Advertisement
Guest User

Untitled

a guest
Jan 22nd, 2021
38
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 173.56 KB | None | 0 0
  1. 9164.96cc: Log file opened: 6.1.16r140961 g_hStartupLog=0000000000000074 g_uNtVerCombined=0xa04a6100
  2. 9164.96cc: \SystemRoot\System32\ntdll.dll:
  3. 9164.96cc: CreationTime: 2020-12-10T19:02:25.584058600Z
  4. 9164.96cc: LastWriteTime: 2020-12-10T19:02:25.724650800Z
  5. 9164.96cc: ChangeTime: 2021-01-13T17:02:56.287236300Z
  6. 9164.96cc: FileAttributes: 0x20
  7. 9164.96cc: Size: 0x1ee738
  8. 9164.96cc: NT Headers: 0xe8
  9. 9164.96cc: Timestamp: 0x27bfa5f0
  10. 9164.96cc: Machine: 0x8664 - amd64
  11. 9164.96cc: Timestamp: 0x27bfa5f0
  12. 9164.96cc: Image Version: 10.0
  13. 9164.96cc: SizeOfImage: 0x1f6000 (2056192)
  14. 9164.96cc: Resource Dir: 0x185000 LB 0x6fdc8
  15. 9164.96cc: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
  16. 9164.96cc: [Raw version resource data: 0x1850f0 LB 0x380, codepage 0x0 (reserved 0x0)]
  17. 9164.96cc: ProductName: Microsoft® Windows® Operating System
  18. 9164.96cc: ProductVersion: 10.0.19041.662
  19. 9164.96cc: FileVersion: 10.0.19041.662 (WinBuild.160101.0800)
  20. 9164.96cc: FileDescription: NT Layer DLL
  21. 9164.96cc: \SystemRoot\System32\kernel32.dll:
  22. 9164.96cc: CreationTime: 2020-12-10T19:01:37.103168400Z
  23. 9164.96cc: LastWriteTime: 2020-12-10T19:01:37.212531800Z
  24. 9164.96cc: ChangeTime: 2021-01-13T17:02:52.941999200Z
  25. 9164.96cc: FileAttributes: 0x20
  26. 9164.96cc: Size: 0xbac30
  27. 9164.96cc: NT Headers: 0xe8
  28. 9164.96cc: Timestamp: 0x4b3a140f
  29. 9164.96cc: Machine: 0x8664 - amd64
  30. 9164.96cc: Timestamp: 0x4b3a140f
  31. 9164.96cc: Image Version: 10.0
  32. 9164.96cc: SizeOfImage: 0xbd000 (774144)
  33. 9164.96cc: Resource Dir: 0xbb000 LB 0x520
  34. 9164.96cc: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
  35. 9164.96cc: [Raw version resource data: 0xbb0b0 LB 0x3a4, codepage 0x0 (reserved 0x0)]
  36. 9164.96cc: ProductName: Microsoft® Windows® Operating System
  37. 9164.96cc: ProductVersion: 10.0.19041.662
  38. 9164.96cc: FileVersion: 10.0.19041.662 (WinBuild.160101.0800)
  39. 9164.96cc: FileDescription: Windows NT BASE API Client DLL
  40. 9164.96cc: \SystemRoot\System32\KernelBase.dll:
  41. 9164.96cc: CreationTime: 2020-12-10T19:02:28.976018700Z
  42. 9164.96cc: LastWriteTime: 2020-12-10T19:02:29.085324600Z
  43. 9164.96cc: ChangeTime: 2021-01-13T17:02:56.287236300Z
  44. 9164.96cc: FileAttributes: 0x20
  45. 9164.96cc: Size: 0x2c9798
  46. 9164.96cc: NT Headers: 0xf0
  47. 9164.96cc: Timestamp: 0xec58f015
  48. 9164.96cc: Machine: 0x8664 - amd64
  49. 9164.96cc: Timestamp: 0xec58f015
  50. 9164.96cc: Image Version: 10.0
  51. 9164.96cc: SizeOfImage: 0x2c9000 (2920448)
  52. 9164.96cc: Resource Dir: 0x2a0000 LB 0x548
  53. 9164.96cc: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
  54. 9164.96cc: [Raw version resource data: 0x2a00b0 LB 0x3bc, codepage 0x0 (reserved 0x0)]
  55. 9164.96cc: ProductName: Microsoft® Windows® Operating System
  56. 9164.96cc: ProductVersion: 10.0.19041.662
  57. 9164.96cc: FileVersion: 10.0.19041.662 (WinBuild.160101.0800)
  58. 9164.96cc: FileDescription: Windows NT BASE API Client DLL
  59. 9164.96cc: \SystemRoot\System32\apisetschema.dll:
  60. 9164.96cc: CreationTime: 2019-12-07T09:08:13.518339400Z
  61. 9164.96cc: LastWriteTime: 2019-12-07T09:08:13.518339400Z
  62. 9164.96cc: ChangeTime: 2021-01-13T17:02:52.754478000Z
  63. 9164.96cc: FileAttributes: 0x20
  64. 9164.96cc: Size: 0x1f538
  65. 9164.96cc: NT Headers: 0xd0
  66. 9164.96cc: Timestamp: 0x31288ce0
  67. 9164.96cc: Machine: 0x8664 - amd64
  68. 9164.96cc: Timestamp: 0x31288ce0
  69. 9164.96cc: Image Version: 10.0
  70. 9164.96cc: SizeOfImage: 0x20000 (131072)
  71. 9164.96cc: Resource Dir: 0x1f000 LB 0x408
  72. 9164.96cc: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
  73. 9164.96cc: [Raw version resource data: 0x1f060 LB 0x3a8, codepage 0x0 (reserved 0x0)]
  74. 9164.96cc: ProductName: Microsoft® Windows® Operating System
  75. 9164.96cc: ProductVersion: 10.0.19041.1
  76. 9164.96cc: FileVersion: 10.0.19041.1 (WinBuild.160101.0800)
  77. 9164.96cc: FileDescription: ApiSet Schema DLL
  78. 9164.96cc: NtOpenDirectoryObject failed on \Driver: 0xc0000022
  79. 9164.96cc: supR3HardenedWinFindAdversaries: 0x0
  80. 9164.96cc: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
  81. 9164.96cc: Calling main()
  82. 9164.96cc: SUPR3HardenedMain: pszProgName=VirtualBoxVM fFlags=0x2
  83. 9164.96cc: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
  84. 9164.96cc: SUPR3HardenedMain: Respawn #1
  85. 9164.96cc: System32: \Device\HarddiskVolume2\Windows\System32
  86. 9164.96cc: WinSxS: \Device\HarddiskVolume2\Windows\WinSxS
  87. 9164.96cc: KnownDllPath: C:\WINDOWS\System32
  88. 9164.96cc: supR3HardenedWinInit: Performing a limited self purification...
  89. 9164.96cc: supHardNtVpScanVirtualMemory: enmKind=SELF_PURIFICATION
  90. 9164.96cc: *0000000000000000-0000000000ceffff 0x0001/0x0000 0x0000000
  91. 9164.96cc: *0000000000cf0000-0000000000cfffff 0x0004/0x0004 0x0040000
  92. 9164.96cc: 0000000000d00000-0000000000d0ffff 0x0001/0x0000 0x0000000
  93. 9164.96cc: *0000000000d10000-0000000000d2cfff 0x0002/0x0002 0x0040000
  94. 9164.96cc: 0000000000d2d000-0000000000d2ffff 0x0001/0x0000 0x0000000
  95. 9164.96cc: *0000000000d30000-0000000000d33fff 0x0002/0x0002 0x0040000
  96. 9164.96cc: 0000000000d34000-0000000000d3ffff 0x0001/0x0000 0x0000000
  97. 9164.96cc: *0000000000d40000-0000000000d41fff 0x0004/0x0004 0x0020000
  98. 9164.96cc: 0000000000d42000-0000000000d4ffff 0x0001/0x0000 0x0000000
  99. 9164.96cc: *0000000000d50000-0000000000d51fff 0x0004/0x0004 0x0020000
  100. 9164.96cc: 0000000000d52000-0000000000d81fff 0x0000/0x0004 0x0020000
  101. 9164.96cc: 0000000000d82000-0000000000dfffff 0x0001/0x0000 0x0000000
  102. 9164.96cc: *0000000000e00000-0000000000f3afff 0x0000/0x0004 0x0020000
  103. 9164.96cc: 0000000000f3b000-0000000000f3dfff 0x0004/0x0004 0x0020000
  104. 9164.96cc: 0000000000f3e000-0000000000ffffff 0x0000/0x0004 0x0020000
  105. 9164.96cc: *0000000001000000-00000000010b8fff 0x0000/0x0004 0x0020000
  106. 9164.96cc: 00000000010b9000-00000000010bbfff 0x0104/0x0004 0x0020000
  107. 9164.96cc: 00000000010bc000-00000000010fffff 0x0004/0x0004 0x0020000
  108. 9164.96cc: *0000000001100000-00000000011c8fff 0x0002/0x0002 0x0040000
  109. 9164.96cc: 00000000011c9000-000000000125ffff 0x0001/0x0000 0x0000000
  110. 9164.96cc: *0000000001260000-0000000001265fff 0x0004/0x0004 0x0020000
  111. 9164.96cc: 0000000001266000-000000000135ffff 0x0000/0x0004 0x0020000
  112. 9164.96cc: *0000000001360000-000000000137cfff 0x0004/0x0004 0x0020000
  113. 9164.96cc: 000000000137d000-000000000145ffff 0x0000/0x0004 0x0020000
  114. 9164.96cc: *0000000001460000-000000000146efff 0x0004/0x0004 0x0020000
  115. 9164.96cc: 000000000146f000-000000000146ffff 0x0000/0x0004 0x0020000
  116. 9164.96cc: *0000000001470000-0000000001470fff 0x0000/0x0004 0x0020000
  117. 9164.96cc: 0000000001471000-0000000001667fff 0x0004/0x0004 0x0020000
  118. 9164.96cc: 0000000001668000-0000000001668fff 0x0000/0x0004 0x0020000
  119. 9164.96cc: 0000000001669000-000000007ffdffff 0x0001/0x0000 0x0000000
  120. 9164.96cc: *000000007ffe0000-000000007ffe0fff 0x0002/0x0002 0x0020000
  121. 9164.96cc: 000000007ffe1000-000000007ffe9fff 0x0001/0x0000 0x0000000
  122. 9164.96cc: *000000007ffea000-000000007ffeafff 0x0002/0x0002 0x0020000
  123. 9164.96cc: 000000007ffeb000-00007ff417d7ffff 0x0001/0x0000 0x0000000
  124. 9164.96cc: *00007ff417d80000-00007ff417d84fff 0x0002/0x0002 0x0040000
  125. 9164.96cc: 00007ff417d85000-00007ff417e7ffff 0x0000/0x0002 0x0040000
  126. 9164.96cc: *00007ff417e80000-00007ff517e9ffff 0x0000/0x0004 0x0020000
  127. 9164.96cc: *00007ff517ea0000-00007ff519e9ffff 0x0000/0x0004 0x0020000
  128. 9164.96cc: 00007ff519ea0000-00007ff519ea0fff 0x0004/0x0004 0x0020000
  129. 9164.96cc: 00007ff519ea1000-00007ff519eaffff 0x0001/0x0000 0x0000000
  130. 9164.96cc: *00007ff519eb0000-00007ff519eb0fff 0x0002/0x0002 0x0040000
  131. 9164.96cc: 00007ff519eb1000-00007ff519ebffff 0x0001/0x0000 0x0000000
  132. 9164.96cc: *00007ff519ec0000-00007ff519ee2fff 0x0002/0x0002 0x0040000
  133. 9164.96cc: 00007ff519ee3000-00007ff64f93ffff 0x0001/0x0000 0x0000000
  134. 9164.96cc: *00007ff64f940000-00007ff64f940fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
  135. 9164.96cc: 00007ff64f941000-00007ff64f9b7fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
  136. 9164.96cc: 00007ff64f9b8000-00007ff64f9b8fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
  137. 9164.96cc: 00007ff64f9b9000-00007ff64fa01fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
  138. 9164.96cc: 00007ff64fa02000-00007ff64fa04fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
  139. 9164.96cc: 00007ff64fa05000-00007ff64fa07fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
  140. 9164.96cc: 00007ff64fa08000-00007ff64fa0afff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
  141. 9164.96cc: 00007ff64fa0b000-00007ff64fa0bfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
  142. 9164.96cc: 00007ff64fa0c000-00007ff64fa0dfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
