Advertisement
Guest User

Untitled

a guest
May 25th, 2015
648
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
Java 215.02 KB | None | 0 0
  1. 20e0.1054: Log file opened: 5.0.0_BETA4r100374 g_hStartupLog=0000000000000058 g_uNtVerCombined=0xa0275a00
  2. 20e0.1054: \SystemRoot\System32\ntdll.dll:
  3. 20e0.1054:     CreationTime:    2015-04-25T03:16:09.483018400Z
  4. 20e0.1054:     LastWriteTime:   2015-04-25T03:16:09.514268400Z
  5. 20e0.1054:     ChangeTime:      2015-04-30T13:25:31.674070200Z
  6. 20e0.1054:     FileAttributes:  0x20
  7. 20e0.1054:     Size:            0x1ba428
  8. 20e0.1054:     NT Headers:      0xe8
  9. 20e0.1054:     Timestamp:       0x553ace18
  10. 20e0.1054:     Machine:         0x8664 - amd64
  11. 20e0.1054:     Timestamp:       0x553ace18
  12. 20e0.1054:     Image Version:   10.0
  13. 20e0.1054:     SizeOfImage:     0x1bd000 (1822720)
  14. 20e0.1054:     Resource Dir:    0x157000 LB 0x64f70
  15. 20e0.1054:     ProductName:     Microsoft® Windows® Operating System
  16. 20e0.1054:     ProductVersion:  10.0.10074.0
  17. 20e0.1054:     FileVersion:     10.0.10074.0 (fbl_impressive.150424-1350)
  18. 20e0.1054:     FileDescription: NT Layer DLL
  19. 20e0.1054: \SystemRoot\System32\kernel32.dll:
  20. 20e0.1054:     CreationTime:    2015-04-25T03:14:22.609869200Z
  21. 20e0.1054:     LastWriteTime:   2015-04-25T03:14:22.609869200Z
  22. 20e0.1054:     ChangeTime:      2015-04-30T13:25:31.486556600Z
  23. 20e0.1054:     FileAttributes:  0x20
  24. 20e0.1054:     Size:            0xad6e8
  25. 20e0.1054:     NT Headers:      0xe8
  26. 20e0.1054:     Timestamp:       0x553acf74
  27. 20e0.1054:     Machine:         0x8664 - amd64
  28. 20e0.1054:     Timestamp:       0x553acf74
  29. 20e0.1054:     Image Version:   10.0
  30. 20e0.1054:     SizeOfImage:     0xaf000 (716800)
  31. 20e0.1054:     Resource Dir:    0xad000 LB 0x518
  32. 20e0.1054:     ProductName:     Microsoft® Windows® Operating System
  33. 20e0.1054:     ProductVersion:  10.0.10074.0
  34. 20e0.1054:     FileVersion:     10.0.10074.0 (fbl_impressive.150424-1350)
  35. 20e0.1054:     FileDescription: Windows NT BASE API Client DLL
  36. 20e0.1054: \SystemRoot\System32\KernelBase.dll:
  37. 20e0.1054:     CreationTime:    2015-04-25T03:16:10.279886300Z
  38. 20e0.1054:     LastWriteTime:   2015-04-25T03:16:10.279886300Z
  39. 20e0.1054:     ChangeTime:      2015-04-30T13:25:31.502182700Z
  40. 20e0.1054:     FileAttributes:  0x20
  41. 20e0.1054:     Size:            0x1d5618
  42. 20e0.1054:     NT Headers:      0x100
  43. 20e0.1054:     Timestamp:       0x553acf7b
  44. 20e0.1054:     Machine:         0x8664 - amd64
  45. 20e0.1054:     Timestamp:       0x553acf7b
  46. 20e0.1054:     Image Version:   10.0
  47. 20e0.1054:     SizeOfImage:     0x1d6000 (1925120)
  48. 20e0.1054:     Resource Dir:    0x1c0000 LB 0x530
  49. 20e0.1054:     ProductName:     Microsoft® Windows® Operating System
  50. 20e0.1054:     ProductVersion:  10.0.10074.0
  51. 20e0.1054:     FileVersion:     10.0.10074.0 (fbl_impressive.150424-1350)
  52. 20e0.1054:     FileDescription: Windows NT BASE API Client DLL
  53. 20e0.1054: \SystemRoot\System32\apisetschema.dll:
  54. 20e0.1054:     CreationTime:    2015-04-25T03:15:36.780163800Z
  55. 20e0.1054:     LastWriteTime:   2015-04-25T03:15:36.780163800Z
  56. 20e0.1054:     ChangeTime:      2015-04-30T13:25:28.579914500Z
  57. 20e0.1054:     FileAttributes:  0x20
  58. 20e0.1054:     Size:            0x159e8
  59. 20e0.1054:     NT Headers:      0xc8
  60. 20e0.1054:     Timestamp:       0x553adc20
  61. 20e0.1054:     Machine:         0x8664 - amd64
  62. 20e0.1054:     Timestamp:       0x553adc20
  63. 20e0.1054:     Image Version:   10.0
  64. 20e0.1054:     SizeOfImage:     0x16000 (90112)
  65. 20e0.1054:     Resource Dir:    0x15000 LB 0x3f8
  66. 20e0.1054:     ProductName:     Microsoft® Windows® Operating System
  67. 20e0.1054:     ProductVersion:  10.0.10074.0
  68. 20e0.1054:     FileVersion:     10.0.10074.0 (fbl_impressive.150424-1350)
  69. 20e0.1054:     FileDescription: ApiSet Schema DLL
  70. 20e0.1054: NtOpenDirectoryObject failed on \Driver: 0xc0000022
  71. 20e0.1054: supR3HardenedWinFindAdversaries: 0x0
  72. 20e0.1054: Calling main()
  73. 20e0.1054: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
  74. 20e0.1054: SUPR3HardenedMain: Respawn #1
  75. 20e0.1054: System32:  \Device\HarddiskVolume4\Windows\System32
  76. 20e0.1054: WinSxS:    \Device\HarddiskVolume4\Windows\WinSxS
  77. 20e0.1054: KnownDllPath: C:\WINDOWS\system32
  78. 20e0.1054: '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
  79. 20e0.1054: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe)
  80. 20e0.1054: supR3HardNtEnableThreadCreation:
  81. 20e0.1054: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffbdbf24140 pvNtTerminateThread=00007ffbdbf4b550
  82. 20e0.1054: supR3HardenedWinDoReSpawn(1): New child b48.eac [kernel32].
  83. 20e0.1054: supR3HardNtChildGatherData: PebBaseAddress=00007ff7b7a3c000 cbPeb=0x388
  84. 20e0.1054: supR3HardNtPuChFindNtdll: uNtDllParentAddr=00007ffbdbec0000 uNtDllChildAddr=00007ffbdbec0000
  85. 20e0.1054: supR3HardenedWinSetupChildInit: uLdrInitThunk=00007ffbdbf24140
  86. 20e0.1054: supR3HardenedWinSetupChildInit: Start child.
  87. 20e0.1054: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
  88. 20e0.1054: supR3HardNtChildPurify: Startup delay kludge #1/0: 262 ms, 30 sleeps
  89. 20e0.1054: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
  90. 20e0.1054:  *0000000000000000-ffffffffffd4ffff 0x0001/0x0000 0x0000000
  91. 20e0.1054:  *00000000002b0000-000000000028ffff 0x0004/0x0004 0x0020000
  92. 20e0.1054:  *00000000002d0000-00000000002bcfff 0x0002/0x0002 0x0040000
  93. 20e0.1054:   00000000002e3000-00000000002d5fff 0x0001/0x0000 0x0000000
  94. 20e0.1054:  *00000000002f0000-00000000001f3fff 0x0000/0x0004 0x0020000
  95. 20e0.1054:   00000000003ec000-00000000003e8fff 0x0104/0x0004 0x0020000
  96. 20e0.1054:   00000000003ef000-00000000003edfff 0x0004/0x0004 0x0020000
  97. 20e0.1054:  *00000000003f0000-00000000003ebfff 0x0002/0x0002 0x0040000
  98. 20e0.1054:   00000000003f4000-00000000003e7fff 0x0001/0x0000 0x0000000
  99. 20e0.1054:  *0000000000400000-00000000003fdfff 0x0004/0x0004 0x0020000
  100. 20e0.1054:   0000000000402000-ffffffff80823fff 0x0001/0x0000 0x0000000
  101. 20e0.1054:  *000000007ffe0000-000000007ffdefff 0x0002/0x0002 0x0020000
  102. 20e0.1054:   000000007ffe1000-000000007ffd1fff 0x0000/0x0002 0x0020000
  103. 20e0.1054:   000000007fff0000-ffff8009485cffff 0x0001/0x0000 0x0000000
  104. 20e0.1054:  *00007ff7b7a10000-00007ff7b79ecfff 0x0002/0x0002 0x0040000
  105. 20e0.1054:   00007ff7b7a33000-00007ff7b7a29fff 0x0001/0x0000 0x0000000
  106. 20e0.1054:  *00007ff7b7a3c000-00007ff7b7a3afff 0x0004/0x0004 0x0020000
  107. 20e0.1054:   00007ff7b7a3d000-00007ff7b7a3bfff 0x0001/0x0000 0x0000000
  108. 20e0.1054:  *00007ff7b7a3e000-00007ff7b7a3bfff 0x0004/0x0004 0x0020000
  109. 20e0.1054:   00007ff7b7a40000-00007ff7b6b2ffff 0x0001/0x0000 0x0000000
  110. 20e0.1054:  *00007ff7b8950000-00007ff7b8950fff 0x0002/0x0080 0x1000000  \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
  111. 20e0.1054:   00007ff7b8951000-00007ff7b89d6fff 0x0020/0x0080 0x1000000  \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
  112. 20e0.1054:   00007ff7b89d7000-00007ff7b89d7fff 0x0080/0x0080 0x1000000  \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
  113. 20e0.1054:   00007ff7b89d8000-00007ff7b8a21fff 0x0002/0x0080 0x1000000  \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
  114. 20e0.1054:   00007ff7b8a22000-00007ff7b8a22fff 0x0004/0x0080 0x1000000  \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
  115. 20e0.1054:   00007ff7b8a23000-00007ff7b8a23fff 0x0008/0x0080 0x1000000  \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
  116. 20e0.1054:   00007ff7b8a24000-00007ff7b8a25fff 0x0004/0x0080 0x1000000  \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
  117. 20e0.1054:   00007ff7b8a26000-00007ff7b8a26fff 0x0008/0x0080 0x1000000  \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
  118. 20e0.1054:   00007ff7b8a27000-00007ff7b8a27fff 0x0004/0x0080 0x1000000  \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
  119. 20e0.1054:   00007ff7b8a28000-00007ff7b8a2bfff 0x0008/0x0080 0x1000000  \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
  120. 20e0.1054:   00007ff7b8a2c000-00007ff7b8a75fff 0x0002/0x0080 0x1000000  \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
  121. 20e0.1054:   00007ff7b8a76000-00007ff39562bfff 0x0001/0x0000 0x0000000
  122. 20e0.1054:  *00007ffbdbec0000-00007ffbdbec0fff 0x0002/0x0080 0x1000000  \Device\HarddiskVolume4\Windows\System32\ntdll.dll
  123. 20e0.1054:   00007ffbdbec1000-00007ffbdbfbbfff 0x0020/0x0080 0x1000000  \Device\HarddiskVolume4\Windows\System32\ntdll.dll
  124. 20e0.1054:   00007ffbdbfbc000-00007ffbdbffcfff 0x0002/0x0080 0x1000000  \Device\HarddiskVolume4\Windows\System32\ntdll.dll
  125. 20e0.1054:   00007ffbdbffd000-00007ffbdc005fff 0x0008/0x0080 0x1000000  \Device\HarddiskVolume4\Windows\System32\ntdll.dll
  126. 20e0.1054:   00007ffbdc006000-00007ffbdc012fff 0x0002/0x0080 0x1000000  \Device\HarddiskVolume4\Windows\System32\ntdll.dll
  127. 20e0.1054:   00007ffbdc013000-00007ffbdc013fff 0x0004/0x0080 0x1000000  \Device\HarddiskVolume4\Windows\System32\ntdll.dll
  128. 20e0.1054:   00007ffbdc014000-00007ffbdc016fff 0x0008/0x0080 0x1000000  \Device\HarddiskVolume4\Windows\System32\ntdll.dll
  129. 20e0.1054:   00007ffbdc017000-00007ffbdc07cfff 0x0002/0x0080 0x1000000  \Device\HarddiskVolume4\Windows\System32\ntdll.dll
  130. 20e0.1054:   00007ffbdc07d000-00007ff7b8119fff 0x0001/0x0000 0x0000000
  131. 20e0.1054:  *00007ffffffe0000-00007ffffffcffff 0x0001/0x0002 0x0020000
  132. 20e0.1054: VirtualBox.exe: timestamp 0x5559f4d1 (rc=VINF_SUCCESS)
  133. 20e0.1054: '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
  134. 20e0.1054: '\Device\HarddiskVolume4\Windows\System32\ntdll.dll' has no imports
  135. 20e0.1054: supR3HardNtChildPurify: Done after 320 ms and 0 fixes (loop #0).
  136. b48.eac: Log file opened: 5.0.0_BETA4r100374 g_hStartupLog=0000000000000004 g_uNtVerCombined=0xa0275a00
  137. b48.eac: supR3HardenedVmProcessInit: uNtDllAddr=00007ffbdbec0000
  138. 20e0.1054: supR3HardNtEnableThreadCreation:
  139. b48.eac: ntdll.dll: timestamp 0x553ace18 (rc=VINF_SUCCESS)
  140. b48.eac: New simple heap: #1 0000000000510000 LB 0x400000 (for 1822720 allocation)
  141. b48.eac: System32:  \Device\HarddiskVolume4\Windows\System32
  142. b48.eac: WinSxS:    \Device\HarddiskVolume4\Windows\WinSxS
  143. b48.eac: KnownDllPath: C:\WINDOWS\system32
  144. b48.eac: supR3HardenedVmProcessInit: Opening vboxdrv stub...
  145. b48.eac: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
  146. b48.eac: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
  147. b48.eac: Registered Dll notification callback with NTDLL.
  148. b48.eac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\kernel32.dll)
  149. b48.eac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\kernel32.dll
  150. b48.eac: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\KERNEL32.DLL (Input=KERNEL32.DLL, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000801:<flags> [calling]
  151. b48.eac: supR3HardenedDllNotificationCallback: load   00007ffbd93c0000 LB 0x001d6000 C:\WINDOWS\system32\KERNELBASE.dll [fFlags=0x0]
  152. b48.eac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\KernelBase.dll)
  153. b48.eac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\KernelBase.dll
  154. b48.eac: supR3HardenedDllNotificationCallback: load   00007ffbdb3c0000 LB 0x000af000 C:\WINDOWS\system32\KERNEL32.DLL [fFlags=0x0]
  155. b48.eac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
  156. b48.eac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbdb3c0000 'C:\WINDOWS\system32\KERNEL32.DLL'
  157. b48.eac: supR3HardenedDllNotificationCallback: load   00007ff7b8950000 LB 0x00126000 C:\Program Files\Oracle\VirtualBox\VirtualBox.exe [fFlags=0x0]
  158. b48.eac: '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
  159. b48.eac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe)
  160. b48.eac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
  161. b48.eac: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffbdbf24140 pvNtTerminateThread=00007ffbdbf4b550
  162. 20e0.1054: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 62 ms.
  163. b48.eac: \SystemRoot\System32\ntdll.dll:
  164. b48.eac:     CreationTime:    2015-04-25T03:16:09.483018400Z
  165. b48.eac:     LastWriteTime:   2015-04-25T03:16:09.514268400Z
  166. b48.eac:     ChangeTime:      2015-04-30T13:25:31.674070200Z
  167. b48.eac:     FileAttributes:  0x20
  168. b48.eac:     Size:            0x1ba428
  169. b48.eac:     NT Headers:      0xe8
  170. b48.eac:     Timestamp:       0x553ace18
  171. b48.eac:     Machine:         0x8664 - amd64
  172. b48.eac:     Timestamp:       0x553ace18
  173. b48.eac:     Image Version:   10.0
  174. b48.eac:     SizeOfImage:     0x1bd000 (1822720)
  175. b48.eac:     Resource Dir:    0x157000 LB 0x64f70
  176. b48.eac:     ProductName:     Microsoft® Windows® Operating System
  177. b48.eac:     ProductVersion:  10.0.10074.0
  178. b48.eac:     FileVersion:     10.0.10074.0 (fbl_impressive.150424-1350)
  179. b48.eac:     FileDescription: NT Layer DLL
  180. b48.eac: \SystemRoot\System32\kernel32.dll:
  181. b48.eac:     CreationTime:    2015-04-25T03:14:22.609869200Z
  182. b48.eac:     LastWriteTime:   2015-04-25T03:14:22.609869200Z
  183. b48.eac:     ChangeTime:      2015-04-30T13:25:31.486556600Z
  184. b48.eac:     FileAttributes:  0x20
  185. b48.eac:     Size:            0xad6e8
  186. b48.eac:     NT Headers:      0xe8
  187. b48.eac:     Timestamp:       0x553acf74
  188. b48.eac:     Machine:         0x8664 - amd64
  189. b48.eac:     Timestamp:       0x553acf74
  190. b48.eac:     Image Version:   10.0
  191. b48.eac:     SizeOfImage:     0xaf000 (716800)
  192. b48.eac:     Resource Dir:    0xad000 LB 0x518
  193. b48.eac:     ProductName:     Microsoft® Windows® Operating System
  194. b48.eac:     ProductVersion:  10.0.10074.0
  195. b48.eac:     FileVersion:     10.0.10074.0 (fbl_impressive.150424-1350)
  196. b48.eac:     FileDescription: Windows NT BASE API Client DLL
  197. b48.eac: \SystemRoot\System32\KernelBase.dll:
  198. b48.eac:     CreationTime:    2015-04-25T03:16:10.279886300Z
  199. b48.eac:     LastWriteTime:   2015-04-25T03:16:10.279886300Z
  200. b48.eac:     ChangeTime:      2015-04-30T13:25:31.502182700Z
  201. b48.eac:     FileAttributes:  0x20
  202. b48.eac:     Size:            0x1d5618
  203. b48.eac:     NT Headers:      0x100
  204. b48.eac:     Timestamp:       0x553acf7b
  205. b48.eac:     Machine:         0x8664 - amd64
  206. b48.eac:     Timestamp:       0x553acf7b
  207. b48.eac:     Image Version:   10.0
  208. b48.eac:     SizeOfImage:     0x1d6000 (1925120)
  209. b48.eac:     Resource Dir:    0x1c0000 LB 0x530
  210. b48.eac:     ProductName:     Microsoft® Windows® Operating System
  211. b48.eac:     ProductVersion:  10.0.10074.0
  212. b48.eac:     FileVersion:     10.0.10074.0 (fbl_impressive.150424-1350)
  213. b48.eac:     FileDescription: Windows NT BASE API Client DLL
  214. b48.eac: \SystemRoot\System32\apisetschema.dll:
  215. b48.eac:     CreationTime:    2015-04-25T03:15:36.780163800Z
  216. b48.eac:     LastWriteTime:   2015-04-25T03:15:36.780163800Z
  217. b48.eac:     ChangeTime:      2015-04-30T13:25:28.579914500Z
  218. b48.eac:     FileAttributes:  0x20
  219. b48.eac:     Size:            0x159e8
  220. b48.eac:     NT Headers:      0xc8
  221. b48.eac:     Timestamp:       0x553adc20
  222. b48.eac:     Machine:         0x8664 - amd64
  223. b48.eac:     Timestamp:       0x553adc20
  224. b48.eac:     Image Version:   10.0
  225. b48.eac:     SizeOfImage:     0x16000 (90112)
  226. b48.eac:     Resource Dir:    0x15000 LB 0x3f8
  227. b48.eac:     ProductName:     Microsoft® Windows® Operating System
  228. b48.eac:     ProductVersion:  10.0.10074.0
  229. b48.eac:     FileVersion:     10.0.10074.0 (fbl_impressive.150424-1350)
  230. b48.eac:     FileDescription: ApiSet Schema DLL
  231. b48.eac: NtOpenDirectoryObject failed on \Driver: 0xc0000022
  232. b48.eac: supR3HardenedWinFindAdversaries: 0x0
  233. b48.eac: Calling main()
  234. b48.eac: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
  235. b48.eac: '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
  236. b48.eac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe)
  237. b48.eac: SUPR3HardenedMain: Respawn #2
  238. b48.eac: supR3HardNtEnableThreadCreation:
  239. b48.eac: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffbdbf24140 pvNtTerminateThread=00007ffbdbf4b550
  240. b48.eac: supR3HardenedWinDoReSpawn(2): New child df0.2050 [kernel32].
  241. b48.eac: supR3HardenedWinReSpawn: NtSetInformationThread/ThreadHideFromDebugger failed: 0xc0000022 (harmless)
  242. b48.eac: supR3HardNtChildGatherData: PebBaseAddress=00007ff7b8894000 cbPeb=0x388
  243. b48.eac: supR3HardNtPuChFindNtdll: uNtDllParentAddr=00007ffbdbec0000 uNtDllChildAddr=00007ffbdbec0000
  244. b48.eac: supR3HardenedWinSetupChildInit: uLdrInitThunk=00007ffbdbf24140
  245. b48.eac: supR3HardenedWinSetupChildInit: Start child.
  246. b48.eac: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
  247. b48.eac: supR3HardNtChildPurify: Startup delay kludge #1/0: 265 ms, 30 sleeps
  248. b48.eac: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
  249. b48.eac:  *0000000000000000-ffffffffff23ffff 0x0001/0x0000 0x0000000
  250. b48.eac:  *0000000000dc0000-0000000000d9ffff 0x0004/0x0004 0x0020000
  251. b48.eac:  *0000000000de0000-0000000000dccfff 0x0002/0x0002 0x0040000
  252. b48.eac:   0000000000df3000-0000000000de5fff 0x0001/0x0000 0x0000000
  253. b48.eac:  *0000000000e00000-0000000000d03fff 0x0000/0x0004 0x0020000
  254. b48.eac:   0000000000efc000-0000000000ef8fff 0x0104/0x0004 0x0020000
  255. b48.eac:   0000000000eff000-0000000000efdfff 0x0004/0x0004 0x0020000
  256. b48.eac:  *0000000000f00000-0000000000efbfff 0x0002/0x0002 0x0040000
  257. b48.eac:   0000000000f04000-0000000000ef7fff 0x0001/0x0000 0x0000000
  258. b48.eac:  *0000000000f10000-0000000000f0dfff 0x0004/0x0004 0x0020000
  259. b48.eac:   0000000000f12000-ffffffff81e43fff 0x0001/0x0000 0x0000000
  260. b48.eac:  *000000007ffe0000-000000007ffdefff 0x0002/0x0002 0x0020000
  261. b48.eac:   000000007ffe1000-000000007ffd1fff 0x0000/0x0002 0x0020000
  262. b48.eac:   000000007fff0000-ffff80094776ffff 0x0001/0x0000 0x0000000
  263. b48.eac:  *00007ff7b8870000-00007ff7b884cfff 0x0002/0x0002 0x0040000
  264. b48.eac:   00007ff7b8893000-00007ff7b8891fff 0x0001/0x0000 0x0000000
  265. b48.eac:  *00007ff7b8894000-00007ff7b8892fff 0x0004/0x0004 0x0020000
  266. b48.eac:   00007ff7b8895000-00007ff7b888bfff 0x0001/0x0000 0x0000000
  267. b48.eac:  *00007ff7b889e000-00007ff7b889bfff 0x0004/0x0004 0x0020000
  268. b48.eac:   00007ff7b88a0000-00007ff7b87effff 0x0001/0x0000 0x0000000
  269. b48.eac:  *00007ff7b8950000-00007ff7b8950fff 0x0002/0x0080 0x1000000  \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
  270. b48.eac:   00007ff7b8951000-00007ff7b89d6fff 0x0020/0x0080 0x1000000  \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
  271. b48.eac:   00007ff7b89d7000-00007ff7b89d7fff 0x0080/0x0080 0x1000000  \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
  272. b48.eac:   00007ff7b89d8000-00007ff7b8a21fff 0x0002/0x0080 0x1000000  \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
  273. b48.eac:   00007ff7b8a22000-00007ff7b8a22fff 0x0004/0x0080 0x1000000  \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
  274. b48.eac:   00007ff7b8a23000-00007ff7b8a23fff 0x0008/0x0080 0x1000000  \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
  275. b48.eac:   00007ff7b8a24000-00007ff7b8a25fff 0x0004/0x0080 0x1000000  \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
  276. b48.eac:   00007ff7b8a26000-00007ff7b8a26fff 0x0008/0x0080 0x1000000  \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
  277. b48.eac:   00007ff7b8a27000-00007ff7b8a27fff 0x0004/0x0080 0x1000000  \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
  278. b48.eac:   00007ff7b8a28000-00007ff7b8a2bfff 0x0008/0x0080 0x1000000  \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
  279. b48.eac:   00007ff7b8a2c000-00007ff7b8a75fff 0x0002/0x0080 0x1000000  \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
  280. b48.eac:   00007ff7b8a76000-00007ff39562bfff 0x0001/0x0000 0x0000000
  281. b48.eac:  *00007ffbdbec0000-00007ffbdbec0fff 0x0002/0x0080 0x1000000  \Device\HarddiskVolume4\Windows\System32\ntdll.dll
  282. b48.eac:   00007ffbdbec1000-00007ffbdbfbbfff 0x0020/0x0080 0x1000000  \Device\HarddiskVolume4\Windows\System32\ntdll.dll
  283. b48.eac:   00007ffbdbfbc000-00007ffbdbffcfff 0x0002/0x0080 0x1000000  \Device\HarddiskVolume4\Windows\System32\ntdll.dll
  284. b48.eac:   00007ffbdbffd000-00007ffbdc005fff 0x0008/0x0080 0x1000000  \Device\HarddiskVolume4\Windows\System32\ntdll.dll
  285. b48.eac:   00007ffbdc006000-00007ffbdc012fff 0x0002/0x0080 0x1000000  \Device\HarddiskVolume4\Windows\System32\ntdll.dll
  286. b48.eac:   00007ffbdc013000-00007ffbdc013fff 0x0004/0x0080 0x1000000  \Device\HarddiskVolume4\Windows\System32\ntdll.dll
  287. b48.eac:   00007ffbdc014000-00007ffbdc016fff 0x0008/0x0080 0x1000000  \Device\HarddiskVolume4\Windows\System32\ntdll.dll
  288. b48.eac:   00007ffbdc017000-00007ffbdc07cfff 0x0002/0x0080 0x1000000  \Device\HarddiskVolume4\Windows\System32\ntdll.dll
  289. b48.eac:   00007ffbdc07d000-00007ff7b8119fff 0x0001/0x0000 0x0000000
  290. b48.eac:  *00007ffffffe0000-00007ffffffcffff 0x0001/0x0002 0x0020000
  291. b48.eac: VirtualBox.exe: timestamp 0x5559f4d1 (rc=VINF_SUCCESS)
  292. b48.eac: '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
  293. b48.eac: '\Device\HarddiskVolume4\Windows\System32\ntdll.dll' has no imports
  294. b48.eac: supR3HardNtChildPurify: Done after 318 ms and 0 fixes (loop #0).
  295. df0.2050: Log file opened: 5.0.0_BETA4r100374 g_hStartupLog=0000000000000004 g_uNtVerCombined=0xa0275a00
  296. df0.2050: supR3HardenedVmProcessInit: uNtDllAddr=00007ffbdbec0000
  297. b48.eac: supR3HardenedEarlyCompact: Removed heap 1 (0x00000000510000 LB 0x400000)
  298. df0.2050: ntdll.dll: timestamp 0x553ace18 (rc=VINF_SUCCESS)
  299. b48.eac: supR3HardNtEnableThreadCreation:
  300. df0.2050: New simple heap: #1 0000000001020000 LB 0x400000 (for 1822720 allocation)
  301. df0.2050: System32:  \Device\HarddiskVolume4\Windows\System32
  302. df0.2050: WinSxS:    \Device\HarddiskVolume4\Windows\WinSxS
  303. df0.2050: KnownDllPath: C:\WINDOWS\system32
  304. df0.2050: supR3HardenedVmProcessInit: Opening vboxdrv...
  305. df0.2050: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
  306. df0.2050: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
  307. df0.2050: Registered Dll notification callback with NTDLL.
  308. df0.2050: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\kernel32.dll)
  309. df0.2050: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\kernel32.dll
  310. df0.2050: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\KERNEL32.DLL (Input=KERNEL32.DLL, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000801:<flags> [calling]
  311. df0.2050: supR3HardenedDllNotificationCallback: load   00007ffbd93c0000 LB 0x001d6000 C:\WINDOWS\system32\KERNELBASE.dll [fFlags=0x0]
  312. df0.2050: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\KernelBase.dll)
  313. df0.2050: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\KernelBase.dll
  314. df0.2050: supR3HardenedDllNotificationCallback: load   00007ffbdb3c0000 LB 0x000af000 C:\WINDOWS\system32\KERNEL32.DLL [fFlags=0x0]
  315. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
  316. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbdb3c0000 'C:\WINDOWS\system32\KERNEL32.DLL'
  317. df0.2050: supR3HardenedDllNotificationCallback: load   00007ff7b8950000 LB 0x00126000 C:\Program Files\Oracle\VirtualBox\VirtualBox.exe [fFlags=0x0]
  318. df0.2050: '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
  319. df0.2050: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe)
  320. df0.2050: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe
  321. df0.2050: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffbdbf24140 pvNtTerminateThread=00007ffbdbf4b550
  322. b48.eac: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 67 ms.
  323. df0.2050: \SystemRoot\System32\ntdll.dll:
  324. df0.2050:     CreationTime:    2015-04-25T03:16:09.483018400Z
  325. df0.2050:     LastWriteTime:   2015-04-25T03:16:09.514268400Z
  326. df0.2050:     ChangeTime:      2015-04-30T13:25:31.674070200Z
  327. df0.2050:     FileAttributes:  0x20
  328. df0.2050:     Size:            0x1ba428
  329. df0.2050:     NT Headers:      0xe8
  330. df0.2050:     Timestamp:       0x553ace18
  331. df0.2050:     Machine:         0x8664 - amd64
  332. df0.2050:     Timestamp:       0x553ace18
  333. df0.2050:     Image Version:   10.0
  334. df0.2050:     SizeOfImage:     0x1bd000 (1822720)
  335. df0.2050:     Resource Dir:    0x157000 LB 0x64f70
  336. df0.2050:     ProductName:     Microsoft® Windows® Operating System
  337. df0.2050:     ProductVersion:  10.0.10074.0
  338. df0.2050:     FileVersion:     10.0.10074.0 (fbl_impressive.150424-1350)
  339. df0.2050:     FileDescription: NT Layer DLL
  340. df0.2050: \SystemRoot\System32\kernel32.dll:
  341. df0.2050:     CreationTime:    2015-04-25T03:14:22.609869200Z
  342. df0.2050:     LastWriteTime:   2015-04-25T03:14:22.609869200Z
  343. df0.2050:     ChangeTime:      2015-04-30T13:25:31.486556600Z
  344. df0.2050:     FileAttributes:  0x20
  345. df0.2050:     Size:            0xad6e8
  346. df0.2050:     NT Headers:      0xe8
  347. df0.2050:     Timestamp:       0x553acf74
  348. df0.2050:     Machine:         0x8664 - amd64
  349. df0.2050:     Timestamp:       0x553acf74
  350. df0.2050:     Image Version:   10.0
  351. df0.2050:     SizeOfImage:     0xaf000 (716800)
  352. df0.2050:     Resource Dir:    0xad000 LB 0x518
  353. df0.2050:     ProductName:     Microsoft® Windows® Operating System
  354. df0.2050:     ProductVersion:  10.0.10074.0
  355. df0.2050:     FileVersion:     10.0.10074.0 (fbl_impressive.150424-1350)
  356. df0.2050:     FileDescription: Windows NT BASE API Client DLL
  357. df0.2050: \SystemRoot\System32\KernelBase.dll:
  358. df0.2050:     CreationTime:    2015-04-25T03:16:10.279886300Z
  359. df0.2050:     LastWriteTime:   2015-04-25T03:16:10.279886300Z
  360. df0.2050:     ChangeTime:      2015-04-30T13:25:31.502182700Z
  361. df0.2050:     FileAttributes:  0x20
  362. df0.2050:     Size:            0x1d5618
  363. df0.2050:     NT Headers:      0x100
  364. df0.2050:     Timestamp:       0x553acf7b
  365. df0.2050:     Machine:         0x8664 - amd64
  366. df0.2050:     Timestamp:       0x553acf7b
  367. df0.2050:     Image Version:   10.0
  368. df0.2050:     SizeOfImage:     0x1d6000 (1925120)
  369. df0.2050:     Resource Dir:    0x1c0000 LB 0x530
  370. df0.2050:     ProductName:     Microsoft® Windows® Operating System
  371. df0.2050:     ProductVersion:  10.0.10074.0
  372. df0.2050:     FileVersion:     10.0.10074.0 (fbl_impressive.150424-1350)
  373. df0.2050:     FileDescription: Windows NT BASE API Client DLL
  374. df0.2050: \SystemRoot\System32\apisetschema.dll:
  375. df0.2050:     CreationTime:    2015-04-25T03:15:36.780163800Z
  376. df0.2050:     LastWriteTime:   2015-04-25T03:15:36.780163800Z
  377. df0.2050:     ChangeTime:      2015-04-30T13:25:28.579914500Z
  378. df0.2050:     FileAttributes:  0x20
  379. df0.2050:     Size:            0x159e8
  380. df0.2050:     NT Headers:      0xc8
  381. df0.2050:     Timestamp:       0x553adc20
  382. df0.2050:     Machine:         0x8664 - amd64
  383. df0.2050:     Timestamp:       0x553adc20
  384. df0.2050:     Image Version:   10.0
  385. df0.2050:     SizeOfImage:     0x16000 (90112)
  386. df0.2050:     Resource Dir:    0x15000 LB 0x3f8
  387. df0.2050:     ProductName:     Microsoft® Windows® Operating System
  388. df0.2050:     ProductVersion:  10.0.10074.0
  389. df0.2050:     FileVersion:     10.0.10074.0 (fbl_impressive.150424-1350)
  390. df0.2050:     FileDescription: ApiSet Schema DLL
  391. df0.2050: NtOpenDirectoryObject failed on \Driver: 0xc0000022
  392. df0.2050: supR3HardenedWinFindAdversaries: 0x0
  393. df0.2050: Calling main()
  394. df0.2050: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
  395. df0.2050: '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
  396. df0.2050: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe)
  397. df0.2050: SUPR3HardenedMain: Final process, opening VBoxDrv...
  398. df0.2050: supR3HardenedEarlyCompact: Removed heap 1 (0x00000001020000 LB 0x400000)
  399. df0.2050: supR3HardNtEnableThreadCreation:
  400. df0.2050: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSupLib.dll)
  401. df0.2050: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSupLib.dll
  402. df0.2050: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
  403. df0.2050: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
  404. df0.2050: supR3HardenedDllNotificationCallback: load   00007ffbd69b0000 LB 0x00005000 C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL [fFlags=0x0]
  405. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
  406. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
  407. df0.2050: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  408. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd69b0000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
  409. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
  410. df0.2050: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  411. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd69b0000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
  412. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd69b0000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
  413. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
  414. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msasn1.dll'.
  415. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'crypt32.dll'.
  416. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #24 'rpcrt4.dll'.
  417. df0.2050: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\wintrust.dll)
  418. df0.2050: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\wintrust.dll
  419. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
  420. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
  421. df0.2050: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll)
  422. df0.2050: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll
  423. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
  424. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume4\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
  425. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
  426. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #27 'msasn1.dll'.
  427. df0.2050: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\crypt32.dll)
  428. df0.2050: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\crypt32.dll
  429. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
  430. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume4\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
  431. df0.2050: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\msasn1.dll)
  432. df0.2050: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\msasn1.dll
  433. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
  434. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
  435. df0.2050: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\msvcrt.dll)
  436. df0.2050: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\msvcrt.dll
  437. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
  438. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume4\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
  439. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
  440. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
  441. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
  442. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
  443. df0.2050: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
  444. df0.2050: supR3HardenedDllNotificationCallback: load   00007ffbdb9f0000 LB 0x0009d000 C:\WINDOWS\system32\msvcrt.dll [fFlags=0x0]
  445. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
  446. df0.2050: supR3HardenedDllNotificationCallback: load   00007ffbd8ad0000 LB 0x00011000 C:\WINDOWS\system32\MSASN1.dll [fFlags=0x0]
  447. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
  448. df0.2050: supR3HardenedDllNotificationCallback: load   00007ffbd9120000 LB 0x001d9000 C:\WINDOWS\system32\CRYPT32.dll [fFlags=0x0]
  449. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
  450. df0.2050: supR3HardenedDllNotificationCallback: load   00007ffbdb290000 LB 0x00126000 C:\WINDOWS\system32\RPCRT4.dll [fFlags=0x0]
  451. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
  452. df0.2050: supR3HardenedDllNotificationCallback: load   00007ffbd9350000 LB 0x00067000 C:\WINDOWS\system32\Wintrust.dll [fFlags=0x0]
  453. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
  454. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9350000 'C:\WINDOWS\system32\Wintrust.dll'
  455. df0.2050: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\bcrypt.dll)
  456. df0.2050: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\bcrypt.dll
  457. df0.2050: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\bcrypt.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
  458. df0.2050: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
  459. df0.2050: supR3HardenedDllNotificationCallback: load   00007ffbd89d0000 LB 0x00028000 C:\WINDOWS\system32\bcrypt.dll [fFlags=0x0]
  460. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
  461. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd89d0000 'C:\WINDOWS\system32\bcrypt.dll'
  462. df0.2050: bcrypt.dll loaded at 00007ffbd89d0000, BCryptOpenAlgorithmProvider at 00007ffbd89d3290, preloading providers:
  463. df0.2050: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\bcryptprimitives.dll)
  464. df0.2050: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\bcryptprimitives.dll
  465. df0.2050: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\bcryptprimitives.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  466. df0.2050: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
  467. df0.2050: supR3HardenedDllNotificationCallback: load   00007ffbd8860000 LB 0x00068000 C:\WINDOWS\system32\bcryptprimitives.dll [fFlags=0x0]
  468. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
  469. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd8860000 'C:\WINDOWS\system32\bcryptprimitives.dll'
  470. df0.2050:     BCryptOpenAlgorithmProvider(,'MD2',0,0) -> 0x0 (hAlgo=00000000015c9680)
  471. df0.2050:     BCryptOpenAlgorithmProvider(,'MD4',0,0) -> 0x0 (hAlgo=00000000015c9d40)
  472. df0.2050:     BCryptOpenAlgorithmProvider(,'MD5',0,0) -> 0x0 (hAlgo=00000000015ca820)
  473. df0.2050:     BCryptOpenAlgorithmProvider(,'SHA1',0,0) -> 0x0 (hAlgo=00000000015caaf0)
  474. df0.2050:     BCryptOpenAlgorithmProvider(,'SHA256',0,0) -> 0x0 (hAlgo=00000000015cae00)
  475. df0.2050:     BCryptOpenAlgorithmProvider(,'SHA512',0,0) -> 0x0 (hAlgo=00000000015cb110)
  476. df0.2050:     BCryptOpenAlgorithmProvider(,'RSA',0,0) -> 0x0 (hAlgo=00000000015cb420)
  477. df0.2050:     BCryptOpenAlgorithmProvider(,'DSA',0,0) -> 0x0 (hAlgo=00000000015cb6f0)
  478. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
  479. df0.2050: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  480. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9350000 'C:\Windows\System32\WINTRUST.DLL'
  481. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
  482. df0.2050: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  483. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9350000 'C:\Windows\System32\WINTRUST.DLL'
  484. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
  485. df0.2050: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  486. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9350000 'C:\Windows\System32\WINTRUST.DLL'
  487. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
  488. df0.2050: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  489. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9350000 'C:\Windows\System32\WINTRUST.DLL'
  490. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
  491. df0.2050: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  492. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9350000 'C:\Windows\System32\WINTRUST.DLL'
  493. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
  494. df0.2050: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  495. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9350000 'C:\Windows\System32\WINTRUST.DLL'
  496. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
  497. df0.2050: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  498. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9350000 'C:\Windows\System32\WINTRUST.DLL'
  499. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'bcrypt.dll'.
  500. df0.2050: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\cryptsp.dll)
  501. df0.2050: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\cryptsp.dll
  502. df0.2050: supR3HardenedDllNotificationCallback: load   00007ffbd8320000 LB 0x00016000 C:\WINDOWS\SYSTEM32\CRYPTSP.dll [fFlags=0x0]
  503. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\cryptsp.dll [lacks WinVerifyTrust]
  504. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'bcrypt.dll'.
  505. df0.2050: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\rsaenh.dll)
  506. df0.2050: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\rsaenh.dll
  507. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
  508. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume4\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
  509. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
  510. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
  511. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume4\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
  512. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
  513. df0.2050: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  514. df0.2050: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
  515. df0.2050: supR3HardenedDllNotificationCallback: load   00007ffbd7f80000 LB 0x00033000 C:\WINDOWS\system32\rsaenh.dll [fFlags=0x0]
  516. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
  517. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7f80000 'C:\WINDOWS\system32\rsaenh.dll'
  518. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'bcryptprimitives.dll'.
  519. df0.2050: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\cryptbase.dll)
  520. df0.2050: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\cryptbase.dll
  521. df0.2050: supR3HardenedDllNotificationCallback: load   00007ffbd8470000 LB 0x0000a000 C:\WINDOWS\SYSTEM32\CRYPTBASE.dll [fFlags=0x0]
  522. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\cryptbase.dll [lacks WinVerifyTrust]
  523. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
  524. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcryptprimitives.dll'...
  525. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcryptprimitives.dll' -> '\Device\HarddiskVolume4\Windows\System32\bcryptprimitives.dll' [rcNtRedir=0xc0150008]
  526. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
  527. df0.2050: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  528. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbdb3c0000 'C:\WINDOWS\system32\kernel32.dll'
  529. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
  530. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9350000 'C:\Windows\System32\WINTRUST.DLL'
  531. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
  532. df0.2050: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\CRYPT32.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
  533. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9120000 'C:\WINDOWS\system32\CRYPT32.dll'
  534. df0.2050: supR3HardenedDllNotificationCallback: load   00007ffbdb840000 LB 0x00018000 C:\WINDOWS\system32\imagehlp.dll [fFlags=0x0]
  535. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
  536. df0.2050: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\imagehlp.dll)
  537. df0.2050: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\imagehlp.dll
  538. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
  539. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
  540. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
  541. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
  542. df0.2050: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  543. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7f80000 'C:\WINDOWS\system32\rsaenh.dll'
  544. df0.2050: supR3HardenedDllNotificationCallback: load   00007ffbd9710000 LB 0x0005a000 C:\WINDOWS\system32\sechost.dll [fFlags=0x0]
  545. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'rpcrt4.dll'.
  546. df0.2050: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\sechost.dll)
  547. df0.2050: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\sechost.dll
  548. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
  549. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'rpcrt4.dll'.
  550. df0.2050: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\gpapi.dll)
  551. df0.2050: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\gpapi.dll
  552. df0.2050: supR3HardenedDllNotificationCallback: load   00007ffbd7a10000 LB 0x00023000 C:\WINDOWS\SYSTEM32\gpapi.dll [fFlags=0x0]
  553. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gpapi.dll [lacks WinVerifyTrust]
  554. df0.2050: supR3HardenedDllNotificationCallback: load   00007ffbd8aa0000 LB 0x00014000 C:\WINDOWS\system32\profapi.dll [fFlags=0x0]
  555. df0.2050: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\profapi.dll)
  556. df0.2050: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\profapi.dll
  557. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
  558. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'crypt32.dll'.
  559. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'wldap32.dll'.
  560. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'bcrypt.dll'.
  561. df0.2050: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\System32\cryptnet.dll)
  562. df0.2050: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\cryptnet.dll
  563. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
  564. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume4\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
  565. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
  566. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wldap32.dll'...
  567. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'wldap32.dll' -> '\Device\HarddiskVolume4\Windows\System32\wldap32.dll' [rcNtRedir=0xc0150008]
  568. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
  569. df0.2050: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\System32\Wldap32.dll)
  570. df0.2050: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\Wldap32.dll
  571. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
  572. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume4\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
  573. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
  574. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
  575. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
  576. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
  577. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
  578. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
  579. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
  580. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
  581. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
  582. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
  583. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
  584. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
  585. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
  586. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
  587. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
  588. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
  589. df0.2050: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\cryptnet.dll (Input=cryptnet.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  590. df0.2050: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
  591. df0.2050: supR3HardenedDllNotificationCallback: load   00007ffbdba90000 LB 0x0005b000 C:\WINDOWS\system32\WLDAP32.dll [fFlags=0x0]
  592. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\Wldap32.dll [lacks WinVerifyTrust]
  593. df0.2050: supR3HardenedDllNotificationCallback: load   00007ffbbf670000 LB 0x00030000 C:\WINDOWS\system32\cryptnet.dll [fFlags=0x0]
  594. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
  595. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
  596. df0.2050: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
  597. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbbf670000 'C:\WINDOWS\system32\cryptnet.dll'
  598. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
  599. df0.2050: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
  600. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbbf670000 'C:\WINDOWS\system32\cryptnet.dll'
  601. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
  602. df0.2050: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
  603. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbbf670000 'C:\WINDOWS\system32\cryptnet.dll'
  604. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
  605. df0.2050: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
  606. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbbf670000 'C:\WINDOWS\system32\cryptnet.dll'
  607. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
  608. df0.2050: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
  609. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbbf670000 'C:\WINDOWS\system32\cryptnet.dll'
  610. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
  611. df0.2050: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
  612. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbbf670000 'C:\WINDOWS\system32\cryptnet.dll'
  613. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
  614. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbbf670000 'C:\WINDOWS\system32\cryptnet.dll'
  615. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
  616. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbbf670000 'C:\WINDOWS\system32\cryptnet.dll'
  617. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
  618. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbbf670000 'C:\WINDOWS\system32\cryptnet.dll'
  619. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
  620. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbbf670000 'C:\WINDOWS\system32\cryptnet.dll'
  621. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
  622. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbbf670000 'C:\WINDOWS\system32\cryptnet.dll'
  623. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbbf670000 'C:\WINDOWS\system32\cryptnet.dll'
  624. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
  625. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbbf670000 'C:\Windows\System32\cryptnet.dll'
  626. df0.2050: supR3HardenedDllNotificationCallback: load   00007ffbdbc00000 LB 0x000a6000 C:\WINDOWS\system32\advapi32.dll [fFlags=0x0]
  627. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
  628. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'sechost.dll'.
  629. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #19 'rpcrt4.dll'.
  630. df0.2050: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\advapi32.dll)
  631. df0.2050: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\advapi32.dll
  632. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
  633. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
  634. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
  635. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
  636. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'sechost.dll'...
  637. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'sechost.dll' -> '\Device\HarddiskVolume4\Windows\System32\sechost.dll' [rcNtRedir=0xc0150008]
  638. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\sechost.dll [lacks WinVerifyTrust]
  639. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
  640. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
  641. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
  642. df0.2050: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  643. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7f80000 'C:\WINDOWS\system32\rsaenh.dll'
  644. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
  645. df0.2050: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  646. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9120000 'C:\WINDOWS\system32\crypt32.dll'
  647. df0.2050: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000000 pwszName=\SystemRoot\System32\ntdll.dll
  648. df0.2050: supR3HardNtViCallWinVerifyTrustCatFile: New context 0000000001633db0
  649. df0.2050: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000001633db0
  650. df0.2050: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=9F044A15A16BC2551C9AA8CF60A3FC7F400CED32
  651. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
  652. df0.2050: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rpcrt4.dll (Input=rpcrt4.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  653. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbdb290000 'C:\WINDOWS\system32\rpcrt4.dll'
  654. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
  655. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9350000 'C:\Windows\System32\WINTRUST.DLL'
  656. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
  657. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9350000 'C:\Windows\System32\WINTRUST.DLL'
  658. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
  659. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9350000 'C:\Windows\System32\WINTRUST.DLL'
  660. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
  661. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9350000 'C:\Windows\System32\WINTRUST.DLL'
  662. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
  663. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9350000 'C:\Windows\System32\WINTRUST.DLL'
  664. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
  665. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9350000 'C:\Windows\System32\WINTRUST.DLL'
  666. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
  667. df0.2050: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  668. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9350000 'C:\Windows\System32\WINTRUST.DLL'
  669. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
  670. df0.2050: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  671. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7f80000 'C:\WINDOWS\system32\rsaenh.dll'
  672. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
  673. df0.2050: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  674. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9120000 'C:\WINDOWS\system32\crypt32.dll'
  675. df0.2050: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Group-minkernel-Package~31bf3856ad364e35~amd64~~10.0.10074.0.cat'; file='\SystemRoot\System32\ntdll.dll'
  676. df0.2050: g_pfnWinVerifyTrust=00007ffbd9357f90
  677. df0.2050: supR3HardenedScreenImage/preload: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll [redoing WinVerifyTrust]
  678. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
  679. df0.2050: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  680. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7f80000 'C:\WINDOWS\system32\rsaenh.dll'
  681. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
  682. df0.2050: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  683. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9120000 'C:\WINDOWS\system32\crypt32.dll'
  684. df0.2050: supR3HardenedScreenImage/preload: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\crypt32.dll'
  685. df0.2050: supR3HardenedScreenImage/preload: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wintrust.dll [redoing WinVerifyTrust]
  686. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
  687. df0.2050: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  688. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7f80000 'C:\WINDOWS\system32\rsaenh.dll'
  689. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll
  690. df0.2050: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  691. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9120000 'C:\WINDOWS\system32\crypt32.dll'
  692. df0.2050: supR3HardenedScreenImage/preload: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\wintrust.dll'
  693. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
  694. df0.2050: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  695. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7f80000 'C:\WINDOWS\system32\rsaenh.dll'
  696. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9120000 'C:\WINDOWS\system32\crypt32.dll'
  697. df0.2050: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\advapi32.dll'
  698. df0.2050: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000388 pwszName=\Device\HarddiskVolume4\Windows\System32\Wldap32.dll
  699. df0.2050: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000001633db0
  700. df0.2050: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000001633db0
  701. df0.2050: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=989C645E7D6AD8298E35D1FD16AF2496965861F9
  702. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
  703. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7f80000 'C:\WINDOWS\system32\rsaenh.dll'
  704. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9120000 'C:\WINDOWS\system32\crypt32.dll'
  705. df0.2050: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-OneCore-CoreSystem-ds-Package~31bf3856ad364e35~amd64~~10.0.10074.0.cat'; file='\Device\HarddiskVolume4\Windows\System32\Wldap32.dll'
  706. df0.2050: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
  707. df0.2050: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\Wldap32.dll'
  708. df0.2050: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000384 pwszName=\Device\HarddiskVolume4\Windows\System32\cryptnet.dll
  709. df0.2050: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000001633db0
  710. df0.2050: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000001633db0
  711. df0.2050: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=FA7C82291D1B0F5E69266CCD2B2673976D4009DA
  712. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
  713. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7f80000 'C:\WINDOWS\system32\rsaenh.dll'
  714. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9120000 'C:\WINDOWS\system32\crypt32.dll'
  715. df0.2050: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-OneCore-CoreSystem-ds-Package~31bf3856ad364e35~amd64~~10.0.10074.0.cat'; file='\Device\HarddiskVolume4\Windows\System32\cryptnet.dll'
  716. df0.2050: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
  717. df0.2050: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\cryptnet.dll'
  718. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
  719. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7f80000 'C:\WINDOWS\system32\rsaenh.dll'
  720. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9120000 'C:\WINDOWS\system32\crypt32.dll'
  721. df0.2050: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\profapi.dll'
  722. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
  723. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7f80000 'C:\WINDOWS\system32\rsaenh.dll'
  724. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9120000 'C:\WINDOWS\system32\crypt32.dll'
  725. df0.2050: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\gpapi.dll'
  726. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
  727. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7f80000 'C:\WINDOWS\system32\rsaenh.dll'
  728. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9120000 'C:\WINDOWS\system32\crypt32.dll'
  729. df0.2050: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\sechost.dll'
  730. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
  731. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7f80000 'C:\WINDOWS\system32\rsaenh.dll'
  732. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9120000 'C:\WINDOWS\system32\crypt32.dll'
  733. df0.2050: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\imagehlp.dll'
  734. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
  735. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7f80000 'C:\WINDOWS\system32\rsaenh.dll'
  736. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll
  737. df0.2050: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  738. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9120000 'C:\WINDOWS\system32\crypt32.dll'
  739. df0.2050: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\cryptbase.dll'
  740. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
  741. df0.2050: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  742. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7f80000 'C:\WINDOWS\system32\rsaenh.dll'
  743. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9120000 'C:\WINDOWS\system32\crypt32.dll'
  744. df0.2050: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\rsaenh.dll'
  745. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7f80000 'C:\WINDOWS\system32\rsaenh.dll'
  746. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9120000 'C:\WINDOWS\system32\crypt32.dll'
  747. df0.2050: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\cryptsp.dll'
  748. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7f80000 'C:\WINDOWS\system32\rsaenh.dll'
  749. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9120000 'C:\WINDOWS\system32\crypt32.dll'
  750. df0.2050: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\bcryptprimitives.dll'
  751. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7f80000 'C:\WINDOWS\system32\rsaenh.dll'
  752. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9120000 'C:\WINDOWS\system32\crypt32.dll'
  753. df0.2050: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\bcrypt.dll'
  754. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7f80000 'C:\WINDOWS\system32\rsaenh.dll'
  755. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9120000 'C:\WINDOWS\system32\crypt32.dll'
  756. df0.2050: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll'
  757. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7f80000 'C:\WINDOWS\system32\rsaenh.dll'
  758. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9120000 'C:\WINDOWS\system32\crypt32.dll'
  759. df0.2050: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\msasn1.dll'
  760. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7f80000 'C:\WINDOWS\system32\rsaenh.dll'
  761. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9120000 'C:\WINDOWS\system32\crypt32.dll'
  762. df0.2050: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll'
  763. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7f80000 'C:\WINDOWS\system32\rsaenh.dll'
  764. df0.2050: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxSupLib.dll'
  765. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7f80000 'C:\WINDOWS\system32\rsaenh.dll'
  766. df0.2050: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe'
  767. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7f80000 'C:\WINDOWS\system32\rsaenh.dll'
  768. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9120000 'C:\WINDOWS\system32\crypt32.dll'
  769. df0.2050: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\KernelBase.dll'
  770. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7f80000 'C:\WINDOWS\system32\rsaenh.dll'
  771. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9120000 'C:\WINDOWS\system32\crypt32.dll'
  772. df0.2050: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\kernel32.dll'
  773. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9120000 'C:\WINDOWS\system32\crypt32.dll'
  774. df0.2050: supR3HardenedWinIsDesiredRootCA: Adding 0x5ad46780fa5df300 DC=com, DC=microsoft, CN=Microsoft Root Certificate Authority
  775. df0.2050: supR3HardenedWinIsDesiredRootCA: Adding 0xea5386456178582b C=ZA, ST=Western Cape, L=Durbanville, O=Thawte, OU=Thawte Certification, CN=Thawte Timestamping CA
  776. df0.2050: supR3HardenedWinIsDesiredRootCA: Adding 0x3be670c1bd02a900 OU=Copyright (c) 1997 Microsoft Corp., OU=Microsoft Corporation, CN=Microsoft Root Authority
  777. df0.2050: supR3HardenedWinIsDesiredRootCA: Adding 0x4d3835aa4180b200 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2011
  778. df0.2050: supR3HardenedWinIsDesiredRootCA: Adding 0x646e3fe3ba08df00 C=US, O=MSFT, CN=Microsoft Authenticode(tm) Root Authority
  779. df0.2050: supR3HardenedWinIsDesiredRootCA: Adding 0xece4e4289e08b900 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010
  780. df0.2050: supR3HardenedWinIsDesiredRootCA: Adding 0x43a9cc371ff5385a O=Microsoft Trust Network, OU=Microsoft Corporation, OU=Microsoft Time Stamping Service Root, OU=Copyright (c) 1997 Microsoft Corp.
  781. df0.2050: supR3HardenedWinIsDesiredRootCA: Adding 0x2e2d2c7c68f0202e O=VeriSign Trust Network, OU=VeriSign, Inc., OU=VeriSign Time Stamping Service Root, OU=NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.
  782. df0.2050: supR3HardenedWinIsDesiredRootCA: Adding 0xd8dbfb2c27bfb200 C=US, O=thawte, Inc., OU=Certification Services Division, OU=(c) 2008 thawte, Inc. - For authorized use only, CN=thawte Primary Root CA - G3
  783. df0.2050: supR3HardenedWinIsDesiredRootCA: Adding 0x91e3728b8b40d000 C=GB, ST=Greater Manchester, L=Salford, O=COMODO CA Limited, CN=COMODO Certification Authority
  784. df0.2050: supR3HardenedWinIsDesiredRootCA: Adding 0x61a3a33f81aace00 C=US, ST=UT, L=Salt Lake City, O=The USERTRUST Network, OU=http://www.usertrust.com, CN=UTN-USERFirst-Object
  785. df0.2050: supR3HardenedWinIsDesiredRootCA: Adding 0xf4fd306318ccda00 C=US, O=GeoTrust Inc., CN=GeoTrust Global CA
  786. df0.2050: supR3HardenedWinIsDesiredRootCA: Adding 0x83085097e9afdf00 O=Digital Signature Trust Co., CN=DST Root CA X3
  787. df0.2050: supR3HardenedWinIsDesiredRootCA: Adding 0x780679907625cc00 OU=GlobalSign Root CA - R3, O=GlobalSign, CN=GlobalSign
  788. df0.2050: supR3HardenedWinIsDesiredRootCA: Adding 0x3d98ab22bb04a300 C=IE, O=Baltimore, OU=CyberTrust, CN=Baltimore CyberTrust Root
  789. df0.2050: supR3HardenedWinIsDesiredRootCA: Adding 0xa0ee62086758b15d C=US, O=Equifax, OU=Equifax Secure Certificate Authority
  790. df0.2050: supR3HardenedWinIsDesiredRootCA: Adding 0x8ff6fc03c1edbd00 C=US, ST=Arizona, L=Scottsdale, O=Starfield Technologies, Inc., CN=Starfield Root Certificate Authority - G2
  791. df0.2050: supR3HardenedWinIsDesiredRootCA: Adding 0xc6fa4243b695b600 C=US, O=Entrust, Inc., OU=www.entrust.net/CPS is incorporated by reference, OU=(c) 2006 Entrust, Inc., CN=Entrust Root Certification Authority
  792. df0.2050: supR3HardenedWinIsDesiredRootCA: Adding 0xa3ce8d99e60eda00 C=BE, O=GlobalSign nv-sa, OU=Root CA, CN=GlobalSign Root CA
  793. df0.2050: supR3HardenedWinIsDesiredRootCA: Adding 0xa671e9fec832b700 C=US, O=Starfield Technologies, Inc., OU=Starfield Class 2 Certification Authority
  794. df0.2050: supR3HardenedWinIsDesiredRootCA: Adding 0xa8de7211e13be200 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root CA
  795. df0.2050: supR3HardenedWinIsDesiredRootCA: Adding 0x7ae89c50f0b6a00f C=US, O=GTE Corporation, OU=GTE CyberTrust Solutions, Inc., CN=GTE CyberTrust Global Root
  796. df0.2050: supR3HardenedWinIsDesiredRootCA: Adding 0xd45980fbf0a0ac00 C=US, O=thawte, Inc., OU=Certification Services Division, OU=(c) 2006 thawte, Inc. - For authorized use only, CN=thawte Primary Root CA
  797. df0.2050: supR3HardenedWinIsDesiredRootCA: Adding 0x298be035a30bab00 C=DE, O=Deutsche Telekom AG, OU=T-TeleSec Trust Center, CN=Deutsche Telekom Root CA 2
  798. df0.2050: supR3HardenedWinIsDesiredRootCA: Adding 0x14018a1bf29e595c C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority
  799. df0.2050: supR3HardenedWinIsDesiredRootCA: Adding 0x35f812d09650dc00 C=FR, O=Certplus, CN=Class 2 Primary CA
  800. df0.2050: supR3HardenedWinIsDesiredRootCA: Adding 0x9e5bc2d78b6a3636 C=ZA, ST=Western Cape, L=Cape Town, O=Thawte Consulting cc, OU=Certification Services Division, CN=Thawte Premium Server CA, Email=premium-server@thawte.com
  801. df0.2050: supR3HardenedWinIsDesiredRootCA: Adding 0x7c4fd32ec1b1ce00 C=PL, O=Unizeto Sp. z o.o., CN=Certum CA
  802. df0.2050: supR3HardenedWinIsDesiredRootCA: Adding 0xd4fbe673e5ccc600 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA
  803. df0.2050: supR3HardenedWinIsDesiredRootCA: Adding 0x16e64d2a56ccf200 C=US, ST=Arizona, L=Scottsdale, O=Starfield Technologies, Inc., OU=http://certificates.starfieldtech.com/repository/, CN=Starfield Services Root Certificate Authority
  804. df0.2050: supR3HardenedWinIsDesiredRootCA: Adding 0x6e2ba21058eedf00 C=US, ST=UT, L=Salt Lake City, O=The USERTRUST Network, OU=http://www.usertrust.com, CN=UTN - DATACorp SGC
  805. df0.2050: supR3HardenedWinIsDesiredRootCA: Adding 0xb28612a94b4dad00 O=Entrust.net, OU=www.entrust.net/CPS_2048 incorp. by ref. (limits liab.), OU=(c) 1999 Entrust.net Limited, CN=Entrust.net Certification Authority (2048)
  806. df0.2050: supR3HardenedWinIsDesiredRootCA: Adding 0x357a29080824af00 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2006 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G5
  807. df0.2050: supR3HardenedWinIsDesiredRootCA: Adding 0x59faf1086271bf00 C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com, Inc., CN=Go Daddy Root Certificate Authority - G2
  808. df0.2050: supR3HardenedWinIsDesiredRootCA: Adding 0x466cbc09db88c100 C=IL, O=StartCom Ltd., OU=Secure Digital Certificate Signing, CN=StartCom Certification Authority
  809. df0.2050: supR3HardenedWinIsDesiredRootCA: Adding 0x3401b15e3761c700 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2008 VeriSign, Inc. - For authorized use only, CN=VeriSign Universal Root Certification Authority
  810. df0.2050: supR3HardenedWinIsDesiredRootCA: Adding 0x7cd4ff7b15b8be00 C=US, O=GeoTrust Inc., CN=GeoTrust Primary Certification Authority
  811. df0.2050: supR3HardenedWinIsDesiredRootCA: Adding 0x491857ead79dde00 C=US, O=The Go Daddy Group, Inc., OU=Go Daddy Class 2 Certification Authority
  812. df0.2050: supR3HardenedWinIsDesiredRootCA: Adding 0x92ac5ed85c2d0e9b C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2007 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G4
  813. df0.2050: supR3HardenedWinIsDesiredRootCA: Adding 0x8043e4ce150ead00 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID Root CA
  814. df0.2050: supR3HardenedWinIsDesiredRootCA: Adding 0x331d58625ee2dc00 C=US, O=GeoTrust Inc., OU=(c) 2008 GeoTrust Inc. - For authorized use only, CN=GeoTrust Primary Certification Authority - G3
  815. df0.2050: supR3HardenedWinIsDesiredRootCA: Adding 0xf2e6331af7b700 C=SE, O=AddTrust AB, OU=AddTrust External TTP Network, CN=AddTrust External CA Root
  816. df0.2050: supR3HardenedWinIsDesiredRootCA: Adding 0x39bb496d7f0fc200 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Development Root Certificate Authority 2014
  817. df0.2050: supR3HardenedWinRetrieveTrustedRootCAs: cAdded=43
  818. df0.2050: SUPR3HardenedMain: Load Runtime...
  819. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7f80000 'C:\WINDOWS\system32\rsaenh.dll'
  820. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
  821. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
  822. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ws2_32.dll'.
  823. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'rpcrt4.dll'.
  824. df0.2050: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll)WinVerifyTrust
  825. df0.2050: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
  826. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
  827. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
  828. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll
  829. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
  830. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
  831. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7f80000 'C:\WINDOWS\system32\rsaenh.dll'
  832. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9120000 'C:\WINDOWS\system32\crypt32.dll'
  833. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #24 'nsi.dll'.
  834. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'rpcrt4.dll'.
  835. df0.2050: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\ws2_32.dll)WinVerifyTrust
  836. df0.2050: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\ws2_32.dll
  837. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
  838. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
  839. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
  840. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
  841. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll
  842. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
  843. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume4\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
  844. df0.2050: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\nsi.dll'.
  845. df0.2050: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\nsi.dll)
  846. df0.2050: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\nsi.dll
  847. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7f80000 'C:\WINDOWS\system32\rsaenh.dll'
  848. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
  849. df0.2050: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll)WinVerifyTrust
  850. df0.2050: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll
  851. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
  852. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
  853. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
  854. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
  855. df0.2050: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll'.
  856. df0.2050: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll)
  857. df0.2050: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll
  858. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7f80000 'C:\WINDOWS\system32\rsaenh.dll'
  859. df0.2050: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll)WinVerifyTrust
  860. df0.2050: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000a01:<flags> [calling]
  861. df0.2050: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
  862. df0.2050: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll [avoiding WinVerifyTrust]
  863. df0.2050: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll
  864. df0.2050: supR3HardenedDllNotificationCallback: load   0000000066bb0000 LB 0x000d2000 C:\Program Files\Oracle\VirtualBox\MSVCR100.dll [fFlags=0x0]
  865. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll [avoiding WinVerifyTrust]
  866. df0.2050: supR3HardenedDllNotificationCallback: load   0000000066b10000 LB 0x00098000 C:\Program Files\Oracle\VirtualBox\MSVCP100.dll [fFlags=0x0]
  867. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll
  868. df0.2050: supR3HardenedDllNotificationCallback: load   00007ffbd9700000 LB 0x00008000 C:\WINDOWS\system32\NSI.dll [fFlags=0x0]
  869. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\nsi.dll [avoiding WinVerifyTrust]
  870. df0.2050: supR3HardenedDllNotificationCallback: load   00007ffbdb4d0000 LB 0x0005b000 C:\WINDOWS\system32\WS2_32.dll [fFlags=0x0]
  871. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ws2_32.dll
  872. df0.2050: supR3HardenedDllNotificationCallback: load   00007ffbcd8d0000 LB 0x00542000 C:\Program Files\Oracle\VirtualBox\VBoxRT.dll [fFlags=0x0]
  873. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
  874. df0.2050: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll'.
  875. df0.2050: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
  876. df0.2050: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\nsi.dll'.
  877. df0.2050: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\nsi.dll' [rescheduled]
  878. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
  879. df0.2050: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  880. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcd8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  881. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
  882. df0.2050: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  883. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcd8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  884. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
  885. df0.2050: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  886. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcd8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  887. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
  888. df0.2050: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  889. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcd8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  890. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
  891. df0.2050: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  892. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcd8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  893. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
  894. df0.2050: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  895. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcd8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  896. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcd8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  897. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcd8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  898. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcd8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  899. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcd8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  900. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcd8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  901. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcd8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  902. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcd8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  903. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
  904. df0.2050: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  905. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcd8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  906. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcd8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  907. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcd8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  908. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcd8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  909. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcd8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  910. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcd8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  911. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcd8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  912. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcd8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  913. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcd8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  914. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcd8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  915. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcd8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  916. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcd8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  917. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcd8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  918. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcd8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  919. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcd8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  920. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcd8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  921. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxRT.dll
  922. df0.2050: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  923. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcd8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  924. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcd8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  925. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcd8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  926. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcd8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  927. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9350000 'C:\WINDOWS\system32\Wintrust.dll'
  928. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7f80000 'C:\WINDOWS\system32\rsaenh.dll'
  929. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9120000 'C:\WINDOWS\system32\crypt32.dll'
  930. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rsaenh.dll
  931. df0.2050: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  932. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7f80000 'C:\WINDOWS\system32\rsaenh.dll'
  933. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9120000 'C:\WINDOWS\system32\crypt32.dll'
  934. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9120000 'C:\WINDOWS\system32\crypt32.dll'
  935. df0.2050: Error -1912 in supR3HardenedMainInitRuntime! (enmWhat=4)
  936. df0.2050: RTR3InitEx failed with rc=-1912
  937. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7f80000 'C:\WINDOWS\system32\rsaenh.dll'
  938. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'opengl32.dll'.
  939. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
  940. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msvcp100.dll'.
  941. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcr100.dll'.
  942. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qtcorevbox4.dll'.
  943. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'qtguivbox4.dll'.
  944. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'qtnetworkvbox4.dll'.
  945. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'qtopenglvbox4.dll'.
  946. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'user32.dll'.
  947. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'gdi32.dll'.
  948. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'advapi32.dll'.
  949. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'shell32.dll'.
  950. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'ole32.dll'.
  951. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'oleaut32.dll'.
  952. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #15 'comdlg32.dll'.
  953. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'winmm.dll'.
  954. df0.2050: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.dll)WinVerifyTrust
  955. df0.2050: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.dll
  956. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
  957. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume4\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
  958. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7f80000 'C:\WINDOWS\system32\rsaenh.dll'
  959. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9120000 'C:\WINDOWS\system32\crypt32.dll'
  960. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'winmmbase.dll'.
  961. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcrt.dll'.
  962. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #32 'user32.dll'.
  963. df0.2050: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\winmm.dll)WinVerifyTrust
  964. df0.2050: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\winmm.dll
  965. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comdlg32.dll'...
  966. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'comdlg32.dll' -> '\Device\HarddiskVolume4\Windows\System32\comdlg32.dll' [rcNtRedir=0xc0150008]
  967. df0.2050: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000047c pwszName=\Device\HarddiskVolume4\Windows\System32\comdlg32.dll
  968. df0.2050: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000001633db0
  969. df0.2050: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000001633db0
  970. df0.2050: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=5997D97350541B1158B81533530D58551CE8DE6E
  971. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
  972. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
  973. df0.2050: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\user32.dll'.
  974. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #31 'gdi32.dll'.
  975. df0.2050: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\user32.dll)
  976. df0.2050: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\user32.dll
  977. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
  978. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
  979. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll
  980. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmmbase.dll'...
  981. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmmbase.dll' -> '\Device\HarddiskVolume4\Windows\System32\winmmbase.dll' [rcNtRedir=0xc0150008]
  982. df0.2050: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\winmmbase.dll'.
  983. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
  984. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'devobj.dll'.
  985. df0.2050: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\winmmbase.dll)
  986. df0.2050: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\winmmbase.dll
  987. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'devobj.dll'...
  988. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'devobj.dll' -> '\Device\HarddiskVolume4\Windows\System32\devobj.dll' [rcNtRedir=0xc0150008]
  989. df0.2050: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\devobj.dll'.
  990. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
  991. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'cfgmgr32.dll'.
  992. df0.2050: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\devobj.dll)
  993. df0.2050: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\devobj.dll
  994. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
  995. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
  996. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
  997. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
  998. df0.2050: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\gdi32.dll'.
  999. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #22 'user32.dll'.
  1000. df0.2050: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\gdi32.dll)
  1001. df0.2050: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\gdi32.dll
  1002. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
  1003. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
  1004. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll [lacks WinVerifyTrust]
  1005. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
  1006. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume4\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
  1007. df0.2050: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\cfgmgr32.dll'.
  1008. df0.2050: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\cfgmgr32.dll)
  1009. df0.2050: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\cfgmgr32.dll
  1010. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
  1011. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
  1012. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7f80000 'C:\WINDOWS\system32\rsaenh.dll'
  1013. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\crypt32.dll
  1014. df0.2050: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  1015. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9120000 'C:\WINDOWS\system32\crypt32.dll'
  1016. df0.2050: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package-AutoMerged-shell~31bf3856ad364e35~amd64~~10.0.10074.0.cat'; file='\Device\HarddiskVolume4\Windows\System32\comdlg32.dll'
  1017. df0.2050: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
  1018. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
  1019. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #27 'user32.dll'.
  1020. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #28 'shlwapi.dll'.
  1021. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #29 'gdi32.dll'.
  1022. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #30 'comctl32.dll'.
  1023. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #31 'shell32.dll'.
  1024. df0.2050: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\comdlg32.dll)WinVerifyTrust
  1025. df0.2050: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\comdlg32.dll
  1026. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
  1027. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume4\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
  1028. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
  1029. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume4\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
  1030. df0.2050: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\shell32.dll'.
  1031. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
  1032. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #64 'user32.dll'.
  1033. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #66 'gdi32.dll'.
  1034. df0.2050: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\shell32.dll)
  1035. df0.2050: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\shell32.dll
  1036. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comctl32.dll'...
  1037. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'comctl32.dll' -> '\Device\HarddiskVolume4\Windows\System32\comctl32.dll' [rcNtRedir=0x0]
  1038. df0.2050: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume4\Windows\System32\comctl32.dll'.
  1039. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'advapi32.dll'.
  1040. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
  1041. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
  1042. df0.2050: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\System32\comctl32.dll)
  1043. df0.2050: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\comctl32.dll
  1044. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
  1045. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
  1046. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
  1047. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
  1048. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume4\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
  1049. df0.2050: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\shlwapi.dll'.
  1050. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
  1051. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #41 'gdi32.dll'.
  1052. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #42 'user32.dll'.
  1053. df0.2050: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\shlwapi.dll)
  1054. df0.2050: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\shlwapi.dll
  1055. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
  1056. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
  1057. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll [lacks WinVerifyTrust]
  1058. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
  1059. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
  1060. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
  1061. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
  1062. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll [lacks WinVerifyTrust]
  1063. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
  1064. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
  1065. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
  1066. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
  1067. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
  1068. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
  1069. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
  1070. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll [lacks WinVerifyTrust]
  1071. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
  1072. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
  1073. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
  1074. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
  1075. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
  1076. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\advapi32.dll
  1077. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
  1078. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
  1079. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
  1080. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
  1081. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
  1082. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll [lacks WinVerifyTrust]
  1083. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
  1084. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
  1085. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7f80000 'C:\WINDOWS\system32\rsaenh.dll'
  1086. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9120000 'C:\WINDOWS\system32\crypt32.dll'
  1087. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
  1088. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'combase.dll'.
  1089. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'rpcrt4.dll'.
  1090. df0.2050: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\oleaut32.dll)WinVerifyTrust
  1091. df0.2050: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\oleaut32.dll
  1092. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
  1093. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
  1094. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
  1095. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
  1096. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll
  1097. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
  1098. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume4\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
  1099. df0.2050: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\combase.dll'.
  1100. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
  1101. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'rpcrt4.dll'.
  1102. df0.2050: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\combase.dll)
  1103. df0.2050: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\combase.dll
  1104. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
  1105. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
  1106. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
  1107. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
  1108. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
  1109. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
  1110. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7f80000 'C:\WINDOWS\system32\rsaenh.dll'
  1111. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9120000 'C:\WINDOWS\system32\crypt32.dll'
  1112. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
  1113. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'rpcrt4.dll'.
  1114. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #43 'gdi32.dll'.
  1115. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #44 'user32.dll'.
  1116. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #45 'combase.dll'.
  1117. df0.2050: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\ole32.dll)WinVerifyTrust
  1118. df0.2050: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\ole32.dll
  1119. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
  1120. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume4\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
  1121. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\shell32.dll [redoing WinVerifyTrust]
  1122. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
  1123. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume4\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
  1124. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\combase.dll [lacks WinVerifyTrust]
  1125. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
  1126. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
  1127. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll [lacks WinVerifyTrust]
  1128. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
  1129. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
  1130. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
  1131. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
  1132. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
  1133. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
  1134. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
  1135. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll
  1136. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7f80000 'C:\WINDOWS\system32\rsaenh.dll'
  1137. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9120000 'C:\WINDOWS\system32\crypt32.dll'
  1138. df0.2050: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\shell32.dll'
  1139. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
  1140. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
  1141. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\advapi32.dll
  1142. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
  1143. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
  1144. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gdi32.dll [redoing WinVerifyTrust]
  1145. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7f80000 'C:\WINDOWS\system32\rsaenh.dll'
  1146. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9120000 'C:\WINDOWS\system32\crypt32.dll'
  1147. df0.2050: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\gdi32.dll'
  1148. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
  1149. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
  1150. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll [redoing WinVerifyTrust]
  1151. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7f80000 'C:\WINDOWS\system32\rsaenh.dll'
  1152. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9120000 'C:\WINDOWS\system32\crypt32.dll'
  1153. df0.2050: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\user32.dll'
  1154. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtopenglvbox4.dll'...
  1155. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtopenglvbox4.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qtopenglvbox4.dll' [rcNtRedir=0xc0150008]
  1156. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7f80000 'C:\WINDOWS\system32\rsaenh.dll'
  1157. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'opengl32.dll'.
  1158. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
  1159. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
  1160. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qtguivbox4.dll'.
  1161. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qtcorevbox4.dll'.
  1162. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcr100.dll'.
  1163. df0.2050: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll)WinVerifyTrust
  1164. df0.2050: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll
  1165. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtnetworkvbox4.dll'...
  1166. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtnetworkvbox4.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qtnetworkvbox4.dll' [rcNtRedir=0xc0150008]
  1167. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
  1168. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
  1169. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
  1170. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtcorevbox4.dll'...
  1171. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtcorevbox4.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qtcorevbox4.dll' [rcNtRedir=0xc0150008]
  1172. df0.2050: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll'.
  1173. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
  1174. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'ole32.dll'.
  1175. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
  1176. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ws2_32.dll'.
  1177. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcp100.dll'.
  1178. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msvcr100.dll'.
  1179. df0.2050: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll)
  1180. df0.2050: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll
  1181. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtguivbox4.dll'...
  1182. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtguivbox4.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qtguivbox4.dll' [rcNtRedir=0xc0150008]
  1183. df0.2050: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll'.
  1184. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
  1185. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'comdlg32.dll'.
  1186. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'oleaut32.dll'.
  1187. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'imm32.dll'.
  1188. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'winmm.dll'.
  1189. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'winspool.drv'.
  1190. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'ole32.dll'.
  1191. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'user32.dll'.
  1192. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'advapi32.dll'.
  1193. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'shell32.dll'.
  1194. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'qtcorevbox4.dll'.
  1195. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'msvcp100.dll'.
  1196. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'msvcr100.dll'.
  1197. df0.2050: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll)
  1198. df0.2050: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll
  1199. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
  1200. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
  1201. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll
  1202. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
  1203. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
  1204. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gdi32.dll
  1205. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
  1206. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume4\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
  1207. df0.2050: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume4\Windows\System32\opengl32.dll'.
  1208. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
  1209. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
  1210. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'gdi32.dll'.
  1211. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'glu32.dll'.
  1212. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'ddraw.dll'.
  1213. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'user32.dll'.
  1214. df0.2050: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\System32\opengl32.dll)
  1215. df0.2050: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\opengl32.dll
  1216. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
  1217. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
  1218. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ddraw.dll'...
  1219. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'ddraw.dll' -> '\Device\HarddiskVolume4\Windows\System32\ddraw.dll' [rcNtRedir=0xc0150008]
  1220. df0.2050: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume4\Windows\System32\ddraw.dll'.
  1221. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
  1222. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #19 'user32.dll'.
  1223. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #20 'gdi32.dll'.
  1224. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #21 'dciman32.dll'.
  1225. df0.2050: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\System32\ddraw.dll)
  1226. df0.2050: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\ddraw.dll
  1227. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'glu32.dll'...
  1228. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'glu32.dll' -> '\Device\HarddiskVolume4\Windows\System32\glu32.dll' [rcNtRedir=0xc0150008]
  1229. df0.2050: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume4\Windows\System32\glu32.dll'.
  1230. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
  1231. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'opengl32.dll'.
  1232. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
  1233. df0.2050: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\System32\glu32.dll)
  1234. df0.2050: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\glu32.dll
  1235. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
  1236. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
  1237. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gdi32.dll
  1238. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
  1239. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
  1240. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\advapi32.dll
  1241. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
  1242. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
  1243. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
  1244. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
  1245. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
  1246. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
  1247. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
  1248. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll
  1249. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtcorevbox4.dll'...
  1250. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtcorevbox4.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qtcorevbox4.dll' [rcNtRedir=0xc0150008]
  1251. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll [lacks WinVerifyTrust]
  1252. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
  1253. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume4\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
  1254. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\shell32.dll
  1255. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
  1256. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
  1257. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\advapi32.dll
  1258. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
  1259. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
  1260. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
  1261. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
  1262. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ole32.dll
  1263. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winspool.drv'...
  1264. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'winspool.drv' -> '\Device\HarddiskVolume4\Windows\System32\winspool.drv' [rcNtRedir=0xc0150008]
  1265. df0.2050: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume4\Windows\System32\winspool.drv'.
  1266. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
  1267. df0.2050: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\System32\winspool.drv)
  1268. df0.2050: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\winspool.drv
  1269. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
  1270. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume4\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
  1271. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winmm.dll
  1272. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
  1273. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume4\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
  1274. df0.2050: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\imm32.dll'.
  1275. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'user32.dll'.
  1276. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'msctf.dll'.
  1277. df0.2050: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\imm32.dll)
  1278. df0.2050: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\imm32.dll
  1279. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
  1280. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume4\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
  1281. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\oleaut32.dll
  1282. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comdlg32.dll'...
  1283. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'comdlg32.dll' -> '\Device\HarddiskVolume4\Windows\System32\comdlg32.dll' [rcNtRedir=0xc0150008]
  1284. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\comdlg32.dll
  1285. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
  1286. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
  1287. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
  1288. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
  1289. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
  1290. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
  1291. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
  1292. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll
  1293. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
  1294. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
  1295. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ws2_32.dll
  1296. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
  1297. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
  1298. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\advapi32.dll
  1299. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
  1300. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
  1301. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ole32.dll
  1302. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
  1303. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
  1304. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msctf.dll'...
  1305. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'msctf.dll' -> '\Device\HarddiskVolume4\Windows\System32\msctf.dll' [rcNtRedir=0xc0150008]
  1306. df0.2050: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\msctf.dll'.
  1307. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
  1308. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'user32.dll'.
  1309. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'gdi32.dll'.
  1310. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #27 'imm32.dll'.
  1311. df0.2050: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\msctf.dll)
  1312. df0.2050: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\msctf.dll
  1313. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
  1314. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
  1315. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
  1316. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
  1317. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
  1318. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
  1319. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
  1320. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume4\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
  1321. df0.2050: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\opengl32.dll [lacks WinVerifyTrust]
  1322. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
  1323. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
  1324. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dciman32.dll'...
  1325. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'dciman32.dll' -> '\Device\HarddiskVolume4\Windows\System32\dciman32.dll' [rcNtRedir=0xc0150008]
  1326. df0.2050: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume4\Windows\System32\dciman32.dll'.
  1327. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
  1328. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'gdi32.dll'.
  1329. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
  1330. df0.2050: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\System32\dciman32.dll)
  1331. df0.2050: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\dciman32.dll
  1332. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
  1333. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
  1334. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
  1335. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
  1336. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
  1337. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
  1338. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
  1339. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
  1340. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
  1341. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
  1342. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
  1343. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
  1344. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
  1345. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume4\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
  1346. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\imm32.dll [lacks WinVerifyTrust]
  1347. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
  1348. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
  1349. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
  1350. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
  1351. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\user32.dll
  1352. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
  1353. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
  1354. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7f80000 'C:\WINDOWS\system32\rsaenh.dll'
  1355. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ws2_32.dll'.
  1356. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'qtcorevbox4.dll'.
  1357. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msvcr100.dll'.
  1358. df0.2050: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtNetworkVBox4.dll)WinVerifyTrust
  1359. df0.2050: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtNetworkVBox4.dll
  1360. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtguivbox4.dll'...
  1361. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtguivbox4.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qtguivbox4.dll' [rcNtRedir=0xc0150008]
  1362. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll [redoing WinVerifyTrust]
  1363. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
  1364. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
  1365. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
  1366. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtcorevbox4.dll'...
  1367. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtcorevbox4.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qtcorevbox4.dll' [rcNtRedir=0xc0150008]
  1368. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll [lacks WinVerifyTrust]
  1369. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
  1370. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume4\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
  1371. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ws2_32.dll
  1372. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7f80000 'C:\WINDOWS\system32\rsaenh.dll'
  1373. df0.2050: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll'
  1374. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qtcorevbox4.dll'...
  1375. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'qtcorevbox4.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\qtcorevbox4.dll' [rcNtRedir=0xc0150008]
  1376. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll [redoing WinVerifyTrust]
  1377. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7f80000 'C:\WINDOWS\system32\rsaenh.dll'
  1378. df0.2050: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll'
  1379. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
  1380. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
  1381. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll [redoing WinVerifyTrust]
  1382. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7f80000 'C:\WINDOWS\system32\rsaenh.dll'
  1383. df0.2050: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcr100.dll'
  1384. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
  1385. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
  1386. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\msvcp100.dll
  1387. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
  1388. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
  1389. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
  1390. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume4\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
  1391. df0.2050: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\opengl32.dll [redoing WinVerifyTrust]
  1392. df0.2050: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004c8 pwszName=\Device\HarddiskVolume4\Windows\System32\opengl32.dll
  1393. df0.2050: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000001633db0
  1394. df0.2050: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000001633db0
  1395. df0.2050: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=0F243467B38B389F3F39A431759E75007C8BD33E
  1396. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7f80000 'C:\WINDOWS\system32\rsaenh.dll'
  1397. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9120000 'C:\WINDOWS\system32\crypt32.dll'
  1398. df0.2050: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package-AutoMerged-windows~31bf3856ad364e35~amd64~~10.0.10074.0.cat'; file='\Device\HarddiskVolume4\Windows\System32\opengl32.dll'
  1399. df0.2050: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
  1400. df0.2050: supR3HardenedScreenImage/Imports: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\opengl32.dll'
  1401. df0.2050: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VirtualBox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000a01:<flags> [calling]
  1402. df0.2050: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.dll
  1403. df0.2050: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\opengl32.dll
  1404. df0.2050: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll
  1405. df0.2050: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll
  1406. df0.2050: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtNetworkVBox4.dll
  1407. df0.2050: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll
  1408. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'advapi32.dll'.
  1409. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
  1410. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
  1411. df0.2050: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.10074.0_none_3a21e2bb56334ae1\comctl32.dll)
  1412. df0.2050: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.10074.0_none_3a21e2bb56334ae1\comctl32.dll
  1413. df0.2050: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winmm.dll
  1414. df0.2050: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\glu32.dll [avoiding WinVerifyTrust]
  1415. df0.2050: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\ddraw.dll [avoiding WinVerifyTrust]
  1416. df0.2050: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\winspool.drv [avoiding WinVerifyTrust]
  1417. df0.2050: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winmmbase.dll [avoiding WinVerifyTrust]
  1418. df0.2050: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\dciman32.dll [avoiding WinVerifyTrust]
  1419. df0.2050: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\devobj.dll [avoiding WinVerifyTrust]
  1420. df0.2050: supR3HardenedDllNotificationCallback: load   00007ffbdb6c0000 LB 0x0016c000 C:\WINDOWS\system32\USER32.dll [fFlags=0x0]
  1421. df0.2050: supR3HardenedDllNotificationCallback: load   00007ffbdb860000 LB 0x00181000 C:\WINDOWS\system32\GDI32.dll [fFlags=0x0]
  1422. df0.2050: supR3HardenedDllNotificationCallback: load   00007ffbc6510000 LB 0x00008000 C:\WINDOWS\SYSTEM32\DCIMAN32.dll [fFlags=0x0]
  1423. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\dciman32.dll [avoiding WinVerifyTrust]
  1424. df0.2050: supR3HardenedDllNotificationCallback: load   00007ffbc0bc0000 LB 0x000f7000 C:\WINDOWS\SYSTEM32\DDRAW.dll [fFlags=0x0]
  1425. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\ddraw.dll [avoiding WinVerifyTrust]
  1426. df0.2050: supR3HardenedDllNotificationCallback: load   00007ffbc0cc0000 LB 0x0002e000 C:\WINDOWS\SYSTEM32\GLU32.dll [fFlags=0x0]
  1427. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\glu32.dll [avoiding WinVerifyTrust]
  1428. df0.2050: supR3HardenedDllNotificationCallback: load   00007ffbc0d30000 LB 0x00128000 C:\WINDOWS\SYSTEM32\OPENGL32.dll [fFlags=0x0]
  1429. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\opengl32.dll
  1430. df0.2050: supR3HardenedDllNotificationCallback: load   00007ffbd9950000 LB 0x00256000 C:\WINDOWS\system32\combase.dll [fFlags=0x0]
  1431. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\combase.dll [avoiding WinVerifyTrust]
  1432. df0.2050: supR3HardenedDllNotificationCallback: load   00007ffbdb530000 LB 0x0013b000 C:\WINDOWS\system32\ole32.dll [fFlags=0x0]
  1433. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ole32.dll
  1434. df0.2050: supR3HardenedDllNotificationCallback: load   0000000065cd0000 LB 0x002de000 C:\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll [fFlags=0x0]
  1435. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll
  1436. df0.2050: supR3HardenedDllNotificationCallback: load   00007ffbd9650000 LB 0x000ac000 C:\WINDOWS\system32\shcore.dll [fFlags=0x0]
  1437. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
  1438. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #38 'combase.dll'.
  1439. df0.2050: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\SHCore.dll)
  1440. df0.2050: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\SHCore.dll
  1441. df0.2050: supR3HardenedDllNotificationCallback: load   00007ffbdb670000 LB 0x00050000 C:\WINDOWS\system32\shlwapi.dll [fFlags=0x0]
  1442. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\shlwapi.dll [avoiding WinVerifyTrust]
  1443. df0.2050: supR3HardenedDllNotificationCallback: load   00007ffbc0410000 LB 0x000aa000 C:\WINDOWS\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.10074.0_none_3a21e2bb56334ae1\COMCTL32.dll [fFlags=0x0]
  1444. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.10074.0_none_3a21e2bb56334ae1\comctl32.dll [avoiding WinVerifyTrust]
  1445. df0.2050: supR3HardenedDllNotificationCallback: load   00007ffbd8ac0000 LB 0x0000e000 C:\WINDOWS\system32\kernel.appcore.dll [fFlags=0x0]
  1446. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcrt.dll'.
  1447. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'rpcrt4.dll'.
  1448. df0.2050: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\kernel.appcore.dll)
  1449. df0.2050: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\kernel.appcore.dll
  1450. df0.2050: supR3HardenedDllNotificationCallback: load   00007ffbd8af0000 LB 0x00048000 C:\WINDOWS\system32\powrprof.dll [fFlags=0x0]
  1451. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
  1452. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'rpcrt4.dll'.
  1453. df0.2050: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\powrprof.dll)
  1454. df0.2050: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\powrprof.dll
  1455. df0.2050: supR3HardenedDllNotificationCallback: load   00007ffbd8b40000 LB 0x005d4000 C:\WINDOWS\system32\windows.storage.dll [fFlags=0x0]
  1456. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
  1457. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #30 'rpcrt4.dll'.
  1458. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #60 'combase.dll'.
  1459. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #66 'profapi.dll'.
  1460. df0.2050: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\windows.storage.dll)
  1461. df0.2050: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\windows.storage.dll
  1462. df0.2050: supR3HardenedDllNotificationCallback: load   00007ffbd9e80000 LB 0x0140d000 C:\WINDOWS\system32\SHELL32.dll [fFlags=0x0]
  1463. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\shell32.dll
  1464. df0.2050: supR3HardenedDllNotificationCallback: load   00007ffbdbaf0000 LB 0x000d0000 C:\WINDOWS\system32\COMDLG32.dll [fFlags=0x0]
  1465. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\comdlg32.dll
  1466. df0.2050: supR3HardenedDllNotificationCallback: load   00007ffbd9bb0000 LB 0x000be000 C:\WINDOWS\system32\OLEAUT32.dll [fFlags=0x0]
  1467. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\oleaut32.dll
  1468. df0.2050: supR3HardenedDllNotificationCallback: load   00007ffbd9c70000 LB 0x0015c000 C:\WINDOWS\system32\MSCTF.dll [fFlags=0x0]
  1469. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msctf.dll [avoiding WinVerifyTrust]
  1470. df0.2050: supR3HardenedDllNotificationCallback: load   00007ffbdbbc0000 LB 0x00035000 C:\WINDOWS\system32\IMM32.dll [fFlags=0x0]
  1471. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\imm32.dll [avoiding WinVerifyTrust]
  1472. df0.2050: supR3HardenedDllNotificationCallback: load   00007ffbd9300000 LB 0x00044000 C:\WINDOWS\system32\cfgmgr32.dll [fFlags=0x0]
  1473. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\cfgmgr32.dll [avoiding WinVerifyTrust]
  1474. df0.2050: supR3HardenedDllNotificationCallback: load   00007ffbd7280000 LB 0x00026000 C:\WINDOWS\SYSTEM32\DEVOBJ.dll [fFlags=0x0]
  1475. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\devobj.dll [avoiding WinVerifyTrust]
  1476. df0.2050: supR3HardenedDllNotificationCallback: load   00007ffbc8c70000 LB 0x0002b000 C:\WINDOWS\SYSTEM32\WINMMBASE.dll [fFlags=0x0]
  1477. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winmmbase.dll [avoiding WinVerifyTrust]
  1478. df0.2050: supR3HardenedDllNotificationCallback: load   00007ffbc8ca0000 LB 0x00022000 C:\WINDOWS\SYSTEM32\WINMM.dll [fFlags=0x0]
  1479. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winmm.dll
  1480. df0.2050: supR3HardenedDllNotificationCallback: load   00007ffbce050000 LB 0x00083000 C:\WINDOWS\SYSTEM32\WINSPOOL.DRV [fFlags=0x0]
  1481. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\winspool.drv [avoiding WinVerifyTrust]
  1482. df0.2050: supR3HardenedDllNotificationCallback: load   0000000065fb0000 LB 0x00969000 C:\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll [fFlags=0x0]
  1483. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll
  1484. df0.2050: supR3HardenedDllNotificationCallback: load   0000000066a00000 LB 0x00105000 C:\Program Files\Oracle\VirtualBox\QtNetworkVBox4.dll [fFlags=0x0]
  1485. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtNetworkVBox4.dll
  1486. df0.2050: supR3HardenedDllNotificationCallback: load   0000000066920000 LB 0x000dc000 C:\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll [fFlags=0x0]
  1487. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll
  1488. df0.2050: supR3HardenedDllNotificationCallback: load   00007ffbbaf80000 LB 0x00a9e000 C:\Program Files\Oracle\VirtualBox\VirtualBox.dll [fFlags=0x0]
  1489. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.dll
  1490. df0.2050: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\windows.storage.dll'.
  1491. df0.2050: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\windows.storage.dll' [rescheduled]
  1492. df0.2050: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\powrprof.dll'.
  1493. df0.2050: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\powrprof.dll' [rescheduled]
  1494. df0.2050: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\kernel.appcore.dll'.
  1495. df0.2050: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\kernel.appcore.dll' [rescheduled]
  1496. df0.2050: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\SHCore.dll'.
  1497. df0.2050: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\SHCore.dll' [rescheduled]
  1498. df0.2050: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume4\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.10074.0_none_3a21e2bb56334ae1\comctl32.dll'.
  1499. df0.2050: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.10074.0_none_3a21e2bb56334ae1\comctl32.dll' [rescheduled]
  1500. df0.2050: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume4\Windows\System32\dciman32.dll'.
  1501. df0.2050: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\dciman32.dll' [rescheduled]
  1502. df0.2050: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\msctf.dll'.
  1503. df0.2050: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\msctf.dll' [rescheduled]
  1504. df0.2050: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\imm32.dll'.
  1505. df0.2050: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\imm32.dll' [rescheduled]
  1506. df0.2050: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume4\Windows\System32\winspool.drv'.
  1507. df0.2050: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\winspool.drv' [rescheduled]
  1508. df0.2050: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume4\Windows\System32\glu32.dll'.
  1509. df0.2050: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\glu32.dll' [rescheduled]
  1510. df0.2050: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume4\Windows\System32\ddraw.dll'.
  1511. df0.2050: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\ddraw.dll' [rescheduled]
  1512. df0.2050: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\combase.dll'.
  1513. df0.2050: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\combase.dll' [rescheduled]
  1514. df0.2050: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\shlwapi.dll'.
  1515. df0.2050: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\shlwapi.dll' [rescheduled]
  1516. df0.2050: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume4\Windows\System32\comctl32.dll'.
  1517. df0.2050: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\comctl32.dll' [rescheduled]
  1518. df0.2050: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\cfgmgr32.dll'.
  1519. df0.2050: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\cfgmgr32.dll' [rescheduled]
  1520. df0.2050: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\devobj.dll'.
  1521. df0.2050: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\devobj.dll' [rescheduled]
  1522. df0.2050: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\winmmbase.dll'.
  1523. df0.2050: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume4\Windows\System32\winmmbase.dll' [rescheduled]
  1524. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\imm32.dll [redoing WinVerifyTrust]
  1525. df0.2050: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\imm32.dll'.
  1526. df0.2050: supR3HardenedScreenImage/LdrLoadDll: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume4\Windows\System32\imm32.dll
  1527. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'profapi.dll'...
  1528. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'profapi.dll' -> '\Device\HarddiskVolume4\Windows\System32\profapi.dll' [rcNtRedir=0xc0150008]
  1529. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\profapi.dll
  1530. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
  1531. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume4\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
  1532. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\combase.dll [redoing WinVerifyTrust]
  1533. df0.2050: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\combase.dll'.
  1534. df0.2050: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume4\Windows\System32\combase.dll
  1535. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
  1536. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
  1537. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
  1538. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
  1539. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
  1540. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
  1541. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
  1542. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
  1543. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
  1544. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
  1545. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
  1546. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
  1547. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
  1548. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume4\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
  1549. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\combase.dll [redoing WinVerifyTrust]
  1550. df0.2050: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume4\Windows\System32\combase.dll'.
  1551. df0.2050: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume4\Windows\System32\combase.dll
  1552. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
  1553. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
  1554. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
  1555. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
  1556. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
  1557. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
  1558. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
  1559. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
  1560. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\advapi32.dll
  1561. df0.2050: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\imm32.dll (Input=imm32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  1562. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbdbbc0000 'C:\WINDOWS\system32\imm32.dll'
  1563. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbbaf80000 'C:\Program Files\Oracle\VirtualBox\VirtualBox.dll'
  1564. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winmm.dll
  1565. df0.2050: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\winmm.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  1566. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbc8ca0000 'C:\WINDOWS\system32\winmm.dll'
  1567. df0.2050: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000620 pwszName=\Device\HarddiskVolume4\Windows\System32\uxtheme.dll
  1568. df0.2050: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000001633db0
  1569. df0.2050: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000001633db0
  1570. df0.2050: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=BC0B49CD4C9AE2496DD3C855F463DF822B214D30
  1571. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7f80000 'C:\WINDOWS\system32\rsaenh.dll'
  1572. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9120000 'C:\WINDOWS\system32\crypt32.dll'
  1573. df0.2050: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package-AutoMerged-shell~31bf3856ad364e35~amd64~~10.0.10074.0.cat'; file='\Device\HarddiskVolume4\Windows\System32\uxtheme.dll'
  1574. df0.2050: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
  1575. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
  1576. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #32 'gdi32.dll'.
  1577. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #33 'user32.dll'.
  1578. df0.2050: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\uxtheme.dll)WinVerifyTrust
  1579. df0.2050: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\uxtheme.dll
  1580. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
  1581. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
  1582. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
  1583. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
  1584. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
  1585. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
  1586. df0.2050: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
  1587. df0.2050: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\uxtheme.dll
  1588. df0.2050: supR3HardenedDllNotificationCallback: load   00007ffbd7530000 LB 0x0008f000 C:\WINDOWS\system32\uxtheme.dll [fFlags=0x0]
  1589. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\uxtheme.dll
  1590. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7530000 'C:\WINDOWS\system32\uxtheme.dll'
  1591. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
  1592. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'rpcrt4.dll'.
  1593. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'iertutil.dll'.
  1594. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'oleaut32.dll'.
  1595. df0.2050: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\System32\edputil.dll)
  1596. df0.2050: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\edputil.dll
  1597. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
  1598. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'combase.dll'.
  1599. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'rpcrt4.dll'.
  1600. df0.2050: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\WinTypes.dll)
  1601. df0.2050: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\WinTypes.dll
  1602. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
  1603. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #45 'cryptsp.dll'.
  1604. df0.2050: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\iertutil.dll)
  1605. df0.2050: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\iertutil.dll
  1606. df0.2050: supR3HardenedDllNotificationCallback: load   00007ffbd70c0000 LB 0x00125000 C:\WINDOWS\SYSTEM32\wintypes.dll [fFlags=0x0]
  1607. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\WinTypes.dll [avoiding WinVerifyTrust]
  1608. df0.2050: supR3HardenedDllNotificationCallback: load   00007ffbd6c60000 LB 0x0034e000 C:\WINDOWS\SYSTEM32\iertutil.dll [fFlags=0x0]
  1609. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\iertutil.dll [avoiding WinVerifyTrust]
  1610. df0.2050: supR3HardenedDllNotificationCallback: load   00007ffbd72b0000 LB 0x00025000 C:\WINDOWS\SYSTEM32\edputil.dll [fFlags=0x0]
  1611. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\edputil.dll [avoiding WinVerifyTrust]
  1612. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
  1613. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'user32.dll'.
  1614. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'gdi32.dll'.
  1615. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #15 'dcomp.dll'.
  1616. df0.2050: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume4\Windows\System32\dwmapi.dll)
  1617. df0.2050: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\dwmapi.dll
  1618. df0.2050: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
  1619. df0.2050: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\dcomp.dll)
  1620. df0.2050: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\dcomp.dll
  1621. df0.2050: supR3HardenedDllNotificationCallback: load   00007ffbd7380000 LB 0x000c9000 C:\WINDOWS\system32\dcomp.dll [fFlags=0x0]
  1622. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\dcomp.dll [avoiding WinVerifyTrust]
  1623. df0.2050: supR3HardenedDllNotificationCallback: load   00007ffbd5d40000 LB 0x00020000 C:\WINDOWS\system32\dwmapi.dll [fFlags=0x0]
  1624. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume4\Windows\System32\dwmapi.dll [avoiding WinVerifyTrust]
  1625. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
  1626. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
  1627. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dcomp.dll'...
  1628. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'dcomp.dll' -> '\Device\HarddiskVolume4\Windows\System32\dcomp.dll' [rcNtRedir=0xc0150008]
  1629. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\dcomp.dll [lacks WinVerifyTrust]
  1630. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
  1631. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume4\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
  1632. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\gdi32.dll
  1633. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
  1634. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
  1635. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
  1636. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
  1637. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cryptsp.dll'...
  1638. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'cryptsp.dll' -> '\Device\HarddiskVolume4\Windows\System32\cryptsp.dll' [rcNtRedir=0xc0150008]
  1639. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\cryptsp.dll
  1640. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
  1641. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
  1642. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
  1643. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
  1644. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
  1645. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume4\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
  1646. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\combase.dll [lacks WinVerifyTrust]
  1647. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
  1648. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
  1649. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
  1650. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume4\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
  1651. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\oleaut32.dll
  1652. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'iertutil.dll'...
  1653. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'iertutil.dll' -> '\Device\HarddiskVolume4\Windows\System32\iertutil.dll' [rcNtRedir=0xc0150008]
  1654. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\iertutil.dll [lacks WinVerifyTrust]
  1655. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
  1656. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
  1657. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
  1658. df0.2050: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
  1659. df0.2050: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msvcrt.dll
  1660. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7f80000 'C:\WINDOWS\system32\rsaenh.dll'
  1661. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9120000 'C:\WINDOWS\system32\crypt32.dll'
  1662. df0.2050: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\dcomp.dll'
  1663. df0.2050: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000650 pwszName=\Device\HarddiskVolume4\Windows\System32\dwmapi.dll
  1664. df0.2050: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000001633db0
  1665. df0.2050: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000001633db0
  1666. df0.2050: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=96BB1C44148B7923D3097A690A78A21E9ABCDDED
  1667. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7f80000 'C:\WINDOWS\system32\rsaenh.dll'
  1668. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9120000 'C:\WINDOWS\system32\crypt32.dll'
  1669. df0.2050: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Composition-Core-windows-Package~31bf3856ad364e35~amd64~~10.0.10074.0.cat'; file='\Device\HarddiskVolume4\Windows\System32\dwmapi.dll'
  1670. df0.2050: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
  1671. df0.2050: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\dwmapi.dll'
  1672. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7f80000 'C:\WINDOWS\system32\rsaenh.dll'
  1673. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9120000 'C:\WINDOWS\system32\crypt32.dll'
  1674. df0.2050: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\iertutil.dll'
  1675. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7f80000 'C:\WINDOWS\system32\rsaenh.dll'
  1676. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9120000 'C:\WINDOWS\system32\crypt32.dll'
  1677. df0.2050: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\WinTypes.dll'
  1678. df0.2050: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000063c pwszName=\Device\HarddiskVolume4\Windows\System32\edputil.dll
  1679. df0.2050: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000001633db0
  1680. df0.2050: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000001633db0
  1681. df0.2050: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=25B755D2EDF7ED52617E5A8F7F4AD10128BF64D7
  1682. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7f80000 'C:\WINDOWS\system32\rsaenh.dll'
  1683. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9120000 'C:\WINDOWS\system32\crypt32.dll'
  1684. df0.2050: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package-AutoMerged-ds~31bf3856ad364e35~amd64~~10.0.10074.0.cat'; file='\Device\HarddiskVolume4\Windows\System32\edputil.dll'
  1685. df0.2050: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
  1686. df0.2050: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\edputil.dll'
  1687. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\shell32.dll
  1688. df0.2050: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  1689. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9e80000 'C:\WINDOWS\system32\shell32.dll'
  1690. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\kernel32.dll
  1691. df0.2050: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\kernel32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  1692. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbdb3c0000 'C:\WINDOWS\system32\kernel32.dll'
  1693. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\uxtheme.dll
  1694. df0.2050: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  1695. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7530000 'C:\WINDOWS\system32\uxtheme.dll'
  1696. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\uxtheme.dll
  1697. df0.2050: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  1698. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7530000 'C:\WINDOWS\system32\uxtheme.dll'
  1699. df0.2050: supR3HardenedMonitor_LdrLoadDll: error opening 'C:\WINDOWS\system32\wintab32.dll': 0 (NtPath=\??\C:\WINDOWS\system32\wintab32.dll; Input=C:\WINDOWS\system32\wintab32.dll; rcNtGetDll=0x0
  1700. df0.2050: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\wintab32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  1701. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000135 'C:\WINDOWS\system32\wintab32.dll'
  1702. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbdb6c0000 'C:\WINDOWS\system32\user32.dll'
  1703. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\uxtheme.dll
  1704. df0.2050: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  1705. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7530000 'C:\WINDOWS\system32\uxtheme.dll'
  1706. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbdb6c0000 'C:\WINDOWS\system32\user32.dll'
  1707. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbdb860000 'C:\WINDOWS\system32\gdi32.dll'
  1708. df0.2050: supR3HardenedMonitor_LdrLoadDll: error opening 'C:\WINDOWS\system32\wintab32.dll': 0 (NtPath=\??\C:\WINDOWS\system32\wintab32.dll; Input=C:\WINDOWS\system32\wintab32.dll; rcNtGetDll=0x0
  1709. df0.2050: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\wintab32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  1710. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000135 'C:\WINDOWS\system32\wintab32.dll'
  1711. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbdb6c0000 'C:\WINDOWS\system32\user32.dll'
  1712. df0.2048: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winmm.dll
  1713. df0.2048: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\SYSTEM32\WINMM.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  1714. df0.2048: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbc8ca0000 'C:\WINDOWS\SYSTEM32\WINMM.dll'
  1715. df0.2050: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msctf.dll [redoing WinVerifyTrust]
  1716. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7f80000 'C:\WINDOWS\system32\rsaenh.dll'
  1717. df0.2048: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
  1718. df0.2048: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'rpcrt4.dll'.
  1719. df0.2048: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'devobj.dll'.
  1720. df0.2048: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\MMDevAPI.dll)
  1721. df0.2048: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\MMDevAPI.dll
  1722. df0.2048: supR3HardenedDllNotificationCallback: load   00007ffbd5100000 LB 0x0006f000 C:\WINDOWS\SYSTEM32\MMDevAPI.DLL [fFlags=0x0]
  1723. df0.2048: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\MMDevAPI.dll [avoiding WinVerifyTrust]
  1724. df0.2048: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'devobj.dll'...
  1725. df0.2048: supR3HardenedWinVerifyCacheProcessImportTodos: 'devobj.dll' -> '\Device\HarddiskVolume4\Windows\System32\devobj.dll' [rcNtRedir=0xc0150008]
  1726. df0.2048: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\devobj.dll [lacks WinVerifyTrust]
  1727. df0.2048: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
  1728. df0.2048: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
  1729. df0.2048: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\rpcrt4.dll
  1730. df0.2048: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
  1731. df0.2048: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
  1732. df0.2048: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7f80000 'C:\WINDOWS\system32\rsaenh.dll'
  1733. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9120000 'C:\WINDOWS\system32\crypt32.dll'
  1734. df0.2048: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9120000 'C:\WINDOWS\system32\crypt32.dll'
  1735. df0.2050: supR3HardenedScreenImage/LdrLoadDll: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\msctf.dll'
  1736. df0.2050: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\MSCTF.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
  1737. df0.2050: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9c70000 'C:\WINDOWS\system32\MSCTF.dll'
  1738. df0.2048: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume4\Windows\System32\MMDevAPI.dll'
  1739. df0.2048: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000006e4 pwszName=\Device\HarddiskVolume4\Windows\System32\wdmaud.drv
  1740. df0.2048: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000001633db0
  1741. df0.2048: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000001633db0
  1742. df0.2048: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=91ED6AA513C557A93E1309CC5A4B544180A1B4C6
  1743. df0.2048: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7f80000 'C:\WINDOWS\system32\rsaenh.dll'
  1744. df0.2048: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9120000 'C:\WINDOWS\system32\crypt32.dll'
  1745. df0.2048: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Multimedia-MMECoreWdmAudio-Package~31bf3856ad364e35~amd64~~10.0.10074.0.cat'; file='\Device\HarddiskVolume4\Windows\System32\wdmaud.drv'
  1746. df0.2048: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
  1747. df0.2048: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
  1748. df0.2048: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #21 'ksuser.dll'.
  1749. df0.2048: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #22 'user32.dll'.
  1750. df0.2048: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'winmm.dll'.
  1751. df0.2048: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'avrt.dll'.
  1752. df0.2048: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'mmdevapi.dll'.
  1753. df0.2048: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\wdmaud.drv)WinVerifyTrust
  1754. df0.2048: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\wdmaud.drv
  1755. df0.2048: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mmdevapi.dll'...
  1756. df0.2048: supR3HardenedWinVerifyCacheProcessImportTodos: 'mmdevapi.dll' -> '\Device\HarddiskVolume4\Windows\System32\mmdevapi.dll' [rcNtRedir=0xc0150008]
  1757. df0.2048: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\MMDevAPI.dll
  1758. df0.2048: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'avrt.dll'...
  1759. df0.2048: supR3HardenedWinVerifyCacheProcessImportTodos: 'avrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\avrt.dll' [rcNtRedir=0xc0150008]
  1760. df0.2048: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7f80000 'C:\WINDOWS\system32\rsaenh.dll'
  1761. df0.2048: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9120000 'C:\WINDOWS\system32\crypt32.dll'
  1762. df0.2048: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\avrt.dll)WinVerifyTrust
  1763. df0.2048: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\avrt.dll
  1764. df0.2048: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
  1765. df0.2048: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume4\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
  1766. df0.2048: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winmm.dll
  1767. df0.2048: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
  1768. df0.2048: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
  1769. df0.2048: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ksuser.dll'...
  1770. df0.2048: supR3HardenedWinVerifyCacheProcessImportTodos: 'ksuser.dll' -> '\Device\HarddiskVolume4\Windows\System32\ksuser.dll' [rcNtRedir=0xc0150008]
  1771. df0.2048: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7f80000 'C:\WINDOWS\system32\rsaenh.dll'
  1772. df0.2048: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9120000 'C:\WINDOWS\system32\crypt32.dll'
  1773. df0.2048: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
  1774. df0.2048: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\ksuser.dll)WinVerifyTrust
  1775. df0.2048: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\ksuser.dll
  1776. df0.2048: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
  1777. df0.2048: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
  1778. df0.2048: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
  1779. df0.2048: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
  1780. df0.2048: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  1781. df0.2048: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wdmaud.drv
  1782. df0.2048: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ksuser.dll
  1783. df0.2048: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\avrt.dll
  1784. df0.2048: supR3HardenedDllNotificationCallback: load   00007ffbd4d90000 LB 0x00008000 C:\WINDOWS\SYSTEM32\ksuser.dll [fFlags=0x0]
  1785. df0.2048: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\ksuser.dll
  1786. df0.2048: supR3HardenedDllNotificationCallback: load   00007ffbd4e20000 LB 0x0000b000 C:\WINDOWS\SYSTEM32\AVRT.dll [fFlags=0x0]
  1787. df0.2048: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\avrt.dll
  1788. df0.2048: supR3HardenedDllNotificationCallback: load   00007ffbc9b00000 LB 0x00042000 C:\WINDOWS\system32\wdmaud.drv [fFlags=0x0]
  1789. df0.2048: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wdmaud.drv
  1790. df0.2048: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbc9b00000 'C:\WINDOWS\system32\wdmaud.drv'
  1791. df0.2048: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wdmaud.drv
  1792. df0.2048: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  1793. df0.2048: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbc9b00000 'C:\WINDOWS\system32\wdmaud.drv'
  1794. df0.2048: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\MMDevAPI.dll
  1795. df0.2048: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\MMDEVAPI.DLL (Input=MMDEVAPI.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  1796. df0.2048: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd5100000 'C:\WINDOWS\system32\MMDEVAPI.DLL'
  1797. df0.2048: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wdmaud.drv
  1798. df0.2048: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  1799. df0.2048: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbc9b00000 'C:\WINDOWS\system32\wdmaud.drv'
  1800. df0.2048: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wdmaud.drv
  1801. df0.2048: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  1802. df0.2048: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbc9b00000 'C:\WINDOWS\system32\wdmaud.drv'
  1803. df0.2048: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\wdmaud.drv
  1804. df0.2048: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  1805. df0.2048: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbc9b00000 'C:\WINDOWS\system32\wdmaud.drv'
  1806. df0.2048: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7f80000 'C:\WINDOWS\system32\rsaenh.dll'
  1807. df0.2048: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9120000 'C:\WINDOWS\system32\crypt32.dll'
  1808. df0.2048: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
  1809. df0.2048: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'rpcrt4.dll'.
  1810. df0.2048: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'oleaut32.dll'.
  1811. df0.2048: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #35 'mmdevapi.dll'.
  1812. df0.2048: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\AudioSes.dll)WinVerifyTrust
  1813. df0.2048: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\AudioSes.dll
  1814. df0.2048: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mmdevapi.dll'...
  1815. df0.2048: supR3HardenedWinVerifyCacheProcessImportTodos: 'mmdevapi.dll' -> '\Device\HarddiskVolume4\Windows\System32\mmdevapi.dll' [rcNtRedir=0xc0150008]
  1816. df0.2048: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\MMDevAPI.dll
  1817. df0.2048: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
  1818. df0.2048: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume4\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
  1819. df0.2048: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\oleaut32.dll
  1820. df0.2048: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
  1821. df0.2048: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume4\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
  1822. df0.2048: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
  1823. df0.2048: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
  1824. df0.2048: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\AUDIOSES.DLL (Input=AUDIOSES.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  1825. df0.2048: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\AudioSes.dll
  1826. df0.2048: supR3HardenedDllNotificationCallback: load   00007ffbca060000 LB 0x00080000 C:\WINDOWS\system32\AUDIOSES.DLL [fFlags=0x0]
  1827. df0.2048: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\AudioSes.dll
  1828. df0.2048: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbca060000 'C:\WINDOWS\system32\AUDIOSES.DLL'
  1829. df0.2048: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000738 pwszName=\Device\HarddiskVolume4\Windows\System32\msacm32.drv
  1830. df0.2048: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000001633db0
  1831. df0.2048: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000001633db0
  1832. df0.2048: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=5D9632F6BCC8D4347E7DA6D39070CE3B5283C521
  1833. df0.2048: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7f80000 'C:\WINDOWS\system32\rsaenh.dll'
  1834. df0.2048: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9120000 'C:\WINDOWS\system32\crypt32.dll'
  1835. df0.2048: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SKU-Foundation-Package-avcore-noindeo-Group-avcore-Package~31bf3856ad364e35~amd64~~10.0.10074.0.cat'; file='\Device\HarddiskVolume4\Windows\System32\msacm32.drv'
  1836. df0.2048: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
  1837. df0.2048: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
  1838. df0.2048: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'mmdevapi.dll'.
  1839. df0.2048: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'msacm32.dll'.
  1840. df0.2048: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'user32.dll'.
  1841. df0.2048: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'winmm.dll'.
  1842. df0.2048: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\msacm32.drv)WinVerifyTrust
  1843. df0.2048: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\msacm32.drv
  1844. df0.2048: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
  1845. df0.2048: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume4\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
  1846. df0.2048: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winmm.dll
  1847. df0.2048: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
  1848. df0.2048: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume4\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
  1849. df0.2048: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msacm32.dll'...
  1850. df0.2048: supR3HardenedWinVerifyCacheProcessImportTodos: 'msacm32.dll' -> '\Device\HarddiskVolume4\Windows\System32\msacm32.dll' [rcNtRedir=0xc0150008]
  1851. df0.2048: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7f80000 'C:\WINDOWS\system32\rsaenh.dll'
  1852. df0.2048: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9120000 'C:\WINDOWS\system32\crypt32.dll'
  1853. df0.2048: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
  1854. df0.2048: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\msacm32.dll)WinVerifyTrust
  1855. df0.2048: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\msacm32.dll
  1856. df0.2048: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mmdevapi.dll'...
  1857. df0.2048: supR3HardenedWinVerifyCacheProcessImportTodos: 'mmdevapi.dll' -> '\Device\HarddiskVolume4\Windows\System32\mmdevapi.dll' [rcNtRedir=0xc0150008]
  1858. df0.2048: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\MMDevAPI.dll
  1859. df0.2048: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
  1860. df0.2048: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
  1861. df0.2048: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
  1862. df0.2048: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
  1863. df0.2048: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  1864. df0.2048: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msacm32.drv
  1865. df0.2048: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msacm32.dll
  1866. df0.2048: supR3HardenedDllNotificationCallback: load   00007ffbcf750000 LB 0x0001c000 C:\WINDOWS\SYSTEM32\MSACM32.dll [fFlags=0x0]
  1867. df0.2048: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msacm32.dll
  1868. df0.2048: supR3HardenedDllNotificationCallback: load   00007ffbcff20000 LB 0x0000c000 C:\WINDOWS\system32\msacm32.drv [fFlags=0x0]
  1869. df0.2048: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msacm32.drv
  1870. df0.2048: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcff20000 'C:\WINDOWS\system32\msacm32.drv'
  1871. df0.2048: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msacm32.drv
  1872. df0.2048: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  1873. df0.2048: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcff20000 'C:\WINDOWS\system32\msacm32.drv'
  1874. df0.2048: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msacm32.drv
  1875. df0.2048: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  1876. df0.2048: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcff20000 'C:\WINDOWS\system32\msacm32.drv'
  1877. df0.2048: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msacm32.drv
  1878. df0.2048: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  1879. df0.2048: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcff20000 'C:\WINDOWS\system32\msacm32.drv'
  1880. df0.2048: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msacm32.drv
  1881. df0.2048: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  1882. df0.2048: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcff20000 'C:\WINDOWS\system32\msacm32.drv'
  1883. df0.2048: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msacm32.drv
  1884. df0.2048: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  1885. df0.2048: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcff20000 'C:\WINDOWS\system32\msacm32.drv'
  1886. df0.2048: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\msacm32.drv
  1887. df0.2048: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  1888. df0.2048: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcff20000 'C:\WINDOWS\system32\msacm32.drv'
  1889. df0.2048: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcff20000 'C:\WINDOWS\system32\msacm32.drv'
  1890. df0.2048: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcff20000 'C:\WINDOWS\system32\msacm32.drv'
  1891. df0.2048: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcff20000 'C:\WINDOWS\system32\msacm32.drv'
  1892. df0.2048: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000074c pwszName=\Device\HarddiskVolume4\Windows\System32\midimap.dll
  1893. df0.2048: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000001633db0
  1894. df0.2048: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000001633db0
  1895. df0.2048: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=4159E36005E1995524345D53A619A4D95E7180C8
  1896. df0.2048: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7f80000 'C:\WINDOWS\system32\rsaenh.dll'
  1897. df0.2048: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd9120000 'C:\WINDOWS\system32\crypt32.dll'
  1898. df0.2048: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SKU-Foundation-Package-avcore-noindeo-Group-avcore-Package~31bf3856ad364e35~amd64~~10.0.10074.0.cat'; file='\Device\HarddiskVolume4\Windows\System32\midimap.dll'
  1899. df0.2048: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
  1900. df0.2048: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
  1901. df0.2048: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'winmm.dll'.
  1902. df0.2048: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Windows\System32\midimap.dll)WinVerifyTrust
  1903. df0.2048: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume4\Windows\System32\midimap.dll
  1904. df0.2048: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
  1905. df0.2048: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume4\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
  1906. df0.2048: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\winmm.dll
  1907. df0.2048: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
  1908. df0.2048: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume4\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
  1909. df0.2048: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  1910. df0.2048: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\midimap.dll
  1911. df0.2048: supR3HardenedDllNotificationCallback: load   00007ffbcfaf0000 LB 0x0000a000 C:\WINDOWS\system32\midimap.dll [fFlags=0x0]
  1912. df0.2048: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\midimap.dll
  1913. df0.2048: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcfaf0000 'C:\WINDOWS\system32\midimap.dll'
  1914. df0.2048: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\midimap.dll
  1915. df0.2048: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  1916. df0.2048: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcfaf0000 'C:\WINDOWS\system32\midimap.dll'
  1917. df0.2048: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\midimap.dll
  1918. df0.2048: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  1919. df0.2048: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcfaf0000 'C:\WINDOWS\system32\midimap.dll'
  1920. df0.2048: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume4\Windows\System32\midimap.dll
  1921. df0.2048: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  1922. df0.2048: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcfaf0000 'C:\WINDOWS\system32\midimap.dll'
  1923. b48.eac: supR3HardNtChildWaitFor[2]: Quitting: ExitCode=0x1 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 2650 ms, the end);
  1924. 20e0.1054: supR3HardNtChildWaitFor[1]: Quitting: ExitCode=0x1 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 3051 ms, the end);
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement