171428.12b8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winsta.dll
28181428.12b8: supR3HardenedDllNotificationCallback: load 000007fefcbc0000 LB 0x0003d000 C:\Windows\system32\WINSTA.dll [fFlags=0x0]
28191428.12b8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winsta.dll
28201428.12b8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcbc0000 'C:\Windows\system32\WINSTA.dll'
28211428.12b8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdd90000 'C:\Windows\system32\ADVAPI32.dll'
28221428.12b8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff7e0000 'C:\Windows\system32\RPCRT4.dll'
28231428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\opengl32.dll'
28241428.12e0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\dwmapi.dll
28251428.12e0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\dwmapi.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000037ba3a0:D:\opt\VirtualBox;C:\Windows\system32 [calling]
28261428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefabd0000 'C:\Windows\system32\dwmapi.dll'
28271428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
28281428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
28291428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
28301428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
28311428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
28321428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
28331428.12e0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\opengl32.dll
28341428.12e0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\OPENGL32.dll (Input=OPENGL32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000037ba720:D:\opt\VirtualBox;C:\Windows\system32 [calling]
28351428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
28361428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
28371428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
28381428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
28391428.142c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
28401428.142c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
28411428.14f0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
28421428.14f0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
28431428.14f0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
28441428.14f0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\opt\VirtualBox\VBoxGuestPropSvc.dll) WinVerifyTrust
28451428.14f0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\opt\VirtualBox\VBoxGuestPropSvc.dll
28461428.14f0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
28471428.14f0: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
28481428.14f0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
28491428.14f0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
28501428.14f0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\msvcp100.dll
28511428.14f0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
28521428.14f0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
28531428.14f0: supR3HardenedMonitor_LdrLoadDll: pName=D:\opt\VirtualBox\VBoxGuestPropSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000389f040:D:\opt\VirtualBox;C:\Windows\system32 [calling]
28541428.14f0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\VBoxGuestPropSvc.dll
28551428.14f0: supR3HardenedDllNotificationCallback: load 000007fef3700000 LB 0x0000f000 D:\opt\VirtualBox\VBoxGuestPropSvc.DLL [fFlags=0x0]
28561428.14f0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\VBoxGuestPropSvc.dll
28571428.14f0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef3700000 'D:\opt\VirtualBox\VBoxGuestPropSvc.DLL'
28581428.1bf4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
28591428.1bf4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
28601428.1bf4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
28611428.1bf4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\opt\VirtualBox\VBoxGuestControlSvc.dll) WinVerifyTrust
28621428.1bf4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\opt\VirtualBox\VBoxGuestControlSvc.dll
28631428.1bf4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
28641428.1bf4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
28651428.1bf4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
28661428.1bf4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
28671428.1bf4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
28681428.1bf4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
28691428.1bf4: supR3HardenedMonitor_LdrLoadDll: pName=D:\opt\VirtualBox\VBoxGuestControlSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000389f040:D:\opt\VirtualBox;C:\Windows\system32 [calling]
28701428.1bf4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\VBoxGuestControlSvc.dll
28711428.1bf4: supR3HardenedDllNotificationCallback: load 000007fef1410000 LB 0x0000e000 D:\opt\VirtualBox\VBoxGuestControlSvc.DLL [fFlags=0x0]
28721428.1bf4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\VBoxGuestControlSvc.dll
28731428.1bf4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef1410000 'D:\opt\VirtualBox\VBoxGuestControlSvc.DLL'
28741428.1a7c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\shell32.dll
28751428.1a7c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32/Shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000037b22a0:D:\opt\VirtualBox;C:\Windows\system32 [calling]
28761428.1a7c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdec0000 'C:\Windows\system32/Shell32.dll'
28771428.1a7c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff9b0000 'C:\Windows\system32\ole32.dll'
28781428.1a7c: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000037b22a0:D:\opt\VirtualBox;C:\Windows\system32 [calling]
28791428.1a7c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdcf0000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
28801428.1a7c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\profapi.dll
28811428.1a7c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\profapi.dll (Input=profapi.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000037b22a0:D:\opt\VirtualBox;C:\Windows\system32 [calling]
28821428.1a7c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd8c0000 'C:\Windows\system32\profapi.dll'
28831428.1a7c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\VBoxVMM.dll
28841428.1a7c: supR3HardenedMonitor_LdrLoadDll: pName=D:\opt\VirtualBox\VBoxVMM.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000037b2150:D:\opt\VirtualBox;C:\Windows\system32 [calling]
28851428.1a7c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee8620000 'D:\opt\VirtualBox\VBoxVMM.DLL'
28861428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
28871428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
28881428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
28891428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ole32.dll'.
28901428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'oleaut32.dll'.
28911428.1a7c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\opt\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll) WinVerifyTrust
28921428.1a7c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\opt\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
28931428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
28941428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume3\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
28951428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
28961428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
28971428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
28981428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
28991428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
29001428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
29011428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
29021428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
29031428.1a7c: supR3HardenedMonitor_LdrLoadDll: pName=D:\opt\VirtualBox/ExtensionPacks/Oracle_VM_VirtualBox_Extension_Pack/win.amd64/VBoxHostWebcam.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000037b2150:D:\opt\VirtualBox;C:\Windows\system32 [calling]
29041428.1a7c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
29051428.1a7c: supR3HardenedDllNotificationCallback: load 000007feeb060000 LB 0x00033000 D:\opt\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL [fFlags=0x0]
29061428.1a7c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
29071428.1a7c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeb060000 'D:\opt\VirtualBox/ExtensionPacks/Oracle_VM_VirtualBox_Extension_Pack/win.amd64/VBoxHostWebcam.DLL'
29081428.1a7c: supR3HardenedDllNotificationCallback: Unload 000007feeb060000 LB 0x00033000 D:\opt\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL [flags=0x0]
29091428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
29101428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
29111428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
29121428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vboxddu.dll'.
29131428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'vboxdd2.dll'.
29141428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
29151428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'setupapi.dll'.
29161428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'ws2_32.dll'.
29171428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'ole32.dll'.
29181428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'iphlpapi.dll'.
29191428.1a7c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\opt\VirtualBox\VBoxDD.dll) WinVerifyTrust
29201428.1a7c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\opt\VirtualBox\VBoxDD.dll
29211428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'iphlpapi.dll'...
29221428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'iphlpapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\iphlpapi.dll' [rcNtRedir=0xc0150008]
29231428.1a7c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000f18 pwszName=\Device\HarddiskVolume3\Windows\System32\IPHLPAPI.DLL
29241428.1a7c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
29251428.1a7c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
29261428.1a7c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=3BDC72529DA09BA841BE702C4C902C8AA1242642
29271428.1a7c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume3\Windows\System32\IPHLPAPI.DLL'
29281428.1a7c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
29291428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
29301428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'nsi.dll'.
29311428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'winnsi.dll'.
29321428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'rpcrt4.dll'.
29331428.1a7c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\IPHLPAPI.DLL) WinVerifyTrust
29341428.1a7c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\IPHLPAPI.DLL
29351428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
29361428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
29371428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
29381428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
29391428.1a7c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ws2_32.dll
29401428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
29411428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
29421428.1a7c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\setupapi.dll
29431428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
29441428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
29451428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxdd2.dll'...
29461428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxdd2.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\vboxdd2.dll' [rcNtRedir=0xc0150008]
29471428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
29481428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
29491428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
29501428.1a7c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\opt\VirtualBox\VBoxDD2.dll) WinVerifyTrust
29511428.1a7c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\opt\VirtualBox\VBoxDD2.dll
29521428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxddu.dll'...
29531428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxddu.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\vboxddu.dll' [rcNtRedir=0xc0150008]
29541428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
29551428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
29561428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
29571428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'setupapi.dll'.
29581428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'newdev.dll'.
29591428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'advapi32.dll'.
29601428.1a7c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\opt\VirtualBox\VBoxDDU.dll) WinVerifyTrust
29611428.1a7c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\opt\VirtualBox\VBoxDDU.dll
29621428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
29631428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
29641428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
29651428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
29661428.1a7c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\VBoxVMM.dll
29671428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
29681428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
29691428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
29701428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
29711428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'newdev.dll'...
29721428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'newdev.dll' -> '\Device\HarddiskVolume3\Windows\System32\newdev.dll' [rcNtRedir=0xc0150008]
29731428.1a7c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000f38 pwszName=\Device\HarddiskVolume3\Windows\System32\newdev.dll
29741428.1a7c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
29751428.1a7c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
29761428.1a7c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2F4B2CF91DA6B4233E3BF5D2EC9677240BFF983C
29771428.1a7c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntph.cat'; file='\Device\HarddiskVolume3\Windows\System32\newdev.dll'
29781428.1a7c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
29791428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
29801428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
29811428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
29821428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
29831428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'uxtheme.dll'.
29841428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'cfgmgr32.dll'.
29851428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'setupapi.dll'.
29861428.1a7c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\newdev.dll) WinVerifyTrust
29871428.1a7c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\newdev.dll
29881428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
29891428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
29901428.1a7c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\setupapi.dll
29911428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
29921428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
29931428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
29941428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
29951428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
29961428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
29971428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
29981428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
29991428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
30001428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
30011428.1a7c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\VBoxVMM.dll
30021428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
30031428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
30041428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
30051428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
30061428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winnsi.dll'...
30071428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'winnsi.dll' -> '\Device\HarddiskVolume3\Windows\System32\winnsi.dll' [rcNtRedir=0xc0150008]
30081428.1a7c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000f24 pwszName=\Device\HarddiskVolume3\Windows\System32\winnsi.dll
30091428.1a7c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
30101428.1a7c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
30111428.1a7c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B28F3E0DF5586B9FB3AEAC48E4ECCA0AFB6ABD91
30121428.1a7c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume3\Windows\System32\winnsi.dll'
30131428.1a7c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
30141428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
30151428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'rpcrt4.dll'.
30161428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'nsi.dll'.
30171428.1a7c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\winnsi.dll) WinVerifyTrust
30181428.1a7c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\winnsi.dll
30191428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
30201428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume3\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
30211428.1a7c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\nsi.dll
30221428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
30231428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
30241428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
30251428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume3\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
30261428.1a7c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\nsi.dll
30271428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
30281428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
30291428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
30301428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
30311428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
30321428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
30331428.1a7c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\setupapi.dll
30341428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
30351428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume3\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
30361428.1a7c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\cfgmgr32.dll
30371428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'uxtheme.dll'...
30381428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'uxtheme.dll' -> '\Device\HarddiskVolume3\Windows\System32\uxtheme.dll' [rcNtRedir=0xc0150008]
30391428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
30401428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
30411428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
30421428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
30431428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
30441428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
30451428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
30461428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
30471428.1a7c: supR3HardenedMonitor_LdrLoadDll: pName=D:\opt\VirtualBox/VBoxDD.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000037b2150:D:\opt\VirtualBox;C:\Windows\system32 [calling]
30481428.1a7c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\VBoxDD.dll
30491428.1a7c: supR3HardenedDllNotificationCallback: load 000007fee6000000 LB 0x008e3000 D:\opt\VirtualBox\VBoxDD.DLL [fFlags=0x0]
30501428.1a7c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\VBoxDD.dll
30511428.1a7c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\VBoxDDU.dll
30521428.1a7c: supR3HardenedDllNotificationCallback: load 000007fef0e00000 LB 0x00061000 D:\opt\VirtualBox\VBoxDDU.dll [fFlags=0x0]
30531428.1a7c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\VBoxDDU.dll
30541428.1a7c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\newdev.dll
30551428.1a7c: supR3HardenedDllNotificationCallback: load 000007feeade0000 LB 0x00051000 C:\Windows\system32\newdev.dll [fFlags=0x0]
30561428.1a7c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\newdev.dll
30571428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
30581428.1a7c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\devrtl.dll)
30591428.1a7c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\devrtl.dll
30601428.1a7c: supR3HardenedDllNotificationCallback: load 000007fefcb30000 LB 0x00012000 C:\Windows\system32\devrtl.DLL [fFlags=0x0]
30611428.1a7c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\devrtl.dll [avoiding WinVerifyTrust]
30621428.1a7c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\VBoxDD2.dll
30631428.1a7c: supR3HardenedDllNotificationCallback: load 000007feeb060000 LB 0x00035000 D:\opt\VirtualBox\VBoxDD2.dll [fFlags=0x0]
30641428.1a7c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\VBoxDD2.dll
30651428.1a7c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\IPHLPAPI.DLL
30661428.1a7c: supR3HardenedDllNotificationCallback: load 000007fefa350000 LB 0x00027000 C:\Windows\system32\IPHLPAPI.DLL [fFlags=0x0]
30671428.1a7c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\IPHLPAPI.DLL
30681428.1a7c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winnsi.dll
30691428.1a7c: supR3HardenedDllNotificationCallback: load 000007fefa340000 LB 0x0000b000 C:\Windows\system32\WINNSI.DLL [fFlags=0x0]
30701428.1a7c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winnsi.dll
30711428.1a7c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee6000000 'D:\opt\VirtualBox/VBoxDD.DLL'
30721428.1a7c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000f44 pwszName=\Device\HarddiskVolume3\Windows\System32\devrtl.dll
30731428.1a7c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
30741428.1a7c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
30751428.1a7c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=445E5B0E9F43B5D56A5B9C4BC3369E3D076ACA1A
30761428.1a7c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume3\Windows\System32\devrtl.dll'
30771428.1a7c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
30781428.1a7c: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\devrtl.dll'
30791428.1a7c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
30801428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
30811428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
30821428.1a7c: supR3HardenedMonitor_LdrLoadDll: pName=D:\opt\VirtualBox/ExtensionPacks/Oracle_VM_VirtualBox_Extension_Pack/win.amd64/VBoxHostWebcam.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000037b2150:D:\opt\VirtualBox;C:\Windows\system32 [calling]
30831428.1a7c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
30841428.1a7c: supR3HardenedDllNotificationCallback: load 000007feeaf20000 LB 0x00033000 D:\opt\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL [fFlags=0x0]
30851428.1a7c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
30861428.1a7c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeaf20000 'D:\opt\VirtualBox/ExtensionPacks/Oracle_VM_VirtualBox_Extension_Pack/win.amd64/VBoxHostWebcam.DLL'
30871428.1a7c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\VBoxC.dll
30881428.1a7c: supR3HardenedMonitor_LdrLoadDll: pName=D:\opt\VirtualBox/VBoxC.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000037b2150:D:\opt\VirtualBox;C:\Windows\system32 [calling]
30891428.1a7c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\VBoxC.dll
30901428.1a7c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee6d60000 'D:\opt\VirtualBox/VBoxC.DLL'
30911428.1a7c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\VBoxDD2.dll
30921428.1a7c: supR3HardenedMonitor_LdrLoadDll: pName=D:\opt\VirtualBox/VBoxDD2.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000037b2150:D:\opt\VirtualBox;C:\Windows\system32 [calling]
30931428.1a7c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\VBoxDD2.dll
30941428.1a7c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeb060000 'D:\opt\VirtualBox/VBoxDD2.DLL'
30951428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
30961428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
30971428.1a7c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\opt\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.dll) WinVerifyTrust
30981428.1a7c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\opt\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.dll
30991428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
31001428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
31011428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
31021428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
31031428.1a7c: supR3HardenedMonitor_LdrLoadDll: pName=D:\opt\VirtualBox/ExtensionPacks/Oracle_VM_VirtualBox_Extension_Pack/win.amd64/VBoxEhciR3.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000037b2150:D:\opt\VirtualBox;C:\Windows\system32 [calling]
31041428.1a7c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.dll
31051428.1a7c: supR3HardenedDllNotificationCallback: load 000007feefed0000 LB 0x0001e000 D:\opt\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.DLL [fFlags=0x0]
31061428.1a7c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.dll
31071428.1a7c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feefed0000 'D:\opt\VirtualBox/ExtensionPacks/Oracle_VM_VirtualBox_Extension_Pack/win.amd64/VBoxEhciR3.DLL'
31081428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
31091428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
31101428.1a7c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\opt\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.dll) WinVerifyTrust
31111428.1a7c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\opt\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.dll
31121428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
31131428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
31141428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
31151428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
31161428.1a7c: supR3HardenedMonitor_LdrLoadDll: pName=D:\opt\VirtualBox/ExtensionPacks/Oracle_VM_VirtualBox_Extension_Pack/win.amd64/VBoxUsbCardReaderR3.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000037b2150:D:\opt\VirtualBox;C:\Windows\system32 [calling]
31171428.1a7c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.dll
31181428.1a7c: supR3HardenedDllNotificationCallback: load 000007feeb040000 LB 0x00018000 D:\opt\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.DLL [fFlags=0x0]
31191428.1a7c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.dll
31201428.1a7c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeb040000 'D:\opt\VirtualBox/ExtensionPacks/Oracle_VM_VirtualBox_Extension_Pack/win.amd64/VBoxUsbCardReaderR3.DLL'
31211428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
31221428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
31231428.1a7c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\opt\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.dll) WinVerifyTrust
31241428.1a7c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\opt\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.dll
31251428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
31261428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
31271428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
31281428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
31291428.1a7c: supR3HardenedMonitor_LdrLoadDll: pName=D:\opt\VirtualBox/ExtensionPacks/Oracle_VM_VirtualBox_Extension_Pack/win.amd64/VBoxUsbWebcamR3.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000037b2150:D:\opt\VirtualBox;C:\Windows\system32 [calling]
31301428.1a7c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.dll
31311428.1a7c: supR3HardenedDllNotificationCallback: load 000007feeaf00000 LB 0x00019000 D:\opt\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.DLL [fFlags=0x0]
31321428.1a7c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.dll
31331428.1a7c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeaf00000 'D:\opt\VirtualBox/ExtensionPacks/Oracle_VM_VirtualBox_Extension_Pack/win.amd64/VBoxUsbWebcamR3.DLL'
31341428.684: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
31351428.684: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
31361428.684: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
31371428.684: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\opt\VirtualBox\VBoxSharedFolders.dll) WinVerifyTrust
31381428.684: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\opt\VirtualBox\VBoxSharedFolders.dll
31391428.684: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
31401428.684: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
31411428.684: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
31421428.684: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
31431428.684: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
31441428.684: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
31451428.684: supR3HardenedMonitor_LdrLoadDll: pName=D:\opt\VirtualBox\VBoxSharedFolders.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=000000000389f040:D:\opt\VirtualBox;C:\Windows\system32 [calling]
31461428.684: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\VBoxSharedFolders.dll
31471428.684: supR3HardenedDllNotificationCallback: load 000007feef990000 LB 0x0000d000 D:\opt\VirtualBox\VBoxSharedFolders.DLL [fFlags=0x0]
31481428.684: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\VBoxSharedFolders.dll
31491428.684: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feef990000 'D:\opt\VirtualBox\VBoxSharedFolders.DLL'
31501428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
31511428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
31521428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
31531428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'gdi32.dll'.
31541428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'advapi32.dll'.
31551428.1a7c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\opt\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.dll) WinVerifyTrust
31561428.1a7c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\opt\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.dll
31571428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
31581428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
31591428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
31601428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
31611428.1a7c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll
31621428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
31631428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
31641428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
31651428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
31661428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
31671428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume5\opt\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
31681428.1a7c: supR3HardenedMonitor_LdrLoadDll: pName=D:\opt\VirtualBox/ExtensionPacks/Oracle_VM_VirtualBox_Extension_Pack/win.amd64/VDPluginCrypt.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000037b2150:D:\opt\VirtualBox;C:\Windows\system32 [calling]
31691428.1a7c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.dll
31701428.1a7c: supR3HardenedDllNotificationCallback: load 000007feeaf60000 LB 0x000c4000 D:\opt\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.DLL [fFlags=0x0]
31711428.1a7c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\opt\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.dll
31721428.1a7c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeaf60000 'D:\opt\VirtualBox/ExtensionPacks/Oracle_VM_VirtualBox_Extension_Pack/win.amd64/VDPluginCrypt.DLL'
31731428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdd90000 'C:\Windows\system32\ADVAPI32.dll'
31741428.1a7c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\IPHLPAPI.DLL
31751428.1a7c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32/Iphlpapi.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000037b2150:D:\opt\VirtualBox;C:\Windows\system32 [calling]
31761428.1a7c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\IPHLPAPI.DLL
31771428.1a7c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa350000 'C:\Windows\system32/Iphlpapi.dll'
31781428.1a7c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000010e0 pwszName=\Device\HarddiskVolume3\Windows\System32\dhcpcsvc.dll
31791428.1a7c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
31801428.1a7c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
31811428.1a7c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=D89E2D6AED9A19082ECA108BEEF81A904C7A9756
31821428.1a7c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume3\Windows\System32\dhcpcsvc.dll'
31831428.1a7c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
31841428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
31851428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'rpcrt4.dll'.
31861428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ws2_32.dll'.
31871428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'nsi.dll'.
31881428.1a7c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\dhcpcsvc.dll) WinVerifyTrust
31891428.1a7c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\dhcpcsvc.dll
31901428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
31911428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume3\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
31921428.1a7c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\nsi.dll
31931428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
31941428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
31951428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
31961428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
31971428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
31981428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
31991428.1a7c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\dhcpcsvc.DLL (Input=dhcpcsvc.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000037b2850:D:\opt\VirtualBox;C:\Windows\system32 [calling]
32001428.1a7c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\dhcpcsvc.dll
32011428.1a7c: supR3HardenedDllNotificationCallback: load 000007fefa0e0000 LB 0x00018000 C:\Windows\system32\dhcpcsvc.DLL [fFlags=0x0]
32021428.1a7c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\dhcpcsvc.dll
32031428.1a7c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa0e0000 'C:\Windows\system32\dhcpcsvc.DLL'
32041428.1a7c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\IPHLPAPI.DLL
32051428.1a7c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\IPHLPAPI.DLL (Input=IPHLPAPI.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000037b2850:D:\opt\VirtualBox;C:\Windows\system32 [calling]
32061428.1a7c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa350000 'C:\Windows\system32\IPHLPAPI.DLL'
32071428.1a7c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000010f8 pwszName=\Device\HarddiskVolume3\Windows\System32\dhcpcsvc6.dll
32081428.1a7c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
32091428.1a7c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
32101428.1a7c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=A719769A21133C3F89F7BEA09AB706365F35DF8F
32111428.1a7c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_26_for_KB2763523~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume3\Windows\System32\dhcpcsvc6.dll'
32121428.1a7c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
32131428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
32141428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'rpcrt4.dll'.
32151428.1a7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ws2_32.dll'.
32161428.1a7c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\dhcpcsvc6.dll) WinVerifyTrust
32171428.1a7c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\dhcpcsvc6.dll
32181428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
32191428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
32201428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
32211428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
32221428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
32231428.1a7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
32241428.1a7c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\dhcpcsvc6.DLL (Input=dhcpcsvc6.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000037b2850:D:\opt\VirtualBox;C:\Windows\system32 [calling]
32251428.1a7c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\dhcpcsvc6.dll
32261428.1a7c: supR3HardenedDllNotificationCallback: load 000007fefa0c0000 LB 0x00011000 C:\Windows\system32\dhcpcsvc6.DLL [fFlags=0x0]
32271428.1a7c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\dhcpcsvc6.dll
32281428.1a7c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa0c0000 'C:\Windows\system32\dhcpcsvc6.DLL'
32291428.1a7c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\IPHLPAPI.DLL
32301428.1a7c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\IPHLPAPI.DLL (Input=IPHLPAPI.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000037b2850:D:\opt\VirtualBox;C:\Windows\system32 [calling]
32311428.1a7c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa350000 'C:\Windows\system32\IPHLPAPI.DLL'
32321428.1a7c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\kernel32.dll
32331428.1a7c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32/kernel32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000037b2850:D:\opt\VirtualBox;C:\Windows\system32 [calling]
32341428.1a7c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\kernel32.dll
32351428.1a7c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077a00000 'C:\Windows\system32/kernel32.dll'
32361428.16b8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\oleaut32.dll
32371428.16b8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\OLEAUT32.dll (Input=OLEAUT32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000037e2080:D:\opt\VirtualBox;C:\Windows\system32 [calling]
32381428.16b8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff390000 'C:\Windows\system32\OLEAUT32.dll'
32391428.197c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000070c pwszName=\Device\HarddiskVolume3\Windows\System32\mswsock.dll
32401428.197c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
32411428.197c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
32421428.197c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wintrust.dll
32431428.197c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\WINTRUST.DLL (Input=WINTRUST.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003809d70:D:\opt\VirtualBox;C:\Windows\system32 [calling]
32441428.197c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd9b0000 'C:\Windows\system32\WINTRUST.DLL'
32451428.197c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll
32461428.197c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPT32.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=0000000003809d70:D:\opt\VirtualBox;C:\Windows\system32 [calling]
32471428.197c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd9f0000 'C:\Windows\system32\CRYPT32.dll'
32481428.197c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=C8E5754748E0E000AB425BF2AEB177780FB43945
32491428.197c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef6250000 'C:\Windows\system32\cryptnet.dll'
32501428.197c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB2888049~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume3\Windows\System32\mswsock.dll'
32511428.197c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
32521428.197c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
32531428.197c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
32541428.197c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rpcrt4.dll'.
32551428.197c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ws2_32.dll'.
32561428.197c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\mswsock.dll) WinVerifyTrust
32571428.197c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\mswsock.dll
32581428.197c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
32591428.197c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
32601428.197c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
32611428.197c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
32621428.197c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
32631428.197c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
32641428.197c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
32651428.197c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
32661428.197c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\mswsock.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003809c90:D:\opt\VirtualBox;C:\Windows\system32 [calling]
32671428.197c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\mswsock.dll
32681428.197c: supR3HardenedDllNotificationCallback: load 000007fefd1a0000 LB 0x00055000 C:\Windows\system32\mswsock.dll [fFlags=0x0]
32691428.197c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\mswsock.dll
32701428.197c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd1a0000 'C:\Windows\system32\mswsock.dll'
32711428.197c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000011e8 pwszName=\Device\HarddiskVolume3\Windows\System32\WSHTCPIP.DLL
32721428.197c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
32731428.197c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
32741428.197c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=1EFFE58BB9FD8A94FD1609B7F82A43C8E09D98AA
32751428.197c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume3\Windows\System32\WSHTCPIP.DLL'
32761428.197c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
32771428.197c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'ws2_32.dll'.
32781428.197c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\WSHTCPIP.DLL) WinVerifyTrust
32791428.197c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\WSHTCPIP.DLL
32801428.197c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
32811428.197c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
32821428.197c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\wshtcpip.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003809c90:D:\opt\VirtualBox;C:\Windows\system32 [calling]
32831428.197c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\WSHTCPIP.DLL
32841428.197c: supR3HardenedDllNotificationCallback: load 000007fefcc90000 LB 0x00007000 C:\Windows\System32\wshtcpip.dll [fFlags=0x0]
32851428.197c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\WSHTCPIP.DLL
32861428.197c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcc90000 'C:\Windows\System32\wshtcpip.dll'
32871428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000001238 pwszName=\Device\HarddiskVolume3\Windows\System32\mscms.dll
32881428.140c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
32891428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
32901428.140c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=77B48D4C63C7308FE42B2B7DF054999F6CE86C20
32911428.140c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-ICM-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume3\Windows\System32\mscms.dll'
32921428.140c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
32931428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
32941428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'userenv.dll'.
32951428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
32961428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
32971428.140c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\mscms.dll) WinVerifyTrust
32981428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\mscms.dll
32991428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
33001428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
33011428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
33021428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
33031428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'userenv.dll'...
33041428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'userenv.dll' -> '\Device\HarddiskVolume3\Windows\System32\userenv.dll' [rcNtRedir=0xc0150008]
33051428.140c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\userenv.dll
33061428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
33071428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
33081428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\mscms.dll (Input=mscms.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000038b6a60:D:\opt\VirtualBox;C:\Windows\system32 [calling]
33091428.140c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\mscms.dll
33101428.140c: supR3HardenedDllNotificationCallback: load 000007fef8c40000 LB 0x0009c000 C:\Windows\system32\mscms.dll [fFlags=0x0]
33111428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\mscms.dll
33121428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef8c40000 'C:\Windows\system32\mscms.dll'
33131428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000125c pwszName=\Device\HarddiskVolume3\Windows\System32\icm32.dll
33141428.140c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
33151428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
33161428.140c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=A467A1C0C873D06FC9374DE3DAC05A8C3CE89002
33171428.140c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-ICM-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume3\Windows\System32\icm32.dll'
33181428.140c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
33191428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
33201428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'mscms.dll'.
33211428.140c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'advapi32.dll'.
33221428.140c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\icm32.dll) WinVerifyTrust
33231428.140c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\icm32.dll
33241428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
33251428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
33261428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mscms.dll'...
33271428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'mscms.dll' -> '\Device\HarddiskVolume3\Windows\System32\mscms.dll' [rcNtRedir=0xc0150008]
33281428.140c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\mscms.dll
33291428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
33301428.140c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
33311428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\icm32.dll (Input=icm32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000038b6a60:D:\opt\VirtualBox;C:\Windows\system32 [calling]
33321428.140c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\icm32.dll
33331428.140c: supR3HardenedDllNotificationCallback: load 000007feead20000 LB 0x00042000 C:\Windows\system32\icm32.dll [fFlags=0x0]
33341428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\icm32.dll
33351428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feead20000 'C:\Windows\system32\icm32.dll'
33361428.140c: supR3HardenedMonitor_LdrLoadDll: 'C:\Windows\system32\comctl32.dll' -> 'C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll' [redir]
33371428.140c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll [redoing WinVerifyTrust]
33381428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000538 pwszName=\Device\HarddiskVolume3\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll
33391428.140c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000008b9e60
33401428.140c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000008b9e60
33411428.140c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=761964761EE466757E306124E042F4C2ACBEA092
33421428.140c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB3059317~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume3\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll'
33431428.140c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
33441428.140c: supR3HardenedScreenImage/LdrLoadDll: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll'
33451428.140c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll (Input=C:\Windows\system32\comctl32.dll, rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=00000000038b6a60:D:\opt\VirtualBox;C:\Windows\system32 [calling]
33461428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef8b90000 'C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6\comctl32.dll'
33471428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdec0000 'C:\Windows\system32\shell32.dll'
33481428.140c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077900000 'C:\Windows\system32\user32.dll'
33491428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
33501428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
33511428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
33521428.142c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
33531428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
33541428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
33551428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
33561428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
33571428.142c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
33581428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
33591428.12e0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\opengl32.dll
33601428.12e0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\OPENGL32.dll (Input=OPENGL32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003751c40:D:\opt\VirtualBox;C:\Windows\system32 [calling]
33611428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
33621428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
33631428.142c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
33641428.142c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
33651428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
33661428.142c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
33671428.142c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
33681428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
33691428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
33701428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
33711428.142c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
33721428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
33731428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
33741428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
33751428.142c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
33761428.142c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
33771428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
33781428.142c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
33791428.142c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
33801428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
33811428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
33821428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
33831428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
33841428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
33851428.142c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
33861428.142c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
33871428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
33881428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
33891428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
33901428.142c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
33911428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
33921428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
33931428.142c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\opengl32.dll
33941428.142c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\OPENGL32.dll (Input=OPENGL32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000038b69f0:D:\opt\VirtualBox;C:\Windows\system32 [calling]
33951428.142c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
33961428.142c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
33971428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
33981428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
33991428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34001428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34011428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34021428.1adc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34031428.1adc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34041428.1adc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34051428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34061428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34071428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34081428.142c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34091428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34101428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34111428.142c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34121428.142c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34131428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34141428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34151428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34161428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34171428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34181428.1adc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34191428.1adc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34201428.1adc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34211428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34221428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34231428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34241428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34251428.1adc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34261428.1adc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34271428.1adc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34281428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34291428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34301428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34311428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34321428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34331428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34341428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34351428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34361428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34371428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34381428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34391428.142c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34401428.142c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34411428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34421428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34431428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34441428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34451428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34461428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34471428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34481428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34491428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34501428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34511428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34521428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34531428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34541428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34551428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34561428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34571428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34581428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34591428.12e0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\opengl32.dll
34601428.12e0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\OPENGL32.dll (Input=OPENGL32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003751c40:D:\opt\VirtualBox;C:\Windows\system32 [calling]
34611428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34621428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34631428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34641428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34651428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34661428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34671428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34681428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34691428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34701428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34711428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34721428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34731428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34741428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34751428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34761428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34771428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34781428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34791428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34801428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34811428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34821428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34831428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34841428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34851428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34861428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34871428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34881428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34891428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34901428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34911428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34921428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34931428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34941428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34951428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34961428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34971428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34981428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
34991428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35001428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35011428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35021428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35031428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35041428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35051428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35061428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35071428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35081428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35091428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35101428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35111428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35121428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35131428.1adc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35141428.1adc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35151428.1adc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35161428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35171428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35181428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35191428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35201428.1adc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35211428.1adc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35221428.1adc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35231428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35241428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35251428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35261428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35271428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35281428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35291428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35301428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35311428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35321428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35331428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35341428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35351428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35361428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35371428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35381428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35391428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35401428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35411428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35421428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35431428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35441428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35451428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35461428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35471428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35481428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35491428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35501428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35511428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35521428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35531428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35541428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35551428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35561428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35571428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35581428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35591428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35601428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35611428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35621428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35631428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35641428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35651428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35661428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35671428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35681428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35691428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35701428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35711428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35721428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35731428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35741428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35751428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35761428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35771428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35781428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35791428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35801428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35811428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35821428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35831428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35841428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35851428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35861428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35871428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35881428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35891428.12e0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\opengl32.dll
35901428.12e0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\OPENGL32.dll (Input=OPENGL32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003751c40:D:\opt\VirtualBox;C:\Windows\system32 [calling]
35911428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35921428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35931428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35941428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35951428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35961428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35971428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35981428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
35991428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
36001428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
36011428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
36021428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
36031428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
36041428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
36051428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
36061428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
36071428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'
36081428.12e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feec880000 'C:\Windows\system32\OPENGL32.dll'

© 2024 Oracle Support Privacy / Do Not Sell My Info Terms of Use Trademark Policy