  143. 9164.96cc: 00007ff64fa0e000-00007ff64fa0efff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
  144. 9164.96cc: 00007ff64fa0f000-00007ff64fa57fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
  145. 9164.96cc: 00007ff64fa58000-00007ff963dcffff 0x0001/0x0000 0x0000000
  146. 9164.96cc: *00007ff963dd0000-00007ff963dd0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\KernelBase.dll
  147. 9164.96cc: 00007ff963dd1000-00007ff963ee2fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\KernelBase.dll
  148. 9164.96cc: 00007ff963ee3000-00007ff96405afff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\KernelBase.dll
  149. 9164.96cc: 00007ff96405b000-00007ff96405efff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\KernelBase.dll
  150. 9164.96cc: 00007ff96405f000-00007ff96405ffff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\KernelBase.dll
  151. 9164.96cc: 00007ff964060000-00007ff964098fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\KernelBase.dll
  152. 9164.96cc: 00007ff964099000-00007ff96643ffff 0x0001/0x0000 0x0000000
  153. 9164.96cc: *00007ff966440000-00007ff966440fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\kernel32.dll
  154. 9164.96cc: 00007ff966441000-00007ff9664befff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\kernel32.dll
  155. 9164.96cc: 00007ff9664bf000-00007ff9664f1fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\kernel32.dll
  156. 9164.96cc: 00007ff9664f2000-00007ff9664f2fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\kernel32.dll
  157. 9164.96cc: 00007ff9664f3000-00007ff9664f3fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\kernel32.dll
  158. 9164.96cc: 00007ff9664f4000-00007ff9664fcfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\kernel32.dll
  159. 9164.96cc: 00007ff9664fd000-00007ff96668ffff 0x0001/0x0000 0x0000000
  160. 9164.96cc: *00007ff966690000-00007ff966690fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
  161. 9164.96cc: 00007ff966691000-00007ff9667abfff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
  162. 9164.96cc: 00007ff9667ac000-00007ff9667f4fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
  163. 9164.96cc: 00007ff9667f5000-00007ff9667f5fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
  164. 9164.96cc: 00007ff9667f6000-00007ff9667f7fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
  165. 9164.96cc: 00007ff9667f8000-00007ff966800fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
  166. 9164.96cc: 00007ff966801000-00007ff966885fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
  167. 9164.96cc: 00007ff966886000-00007ffffffeffff 0x0001/0x0000 0x0000000
  168. 9164.96cc: kernel32.dll: timestamp 0x4b3a140f (rc=VINF_SUCCESS)
  169. 9164.96cc: kernelbase.dll: timestamp 0xec58f015 (rc=VINF_SUCCESS)
  170. 9164.96cc: VirtualBoxVM.exe: timestamp 0x5f89bd71 (rc=VINF_SUCCESS)
  171. 9164.96cc: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe: Signature #1/2: info status: 24202
  172. 9164.96cc: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
  173. 9164.96cc: '\Device\HarddiskVolume2\Windows\System32\ntdll.dll' has no imports
  174. 9164.96cc: supR3HardenedWinInit: SUPHARDNTVPKIND_SELF_PURIFICATION_LIMITED -> VINF_SUCCESS, cFixes=0
  175. 9164.96cc: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe: Signature #1/2: info status: 24202
  176. 9164.96cc: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
  177. 9164.96cc: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe)
  178. 9164.96cc: supR3HardNtEnableThreadCreationEx:
  179. 9164.96cc: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ff966704970 pvNtTerminateThread=00007ff96672ca00
  180. 9164.96cc: supR3HardenedWinDoReSpawn(1): New child 9464.7db8 [kernel32].
  181. 9164.96cc: supR3HardNtChildGatherData: PebBaseAddress=00000000010ac000 cbPeb=0x388
  182. 9164.96cc: supR3HardNtPuChFindNtdll: uNtDllParentAddr=00007ff966690000 uNtDllChildAddr=00007ff966690000
  183. 9164.96cc: supR3HardenedWinSetupChildInit: uLdrInitThunk=00007ff966704970
  184. 9164.96cc: supR3HardenedWinSetupChildInit: Initial context:
  185. rax=0000000000000000 rbx=0000000000000000 rcx=00007ff64f947900 rdx=00000000010ac000
  186. rsi=0000000000000000 rdi=0000000000000000 r8 =0000000000000000 r9 =0000000000000000
  187. r10=0000000000000000 r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
  188. r14=0000000000000000 r15=0000000000000000 P1=0000000000000000 P2=0000000000000000
  189. rip=00007ff9666dd0b0 rsp=000000000133f7f8 rbp=0000000000000000 ctxflags=0010001b
  190. cs=0033 ss=002b ds=0000 es=0000 fs=0000 gs=0000 eflags=00000200 mxcrx=00001f80
  191. P3=0000000000000000 P4=0000000000000000 P5=0000000000000000 P6=0000000000000000
  192. dr0=0000000000000000 dr1=0000000000000000 dr2=0000000000000000 dr3=0000000000000000
  193. dr6=0000000000000000 dr7=0000000000000000 vcr=0000000000000000 dcr=0000000000000000
  194. lbt=0000000000000000 lbf=0000000000000000 lxt=0000000000000000 lxf=0000000000000000
  195. 9164.96cc: supR3HardenedWinSetupChildInit: Start child.
  196. 9164.96cc: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
  197. 9164.96cc: supR3HardNtChildPurify: Startup delay kludge #1/0: 264 ms, 17 sleeps
  198. 9164.96cc: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
  199. 9164.96cc: *0000000000000000-0000000000feffff 0x0001/0x0000 0x0000000
  200. 9164.96cc: *0000000000ff0000-0000000000ff3fff 0x0002/0x0002 0x0040000
  201. 9164.96cc: 0000000000ff4000-0000000000ffffff 0x0001/0x0000 0x0000000
  202. 9164.96cc: *0000000001000000-00000000010abfff 0x0000/0x0004 0x0020000
  203. 9164.96cc: 00000000010ac000-00000000010aefff 0x0004/0x0004 0x0020000
  204. 9164.96cc: 00000000010af000-00000000011fffff 0x0000/0x0004 0x0020000
  205. 9164.96cc: *0000000001200000-000000000121ffff 0x0004/0x0004 0x0020000
  206. 9164.96cc: *0000000001220000-000000000123cfff 0x0002/0x0002 0x0040000
  207. 9164.96cc: 000000000123d000-000000000123ffff 0x0001/0x0000 0x0000000
  208. 9164.96cc: *0000000001240000-000000000133afff 0x0000/0x0004 0x0020000
  209. 9164.96cc: 000000000133b000-000000000133dfff 0x0104/0x0004 0x0020000
  210. 9164.96cc: 000000000133e000-000000000133ffff 0x0004/0x0004 0x0020000
  211. 9164.96cc: *0000000001340000-0000000001341fff 0x0004/0x0004 0x0020000
  212. 9164.96cc: 0000000001342000-000000007ffdffff 0x0001/0x0000 0x0000000
  213. 9164.96cc: *000000007ffe0000-000000007ffe0fff 0x0002/0x0002 0x0020000
  214. 9164.96cc: 000000007ffe1000-000000007ffe9fff 0x0001/0x0000 0x0000000
  215. 9164.96cc: *000000007ffea000-000000007ffeafff 0x0002/0x0002 0x0020000
  216. 9164.96cc: 000000007ffeb000-00007ff555f6ffff 0x0001/0x0000 0x0000000
  217. 9164.96cc: *00007ff555f70000-00007ff555f70fff 0x0002/0x0002 0x0040000
  218. 9164.96cc: 00007ff555f71000-00007ff555f7ffff 0x0001/0x0000 0x0000000
  219. 9164.96cc: *00007ff555f80000-00007ff555fa2fff 0x0002/0x0002 0x0040000
  220. 9164.96cc: 00007ff555fa3000-00007ff64f93ffff 0x0001/0x0000 0x0000000
  221. 9164.96cc: *00007ff64f940000-00007ff64f940fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
  222. 9164.96cc: 00007ff64f941000-00007ff64f9b7fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
  223. 9164.96cc: 00007ff64f9b8000-00007ff64f9b8fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
  224. 9164.96cc: 00007ff64f9b9000-00007ff64fa01fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
  225. 9164.96cc: 00007ff64fa02000-00007ff64fa02fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
  226. 9164.96cc: 00007ff64fa03000-00007ff64fa03fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
  227. 9164.96cc: 00007ff64fa04000-00007ff64fa08fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
  228. 9164.96cc: 00007ff64fa09000-00007ff64fa09fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
  229. 9164.96cc: 00007ff64fa0a000-00007ff64fa0afff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
  230. 9164.96cc: 00007ff64fa0b000-00007ff64fa0efff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
  231. 9164.96cc: 00007ff64fa0f000-00007ff64fa57fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
  232. 9164.96cc: 00007ff64fa58000-00007ff96668ffff 0x0001/0x0000 0x0000000
  233. 9164.96cc: *00007ff966690000-00007ff966690fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
  234. 9164.96cc: 00007ff966691000-00007ff9667abfff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
  235. 9164.96cc: 00007ff9667ac000-00007ff9667f4fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
  236. 9164.96cc: 00007ff9667f5000-00007ff966800fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
  237. 9164.96cc: 00007ff966801000-00007ff96680ffff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
  238. 9164.96cc: 00007ff966810000-00007ff966810fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
  239. 9164.96cc: 00007ff966811000-00007ff966813fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
  240. 9164.96cc: 00007ff966814000-00007ff966885fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
  241. 9164.96cc: 00007ff966886000-00007ffffffeffff 0x0001/0x0000 0x0000000
  242. 9164.96cc: supR3HardNtChildPurify: Done after 268 ms and 0 fixes (loop #0).
  243. 9464.7db8: Log file opened: 6.1.16r140961 g_hStartupLog=0000000000000004 g_uNtVerCombined=0xa04a6100
  244. 9464.7db8: supR3HardenedVmProcessInit: uNtDllAddr=00007ff966690000 g_uNtVerCombined=0xa04a6100 (stack ~000000000133f288)
  245. 9464.7db8: ntdll.dll: timestamp 0x27bfa5f0 (rc=VINF_SUCCESS)
  246. 9464.7db8: New simple heap: #1 0000000001450000 LB 0x400000 (for 2056192 allocation)
  247. 9164.96cc: supR3HardNtEnableThreadCreationEx:
  248. 9464.7db8: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
  249. 9464.7db8: System32: \Device\HarddiskVolume2\Windows\System32
  250. 9464.7db8: WinSxS: \Device\HarddiskVolume2\Windows\WinSxS
  251. 9464.7db8: KnownDllPath: C:\WINDOWS\System32
  252. 9464.7db8: supR3HardenedVmProcessInit: Opening vboxdrv stub...
  253. 9464.7db8: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
  254. 9464.7db8: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
  255. 9464.7db8: Registered Dll notification callback with NTDLL.
  256. 9464.7db8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\kernel32.dll)
  257. 9464.7db8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\kernel32.dll
  258. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\KERNEL32.DLL (Input=KERNEL32.DLL, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000004001:<flags> [calling]
  259. 9464.7db8: supR3HardenedDllNotificationCallback: load 00007ff963dd0000 LB 0x002c9000 C:\WINDOWS\System32\KERNELBASE.dll [fFlags=0x0]
  260. 9464.7db8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\KernelBase.dll)
  261. 9464.7db8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\KernelBase.dll
  262. 9464.7db8: supR3HardenedDllNotificationCallback: load 00007ff966440000 LB 0x000bd000 C:\WINDOWS\System32\KERNEL32.DLL [fFlags=0x0]
  263. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
  264. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff966440000 'C:\WINDOWS\System32\KERNEL32.DLL'
  265. 9464.7db8: supR3HardenedDllNotificationCallback: load 00007ff64f940000 LB 0x00118000 C:\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe [fFlags=0x0]
  266. 9464.7db8: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe: Signature #1/2: info status: 24202
  267. 9464.7db8: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
  268. 9464.7db8: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe)
  269. 9464.7db8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
  270. 9464.7db8: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ff966704970 pvNtTerminateThread=00007ff96672ca00
  271. 9164.96cc: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 131 ms.
  272. 9464.7db8: \SystemRoot\System32\ntdll.dll:
  273. 9464.7db8: CreationTime: 2020-12-10T19:02:25.584058600Z
  274. 9464.7db8: LastWriteTime: 2020-12-10T19:02:25.724650800Z
  275. 9464.7db8: ChangeTime: 2021-01-13T17:02:56.287236300Z
  276. 9464.7db8: FileAttributes: 0x20
  277. 9464.7db8: Size: 0x1ee738
  278. 9464.7db8: NT Headers: 0xe8
  279. 9464.7db8: Timestamp: 0x27bfa5f0
  280. 9464.7db8: Machine: 0x8664 - amd64
  281. 9464.7db8: Timestamp: 0x27bfa5f0
  282. 9464.7db8: Image Version: 10.0
  283. 9464.7db8: SizeOfImage: 0x1f6000 (2056192)
  284. 9464.7db8: Resource Dir: 0x185000 LB 0x6fdc8
  285. 9464.7db8: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
  286. 9464.7db8: [Raw version resource data: 0x1850f0 LB 0x380, codepage 0x0 (reserved 0x0)]
  287. 9464.7db8: ProductName: Microsoft® Windows® Operating System
  288. 9464.7db8: ProductVersion: 10.0.19041.662
  289. 9464.7db8: FileVersion: 10.0.19041.662 (WinBuild.160101.0800)
  290. 9464.7db8: FileDescription: NT Layer DLL
  291. 9464.7db8: \SystemRoot\System32\kernel32.dll:
  292. 9464.7db8: CreationTime: 2020-12-10T19:01:37.103168400Z
  293. 9464.7db8: LastWriteTime: 2020-12-10T19:01:37.212531800Z
  294. 9464.7db8: ChangeTime: 2021-01-13T17:02:52.941999200Z
  295. 9464.7db8: FileAttributes: 0x20
  296. 9464.7db8: Size: 0xbac30
  297. 9464.7db8: NT Headers: 0xe8
  298. 9464.7db8: Timestamp: 0x4b3a140f
  299. 9464.7db8: Machine: 0x8664 - amd64
  300. 9464.7db8: Timestamp: 0x4b3a140f
  301. 9464.7db8: Image Version: 10.0
  302. 9464.7db8: SizeOfImage: 0xbd000 (774144)
  303. 9464.7db8: Resource Dir: 0xbb000 LB 0x520
  304. 9464.7db8: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
  305. 9464.7db8: [Raw version resource data: 0xbb0b0 LB 0x3a4, codepage 0x0 (reserved 0x0)]
  306. 9464.7db8: ProductName: Microsoft® Windows® Operating System
  307. 9464.7db8: ProductVersion: 10.0.19041.662
  308. 9464.7db8: FileVersion: 10.0.19041.662 (WinBuild.160101.0800)
  309. 9464.7db8: FileDescription: Windows NT BASE API Client DLL
  310. 9464.7db8: \SystemRoot\System32\KernelBase.dll:
  311. 9464.7db8: CreationTime: 2020-12-10T19:02:28.976018700Z
  312. 9464.7db8: LastWriteTime: 2020-12-10T19:02:29.085324600Z
  313. 9464.7db8: ChangeTime: 2021-01-13T17:02:56.287236300Z
  314. 9464.7db8: FileAttributes: 0x20
  315. 9464.7db8: Size: 0x2c9798
  316. 9464.7db8: NT Headers: 0xf0
  317. 9464.7db8: Timestamp: 0xec58f015
  318. 9464.7db8: Machine: 0x8664 - amd64
  319. 9464.7db8: Timestamp: 0xec58f015
  320. 9464.7db8: Image Version: 10.0
  321. 9464.7db8: SizeOfImage: 0x2c9000 (2920448)
  322. 9464.7db8: Resource Dir: 0x2a0000 LB 0x548
  323. 9464.7db8: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
  324. 9464.7db8: [Raw version resource data: 0x2a00b0 LB 0x3bc, codepage 0x0 (reserved 0x0)]
  325. 9464.7db8: ProductName: Microsoft® Windows® Operating System
  326. 9464.7db8: ProductVersion: 10.0.19041.662
  327. 9464.7db8: FileVersion: 10.0.19041.662 (WinBuild.160101.0800)
  328. 9464.7db8: FileDescription: Windows NT BASE API Client DLL
  329. 9464.7db8: \SystemRoot\System32\apisetschema.dll:
  330. 9464.7db8: CreationTime: 2019-12-07T09:08:13.518339400Z
  331. 9464.7db8: LastWriteTime: 2019-12-07T09:08:13.518339400Z
  332. 9464.7db8: ChangeTime: 2021-01-13T17:02:52.754478000Z
  333. 9464.7db8: FileAttributes: 0x20
  334. 9464.7db8: Size: 0x1f538
  335. 9464.7db8: NT Headers: 0xd0
  336. 9464.7db8: Timestamp: 0x31288ce0
  337. 9464.7db8: Machine: 0x8664 - amd64
  338. 9464.7db8: Timestamp: 0x31288ce0
  339. 9464.7db8: Image Version: 10.0
  340. 9464.7db8: SizeOfImage: 0x20000 (131072)
  341. 9464.7db8: Resource Dir: 0x1f000 LB 0x408
  342. 9464.7db8: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
  343. 9464.7db8: [Raw version resource data: 0x1f060 LB 0x3a8, codepage 0x0 (reserved 0x0)]
  344. 9464.7db8: ProductName: Microsoft® Windows® Operating System
  345. 9464.7db8: ProductVersion: 10.0.19041.1
  346. 9464.7db8: FileVersion: 10.0.19041.1 (WinBuild.160101.0800)
  347. 9464.7db8: FileDescription: ApiSet Schema DLL
  348. 9464.7db8: NtOpenDirectoryObject failed on \Driver: 0xc0000022
  349. 9464.7db8: supR3HardenedWinFindAdversaries: 0x0
  350. 9464.7db8: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
  351. 9464.7db8: Calling main()
  352. 9464.7db8: SUPR3HardenedMain: pszProgName=VirtualBoxVM fFlags=0x2
  353. 9464.7db8: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
  354. 9464.7db8: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe: Signature #1/2: info status: 24202
  355. 9464.7db8: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
  356. 9464.7db8: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe)
  357. 9464.7db8: SUPR3HardenedMain: Respawn #2
  358. 9464.7db8: supR3HardNtEnableThreadCreationEx:
  359. 9464.7db8: supR3HardenedDllNotificationCallback: load 00007ff9662b0000 LB 0x0012b000 C:\WINDOWS\System32\RPCRT4.dll [fFlags=0x0]
  360. 9464.7db8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll)
  361. 9464.7db8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
  362. 9464.7db8: supR3HardenedDllNotificationCallback: load 00007ff965870000 LB 0x0009c000 C:\WINDOWS\System32\sechost.dll [fFlags=0x0]
  363. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'rpcrt4.dll'.
  364. 9464.7db8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\sechost.dll)
  365. 9464.7db8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\sechost.dll
  366. 9464.7db8: '\Device\HarddiskVolume2\Windows\System32\ntdll.dll' has no imports
  367. 9464.7db8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ntdll.dll)
  368. 9464.7db8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ntdll.dll
  369. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
  370. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
  371. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
  372. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\ntdll.dll (Input=ntdll.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
  373. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff966690000 'C:\WINDOWS\System32\ntdll.dll'
  374. 9464.7db8: Error -104 in supR3HardenedWinReSpawn! (enmWhat=5)
  375. 9464.7db8: Error relaunching VirtualBox VM process: 5
  376. Command line: '60eaff78-4bdd-042d-2e72-669728efd737-suplib-3rdchild --comment "Ubuntu 2020" --startvm c8b8be09-d024-435a-a903-e591d40e4f59 --no-startvm-errormsgbox "--sup-hardening-log=C:\Users\12488\VirtualBox VMs\Ubuntu 2020\Logs\VBoxHardening.log"'
  377. 9464.7db8: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll: Signature #1/2: info status: 24202
  378. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'opengl32.dll'.
  379. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'uicommon.dll'.
  380. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
  381. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcp100.dll'.
  382. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msvcr100.dll'.
  383. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'qt5corevbox.dll'.
  384. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'qt5guivbox.dll'.
  385. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'qt5widgetsvbox.dll'.
  386. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'qt5openglvbox.dll'.
  387. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'user32.dll'.
  388. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'ole32.dll'.
  389. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'oleaut32.dll'.
  390. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'winmm.dll'.
  391. 9464.7db8: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll)
  392. 9464.7db8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll
  393. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
  394. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
  395. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
  396. 9464.7db8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\winmm.dll)
  397. 9464.7db8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\winmm.dll
  398. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
  399. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
  400. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
  401. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'combase.dll'.
  402. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #21 'rpcrt4.dll'.
  403. 9464.7db8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\oleaut32.dll)
  404. 9464.7db8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
  405. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
  406. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
  407. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #21 'rpcrt4.dll'.
  408. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #49 'gdi32.dll'.
  409. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #50 'user32.dll'.
  410. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #51 'combase.dll'.
  411. 9464.7db8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ole32.dll)
  412. 9464.7db8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ole32.dll
  413. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
  414. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
  415. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'win32u.dll'.
  416. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #37 'gdi32.dll'.
  417. 9464.7db8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\user32.dll)
  418. 9464.7db8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\user32.dll
  419. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5openglvbox.dll'...
  420. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5openglvbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5openglvbox.dll' [rcNtRedir=0xc0150008]
  421. 9464.7db8: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll: Signature #1/2: info status: 24202
  422. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'qt5widgetsvbox.dll'.
  423. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'qt5guivbox.dll'.
  424. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5corevbox.dll'.
  425. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcr100.dll'.
  426. 9464.7db8: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll)
  427. 9464.7db8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll
  428. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
  429. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
  430. 9464.7db8: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll: Signature #1/2: info status: 24202
  431. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
  432. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
  433. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5guivbox.dll'.
  434. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qt5corevbox.dll'.
  435. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'shell32.dll'.
  436. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcp100.dll'.
  437. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msvcr100.dll'.
  438. 9464.7db8: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll)
  439. 9464.7db8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll
  440. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
  441. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
  442. 9464.7db8: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll: Signature #1/2: info status: 24202
  443. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ole32.dll'.
  444. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'opengl32.dll'.
  445. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
  446. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
  447. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qt5corevbox.dll'.
  448. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcp100.dll'.
  449. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msvcr100.dll'.
  450. 9464.7db8: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll)
  451. 9464.7db8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
  452. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
  453. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
  454. 9464.7db8: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll: Signature #1/2: info status: 24202
  455. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
  456. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'shell32.dll'.
  457. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ole32.dll'.
  458. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
  459. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ws2_32.dll'.
  460. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'mpr.dll'.
  461. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'msvcp100.dll'.
  462. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'msvcr100.dll'.
  463. 9464.7db8: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll)
  464. 9464.7db8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
  465. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
  466. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
  467. 9464.7db8: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll: Signature #1/2: info status: 24202
  468. 9464.7db8: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll)
  469. 9464.7db8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll
  470. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
  471. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
  472. 9464.7db8: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll: Signature #1/2: info status: 24202
  473. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
  474. 9464.7db8: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll)
  475. 9464.7db8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll
  476. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
  477. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
  478. 9464.7db8: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll: Signature #1/2: info status: 24202
  479. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
  480. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
  481. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rpcrt4.dll'.
  482. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ws2_32.dll'.
  483. 9464.7db8: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll)
  484. 9464.7db8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll
  485. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'uicommon.dll'...
  486. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'uicommon.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\uicommon.dll' [rcNtRedir=0xc0150008]
  487. 9464.7db8: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\UICommon.dll: Signature #1/2: info status: 24202
  488. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'vboxrt.dll'.
  489. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcr100.dll'.
  490. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5corevbox.dll'.
  491. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qt5guivbox.dll'.
  492. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qt5widgetsvbox.dll'.
  493. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
  494. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'advapi32.dll'.
  495. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'ole32.dll'.
  496. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'oleaut32.dll'.
  497. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'rpcrt4.dll'.
  498. 9464.7db8: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\UICommon.dll)
  499. 9464.7db8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\UICommon.dll
  500. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
  501. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
  502. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
  503. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'advapi32.dll'.
  504. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
  505. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'gdi32.dll'.
  506. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'glu32.dll'.
  507. 9464.7db8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\opengl32.dll)
  508. 9464.7db8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\opengl32.dll
  509. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'glu32.dll'...
  510. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'glu32.dll' -> '\Device\HarddiskVolume2\Windows\System32\glu32.dll' [rcNtRedir=0xc0150008]
  511. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
  512. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
  513. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'opengl32.dll'.
  514. 9464.7db8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\glu32.dll)
  515. 9464.7db8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\glu32.dll
  516. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
  517. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
  518. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'win32u.dll'.
  519. 9464.7db8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\gdi32.dll)
  520. 9464.7db8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\gdi32.dll
  521. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
  522. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
  523. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
  524. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
  525. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
  526. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
  527. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'sechost.dll'.
  528. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #27 'rpcrt4.dll'.
  529. 9464.7db8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\advapi32.dll)
  530. 9464.7db8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\advapi32.dll
  531. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
  532. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
  533. 9464.7db8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\msvcrt.dll)
  534. 9464.7db8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
  535. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
  536. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
  537. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
  538. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
  539. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
  540. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll [lacks WinVerifyTrust]
  541. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
  542. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
  543. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll [lacks WinVerifyTrust]
  544. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
  545. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
  546. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
  547. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
  548. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
  549. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
  550. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
  551. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
  552. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll [lacks WinVerifyTrust]
  553. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
  554. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
  555. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll [lacks WinVerifyTrust]
  556. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
  557. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
  558. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [lacks WinVerifyTrust]
  559. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
  560. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
  561. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
  562. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
  563. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
  564. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll [lacks WinVerifyTrust]
  565. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
  566. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
  567. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'rpcrt4.dll'.
  568. 9464.7db8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ws2_32.dll)
  569. 9464.7db8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
  570. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
  571. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
  572. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
  573. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
  574. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
  575. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll [lacks WinVerifyTrust]
  576. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
  577. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
  578. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
  579. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
  580. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
  581. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
  582. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
  583. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
  584. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
  585. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
  586. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
  587. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll [lacks WinVerifyTrust]
  588. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mpr.dll'...
  589. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'mpr.dll' -> '\Device\HarddiskVolume2\Windows\System32\mpr.dll' [rcNtRedir=0xc0150008]
  590. 9464.7db8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\mpr.dll)
  591. 9464.7db8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\mpr.dll
  592. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
  593. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
  594. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll [lacks WinVerifyTrust]
  595. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
  596. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
  597. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
  598. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
  599. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
  600. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll [lacks WinVerifyTrust]
  601. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
  602. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
  603. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
  604. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #72 'user32.dll'.
  605. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #74 'gdi32.dll'.
  606. 9464.7db8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\shell32.dll)
  607. 9464.7db8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\shell32.dll
  608. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
  609. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
  610. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
  611. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
  612. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
  613. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
  614. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
  615. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
  616. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll [lacks WinVerifyTrust]
  617. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
  618. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
  619. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [lacks WinVerifyTrust]
  620. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
  621. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
  622. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
  623. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
  624. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
  625. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
  626. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
  627. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
  628. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll [lacks WinVerifyTrust]
  629. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
  630. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
  631. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll [lacks WinVerifyTrust]
  632. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
  633. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
  634. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
  635. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
  636. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
  637. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll [lacks WinVerifyTrust]
  638. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
  639. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
  640. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll [lacks WinVerifyTrust]
  641. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
  642. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
  643. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [lacks WinVerifyTrust]
  644. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
  645. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
  646. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll [lacks WinVerifyTrust]
  647. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
  648. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
  649. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
  650. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
  651. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
  652. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
  653. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
  654. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
  655. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
  656. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
  657. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
  658. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [lacks WinVerifyTrust]
  659. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
  660. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
  661. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll [lacks WinVerifyTrust]
  662. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
  663. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
  664. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll [lacks WinVerifyTrust]
  665. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
  666. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
  667. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
  668. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
  669. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume2\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
  670. 9464.7db8: '\Device\HarddiskVolume2\Windows\System32\win32u.dll' has no imports
  671. 9464.7db8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\win32u.dll)
  672. 9464.7db8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\win32u.dll
  673. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
  674. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume2\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
  675. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rpcrt4.dll'.
  676. 9464.7db8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\combase.dll)
  677. 9464.7db8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\combase.dll
  678. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
  679. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
  680. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
  681. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
  682. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
  683. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
  684. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
  685. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
  686. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
  687. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
  688. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
  689. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
  690. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
  691. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume2\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
  692. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\combase.dll [lacks WinVerifyTrust]
  693. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
  694. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
  695. 9464.7db8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\msvcp_win.dll)
  696. 9464.7db8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msvcp_win.dll
  697. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
  698. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
  699. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
  700. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
  701. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
  702. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
  703. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
  704. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
  705. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
  706. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
  707. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
  708. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
  709. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
  710. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
  711. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcp_win.dll [lacks WinVerifyTrust]
  712. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
  713. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
  714. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
  715. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
  716. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
  717. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
  718. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'sechost.dll'...
  719. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'sechost.dll' -> '\Device\HarddiskVolume2\Windows\System32\sechost.dll' [rcNtRedir=0xc0150008]
  720. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\sechost.dll [lacks WinVerifyTrust]
  721. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
  722. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
  723. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
  724. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
  725. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume2\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
  726. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\win32u.dll [lacks WinVerifyTrust]
  727. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
  728. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
  729. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll [lacks WinVerifyTrust]
  730. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
  731. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
  732. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
  733. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
  734. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
  735. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
  736. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000a01:<flags> [calling]
  737. 9464.7db8: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll [lacks WinVerifyTrust]
  738. 9464.7db8: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll [lacks WinVerifyTrust]
  739. 9464.7db8: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\UICommon.dll [lacks WinVerifyTrust]
  740. 9464.7db8: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll [lacks WinVerifyTrust]
  741. 9464.7db8: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll [lacks WinVerifyTrust]
  742. 9464.7db8: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
  743. 9464.7db8: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [lacks WinVerifyTrust]
  744. 9464.7db8: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll [lacks WinVerifyTrust]
  745. 9464.7db8: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll [lacks WinVerifyTrust]
  746. 9464.7db8: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll [lacks WinVerifyTrust]
  747. 9464.7db8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll [lacks WinVerifyTrust]
  748. 9464.7db8: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\glu32.dll [lacks WinVerifyTrust]
  749. 9464.7db8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\mpr.dll [lacks WinVerifyTrust]
  750. 9464.7db8: supR3HardenedDllNotificationCallback: load 00007ff9646f0000 LB 0x0009e000 C:\WINDOWS\System32\msvcrt.dll [fFlags=0x0]
  751. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
  752. 9464.7db8: supR3HardenedDllNotificationCallback: load 00007ff964990000 LB 0x000ac000 C:\WINDOWS\System32\ADVAPI32.dll [fFlags=0x0]
  753. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
  754. 9464.7db8: supR3HardenedDllNotificationCallback: load 00007ff964340000 LB 0x00022000 C:\WINDOWS\System32\win32u.dll [fFlags=0x0]
  755. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\win32u.dll [lacks WinVerifyTrust]
  756. 9464.7db8: supR3HardenedDllNotificationCallback: load 00007ff9640d0000 LB 0x00100000 C:\WINDOWS\System32\ucrtbase.dll [fFlags=0x0]
  757. 9464.7db8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ucrtbase.dll)
  758. 9464.7db8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ucrtbase.dll
  759. 9464.7db8: supR3HardenedDllNotificationCallback: load 00007ff964220000 LB 0x0009d000 C:\WINDOWS\System32\msvcp_win.dll [fFlags=0x0]
  760. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcp_win.dll [lacks WinVerifyTrust]
  761. 9464.7db8: supR3HardenedDllNotificationCallback: load 00007ff964370000 LB 0x0010b000 C:\WINDOWS\System32\gdi32full.dll [fFlags=0x0]
  762. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
  763. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #33 'gdi32.dll'.
  764. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #35 'user32.dll'.
  765. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #36 'win32u.dll'.
  766. 9464.7db8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\gdi32full.dll)
  767. 9464.7db8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\gdi32full.dll
  768. 9464.7db8: supR3HardenedDllNotificationCallback: load 00007ff9659f0000 LB 0x0002a000 C:\WINDOWS\System32\GDI32.dll [fFlags=0x0]
  769. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
  770. 9464.7db8: supR3HardenedDllNotificationCallback: load 00007ff964a50000 LB 0x001a0000 C:\WINDOWS\System32\USER32.dll [fFlags=0x0]
  771. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
  772. 9464.7db8: supR3HardenedDllNotificationCallback: load 00007ff965a20000 LB 0x00356000 C:\WINDOWS\System32\combase.dll [fFlags=0x0]
  773. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\combase.dll [lacks WinVerifyTrust]
  774. 9464.7db8: supR3HardenedDllNotificationCallback: load 00007ff9356f0000 LB 0x0002c000 C:\WINDOWS\SYSTEM32\GLU32.dll [fFlags=0x0]
  775. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\glu32.dll [lacks WinVerifyTrust]
  776. 9464.7db8: supR3HardenedDllNotificationCallback: load 00007ff931a00000 LB 0x00125000 C:\WINDOWS\SYSTEM32\OPENGL32.dll [fFlags=0x0]
  777. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll [lacks WinVerifyTrust]
  778. 9464.7db8: supR3HardenedDllNotificationCallback: load 000000005ed80000 LB 0x000d2000 C:\Program Files\Oracle\VirtualBox\MSVCR100.dll [fFlags=0x0]
  779. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
  780. 9464.7db8: supR3HardenedDllNotificationCallback: load 000000005e200000 LB 0x00098000 C:\Program Files\Oracle\VirtualBox\MSVCP100.dll [fFlags=0x0]
  781. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcp100.dll [lacks WinVerifyTrust]
  782. 9464.7db8: supR3HardenedDllNotificationCallback: load 00007ff964920000 LB 0x0006b000 C:\WINDOWS\System32\WS2_32.dll [fFlags=0x0]
  783. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll [lacks WinVerifyTrust]
  784. 9464.7db8: supR3HardenedDllNotificationCallback: load 00007ff92d8d0000 LB 0x005e1000 C:\Program Files\Oracle\VirtualBox\VBoxRT.dll [fFlags=0x0]
  785. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll [lacks WinVerifyTrust]
  786. 9464.7db8: supR3HardenedDllNotificationCallback: load 00007ff964ca0000 LB 0x00743000 C:\WINDOWS\System32\SHELL32.dll [fFlags=0x0]
  787. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll [lacks WinVerifyTrust]
  788. 9464.7db8: supR3HardenedDllNotificationCallback: load 00007ff9654c0000 LB 0x0012a000 C:\WINDOWS\System32\ole32.dll [fFlags=0x0]
  789. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll [lacks WinVerifyTrust]
  790. 9464.7db8: supR3HardenedDllNotificationCallback: load 00007ff951fa0000 LB 0x0001d000 C:\WINDOWS\SYSTEM32\MPR.dll [fFlags=0x0]
  791. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\mpr.dll [lacks WinVerifyTrust]
  792. 9464.7db8: supR3HardenedDllNotificationCallback: load 000000005e810000 LB 0x00565000 C:\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [fFlags=0x0]
  793. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [lacks WinVerifyTrust]
  794. 9464.7db8: supR3HardenedDllNotificationCallback: load 00007ff92ae00000 LB 0x005f7000 C:\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll [fFlags=0x0]
  795. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll [lacks WinVerifyTrust]
  796. 9464.7db8: supR3HardenedDllNotificationCallback: load 000000005e2a0000 LB 0x00561000 C:\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll [fFlags=0x0]
  797. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll [lacks WinVerifyTrust]
  798. 9464.7db8: supR3HardenedDllNotificationCallback: load 00007ff9655f0000 LB 0x000cd000 C:\WINDOWS\System32\OLEAUT32.dll [fFlags=0x0]
  799. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll [lacks WinVerifyTrust]
  800. 9464.7db8: supR3HardenedDllNotificationCallback: load 00007ff92b400000 LB 0x02317000 C:\Program Files\Oracle\VirtualBox\UICommon.dll [fFlags=0x0]
  801. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\UICommon.dll [lacks WinVerifyTrust]
  802. 9464.7db8: supR3HardenedDllNotificationCallback: load 000000005dd80000 LB 0x00054000 C:\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll [fFlags=0x0]
  803. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll [lacks WinVerifyTrust]
  804. 9464.7db8: supR3HardenedDllNotificationCallback: load 00007ff95ac40000 LB 0x00027000 C:\WINDOWS\SYSTEM32\WINMM.dll [fFlags=0x0]
  805. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll [lacks WinVerifyTrust]
  806. 9464.7db8: supR3HardenedDllNotificationCallback: load 00007ff9299f0000 LB 0x001c8000 C:\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll [fFlags=0x0]
  807. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll [lacks WinVerifyTrust]
  808. 9464.7db8: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
  809. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
  810. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff963dd0000 'api-ms-win-core-synch-l1-2-0'
  811. 9464.7db8: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-fibers-l1-1-1) -> 0x0, fPresent=1
  812. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
  813. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff963dd0000 'api-ms-win-core-fibers-l1-1-1'
  814. 9464.7db8: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-fibers-l1-1-1) -> 0x0, fPresent=1
  815. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
  816. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff963dd0000 'api-ms-win-core-fibers-l1-1-1'
  817. 9464.7db8: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
  818. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
  819. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff963dd0000 'api-ms-win-core-synch-l1-2-0'
  820. 9464.7db8: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-l1-2-1) -> 0x0, fPresent=1
  821. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-l1-2-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
  822. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff963dd0000 'api-ms-win-core-localization-l1-2-1'
  823. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
  824. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
  825. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume2\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
  826. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\win32u.dll [lacks WinVerifyTrust]
  827. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
  828. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
  829. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
  830. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
  831. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
  832. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
  833. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
  834. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
  835. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcp_win.dll [lacks WinVerifyTrust]
  836. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\kernel32.dll (Input=kernel32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
  837. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff966440000 'C:\WINDOWS\System32\kernel32.dll'
  838. 9464.7db8: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-string-l1-1-0) -> 0x0, fPresent=1
  839. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-string-l1-1-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
  840. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff963dd0000 'api-ms-win-core-string-l1-1-0'
  841. 9464.7db8: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-datetime-l1-1-1) -> 0x0, fPresent=1
  842. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-datetime-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
  843. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff963dd0000 'api-ms-win-core-datetime-l1-1-1'
  844. 9464.7db8: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-obsolete-l1-2-0) -> 0x0, fPresent=1
  845. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-obsolete-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
  846. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff963dd0000 'api-ms-win-core-localization-obsolete-l1-2-0'
  847. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'user32.dll'.
  848. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'win32u.dll'.
  849. 9464.7db8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\imm32.dll)
  850. 9464.7db8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\imm32.dll
  851. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
  852. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume2\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
  853. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\win32u.dll [lacks WinVerifyTrust]
  854. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
  855. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
  856. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
  857. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\IMM32.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
  858. 9464.7db8: supR3HardenedDllNotificationCallback: load 00007ff966500000 LB 0x00030000 C:\WINDOWS\System32\IMM32.DLL [fFlags=0x0]
  859. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\imm32.dll [lacks WinVerifyTrust]
  860. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff966500000 'C:\WINDOWS\system32\IMM32.DLL'
  861. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: error opening 'C:\WINDOWS\System32\edgegdi.dll': 0 (NtPath=\??\C:\WINDOWS\System32\edgegdi.dll; Input=edgegdi.dll; rcNtGetDll=0xc0000135
  862. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000034 'C:\WINDOWS\System32\edgegdi.dll'
  863. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll [lacks WinVerifyTrust]
  864. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  865. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff92d8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  866. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll [lacks WinVerifyTrust]
  867. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  868. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff92d8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  869. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll [lacks WinVerifyTrust]
  870. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  871. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff92d8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  872. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll [lacks WinVerifyTrust]
  873. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  874. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff92d8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  875. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll [lacks WinVerifyTrust]
  876. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  877. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff92d8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  878. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll [lacks WinVerifyTrust]
  879. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff92d8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  880. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll [lacks WinVerifyTrust]
  881. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff92d8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  882. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll [lacks WinVerifyTrust]
  883. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff92d8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  884. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll [lacks WinVerifyTrust]
  885. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff92d8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  886. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll [lacks WinVerifyTrust]
  887. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff92d8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  888. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll [lacks WinVerifyTrust]
  889. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff92d8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  890. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll [lacks WinVerifyTrust]
  891. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff92d8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  892. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll [lacks WinVerifyTrust]
  893. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  894. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff92d8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  895. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll [lacks WinVerifyTrust]
  896. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff92d8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  897. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll [lacks WinVerifyTrust]
  898. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff92d8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  899. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll [lacks WinVerifyTrust]
  900. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff92d8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  901. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll [lacks WinVerifyTrust]
  902. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff92d8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  903. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll [lacks WinVerifyTrust]
  904. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff92d8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  905. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll [lacks WinVerifyTrust]
  906. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff92d8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  907. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll [lacks WinVerifyTrust]
  908. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff92d8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  909. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll [lacks WinVerifyTrust]
  910. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff92d8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  911. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll [lacks WinVerifyTrust]
  912. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff92d8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  913. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll [lacks WinVerifyTrust]
  914. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff92d8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  915. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll [lacks WinVerifyTrust]
  916. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff92d8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  917. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll [lacks WinVerifyTrust]
  918. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff92d8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  919. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll [lacks WinVerifyTrust]
  920. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff92d8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  921. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll [lacks WinVerifyTrust]
  922. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff92d8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  923. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll [lacks WinVerifyTrust]
  924. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff92d8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  925. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll [lacks WinVerifyTrust]
  926. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  927. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff92d8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  928. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll [lacks WinVerifyTrust]
  929. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff92d8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  930. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll [lacks WinVerifyTrust]
  931. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff92d8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  932. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VBoxRT.dll [lacks WinVerifyTrust]
  933. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff92d8d0000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
  934. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
  935. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\ADVAPI32.DLL (Input=ADVAPI32.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  936. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff964990000 'C:\WINDOWS\System32\ADVAPI32.DLL'
  937. 9464.7db8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\cryptbase.dll)
  938. 9464.7db8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cryptbase.dll
  939. 9464.7db8: supR3HardenedDllNotificationCallback: load 00007ff9636b0000 LB 0x0000c000 C:\WINDOWS\SYSTEM32\CRYPTBASE.DLL [fFlags=0x0]
  940. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cryptbase.dll [lacks WinVerifyTrust]
  941. 9464.7db8: supR3HardenedDllNotificationCallback: load 00007ff9642c0000 LB 0x00080000 C:\WINDOWS\System32\bcryptPrimitives.dll [fFlags=0x0]
  942. 9464.7db8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll)
  943. 9464.7db8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll
  944. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9299f0000 'C:\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll'
  945. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #31 'combase.dll'.
  946. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #32 'msvcp_win.dll'.
  947. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #34 'wldp.dll'.
  948. 9464.7db8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\windows.storage.dll)
  949. 9464.7db8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\windows.storage.dll
  950. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
  951. 9464.7db8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\wldp.dll)
  952. 9464.7db8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wldp.dll
  953. 9464.7db8: supR3HardenedDllNotificationCallback: load 00007ff963760000 LB 0x0002c000 C:\WINDOWS\SYSTEM32\Wldp.dll [fFlags=0x0]
  954. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wldp.dll [lacks WinVerifyTrust]
  955. 9464.7db8: supR3HardenedDllNotificationCallback: load 00007ff961f50000 LB 0x0078f000 C:\WINDOWS\SYSTEM32\windows.storage.dll [fFlags=0x0]
  956. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\windows.storage.dll [lacks WinVerifyTrust]
  957. 9464.7db8: supR3HardenedDllNotificationCallback: load 00007ff964790000 LB 0x000ae000 C:\WINDOWS\System32\SHCORE.dll [fFlags=0x0]
  958. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
  959. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #42 'combase.dll'.
  960. 9464.7db8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\SHCore.dll)
  961. 9464.7db8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\SHCore.dll
  962. 9464.7db8: supR3HardenedDllNotificationCallback: load 00007ff9653f0000 LB 0x00055000 C:\WINDOWS\System32\shlwapi.dll [fFlags=0x0]
  963. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
  964. 9464.7db8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\shlwapi.dll)
  965. 9464.7db8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\shlwapi.dll
  966. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
  967. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
  968. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
  969. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
  970. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
  971. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume2\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
  972. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\combase.dll [lacks WinVerifyTrust]
  973. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
  974. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
  975. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
  976. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
  977. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
  978. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
  979. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wldp.dll'...
  980. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'wldp.dll' -> '\Device\HarddiskVolume2\Windows\System32\wldp.dll' [rcNtRedir=0xc0150008]
  981. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wldp.dll [lacks WinVerifyTrust]
  982. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
  983. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
  984. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcp_win.dll [lacks WinVerifyTrust]
  985. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
  986. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume2\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
  987. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\combase.dll [lacks WinVerifyTrust]
  988. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  989. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff966440000 'C:\WINDOWS\System32\kernel32.dll'
  990. 9464.7db8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\profapi.dll)
  991. 9464.7db8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\profapi.dll
  992. 9464.7db8: supR3HardenedDllNotificationCallback: load 00007ff963d00000 LB 0x00026000 C:\WINDOWS\SYSTEM32\profapi.dll [fFlags=0x0]
  993. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\profapi.dll [lacks WinVerifyTrust]
  994. 9464.7db8: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\platforms\qwindows.dll: Signature #1/2: info status: 24202
  995. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
  996. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'ole32.dll'.
  997. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
  998. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'imm32.dll'.
  999. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'winmm.dll'.
  1000. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'oleaut32.dll'.
  1001. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'shell32.dll'.
  1002. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'advapi32.dll'.
  1003. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'qt5guivbox.dll'.
  1004. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'qt5corevbox.dll'.
  1005. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'msvcr100.dll'.
  1006. 9464.7db8: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\platforms\qwindows.dll)
  1007. 9464.7db8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\platforms\qwindows.dll
  1008. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
  1009. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
  1010. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\msvcr100.dll [lacks WinVerifyTrust]
  1011. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
  1012. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
  1013. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [lacks WinVerifyTrust]
  1014. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
  1015. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
  1016. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll [lacks WinVerifyTrust]
  1017. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
  1018. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
  1019. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
  1020. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
  1021. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
  1022. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll [lacks WinVerifyTrust]
  1023. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
  1024. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
  1025. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll [lacks WinVerifyTrust]
  1026. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
  1027. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
  1028. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll [lacks WinVerifyTrust]
  1029. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
  1030. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume2\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
  1031. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\imm32.dll [lacks WinVerifyTrust]
  1032. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
  1033. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
  1034. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
  1035. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
  1036. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
  1037. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll [lacks WinVerifyTrust]
  1038. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
  1039. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
  1040. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
  1041. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\platforms\qwindows.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  1042. 9464.7db8: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\platforms\qwindows.dll [lacks WinVerifyTrust]
  1043. 9464.7db8: supR3HardenedDllNotificationCallback: load 00007ff92e6c0000 LB 0x0012e000 C:\Program Files\Oracle\VirtualBox\platforms\qwindows.dll [fFlags=0x0]
  1044. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\platforms\qwindows.dll [lacks WinVerifyTrust]
  1045. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff92e6c0000 'C:\Program Files\Oracle\VirtualBox\platforms\qwindows.dll'
  1046. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'msvcrt.dll'.
  1047. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'rpcrt4.dll'.
  1048. 9464.7db8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\kernel.appcore.dll)
  1049. 9464.7db8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\kernel.appcore.dll
  1050. 9464.7db8: supR3HardenedDllNotificationCallback: load 00007ff961d50000 LB 0x00012000 C:\WINDOWS\SYSTEM32\kernel.appcore.dll [fFlags=0x0]
  1051. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\kernel.appcore.dll [lacks WinVerifyTrust]
  1052. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
  1053. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #33 'gdi32.dll'.
  1054. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #34 'user32.dll'.
  1055. 9464.7db8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\uxtheme.dll)
  1056. 9464.7db8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
  1057. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
  1058. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
  1059. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
  1060. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
  1061. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
  1062. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
  1063. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
  1064. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
  1065. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
  1066. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
  1067. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
  1068. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
  1069. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
  1070. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
  1071. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
  1072. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
  1073. 9464.7db8: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll [lacks WinVerifyTrust]
  1074. 9464.7db8: supR3HardenedDllNotificationCallback: load 00007ff961890000 LB 0x0009e000 C:\WINDOWS\system32\uxtheme.dll [fFlags=0x0]
  1075. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll [lacks WinVerifyTrust]
  1076. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff961890000 'C:\WINDOWS\system32\uxtheme.dll'
  1077. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
  1078. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff964a50000 'C:\WINDOWS\system32\user32.dll'
  1079. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll [lacks WinVerifyTrust]
  1080. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  1081. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff964ca0000 'C:\WINDOWS\system32\shell32.dll'
  1082. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\SHCore.dll [lacks WinVerifyTrust]
  1083. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\SHCore.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  1084. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff964790000 'C:\WINDOWS\system32\SHCore.dll'
  1085. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: error opening 'C:\WINDOWS\system32\wintab32.dll': 0 (NtPath=\??\C:\WINDOWS\system32\wintab32.dll; Input=C:\WINDOWS\system32\wintab32.dll; rcNtGetDll=0x0
  1086. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000034 'C:\WINDOWS\system32\wintab32.dll'
  1087. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll [lacks WinVerifyTrust]
  1088. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\winmm.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  1089. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff95ac40000 'C:\WINDOWS\system32\winmm.dll'
  1090. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll [lacks WinVerifyTrust]
  1091. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\winmm.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  1092. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff95ac40000 'C:\WINDOWS\system32\winmm.dll'
  1093. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll [lacks WinVerifyTrust]
  1094. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  1095. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff964ca0000 'C:\WINDOWS\system32\shell32.dll'
  1096. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll [lacks WinVerifyTrust]
  1097. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  1098. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff961890000 'C:\WINDOWS\system32\uxtheme.dll'
  1099. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
  1100. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9659f0000 'C:\WINDOWS\system32\gdi32.dll'
  1101. 9464.7db8: supR3HardenedDllNotificationCallback: load 00007ff966530000 LB 0x00116000 C:\WINDOWS\System32\MSCTF.dll [fFlags=0x0]
  1102. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
  1103. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'oleaut32.dll'.
  1104. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #36 'user32.dll'.
  1105. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #37 'gdi32.dll'.
  1106. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #38 'imm32.dll'.
  1107. 9464.7db8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\msctf.dll)
  1108. 9464.7db8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msctf.dll
  1109. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
  1110. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
  1111. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume2\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
  1112. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\imm32.dll [lacks WinVerifyTrust]
  1113. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
  1114. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
  1115. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
  1116. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
  1117. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
  1118. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
  1119. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
  1120. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
  1121. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll [lacks WinVerifyTrust]
  1122. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
  1123. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
  1124. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
  1125. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9662b0000 'C:\WINDOWS\System32\rpcrt4.dll'
  1126. 9464.7db8: supR3HardenedDllNotificationCallback: load 00007ff964bf0000 LB 0x000a9000 C:\WINDOWS\System32\clbcatq.dll [fFlags=0x0]
  1127. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
  1128. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #30 'rpcrt4.dll'.
  1129. 9464.7db8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\clbcatq.dll)
  1130. 9464.7db8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\clbcatq.dll
  1131. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
  1132. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'd3d11.dll'.
  1133. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #27 'dcomp.dll'.
  1134. 9464.7db8: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\DataExchange.dll)
  1135. 9464.7db8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\DataExchange.dll
  1136. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dcomp.dll'...
  1137. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'dcomp.dll' -> '\Device\HarddiskVolume2\Windows\System32\dcomp.dll' [rcNtRedir=0xc0150008]
  1138. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'win32u.dll'.
  1139. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp_win.dll'.
  1140. 9464.7db8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\dcomp.dll)
  1141. 9464.7db8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\dcomp.dll
  1142. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'd3d11.dll'...
  1143. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'd3d11.dll' -> '\Device\HarddiskVolume2\Windows\System32\d3d11.dll' [rcNtRedir=0xc0150008]
  1144. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
  1145. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'dxgi.dll'.
  1146. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #28 'win32u.dll'.
  1147. 9464.7db8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\d3d11.dll)
  1148. 9464.7db8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\d3d11.dll
  1149. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
  1150. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
  1151. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
  1152. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
  1153. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
  1154. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
  1155. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
  1156. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
  1157. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
  1158. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
  1159. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume2\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
  1160. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\win32u.dll [lacks WinVerifyTrust]
  1161. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dxgi.dll'...
  1162. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'dxgi.dll' -> '\Device\HarddiskVolume2\Windows\System32\dxgi.dll' [rcNtRedir=0xc0150008]
  1163. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
  1164. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'win32u.dll'.
  1165. 9464.7db8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\dxgi.dll)
  1166. 9464.7db8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\dxgi.dll
  1167. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
  1168. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
  1169. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
  1170. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
  1171. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
  1172. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcp_win.dll [lacks WinVerifyTrust]
  1173. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
  1174. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume2\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
  1175. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\win32u.dll [lacks WinVerifyTrust]
  1176. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
  1177. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume2\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
  1178. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\win32u.dll [lacks WinVerifyTrust]
  1179. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
  1180. 9464.7db8: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
  1181. 9464.7db8: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
  1182. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\dataexchange.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
  1183. 9464.7db8: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\DataExchange.dll [lacks WinVerifyTrust]
  1184. 9464.7db8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\d3d11.dll [lacks WinVerifyTrust]
  1185. 9464.7db8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dcomp.dll [lacks WinVerifyTrust]
  1186. 9464.7db8: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dxgi.dll [lacks WinVerifyTrust]
  1187. 9464.7db8: supR3HardenedDllNotificationCallback: load 00007ff962720000 LB 0x000f3000 C:\WINDOWS\system32\dxgi.dll [fFlags=0x0]
  1188. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dxgi.dll [lacks WinVerifyTrust]
  1189. 9464.7db8: supR3HardenedDllNotificationCallback: load 00007ff960310000 LB 0x00264000 C:\WINDOWS\system32\d3d11.dll [fFlags=0x0]
  1190. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\d3d11.dll [lacks WinVerifyTrust]
  1191. 9464.7db8: supR3HardenedDllNotificationCallback: load 00007ff960b60000 LB 0x001e7000 C:\WINDOWS\system32\dcomp.dll [fFlags=0x0]
  1192. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dcomp.dll [lacks WinVerifyTrust]
  1193. 9464.7db8: supR3HardenedDllNotificationCallback: load 00007ff950240000 LB 0x0003e000 C:\WINDOWS\system32\dataexchange.dll [fFlags=0x0]
  1194. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\DataExchange.dll [lacks WinVerifyTrust]
  1195. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
  1196. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9659f0000 'C:\WINDOWS\System32\gdi32.dll'
  1197. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff950240000 'C:\WINDOWS\system32\dataexchange.dll'
  1198. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #30 'rpcrt4.dll'.
  1199. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #43 'combase.dll'.
  1200. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #45 'msvcp_win.dll'.
  1201. 9464.7db8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\twinapi.appcore.dll)
  1202. 9464.7db8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\twinapi.appcore.dll
  1203. 9464.7db8: supR3HardenedDllNotificationCallback: load 00007ff95fab0000 LB 0x00201000 C:\WINDOWS\system32\twinapi.appcore.dll [fFlags=0x0]
  1204. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\twinapi.appcore.dll [lacks WinVerifyTrust]
  1205. 9464.5698: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
  1206. 9464.5698: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\winmmbase.dll)
  1207. 9464.5698: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\winmmbase.dll
  1208. 9464.5698: supR3HardenedDllNotificationCallback: load 00007ff951e60000 LB 0x00026000 C:\WINDOWS\SYSTEM32\winmmbase.dll [fFlags=0x0]
  1209. 9464.5698: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmmbase.dll [lacks WinVerifyTrust]
  1210. 9464.5698: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
  1211. 9464.5698: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'rpcrt4.dll'.
  1212. 9464.5698: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #28 'devobj.dll'.
  1213. 9464.5698: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll)
  1214. 9464.5698: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
  1215. 9464.5698: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'cfgmgr32.dll'.
  1216. 9464.5698: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\devobj.dll)
  1217. 9464.5698: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\devobj.dll
  1218. 9464.5698: supR3HardenedDllNotificationCallback: load 00007ff9641d0000 LB 0x0004e000 C:\WINDOWS\System32\cfgmgr32.dll [fFlags=0x0]
  1219. 9464.5698: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll)
  1220. 9464.5698: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll
  1221. 9464.5698: supR3HardenedDllNotificationCallback: load 00007ff963ab0000 LB 0x0002c000 C:\WINDOWS\SYSTEM32\DEVOBJ.dll [fFlags=0x0]
  1222. 9464.5698: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\devobj.dll [lacks WinVerifyTrust]
  1223. 9464.5698: supR3HardenedDllNotificationCallback: load 00007ff95ea70000 LB 0x00085000 C:\WINDOWS\SYSTEM32\MMDevAPI.DLL [fFlags=0x0]
  1224. 9464.5698: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll [lacks WinVerifyTrust]
  1225. 9464.5698: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
  1226. 9464.5698: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'mmdevapi.dll'.
  1227. 9464.5698: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'ksuser.dll'.
  1228. 9464.5698: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #30 'avrt.dll'.
  1229. 9464.5698: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\wdmaud.drv)
  1230. 9464.5698: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
  1231. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'avrt.dll'...
  1232. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: 'avrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\avrt.dll' [rcNtRedir=0xc0150008]
  1233. 9464.5698: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\avrt.dll)
  1234. 9464.5698: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\avrt.dll
  1235. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ksuser.dll'...
  1236. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: 'ksuser.dll' -> '\Device\HarddiskVolume2\Windows\System32\ksuser.dll' [rcNtRedir=0xc0150008]
  1237. 9464.5698: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
  1238. 9464.5698: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ksuser.dll)
  1239. 9464.5698: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ksuser.dll
  1240. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mmdevapi.dll'...
  1241. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: 'mmdevapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\mmdevapi.dll' [rcNtRedir=0xc0150008]
  1242. 9464.5698: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll [lacks WinVerifyTrust]
  1243. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
  1244. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
  1245. 9464.5698: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
  1246. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
  1247. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
  1248. 9464.5698: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll [lacks WinVerifyTrust]
  1249. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'devobj.dll'...
  1250. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: 'devobj.dll' -> '\Device\HarddiskVolume2\Windows\System32\devobj.dll' [rcNtRedir=0xc0150008]
  1251. 9464.5698: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\devobj.dll [lacks WinVerifyTrust]
  1252. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
  1253. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
  1254. 9464.5698: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
  1255. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
  1256. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
  1257. 9464.5698: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcp_win.dll [lacks WinVerifyTrust]
  1258. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
  1259. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
  1260. 9464.5698: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
  1261. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
  1262. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
  1263. 9464.5698: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcp_win.dll [lacks WinVerifyTrust]
  1264. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
  1265. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume2\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
  1266. 9464.5698: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\combase.dll [lacks WinVerifyTrust]
  1267. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
  1268. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
  1269. 9464.5698: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
  1270. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
  1271. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
  1272. 9464.5698: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
  1273. 9464.5698: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
  1274. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
  1275. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #15 'oleaut32.dll'.
  1276. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'rpcrt4.dll'.
  1277. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #20 'coreuicomponents.dll'.
  1278. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #21 'coremessaging.dll'.
  1279. 9464.7db8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\TextInputFramework.dll)
  1280. 9464.7db8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\TextInputFramework.dll
  1281. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
  1282. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #35 'coremessaging.dll'.
  1283. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #40 'rpcrt4.dll'.
  1284. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #48 'shcore.dll'.
  1285. 9464.7db8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\CoreUIComponents.dll)
  1286. 9464.7db8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\CoreUIComponents.dll
  1287. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
  1288. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #20 'ws2_32.dll'.
  1289. 9464.7db8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\CoreMessaging.dll)
  1290. 9464.7db8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\CoreMessaging.dll
  1291. 9464.7db8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ntmarta.dll)
  1292. 9464.7db8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ntmarta.dll
  1293. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'combase.dll'.
  1294. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #24 'rpcrt4.dll'.
  1295. 9464.7db8: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #32 'bcryptprimitives.dll'.
  1296. 9464.7db8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\WinTypes.dll)
  1297. 9464.7db8: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\WinTypes.dll
  1298. 9464.7db8: supR3HardenedDllNotificationCallback: load 00007ff962b10000 LB 0x00033000 C:\WINDOWS\SYSTEM32\ntmarta.dll [fFlags=0x0]
  1299. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ntmarta.dll [lacks WinVerifyTrust]
  1300. 9464.7db8: supR3HardenedDllNotificationCallback: load 00007ff961230000 LB 0x000f2000 C:\WINDOWS\System32\CoreMessaging.dll [fFlags=0x0]
  1301. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\CoreMessaging.dll [lacks WinVerifyTrust]
  1302. 9464.7db8: supR3HardenedDllNotificationCallback: load 00007ff9610d0000 LB 0x00154000 C:\WINDOWS\SYSTEM32\wintypes.dll [fFlags=0x0]
  1303. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\WinTypes.dll [lacks WinVerifyTrust]
  1304. 9464.7db8: supR3HardenedDllNotificationCallback: load 00007ff961480000 LB 0x0035e000 C:\WINDOWS\System32\CoreUIComponents.dll [fFlags=0x0]
  1305. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\CoreUIComponents.dll [lacks WinVerifyTrust]
  1306. 9464.7db8: supR3HardenedDllNotificationCallback: load 00007ff950330000 LB 0x000fb000 C:\WINDOWS\SYSTEM32\textinputframework.dll [fFlags=0x0]
  1307. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\TextInputFramework.dll [lacks WinVerifyTrust]
  1308. 9464.5698: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv [lacks WinVerifyTrust]
  1309. 9464.5698: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ksuser.dll [lacks WinVerifyTrust]
  1310. 9464.5698: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\avrt.dll [lacks WinVerifyTrust]
  1311. 9464.7db8: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(ext-ms-win-rtcore-ntuser-window-ext-l1-1-0.dll) -> 0x0, fPresent=1
  1312. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: pName=ext-ms-win-rtcore-ntuser-window-ext-l1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  1313. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff964a50000 'ext-ms-win-rtcore-ntuser-window-ext-l1-1-0.dll'
  1314. 9464.5698: supR3HardenedDllNotificationCallback: load 00007ff95fe90000 LB 0x00009000 C:\WINDOWS\SYSTEM32\ksuser.dll [fFlags=0x0]
  1315. 9464.5698: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ksuser.dll [lacks WinVerifyTrust]
  1316. 9464.5698: supR3HardenedDllNotificationCallback: load 00007ff958170000 LB 0x0000a000 C:\WINDOWS\SYSTEM32\AVRT.dll [fFlags=0x0]
  1317. 9464.5698: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\avrt.dll [lacks WinVerifyTrust]
  1318. 9464.5698: supR3HardenedDllNotificationCallback: load 00007ff945020000 LB 0x00046000 C:\WINDOWS\System32\wdmaud.drv [fFlags=0x0]
  1319. 9464.5698: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv [lacks WinVerifyTrust]
  1320. 9464.7db8: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(ext-ms-win-rtcore-ntuser-integration-l1-1-0.dll) -> 0x0, fPresent=1
  1321. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: pName=ext-ms-win-rtcore-ntuser-integration-l1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  1322. 9464.5698: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff945020000 'C:\WINDOWS\System32\wdmaud.drv'
  1323. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff964a50000 'ext-ms-win-rtcore-ntuser-integration-l1-1-0.dll'
  1324. 9464.5698: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv [lacks WinVerifyTrust]
  1325. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcryptprimitives.dll'...
  1326. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcryptprimitives.dll' -> '\Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll' [rcNtRedir=0xc0150008]
  1327. 9464.5698: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
  1328. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
  1329. 9464.7db8: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-com-l1-1-0.dll) -> 0x0, fPresent=1
  1330. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-com-l1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  1331. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff965a20000 'api-ms-win-core-com-l1-1-0.dll'
  1332. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
  1333. 9464.5698: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
  1334. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
  1335. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume2\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
  1336. 9464.5698: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\combase.dll [lacks WinVerifyTrust]
  1337. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
  1338. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
  1339. 9464.5698: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll [lacks WinVerifyTrust]
  1340. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
  1341. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
  1342. 9464.5698: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
  1343. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shcore.dll'...
  1344. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: 'shcore.dll' -> '\Device\HarddiskVolume2\Windows\System32\shcore.dll' [rcNtRedir=0xc0150008]
  1345. 9464.5698: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\SHCore.dll [lacks WinVerifyTrust]
  1346. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
  1347. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
  1348. 9464.5698: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
  1349. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'coremessaging.dll'...
  1350. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: 'coremessaging.dll' -> '\Device\HarddiskVolume2\Windows\System32\coremessaging.dll' [rcNtRedir=0xc0150008]
  1351. 9464.5698: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\CoreMessaging.dll [lacks WinVerifyTrust]
  1352. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
  1353. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
  1354. 9464.5698: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
  1355. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'coremessaging.dll'...
  1356. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: 'coremessaging.dll' -> '\Device\HarddiskVolume2\Windows\System32\coremessaging.dll' [rcNtRedir=0xc0150008]
  1357. 9464.5698: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\CoreMessaging.dll [lacks WinVerifyTrust]
  1358. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'coreuicomponents.dll'...
  1359. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: 'coreuicomponents.dll' -> '\Device\HarddiskVolume2\Windows\System32\coreuicomponents.dll' [rcNtRedir=0xc0150008]
  1360. 9464.5698: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\CoreUIComponents.dll [lacks WinVerifyTrust]
  1361. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
  1362. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
  1363. 9464.5698: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
  1364. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
  1365. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
  1366. 9464.5698: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll [lacks WinVerifyTrust]
  1367. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
  1368. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll [lacks WinVerifyTrust]
  1369. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\system32\ole32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
  1370. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
  1371. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9654c0000 'C:\WINDOWS\system32\ole32.dll'
  1372. 9464.5698: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
  1373. 9464.5698: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
  1374. 9464.5698: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff945020000 'C:\WINDOWS\System32\wdmaud.drv'
  1375. 9464.5698: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll [lacks WinVerifyTrust]
  1376. 9464.5698: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\MMDEVAPI.DLL (Input=MMDEVAPI.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  1377. 9464.5698: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff95ea70000 'C:\WINDOWS\System32\MMDEVAPI.DLL'
  1378. 9464.7db8: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msctf.dll [lacks WinVerifyTrust]
  1379. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\MSCTF.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
  1380. 9464.7db8: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff966530000 'C:\WINDOWS\System32\MSCTF.dll'
  1381. 9464.5698: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv [lacks WinVerifyTrust]
  1382. 9464.5698: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
  1383. 9464.5698: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff945020000 'C:\WINDOWS\System32\wdmaud.drv'
  1384. 9464.5698: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv [lacks WinVerifyTrust]
  1385. 9464.5698: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
  1386. 9464.5698: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff945020000 'C:\WINDOWS\System32\wdmaud.drv'
  1387. 9464.5698: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv [lacks WinVerifyTrust]
  1388. 9464.5698: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
  1389. 9464.5698: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff945020000 'C:\WINDOWS\System32\wdmaud.drv'
  1390. 9464.5698: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
  1391. 9464.5698: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'rpcrt4.dll'.
  1392. 9464.5698: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'oleaut32.dll'.
  1393. 9464.5698: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #29 'mmdevapi.dll'.
  1394. 9464.5698: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\AudioSes.dll)
  1395. 9464.5698: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\AudioSes.dll
  1396. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mmdevapi.dll'...
  1397. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: 'mmdevapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\mmdevapi.dll' [rcNtRedir=0xc0150008]
  1398. 9464.5698: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll [lacks WinVerifyTrust]
  1399. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
  1400. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
  1401. 9464.5698: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll [lacks WinVerifyTrust]
  1402. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
  1403. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
  1404. 9464.5698: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
  1405. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
  1406. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
  1407. 9464.5698: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcp_win.dll [lacks WinVerifyTrust]
  1408. 9464.5698: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\AUDIOSES.DLL (Input=AUDIOSES.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
  1409. 9464.5698: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\AudioSes.dll [lacks WinVerifyTrust]
  1410. 9464.5698: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'rpcrt4.dll'.
  1411. 9464.5698: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\powrprof.dll)
  1412. 9464.5698: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\powrprof.dll
  1413. 9464.5698: supR3HardenedDllNotificationCallback: load 00007ff963c30000 LB 0x0004b000 C:\WINDOWS\SYSTEM32\powrprof.dll [fFlags=0x0]
  1414. 9464.5698: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\powrprof.dll [lacks WinVerifyTrust]
  1415. 9464.5698: supR3HardenedDllNotificationCallback: load 00007ff95c5e0000 LB 0x00183000 C:\WINDOWS\System32\AUDIOSES.DLL [fFlags=0x0]
  1416. 9464.5698: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\AudioSes.dll [lacks WinVerifyTrust]
  1417. 9464.5698: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\umpdc.dll)
  1418. 9464.5698: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\umpdc.dll
  1419. 9464.5698: supR3HardenedDllNotificationCallback: load 00007ff963c10000 LB 0x00012000 C:\WINDOWS\SYSTEM32\UMPDC.dll [fFlags=0x0]
  1420. 9464.5698: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\umpdc.dll [lacks WinVerifyTrust]
  1421. 9464.5698: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff95c5e0000 'C:\WINDOWS\System32\AUDIOSES.DLL'
  1422. 9464.5698: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv [lacks WinVerifyTrust]
  1423. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
  1424. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
  1425. 9464.5698: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
  1426. 9464.5698: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
  1427. 9464.5698: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff945020000 'C:\WINDOWS\System32\wdmaud.drv'
  1428. 9464.5698: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv [lacks WinVerifyTrust]
  1429. 9464.5698: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
  1430. 9464.5698: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff945020000 'C:\WINDOWS\System32\wdmaud.drv'
  1431. 9464.5698: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv [lacks WinVerifyTrust]
  1432. 9464.5698: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff945020000 'C:\WINDOWS\System32\wdmaud.drv'
  1433. 9464.5698: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv [lacks WinVerifyTrust]
  1434. 9464.5698: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff945020000 'C:\WINDOWS\System32\wdmaud.drv'
  1435. 9464.5698: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv [lacks WinVerifyTrust]
  1436. 9464.5698: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff945020000 'C:\WINDOWS\System32\wdmaud.drv'
  1437. 9464.5698: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv [lacks WinVerifyTrust]
  1438. 9464.5698: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff945020000 'C:\WINDOWS\System32\wdmaud.drv'
  1439. 9464.5698: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
  1440. 9464.5698: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'mmdevapi.dll'.
  1441. 9464.5698: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'msacm32.dll'.
  1442. 9464.5698: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\msacm32.drv)
  1443. 9464.5698: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msacm32.drv
  1444. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msacm32.dll'...
  1445. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: 'msacm32.dll' -> '\Device\HarddiskVolume2\Windows\System32\msacm32.dll' [rcNtRedir=0xc0150008]
  1446. 9464.5698: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
  1447. 9464.5698: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\msacm32.dll)
  1448. 9464.5698: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msacm32.dll
  1449. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mmdevapi.dll'...
  1450. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: 'mmdevapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\mmdevapi.dll' [rcNtRedir=0xc0150008]
  1451. 9464.5698: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll [lacks WinVerifyTrust]
  1452. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
  1453. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
  1454. 9464.5698: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
  1455. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
  1456. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
  1457. 9464.5698: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
  1458. 9464.5698: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
  1459. 9464.5698: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv [lacks WinVerifyTrust]
  1460. 9464.5698: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.dll [lacks WinVerifyTrust]
  1461. 9464.5698: supR3HardenedDllNotificationCallback: load 00007ff95ccb0000 LB 0x0001e000 C:\WINDOWS\SYSTEM32\MSACM32.dll [fFlags=0x0]
  1462. 9464.5698: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.dll [lacks WinVerifyTrust]
  1463. 9464.5698: supR3HardenedDllNotificationCallback: load 00007ff95fe70000 LB 0x0000d000 C:\WINDOWS\System32\msacm32.drv [fFlags=0x0]
  1464. 9464.5698: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv [lacks WinVerifyTrust]
  1465. 9464.5698: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff95fe70000 'C:\WINDOWS\System32\msacm32.drv'
  1466. 9464.5698: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv [lacks WinVerifyTrust]
  1467. 9464.5698: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
  1468. 9464.5698: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff95fe70000 'C:\WINDOWS\System32\msacm32.drv'
  1469. 9464.5698: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv [lacks WinVerifyTrust]
  1470. 9464.5698: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
  1471. 9464.5698: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff95fe70000 'C:\WINDOWS\System32\msacm32.drv'
  1472. 9464.5698: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv [lacks WinVerifyTrust]
  1473. 9464.5698: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
  1474. 9464.5698: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff95fe70000 'C:\WINDOWS\System32\msacm32.drv'
  1475. 9464.5698: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv [lacks WinVerifyTrust]
  1476. 9464.5698: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
  1477. 9464.5698: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff95fe70000 'C:\WINDOWS\System32\msacm32.drv'
  1478. 9464.5698: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv [lacks WinVerifyTrust]
  1479. 9464.5698: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
  1480. 9464.5698: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff95fe70000 'C:\WINDOWS\System32\msacm32.drv'
  1481. 9464.5698: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv [lacks WinVerifyTrust]
  1482. 9464.5698: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
  1483. 9464.5698: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff95fe70000 'C:\WINDOWS\System32\msacm32.drv'
  1484. 9464.5698: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv [lacks WinVerifyTrust]
  1485. 9464.5698: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff95fe70000 'C:\WINDOWS\System32\msacm32.drv'
  1486. 9464.5698: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv [lacks WinVerifyTrust]
  1487. 9464.5698: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff95fe70000 'C:\WINDOWS\System32\msacm32.drv'
  1488. 9464.5698: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv [lacks WinVerifyTrust]
  1489. 9464.5698: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff95fe70000 'C:\WINDOWS\System32\msacm32.drv'
  1490. 9464.5698: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
  1491. 9464.5698: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'winmmbase.dll'.
  1492. 9464.5698: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\midimap.dll)
  1493. 9464.5698: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\midimap.dll
  1494. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmmbase.dll'...
  1495. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmmbase.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmmbase.dll' [rcNtRedir=0xc0150008]
  1496. 9464.5698: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmmbase.dll [lacks WinVerifyTrust]
  1497. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
  1498. 9464.5698: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
  1499. 9464.5698: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
  1500. 9464.5698: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
  1501. 9464.5698: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\midimap.dll [lacks WinVerifyTrust]
  1502. 9464.5698: supR3HardenedDllNotificationCallback: load 00007ff95e1d0000 LB 0x0000b000 C:\WINDOWS\System32\midimap.dll [fFlags=0x0]
  1503. 9464.5698: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\midimap.dll [lacks WinVerifyTrust]
  1504. 9464.5698: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff95e1d0000 'C:\WINDOWS\System32\midimap.dll'
  1505. 9464.5698: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\midimap.dll [lacks WinVerifyTrust]
  1506. 9464.5698: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
  1507. 9464.5698: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff95e1d0000 'C:\WINDOWS\System32\midimap.dll'
  1508. 9464.5698: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\midimap.dll [lacks WinVerifyTrust]
  1509. 9464.5698: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
  1510. 9464.5698: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff95e1d0000 'C:\WINDOWS\System32\midimap.dll'
  1511. 9464.5698: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\midimap.dll [lacks WinVerifyTrust]
  1512. 9464.5698: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000001001:<flags> [calling]
  1513. 9464.5698: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff95e1d0000 'C:\WINDOWS\System32\midimap.dll'
  1514. 9464.96f0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll [lacks WinVerifyTrust]
  1515. 9464.96f0: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\MMDevApi.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
  1516. 9464.96f0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff95ea70000 'C:\WINDOWS\System32\MMDevApi.dll'
  1517. 9164.96cc: supR3HardNtChildWaitFor[1]: Quitting: ExitCode=0x1 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 3547 ms, the end);
  1518.  
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement