Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 510.1fd0: Log file opened: 5.2.8r121009 g_hStartupLog=0000000000000014 g_uNtVerCombined=0x611db110
- 510.1fd0: \SystemRoot\System32\ntdll.dll:
- 510.1fd0: CreationTime: 2014-07-29T15:15:12.093598700Z
- 510.1fd0: LastWriteTime: 2013-08-29T02:16:35.515578900Z
- 510.1fd0: ChangeTime: 2014-07-29T15:42:24.768970900Z
- 510.1fd0: FileAttributes: 0x20
- 510.1fd0: Size: 0x1a6dc0
- 510.1fd0: NT Headers: 0xe0
- 510.1fd0: Timestamp: 0x521eaf24
- 510.1fd0: Machine: 0x8664 - amd64
- 510.1fd0: Timestamp: 0x521eaf24
- 510.1fd0: Image Version: 6.1
- 510.1fd0: SizeOfImage: 0x1a9000 (1740800)
- 510.1fd0: Resource Dir: 0x151000 LB 0x560d8
- 510.1fd0: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 510.1fd0: [Raw version resource data: 0x1510f0 LB 0x380, codepage 0x0 (reserved 0x0)]
- 510.1fd0: ProductName: Microsoft® Windows® Operating System
- 510.1fd0: ProductVersion: 6.1.7601.18247
- 510.1fd0: FileVersion: 6.1.7601.18247 (win7sp1_gdr.130828-1532)
- 510.1fd0: FileDescription: NT Layer DLL
- 510.1fd0: \SystemRoot\System32\kernel32.dll:
- 510.1fd0: CreationTime: 2014-07-29T15:11:12.789178400Z
- 510.1fd0: LastWriteTime: 2014-03-04T09:44:00.336000000Z
- 510.1fd0: ChangeTime: 2014-07-29T15:42:24.035769600Z
- 510.1fd0: FileAttributes: 0x20
- 510.1fd0: Size: 0x11c000
- 510.1fd0: NT Headers: 0xe8
- 510.1fd0: Timestamp: 0x5315a059
- 510.1fd0: Machine: 0x8664 - amd64
- 510.1fd0: Timestamp: 0x5315a059
- 510.1fd0: Image Version: 6.1
- 510.1fd0: SizeOfImage: 0x11f000 (1175552)
- 510.1fd0: Resource Dir: 0x116000 LB 0x528
- 510.1fd0: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 510.1fd0: [Raw version resource data: 0x1160b0 LB 0x3a4, codepage 0x0 (reserved 0x0)]
- 510.1fd0: ProductName: Microsoft® Windows® Operating System
- 510.1fd0: ProductVersion: 6.1.7601.18409
- 510.1fd0: FileVersion: 6.1.7601.18409 (win7sp1_gdr.140303-2144)
- 510.1fd0: FileDescription: Windows NT BASE API Client DLL
- 510.1fd0: \SystemRoot\System32\KernelBase.dll:
- 510.1fd0: CreationTime: 2014-07-29T15:50:33.070665800Z
- 510.1fd0: LastWriteTime: 2014-03-04T09:44:00.336000000Z
- 510.1fd0: ChangeTime: 2014-07-29T15:55:55.374432100Z
- 510.1fd0: FileAttributes: 0x20
- 510.1fd0: Size: 0x67c00
- 510.1fd0: NT Headers: 0xe8
- 510.1fd0: Timestamp: 0x5315a05a
- 510.1fd0: Machine: 0x8664 - amd64
- 510.1fd0: Timestamp: 0x5315a05a
- 510.1fd0: Image Version: 6.1
- 510.1fd0: SizeOfImage: 0x6c000 (442368)
- 510.1fd0: Resource Dir: 0x6a000 LB 0x530
- 510.1fd0: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 510.1fd0: [Raw version resource data: 0x6a0b0 LB 0x3ac, codepage 0x0 (reserved 0x0)]
- 510.1fd0: ProductName: Microsoft® Windows® Operating System
- 510.1fd0: ProductVersion: 6.1.7601.18409
- 510.1fd0: FileVersion: 6.1.7601.18409 (win7sp1_gdr.140303-2144)
- 510.1fd0: FileDescription: Windows NT BASE API Client DLL
- 510.1fd0: \SystemRoot\System32\apisetschema.dll:
- 510.1fd0: CreationTime: 2014-07-29T15:14:28.210721700Z
- 510.1fd0: LastWriteTime: 2013-08-02T02:12:20.275000000Z
- 510.1fd0: ChangeTime: 2014-07-29T15:42:25.455372100Z
- 510.1fd0: FileAttributes: 0x20
- 510.1fd0: Size: 0x1a00
- 510.1fd0: NT Headers: 0xc0
- 510.1fd0: Timestamp: 0x51fb15ca
- 510.1fd0: Machine: 0x8664 - amd64
- 510.1fd0: Timestamp: 0x51fb15ca
- 510.1fd0: Image Version: 6.1
- 510.1fd0: SizeOfImage: 0x50000 (327680)
- 510.1fd0: Resource Dir: 0x30000 LB 0x3f8
- 510.1fd0: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 510.1fd0: [Raw version resource data: 0x30060 LB 0x398, codepage 0x0 (reserved 0x0)]
- 510.1fd0: ProductName: Microsoft® Windows® Operating System
- 510.1fd0: ProductVersion: 6.1.7601.18229
- 510.1fd0: FileVersion: 6.1.7601.18229 (win7sp1_gdr.130801-1533)
- 510.1fd0: FileDescription: ApiSet Schema DLL
- 510.1fd0: supR3HardenedWinFindAdversaries: 0x88
- 510.1fd0: \SystemRoot\System32\drivers\tmcomm.sys:
- 510.1fd0: CreationTime: 2017-04-13T02:38:07.967000100Z
- 510.1fd0: LastWriteTime: 2016-08-22T19:20:54.000000000Z
- 510.1fd0: ChangeTime: 2017-04-13T02:44:35.055140200Z
- 510.1fd0: FileAttributes: 0x20
- 510.1fd0: Size: 0x512e0
- 510.1fd0: NT Headers: 0xe8
- 510.1fd0: Timestamp: 0x57a30a7f
- 510.1fd0: Machine: 0x8664 - amd64
- 510.1fd0: Timestamp: 0x57a30a7f
- 510.1fd0: Image Version: 6.0
- 510.1fd0: SizeOfImage: 0x52000 (335872)
- 510.1fd0: Resource Dir: 0x50000 LB 0x758
- 510.1fd0: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 510.1fd0: [Raw version resource data: 0x50060 LB 0x6f8, codepage 0x0 (reserved 0x0)]
- 510.1fd0: ProductName: Trend Micro Eyes
- 510.1fd0: ProductVersion: 6.70
- 510.1fd0: FileVersion: 6.70.0.1098
- 510.1fd0: SpecialBuild: 1098
- 510.1fd0: PrivateBuild: Build 1098 - 8/4/2016
- 510.1fd0: FileDescription: TrendMicro Common Module
- 510.1fd0: \SystemRoot\System32\drivers\MBAMSwissArmy.sys:
- 510.1fd0: CreationTime: 2018-04-06T14:09:49.814773500Z
- 510.1fd0: LastWriteTime: 2018-04-16T03:50:05.507809600Z
- 510.1fd0: ChangeTime: 2018-04-16T03:50:05.710821200Z
- 510.1fd0: FileAttributes: 0x20
- 510.1fd0: Size: 0x3dee0
- 510.1fd0: NT Headers: 0x110
- 510.1fd0: Timestamp: 0x5aa00b51
- 510.1fd0: Machine: 0x8664 - amd64
- 510.1fd0: Timestamp: 0x5aa00b51
- 510.1fd0: Image Version: 6.3
- 510.1fd0: SizeOfImage: 0x40000 (262144)
- 510.1fd0: Resource Dir: 0x3e000 LB 0x3b8
- 510.1fd0: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 510.1fd0: [Raw version resource data: 0x3e060 LB 0x358, codepage 0x0 (reserved 0x0)]
- 510.1fd0: ProductName: Malwarebytes SwissArmy
- 510.1fd0: ProductVersion: 4.2.0.150
- 510.1fd0: FileVersion: 4.2.0.150
- 510.1fd0: FileDescription: Malwarebytes SwissArmy
- 510.1fd0: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume7\apps\virtualbox'
- 510.1fd0: Calling main()
- 510.1fd0: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
- 510.1fd0: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume7\apps\virtualbox'
- 510.1fd0: SUPR3HardenedMain: Respawn #1
- 510.1fd0: System32: \Device\HarddiskVolume2\Windows\System32
- 510.1fd0: WinSxS: \Device\HarddiskVolume2\Windows\winsxs
- 510.1fd0: KnownDllPath: C:\Windows\system32
- 510.1fd0: '\Device\HarddiskVolume7\apps\virtualbox\VirtualBox.exe' has no imports
- 510.1fd0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume7\apps\virtualbox\VirtualBox.exe)
- 510.1fd0: supR3HardNtEnableThreadCreation:
- 510.1fd0: supR3HardNtDisableThreadCreation: pvLdrInitThunk=0000000077adc340 pvNtTerminateThread=0000000077b017e0
- 510.1fd0: supR3HardenedWinDoReSpawn(1): New child 1890.d3c [kernel32].
- 510.1fd0: supR3HardNtChildGatherData: PebBaseAddress=000007fffffd8000 cbPeb=0x380
- 510.1fd0: supR3HardNtPuChFindNtdll: uNtDllParentAddr=0000000077ab0000 uNtDllChildAddr=0000000077ab0000
- 510.1fd0: supR3HardenedWinSetupChildInit: uLdrInitThunk=0000000077adc340
- 510.1fd0: supR3HardenedWinSetupChildInit: Start child.
- 510.1fd0: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
- 510.1fd0: supR3HardNtChildPurify: Startup delay kludge #1/0: 515 ms, 60 sleeps
- 510.1fd0: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
- 510.1fd0: *0000000000000000-000000000000ffff 0x0001/0x0000 0x0000000
- 510.1fd0: *0000000000010000-000000000002ffff 0x0004/0x0004 0x0020000
- 510.1fd0: *0000000000030000-0000000000033fff 0x0002/0x0002 0x0040000
- 510.1fd0: 0000000000034000-000000000003ffff 0x0001/0x0000 0x0000000
- 510.1fd0: *0000000000040000-0000000000040fff 0x0004/0x0004 0x0020000
- 510.1fd0: 0000000000041000-000000000015ffff 0x0001/0x0000 0x0000000
- 510.1fd0: *0000000000160000-000000000025bfff 0x0000/0x0004 0x0020000
- 510.1fd0: 000000000025c000-000000000025dfff 0x0104/0x0004 0x0020000
- 510.1fd0: 000000000025e000-000000000025ffff 0x0004/0x0004 0x0020000
- 510.1fd0: 0000000000260000-0000000077aaffff 0x0001/0x0000 0x0000000
- 510.1fd0: *0000000077ab0000-0000000077ab0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
- 510.1fd0: 0000000077ab1000-0000000077bb2fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
- 510.1fd0: 0000000077bb3000-0000000077be1fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
- 510.1fd0: 0000000077be2000-0000000077be9fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
- 510.1fd0: 0000000077bea000-0000000077beafff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
- 510.1fd0: 0000000077beb000-0000000077bedfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
- 510.1fd0: 0000000077bee000-0000000077c58fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
- 510.1fd0: 0000000077c59000-000000007efdffff 0x0001/0x0000 0x0000000
- 510.1fd0: *000000007efe0000-000000007ffdffff 0x0000/0x0002 0x0020000
- 510.1fd0: *000000007ffe0000-000000007ffe0fff 0x0002/0x0002 0x0020000
- 510.1fd0: 000000007ffe1000-000000007ffeffff 0x0000/0x0002 0x0020000
- 510.1fd0: 000000007fff0000-000000013f18ffff 0x0001/0x0000 0x0000000
- 510.1fd0: *000000013f190000-000000013f190fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume7\apps\virtualbox\VirtualBox.exe
- 510.1fd0: 000000013f191000-000000013f201fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume7\apps\virtualbox\VirtualBox.exe
- 510.1fd0: 000000013f202000-000000013f202fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume7\apps\virtualbox\VirtualBox.exe
- 510.1fd0: 000000013f203000-000000013f248fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume7\apps\virtualbox\VirtualBox.exe
- 510.1fd0: 000000013f249000-000000013f249fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume7\apps\virtualbox\VirtualBox.exe
- 510.1fd0: 000000013f24a000-000000013f24afff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume7\apps\virtualbox\VirtualBox.exe
- 510.1fd0: 000000013f24b000-000000013f24ffff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume7\apps\virtualbox\VirtualBox.exe
- 510.1fd0: 000000013f250000-000000013f250fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume7\apps\virtualbox\VirtualBox.exe
- 510.1fd0: 000000013f251000-000000013f251fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume7\apps\virtualbox\VirtualBox.exe
- 510.1fd0: 000000013f252000-000000013f255fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume7\apps\virtualbox\VirtualBox.exe
- 510.1fd0: 000000013f256000-000000013f29dfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume7\apps\virtualbox\VirtualBox.exe
- 510.1fd0: 000000013f29e000-000007feffdcffff 0x0001/0x0000 0x0000000
- 510.1fd0: *000007feffdd0000-000007feffdd0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\apisetschema.dll
- 510.1fd0: 000007feffdd1000-000007fffffaffff 0x0001/0x0000 0x0000000
- 510.1fd0: *000007fffffb0000-000007fffffd2fff 0x0002/0x0002 0x0040000
- 510.1fd0: 000007fffffd3000-000007fffffd7fff 0x0001/0x0000 0x0000000
- 510.1fd0: *000007fffffd8000-000007fffffd8fff 0x0004/0x0004 0x0020000
- 510.1fd0: 000007fffffd9000-000007fffffddfff 0x0001/0x0000 0x0000000
- 510.1fd0: *000007fffffde000-000007fffffdffff 0x0004/0x0004 0x0020000
- 510.1fd0: *000007fffffe0000-000007fffffeffff 0x0001/0x0002 0x0020000
- 510.1fd0: apisetschema.dll: timestamp 0x51fb15ca (rc=VINF_SUCCESS)
- 510.1fd0: VirtualBox.exe: timestamp 0x5a942b95 (rc=VINF_SUCCESS)
- 510.1fd0: '\Device\HarddiskVolume7\apps\virtualbox\VirtualBox.exe' has no imports
- 510.1fd0: '\Device\HarddiskVolume2\Windows\System32\apisetschema.dll' has no imports
- 510.1fd0: '\Device\HarddiskVolume2\Windows\System32\ntdll.dll' has no imports
- 510.1fd0: supR3HardNtChildPurify: Done after 577 ms and 0 fixes (loop #0).
- 1890.d3c: Log file opened: 5.2.8r121009 g_hStartupLog=0000000000000004 g_uNtVerCombined=0x611db100
- 1890.d3c: supR3HardenedVmProcessInit: uNtDllAddr=0000000077ab0000 g_uNtVerCombined=0x611db100
- 1890.d3c: ntdll.dll: timestamp 0x521eaf24 (rc=VINF_SUCCESS)
- 1890.d3c: New simple heap: #1 0000000000260000 LB 0x400000 (for 1740800 allocation)
- 510.1fd0: supR3HardNtEnableThreadCreation:
- 1890.d3c: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume7\apps\virtualbox'
- 1890.d3c: System32: \Device\HarddiskVolume2\Windows\System32
- 1890.d3c: WinSxS: \Device\HarddiskVolume2\Windows\winsxs
- 1890.d3c: KnownDllPath: C:\Windows\system32
- 1890.d3c: supR3HardenedVmProcessInit: Opening vboxdrv stub...
- 1890.d3c: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
- 1890.d3c: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
- 1890.d3c: Registered Dll notification callback with NTDLL.
- 1890.d3c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\kernel32.dll)
- 1890.d3c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\kernel32.dll
- 1890.d3c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
- 1890.d3c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
- 1890.d3c: supR3HardenedDllNotificationCallback: load 0000000077990000 LB 0x0011f000 C:\Windows\system32\kernel32.dll [fFlags=0x0]
- 1890.d3c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
- 1890.d3c: supR3HardenedDllNotificationCallback: load 000007fefd9e0000 LB 0x0006c000 C:\Windows\system32\KERNELBASE.dll [fFlags=0x0]
- 1890.d3c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\KernelBase.dll)
- 1890.d3c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\KernelBase.dll
- 1890.d3c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077990000 'C:\Windows\system32\kernel32.dll'
- 1890.d3c: supR3HardNtDisableThreadCreation: pvLdrInitThunk=0000000077adc340 pvNtTerminateThread=0000000077b017e0
- 510.1fd0: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 62 ms.
- 1890.d3c: \SystemRoot\System32\ntdll.dll:
- 1890.d3c: CreationTime: 2014-07-29T15:15:12.093598700Z
- 1890.d3c: LastWriteTime: 2013-08-29T02:16:35.515578900Z
- 1890.d3c: ChangeTime: 2014-07-29T15:42:24.768970900Z
- 1890.d3c: FileAttributes: 0x20
- 1890.d3c: Size: 0x1a6dc0
- 1890.d3c: NT Headers: 0xe0
- 1890.d3c: Timestamp: 0x521eaf24
- 1890.d3c: Machine: 0x8664 - amd64
- 1890.d3c: Timestamp: 0x521eaf24
- 1890.d3c: Image Version: 6.1
- 1890.d3c: SizeOfImage: 0x1a9000 (1740800)
- 1890.d3c: Resource Dir: 0x151000 LB 0x560d8
- 1890.d3c: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 1890.d3c: [Raw version resource data: 0x1510f0 LB 0x380, codepage 0x0 (reserved 0x0)]
- 1890.d3c: ProductName: Microsoft® Windows® Operating System
- 1890.d3c: ProductVersion: 6.1.7601.18247
- 1890.d3c: FileVersion: 6.1.7601.18247 (win7sp1_gdr.130828-1532)
- 1890.d3c: FileDescription: NT Layer DLL
- 1890.d3c: \SystemRoot\System32\kernel32.dll:
- 1890.d3c: CreationTime: 2014-07-29T15:11:12.789178400Z
- 1890.d3c: LastWriteTime: 2014-03-04T09:44:00.336000000Z
- 1890.d3c: ChangeTime: 2014-07-29T15:42:24.035769600Z
- 1890.d3c: FileAttributes: 0x20
- 1890.d3c: Size: 0x11c000
- 1890.d3c: NT Headers: 0xe8
- 1890.d3c: Timestamp: 0x5315a059
- 1890.d3c: Machine: 0x8664 - amd64
- 1890.d3c: Timestamp: 0x5315a059
- 1890.d3c: Image Version: 6.1
- 1890.d3c: SizeOfImage: 0x11f000 (1175552)
- 1890.d3c: Resource Dir: 0x116000 LB 0x528
- 1890.d3c: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 1890.d3c: [Raw version resource data: 0x1160b0 LB 0x3a4, codepage 0x0 (reserved 0x0)]
- 1890.d3c: ProductName: Microsoft® Windows® Operating System
- 1890.d3c: ProductVersion: 6.1.7601.18409
- 1890.d3c: FileVersion: 6.1.7601.18409 (win7sp1_gdr.140303-2144)
- 1890.d3c: FileDescription: Windows NT BASE API Client DLL
- 1890.d3c: \SystemRoot\System32\KernelBase.dll:
- 1890.d3c: CreationTime: 2014-07-29T15:50:33.070665800Z
- 1890.d3c: LastWriteTime: 2014-03-04T09:44:00.336000000Z
- 1890.d3c: ChangeTime: 2014-07-29T15:55:55.374432100Z
- 1890.d3c: FileAttributes: 0x20
- 1890.d3c: Size: 0x67c00
- 1890.d3c: NT Headers: 0xe8
- 1890.d3c: Timestamp: 0x5315a05a
- 1890.d3c: Machine: 0x8664 - amd64
- 1890.d3c: Timestamp: 0x5315a05a
- 1890.d3c: Image Version: 6.1
- 1890.d3c: SizeOfImage: 0x6c000 (442368)
- 1890.d3c: Resource Dir: 0x6a000 LB 0x530
- 1890.d3c: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 1890.d3c: [Raw version resource data: 0x6a0b0 LB 0x3ac, codepage 0x0 (reserved 0x0)]
- 1890.d3c: ProductName: Microsoft® Windows® Operating System
- 1890.d3c: ProductVersion: 6.1.7601.18409
- 1890.d3c: FileVersion: 6.1.7601.18409 (win7sp1_gdr.140303-2144)
- 1890.d3c: FileDescription: Windows NT BASE API Client DLL
- 1890.d3c: \SystemRoot\System32\apisetschema.dll:
- 1890.d3c: CreationTime: 2014-07-29T15:14:28.210721700Z
- 1890.d3c: LastWriteTime: 2013-08-02T02:12:20.275000000Z
- 1890.d3c: ChangeTime: 2014-07-29T15:42:25.455372100Z
- 1890.d3c: FileAttributes: 0x20
- 1890.d3c: Size: 0x1a00
- 1890.d3c: NT Headers: 0xc0
- 1890.d3c: Timestamp: 0x51fb15ca
- 1890.d3c: Machine: 0x8664 - amd64
- 1890.d3c: Timestamp: 0x51fb15ca
- 1890.d3c: Image Version: 6.1
- 1890.d3c: SizeOfImage: 0x50000 (327680)
- 1890.d3c: Resource Dir: 0x30000 LB 0x3f8
- 1890.d3c: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 1890.d3c: [Raw version resource data: 0x30060 LB 0x398, codepage 0x0 (reserved 0x0)]
- 1890.d3c: ProductName: Microsoft® Windows® Operating System
- 1890.d3c: ProductVersion: 6.1.7601.18229
- 1890.d3c: FileVersion: 6.1.7601.18229 (win7sp1_gdr.130801-1533)
- 1890.d3c: FileDescription: ApiSet Schema DLL
- 1890.d3c: supR3HardenedWinFindAdversaries: 0x88
- 1890.d3c: \SystemRoot\System32\drivers\tmcomm.sys:
- 1890.d3c: CreationTime: 2017-04-13T02:38:07.967000100Z
- 1890.d3c: LastWriteTime: 2016-08-22T19:20:54.000000000Z
- 1890.d3c: ChangeTime: 2017-04-13T02:44:35.055140200Z
- 1890.d3c: FileAttributes: 0x20
- 1890.d3c: Size: 0x512e0
- 1890.d3c: NT Headers: 0xe8
- 1890.d3c: Timestamp: 0x57a30a7f
- 1890.d3c: Machine: 0x8664 - amd64
- 1890.d3c: Timestamp: 0x57a30a7f
- 1890.d3c: Image Version: 6.0
- 1890.d3c: SizeOfImage: 0x52000 (335872)
- 1890.d3c: Resource Dir: 0x50000 LB 0x758
- 1890.d3c: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 1890.d3c: [Raw version resource data: 0x50060 LB 0x6f8, codepage 0x0 (reserved 0x0)]
- 1890.d3c: ProductName: Trend Micro Eyes
- 1890.d3c: ProductVersion: 6.70
- 1890.d3c: FileVersion: 6.70.0.1098
- 1890.d3c: SpecialBuild: 1098
- 1890.d3c: PrivateBuild: Build 1098 - 8/4/2016
- 1890.d3c: FileDescription: TrendMicro Common Module
- 1890.d3c: \SystemRoot\System32\drivers\MBAMSwissArmy.sys:
- 1890.d3c: CreationTime: 2018-04-06T14:09:49.814773500Z
- 1890.d3c: LastWriteTime: 2018-04-16T03:50:05.507809600Z
- 1890.d3c: ChangeTime: 2018-04-16T03:50:05.710821200Z
- 1890.d3c: FileAttributes: 0x20
- 1890.d3c: Size: 0x3dee0
- 1890.d3c: NT Headers: 0x110
- 1890.d3c: Timestamp: 0x5aa00b51
- 1890.d3c: Machine: 0x8664 - amd64
- 1890.d3c: Timestamp: 0x5aa00b51
- 1890.d3c: Image Version: 6.3
- 1890.d3c: SizeOfImage: 0x40000 (262144)
- 1890.d3c: Resource Dir: 0x3e000 LB 0x3b8
- 1890.d3c: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 1890.d3c: [Raw version resource data: 0x3e060 LB 0x358, codepage 0x0 (reserved 0x0)]
- 1890.d3c: ProductName: Malwarebytes SwissArmy
- 1890.d3c: ProductVersion: 4.2.0.150
- 1890.d3c: FileVersion: 4.2.0.150
- 1890.d3c: FileDescription: Malwarebytes SwissArmy
- 1890.d3c: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume7\apps\virtualbox'
- 1890.d3c: Calling main()
- 1890.d3c: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
- 1890.d3c: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume7\apps\virtualbox'
- 1890.d3c: '\Device\HarddiskVolume7\apps\virtualbox\VirtualBox.exe' has no imports
- 1890.d3c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume7\apps\virtualbox\VirtualBox.exe)
- 1890.d3c: SUPR3HardenedMain: Respawn #2
- 1890.d3c: supR3HardNtEnableThreadCreation:
- 1890.d3c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\apphelp.dll)
- 1890.d3c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\apphelp.dll
- 1890.d3c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\apphelp.dll (rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
- 1890.d3c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\apphelp.dll [lacks WinVerifyTrust]
- 1890.d3c: supR3HardenedDllNotificationCallback: load 000007fefd7b0000 LB 0x00057000 C:\Windows\system32\apphelp.dll [fFlags=0x0]
- 1890.d3c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\apphelp.dll [lacks WinVerifyTrust]
- 1890.d3c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd7b0000 'C:\Windows\system32\apphelp.dll'
- 1890.d3c: supR3HardNtDisableThreadCreation: pvLdrInitThunk=0000000077adc340 pvNtTerminateThread=0000000077b017e0
- 1890.d3c: supR3HardenedWinDoReSpawn(2): New child 1db4.1c50 [kernel32].
- 1890.d3c: supR3HardNtChildGatherData: PebBaseAddress=000007fffffda000 cbPeb=0x380
- 1890.d3c: supR3HardNtPuChFindNtdll: uNtDllParentAddr=0000000077ab0000 uNtDllChildAddr=0000000077ab0000
- 1890.d3c: supR3HardenedWinSetupChildInit: uLdrInitThunk=0000000077adc340
- 1890.d3c: supR3HardenedWinSetupChildInit: Start child.
- 1890.d3c: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
- 1890.d3c: supR3HardNtChildPurify: Startup delay kludge #1/0: 516 ms, 33 sleeps
- 1890.d3c: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
- 1890.d3c: *0000000000000000-000000000000ffff 0x0001/0x0000 0x0000000
- 1890.d3c: *0000000000010000-000000000002ffff 0x0004/0x0004 0x0020000
- 1890.d3c: *0000000000030000-0000000000033fff 0x0002/0x0002 0x0040000
- 1890.d3c: 0000000000034000-000000000003ffff 0x0001/0x0000 0x0000000
- 1890.d3c: *0000000000040000-0000000000040fff 0x0004/0x0004 0x0020000
- 1890.d3c: 0000000000041000-000000000014ffff 0x0001/0x0000 0x0000000
- 1890.d3c: *0000000000150000-000000000024bfff 0x0000/0x0004 0x0020000
- 1890.d3c: 000000000024c000-000000000024dfff 0x0104/0x0004 0x0020000
- 1890.d3c: 000000000024e000-000000000024ffff 0x0004/0x0004 0x0020000
- 1890.d3c: 0000000000250000-0000000077aaffff 0x0001/0x0000 0x0000000
- 1890.d3c: *0000000077ab0000-0000000077ab0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
- 1890.d3c: 0000000077ab1000-0000000077bb2fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
- 1890.d3c: 0000000077bb3000-0000000077be1fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
- 1890.d3c: 0000000077be2000-0000000077be9fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
- 1890.d3c: 0000000077bea000-0000000077beafff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
- 1890.d3c: 0000000077beb000-0000000077bedfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
- 1890.d3c: 0000000077bee000-0000000077c58fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
- 1890.d3c: 0000000077c59000-000000007efdffff 0x0001/0x0000 0x0000000
- 1890.d3c: *000000007efe0000-000000007ffdffff 0x0000/0x0002 0x0020000
- 1890.d3c: *000000007ffe0000-000000007ffe0fff 0x0002/0x0002 0x0020000
- 1890.d3c: 000000007ffe1000-000000007ffeffff 0x0000/0x0002 0x0020000
- 1890.d3c: 000000007fff0000-000000013f18ffff 0x0001/0x0000 0x0000000
- 1890.d3c: *000000013f190000-000000013f190fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume7\apps\virtualbox\VirtualBox.exe
- 1890.d3c: 000000013f191000-000000013f201fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume7\apps\virtualbox\VirtualBox.exe
- 1890.d3c: 000000013f202000-000000013f202fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume7\apps\virtualbox\VirtualBox.exe
- 1890.d3c: 000000013f203000-000000013f248fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume7\apps\virtualbox\VirtualBox.exe
- 1890.d3c: 000000013f249000-000000013f249fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume7\apps\virtualbox\VirtualBox.exe
- 1890.d3c: 000000013f24a000-000000013f24afff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume7\apps\virtualbox\VirtualBox.exe
- 1890.d3c: 000000013f24b000-000000013f24ffff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume7\apps\virtualbox\VirtualBox.exe
- 1890.d3c: 000000013f250000-000000013f250fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume7\apps\virtualbox\VirtualBox.exe
- 1890.d3c: 000000013f251000-000000013f251fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume7\apps\virtualbox\VirtualBox.exe
- 1890.d3c: 000000013f252000-000000013f255fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume7\apps\virtualbox\VirtualBox.exe
- 1890.d3c: 000000013f256000-000000013f29dfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume7\apps\virtualbox\VirtualBox.exe
- 1890.d3c: 000000013f29e000-000007feffdcffff 0x0001/0x0000 0x0000000
- 1890.d3c: *000007feffdd0000-000007feffdd0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\apisetschema.dll
- 1890.d3c: 000007feffdd1000-000007fffffaffff 0x0001/0x0000 0x0000000
- 1890.d3c: *000007fffffb0000-000007fffffd2fff 0x0002/0x0002 0x0040000
- 1890.d3c: 000007fffffd3000-000007fffffd9fff 0x0001/0x0000 0x0000000
- 1890.d3c: *000007fffffda000-000007fffffdafff 0x0004/0x0004 0x0020000
- 1890.d3c: 000007fffffdb000-000007fffffddfff 0x0001/0x0000 0x0000000
- 1890.d3c: *000007fffffde000-000007fffffdffff 0x0004/0x0004 0x0020000
- 1890.d3c: *000007fffffe0000-000007fffffeffff 0x0001/0x0002 0x0020000
- 1890.d3c: apisetschema.dll: timestamp 0x51fb15ca (rc=VINF_SUCCESS)
- 1890.d3c: VirtualBox.exe: timestamp 0x5a942b95 (rc=VINF_SUCCESS)
- 1890.d3c: '\Device\HarddiskVolume7\apps\virtualbox\VirtualBox.exe' has no imports
- 1890.d3c: '\Device\HarddiskVolume2\Windows\System32\apisetschema.dll' has no imports
- 1890.d3c: '\Device\HarddiskVolume2\Windows\System32\ntdll.dll' has no imports
- 1890.d3c: supR3HardNtChildPurify: Done after 578 ms and 0 fixes (loop #0).
- 1db4.1c50: Log file opened: 5.2.8r121009 g_hStartupLog=0000000000000004 g_uNtVerCombined=0x611db100
- 1db4.1c50: supR3HardenedVmProcessInit: uNtDllAddr=0000000077ab0000 g_uNtVerCombined=0x611db100
- 1890.d3c: supR3HardenedEarlyCompact: Removed heap 1 (0x00000000260000 LB 0x400000)
- 1890.d3c: supR3HardNtEnableThreadCreation:
- 1db4.1c50: ntdll.dll: timestamp 0x521eaf24 (rc=VINF_SUCCESS)
- 1db4.1c50: New simple heap: #1 0000000000250000 LB 0x400000 (for 1740800 allocation)
- 1db4.1c50: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume7\apps\virtualbox'
- 1db4.1c50: System32: \Device\HarddiskVolume2\Windows\System32
- 1db4.1c50: WinSxS: \Device\HarddiskVolume2\Windows\winsxs
- 1db4.1c50: KnownDllPath: C:\Windows\system32
- 1db4.1c50: supR3HardenedVmProcessInit: Opening vboxdrv...
- 1db4.1c50: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
- 1db4.1c50: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
- 1db4.1c50: Registered Dll notification callback with NTDLL.
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\kernel32.dll)
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\kernel32.dll
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
- 1db4.1c50: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 0000000077990000 LB 0x0011f000 C:\Windows\system32\kernel32.dll [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 000007fefd9e0000 LB 0x0006c000 C:\Windows\system32\KERNELBASE.dll [fFlags=0x0]
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\KernelBase.dll)
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\KernelBase.dll
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077990000 'C:\Windows\system32\kernel32.dll'
- 1db4.1c50: supR3HardNtDisableThreadCreation: pvLdrInitThunk=0000000077adc340 pvNtTerminateThread=0000000077b017e0
- 1890.d3c: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 94 ms.
- 1db4.1c50: \SystemRoot\System32\ntdll.dll:
- 1db4.1c50: CreationTime: 2014-07-29T15:15:12.093598700Z
- 1db4.1c50: LastWriteTime: 2013-08-29T02:16:35.515578900Z
- 1db4.1c50: ChangeTime: 2014-07-29T15:42:24.768970900Z
- 1db4.1c50: FileAttributes: 0x20
- 1db4.1c50: Size: 0x1a6dc0
- 1db4.1c50: NT Headers: 0xe0
- 1db4.1c50: Timestamp: 0x521eaf24
- 1db4.1c50: Machine: 0x8664 - amd64
- 1db4.1c50: Timestamp: 0x521eaf24
- 1db4.1c50: Image Version: 6.1
- 1db4.1c50: SizeOfImage: 0x1a9000 (1740800)
- 1db4.1c50: Resource Dir: 0x151000 LB 0x560d8
- 1db4.1c50: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 1db4.1c50: [Raw version resource data: 0x1510f0 LB 0x380, codepage 0x0 (reserved 0x0)]
- 1db4.1c50: ProductName: Microsoft® Windows® Operating System
- 1db4.1c50: ProductVersion: 6.1.7601.18247
- 1db4.1c50: FileVersion: 6.1.7601.18247 (win7sp1_gdr.130828-1532)
- 1db4.1c50: FileDescription: NT Layer DLL
- 1db4.1c50: \SystemRoot\System32\kernel32.dll:
- 1db4.1c50: CreationTime: 2014-07-29T15:11:12.789178400Z
- 1db4.1c50: LastWriteTime: 2014-03-04T09:44:00.336000000Z
- 1db4.1c50: ChangeTime: 2014-07-29T15:42:24.035769600Z
- 1db4.1c50: FileAttributes: 0x20
- 1db4.1c50: Size: 0x11c000
- 1db4.1c50: NT Headers: 0xe8
- 1db4.1c50: Timestamp: 0x5315a059
- 1db4.1c50: Machine: 0x8664 - amd64
- 1db4.1c50: Timestamp: 0x5315a059
- 1db4.1c50: Image Version: 6.1
- 1db4.1c50: SizeOfImage: 0x11f000 (1175552)
- 1db4.1c50: Resource Dir: 0x116000 LB 0x528
- 1db4.1c50: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 1db4.1c50: [Raw version resource data: 0x1160b0 LB 0x3a4, codepage 0x0 (reserved 0x0)]
- 1db4.1c50: ProductName: Microsoft® Windows® Operating System
- 1db4.1c50: ProductVersion: 6.1.7601.18409
- 1db4.1c50: FileVersion: 6.1.7601.18409 (win7sp1_gdr.140303-2144)
- 1db4.1c50: FileDescription: Windows NT BASE API Client DLL
- 1db4.1c50: \SystemRoot\System32\KernelBase.dll:
- 1db4.1c50: CreationTime: 2014-07-29T15:50:33.070665800Z
- 1db4.1c50: LastWriteTime: 2014-03-04T09:44:00.336000000Z
- 1db4.1c50: ChangeTime: 2014-07-29T15:55:55.374432100Z
- 1db4.1c50: FileAttributes: 0x20
- 1db4.1c50: Size: 0x67c00
- 1db4.1c50: NT Headers: 0xe8
- 1db4.1c50: Timestamp: 0x5315a05a
- 1db4.1c50: Machine: 0x8664 - amd64
- 1db4.1c50: Timestamp: 0x5315a05a
- 1db4.1c50: Image Version: 6.1
- 1db4.1c50: SizeOfImage: 0x6c000 (442368)
- 1db4.1c50: Resource Dir: 0x6a000 LB 0x530
- 1db4.1c50: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 1db4.1c50: [Raw version resource data: 0x6a0b0 LB 0x3ac, codepage 0x0 (reserved 0x0)]
- 1db4.1c50: ProductName: Microsoft® Windows® Operating System
- 1db4.1c50: ProductVersion: 6.1.7601.18409
- 1db4.1c50: FileVersion: 6.1.7601.18409 (win7sp1_gdr.140303-2144)
- 1db4.1c50: FileDescription: Windows NT BASE API Client DLL
- 1db4.1c50: \SystemRoot\System32\apisetschema.dll:
- 1db4.1c50: CreationTime: 2014-07-29T15:14:28.210721700Z
- 1db4.1c50: LastWriteTime: 2013-08-02T02:12:20.275000000Z
- 1db4.1c50: ChangeTime: 2014-07-29T15:42:25.455372100Z
- 1db4.1c50: FileAttributes: 0x20
- 1db4.1c50: Size: 0x1a00
- 1db4.1c50: NT Headers: 0xc0
- 1db4.1c50: Timestamp: 0x51fb15ca
- 1db4.1c50: Machine: 0x8664 - amd64
- 1db4.1c50: Timestamp: 0x51fb15ca
- 1db4.1c50: Image Version: 6.1
- 1db4.1c50: SizeOfImage: 0x50000 (327680)
- 1db4.1c50: Resource Dir: 0x30000 LB 0x3f8
- 1db4.1c50: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 1db4.1c50: [Raw version resource data: 0x30060 LB 0x398, codepage 0x0 (reserved 0x0)]
- 1db4.1c50: ProductName: Microsoft® Windows® Operating System
- 1db4.1c50: ProductVersion: 6.1.7601.18229
- 1db4.1c50: FileVersion: 6.1.7601.18229 (win7sp1_gdr.130801-1533)
- 1db4.1c50: FileDescription: ApiSet Schema DLL
- 1db4.1c50: supR3HardenedWinFindAdversaries: 0x88
- 1db4.1c50: \SystemRoot\System32\drivers\tmcomm.sys:
- 1db4.1c50: CreationTime: 2017-04-13T02:38:07.967000100Z
- 1db4.1c50: LastWriteTime: 2016-08-22T19:20:54.000000000Z
- 1db4.1c50: ChangeTime: 2017-04-13T02:44:35.055140200Z
- 1db4.1c50: FileAttributes: 0x20
- 1db4.1c50: Size: 0x512e0
- 1db4.1c50: NT Headers: 0xe8
- 1db4.1c50: Timestamp: 0x57a30a7f
- 1db4.1c50: Machine: 0x8664 - amd64
- 1db4.1c50: Timestamp: 0x57a30a7f
- 1db4.1c50: Image Version: 6.0
- 1db4.1c50: SizeOfImage: 0x52000 (335872)
- 1db4.1c50: Resource Dir: 0x50000 LB 0x758
- 1db4.1c50: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 1db4.1c50: [Raw version resource data: 0x50060 LB 0x6f8, codepage 0x0 (reserved 0x0)]
- 1db4.1c50: ProductName: Trend Micro Eyes
- 1db4.1c50: ProductVersion: 6.70
- 1db4.1c50: FileVersion: 6.70.0.1098
- 1db4.1c50: SpecialBuild: 1098
- 1db4.1c50: PrivateBuild: Build 1098 - 8/4/2016
- 1db4.1c50: FileDescription: TrendMicro Common Module
- 1db4.1c50: \SystemRoot\System32\drivers\MBAMSwissArmy.sys:
- 1db4.1c50: CreationTime: 2018-04-06T14:09:49.814773500Z
- 1db4.1c50: LastWriteTime: 2018-04-16T03:50:05.507809600Z
- 1db4.1c50: ChangeTime: 2018-04-16T03:50:05.710821200Z
- 1db4.1c50: FileAttributes: 0x20
- 1db4.1c50: Size: 0x3dee0
- 1db4.1c50: NT Headers: 0x110
- 1db4.1c50: Timestamp: 0x5aa00b51
- 1db4.1c50: Machine: 0x8664 - amd64
- 1db4.1c50: Timestamp: 0x5aa00b51
- 1db4.1c50: Image Version: 6.3
- 1db4.1c50: SizeOfImage: 0x40000 (262144)
- 1db4.1c50: Resource Dir: 0x3e000 LB 0x3b8
- 1db4.1c50: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 1db4.1c50: [Raw version resource data: 0x3e060 LB 0x358, codepage 0x0 (reserved 0x0)]
- 1db4.1c50: ProductName: Malwarebytes SwissArmy
- 1db4.1c50: ProductVersion: 4.2.0.150
- 1db4.1c50: FileVersion: 4.2.0.150
- 1db4.1c50: FileDescription: Malwarebytes SwissArmy
- 1db4.1c50: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume7\apps\virtualbox'
- 1db4.1c50: Calling main()
- 1db4.1c50: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
- 1db4.1c50: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume7\apps\virtualbox'
- 1db4.1c50: '\Device\HarddiskVolume7\apps\virtualbox\VirtualBox.exe' has no imports
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume7\apps\virtualbox\VirtualBox.exe)
- 1db4.1c50: SUPR3HardenedMain: Final process, opening VBoxDrv...
- 1db4.1c50: supR3HardenedEarlyCompact: Removed heap 1 (0x00000000250000 LB 0x400000)
- 1db4.1c50: supR3HardNtEnableThreadCreation:
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume7\apps\virtualbox\VBoxSupLib.dll)
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume7\apps\virtualbox\VBoxSupLib.dll
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=E:\apps\virtualbox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000695020:C:\Windows\system32 [calling]
- 1db4.1c50: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\VBoxSupLib.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 000007feed6a0000 LB 0x00005000 E:\apps\virtualbox\VBoxSupLib.DLL [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\VBoxSupLib.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\VBoxSupLib.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=E:\apps\virtualbox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000695c50:E:\apps\virtualbox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;E:\apps\Iridium Browser;C:\Program Files (x86)\Google\Chrome\Application;C:\Windows\system32;C:\Windows;C:\Windows\system32\wbem;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\Dell\DW WLAN Card;C:\Ruby-install\bin;C:\Windows\System32\WindowsPowerShell\v1.0;C:\Program Files (x86)\Common Files\Adobe\AGL;C:\Program Files\Microsoft SQL Server\110\Tools\Binn;C:\Program Files\WIDCOMM\Bluetooth Software;C:\Program Files\WIDCOMM\Bluetooth Software\syswow64;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit;E:\apps\CMake\bin;E:\apps\PDFtk\bin;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5\Doctrine extensions for PHP;C:\adb;E:\apps\Tesseract-OCR;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x64;E:\apps\NodeJS\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;E:\apps\python;E:\apps\Python\Scripts\;E:\apps\Python\;C:\Users\TouchOdeath\AppData\Roaming\npm [calling]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed6a0000 'E:\apps\virtualbox\VBoxSupLib.DLL'
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\VBoxSupLib.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=E:\apps\virtualbox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000695c50:E:\apps\virtualbox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;E:\apps\Iridium Browser;C:\Program Files (x86)\Google\Chrome\Application;C:\Windows\system32;C:\Windows;C:\Windows\system32\wbem;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\Dell\DW WLAN Card;C:\Ruby-install\bin;C:\Windows\System32\WindowsPowerShell\v1.0;C:\Program Files (x86)\Common Files\Adobe\AGL;C:\Program Files\Microsoft SQL Server\110\Tools\Binn;C:\Program Files\WIDCOMM\Bluetooth Software;C:\Program Files\WIDCOMM\Bluetooth Software\syswow64;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit;E:\apps\CMake\bin;E:\apps\PDFtk\bin;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5\Doctrine extensions for PHP;C:\adb;E:\apps\Tesseract-OCR;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x64;E:\apps\NodeJS\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;E:\apps\python;E:\apps\Python\Scripts\;E:\apps\Python\;C:\Users\TouchOdeath\AppData\Roaming\npm [calling]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed6a0000 'E:\apps\virtualbox\VBoxSupLib.DLL'
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed6a0000 'E:\apps\virtualbox\VBoxSupLib.DLL'
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'crypt32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msasn1.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\wintrust.dll)
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wintrust.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll)
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume2\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\msasn1.dll)
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msasn1.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume2\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msasn1.dll'.
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\crypt32.dll)
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\crypt32.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\msvcrt.dll)
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume2\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000695020:C:\Windows\system32 [calling]
- 1db4.1c50: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 000007fefd980000 LB 0x0003a000 C:\Windows\system32\Wintrust.dll [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 000007feff210000 LB 0x0009f000 C:\Windows\system32\msvcrt.dll [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 000007fefda70000 LB 0x0016c000 C:\Windows\system32\CRYPT32.dll [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 000007fefd8d0000 LB 0x0000f000 C:\Windows\system32\MSASN1.dll [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 000007feffc90000 LB 0x0012d000 C:\Windows\system32\RPCRT4.dll [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd980000 'C:\Windows\system32\Wintrust.dll'
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\bcrypt.dll)
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\bcrypt.dll
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\bcrypt.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000006da920:C:\Windows\system32 [calling]
- 1db4.1c50: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 000007fefd210000 LB 0x00022000 C:\Windows\system32\bcrypt.dll [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd210000 'C:\Windows\system32\bcrypt.dll'
- 1db4.1c50: bcrypt.dll loaded at 000007fefd210000, BCryptOpenAlgorithmProvider at 000007fefd212640, preloading providers:
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'advapi32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'bcrypt.dll'.
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll)
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume2\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'rpcrt4.dll'.
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\advapi32.dll)
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\advapi32.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\bcryptprimitives.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000695c50:E:\apps\virtualbox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;E:\apps\Iridium Browser;C:\Program Files (x86)\Google\Chrome\Application;C:\Windows\system32;C:\Windows;C:\Windows\system32\wbem;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\Dell\DW WLAN Card;C:\Ruby-install\bin;C:\Windows\System32\WindowsPowerShell\v1.0;C:\Program Files (x86)\Common Files\Adobe\AGL;C:\Program Files\Microsoft SQL Server\110\Tools\Binn;C:\Program Files\WIDCOMM\Bluetooth Software;C:\Program Files\WIDCOMM\Bluetooth Software\syswow64;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit;E:\apps\CMake\bin;E:\apps\PDFtk\bin;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5\Doctrine extensions for PHP;C:\adb;E:\apps\Tesseract-OCR;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x64;E:\apps\NodeJS\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;E:\apps\python;E:\apps\Python\Scripts\;E:\apps\Python\;C:\Users\TouchOdeath\AppData\Roaming\npm [calling]
- 1db4.1c50: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 000007fefcd00000 LB 0x0004c000 C:\Windows\system32\bcryptprimitives.dll [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 000007fefde70000 LB 0x000db000 C:\Windows\system32\ADVAPI32.dll [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msvcrt.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'rpcrt4.dll'.
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\sechost.dll)
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\sechost.dll
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 000007fefe110000 LB 0x0001f000 C:\Windows\SYSTEM32\sechost.dll [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\sechost.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcd00000 'C:\Windows\system32\bcryptprimitives.dll'
- 1db4.1c50: BCryptOpenAlgorithmProvider(,'MD2',0,0) -> 0x0 (hAlgo=00000000006dd690)
- 1db4.1c50: BCryptOpenAlgorithmProvider(,'MD4',0,0) -> 0x0 (hAlgo=00000000006ddf20)
- 1db4.1c50: BCryptOpenAlgorithmProvider(,'MD5',0,0) -> 0x0 (hAlgo=00000000006de040)
- 1db4.1c50: BCryptOpenAlgorithmProvider(,'SHA1',0,0) -> 0x0 (hAlgo=00000000006de250)
- 1db4.1c50: BCryptOpenAlgorithmProvider(,'SHA256',0,0) -> 0x0 (hAlgo=00000000006de370)
- 1db4.1c50: BCryptOpenAlgorithmProvider(,'SHA512',0,0) -> 0x0 (hAlgo=00000000006de490)
- 1db4.1c50: BCryptOpenAlgorithmProvider(,'RSA',0,0) -> 0x0 (hAlgo=00000000006de6d0)
- 1db4.1c50: BCryptOpenAlgorithmProvider(,'DSA',0,0) -> 0x0 (hAlgo=00000000006de7f0)
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\cryptsp.dll)
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cryptsp.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTSP.dll (Input=CRYPTSP.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000695c50:E:\apps\virtualbox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;E:\apps\Iridium Browser;C:\Program Files (x86)\Google\Chrome\Application;C:\Windows\system32;C:\Windows;C:\Windows\system32\wbem;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\Dell\DW WLAN Card;C:\Ruby-install\bin;C:\Windows\System32\WindowsPowerShell\v1.0;C:\Program Files (x86)\Common Files\Adobe\AGL;C:\Program Files\Microsoft SQL Server\110\Tools\Binn;C:\Program Files\WIDCOMM\Bluetooth Software;C:\Program Files\WIDCOMM\Bluetooth Software\syswow64;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit;E:\apps\CMake\bin;E:\apps\PDFtk\bin;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5\Doctrine extensions for PHP;C:\adb;E:\apps\Tesseract-OCR;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x64;E:\apps\NodeJS\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;E:\apps\python;E:\apps\Python\Scripts\;E:\apps\Python\;C:\Users\TouchOdeath\AppData\Roaming\npm [calling]
- 1db4.1c50: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptsp.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 000007fefd0c0000 LB 0x00017000 C:\Windows\system32\CRYPTSP.dll [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptsp.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd0c0000 'C:\Windows\system32\CRYPTSP.dll'
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\rsaenh.dll)
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\rsaenh.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000695c50:E:\apps\virtualbox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;E:\apps\Iridium Browser;C:\Program Files (x86)\Google\Chrome\Application;C:\Windows\system32;C:\Windows;C:\Windows\system32\wbem;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\Dell\DW WLAN Card;C:\Ruby-install\bin;C:\Windows\System32\WindowsPowerShell\v1.0;C:\Program Files (x86)\Common Files\Adobe\AGL;C:\Program Files\Microsoft SQL Server\110\Tools\Binn;C:\Program Files\WIDCOMM\Bluetooth Software;C:\Program Files\WIDCOMM\Bluetooth Software\syswow64;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit;E:\apps\CMake\bin;E:\apps\PDFtk\bin;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5\Doctrine extensions for PHP;C:\adb;E:\apps\Tesseract-OCR;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x64;E:\apps\NodeJS\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;E:\apps\python;E:\apps\Python\Scripts\;E:\apps\Python\;C:\Users\TouchOdeath\AppData\Roaming\npm [calling]
- 1db4.1c50: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 000007fefcdc0000 LB 0x00047000 C:\Windows\system32\rsaenh.dll [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcdc0000 'C:\Windows\system32\rsaenh.dll'
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ADVAPI32.dll (Input=ADVAPI32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000695c50:E:\apps\virtualbox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;E:\apps\Iridium Browser;C:\Program Files (x86)\Google\Chrome\Application;C:\Windows\system32;C:\Windows;C:\Windows\system32\wbem;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\Dell\DW WLAN Card;C:\Ruby-install\bin;C:\Windows\System32\WindowsPowerShell\v1.0;C:\Program Files (x86)\Common Files\Adobe\AGL;C:\Program Files\Microsoft SQL Server\110\Tools\Binn;C:\Program Files\WIDCOMM\Bluetooth Software;C:\Program Files\WIDCOMM\Bluetooth Software\syswow64;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit;E:\apps\CMake\bin;E:\apps\PDFtk\bin;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5\Doctrine extensions for PHP;C:\adb;E:\apps\Tesseract-OCR;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x64;E:\apps\NodeJS\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;E:\apps\python;E:\apps\Python\Scripts\;E:\apps\Python\;C:\Users\TouchOdeath\AppData\Roaming\npm [calling]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefde70000 'C:\Windows\system32\ADVAPI32.dll'
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\cryptbase.dll)
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cryptbase.dll
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTBASE.dll (Input=CRYPTBASE.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000695c50:E:\apps\virtualbox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;E:\apps\Iridium Browser;C:\Program Files (x86)\Google\Chrome\Application;C:\Windows\system32;C:\Windows;C:\Windows\system32\wbem;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\Dell\DW WLAN Card;C:\Ruby-install\bin;C:\Windows\System32\WindowsPowerShell\v1.0;C:\Program Files (x86)\Common Files\Adobe\AGL;C:\Program Files\Microsoft SQL Server\110\Tools\Binn;C:\Program Files\WIDCOMM\Bluetooth Software;C:\Program Files\WIDCOMM\Bluetooth Software\syswow64;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit;E:\apps\CMake\bin;E:\apps\PDFtk\bin;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5\Doctrine extensions for PHP;C:\adb;E:\apps\Tesseract-OCR;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x64;E:\apps\NodeJS\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;E:\apps\python;E:\apps\Python\Scripts\;E:\apps\Python\;C:\Users\TouchOdeath\AppData\Roaming\npm [calling]
- 1db4.1c50: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptbase.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 000007fefd6c0000 LB 0x0000f000 C:\Windows\system32\CRYPTBASE.dll [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptbase.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd6c0000 'C:\Windows\system32\CRYPTBASE.dll'
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000695c50:E:\apps\virtualbox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;E:\apps\Iridium Browser;C:\Program Files (x86)\Google\Chrome\Application;C:\Windows\system32;C:\Windows;C:\Windows\system32\wbem;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\Dell\DW WLAN Card;C:\Ruby-install\bin;C:\Windows\System32\WindowsPowerShell\v1.0;C:\Program Files (x86)\Common Files\Adobe\AGL;C:\Program Files\Microsoft SQL Server\110\Tools\Binn;C:\Program Files\WIDCOMM\Bluetooth Software;C:\Program Files\WIDCOMM\Bluetooth Software\syswow64;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit;E:\apps\CMake\bin;E:\apps\PDFtk\bin;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5\Doctrine extensions for PHP;C:\adb;E:\apps\Tesseract-OCR;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x64;E:\apps\NodeJS\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;E:\apps\python;E:\apps\Python\Scripts\;E:\apps\Python\;C:\Users\TouchOdeath\AppData\Roaming\npm [calling]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077990000 'C:\Windows\system32\kernel32.dll'
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\WINTRUST.DLL (Input=WINTRUST.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000695c50:E:\apps\virtualbox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;E:\apps\Iridium Browser;C:\Program Files (x86)\Google\Chrome\Application;C:\Windows\system32;C:\Windows;C:\Windows\system32\wbem;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\Dell\DW WLAN Card;C:\Ruby-install\bin;C:\Windows\System32\WindowsPowerShell\v1.0;C:\Program Files (x86)\Common Files\Adobe\AGL;C:\Program Files\Microsoft SQL Server\110\Tools\Binn;C:\Program Files\WIDCOMM\Bluetooth Software;C:\Program Files\WIDCOMM\Bluetooth Software\syswow64;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit;E:\apps\CMake\bin;E:\apps\PDFtk\bin;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5\Doctrine extensions for PHP;C:\adb;E:\apps\Tesseract-OCR;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x64;E:\apps\NodeJS\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;E:\apps\python;E:\apps\Python\Scripts\;E:\apps\Python\;C:\Users\TouchOdeath\AppData\Roaming\npm [calling]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd980000 'C:\Windows\system32\WINTRUST.DLL'
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPT32.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=0000000000695c50:E:\apps\virtualbox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;E:\apps\Iridium Browser;C:\Program Files (x86)\Google\Chrome\Application;C:\Windows\system32;C:\Windows;C:\Windows\system32\wbem;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\Dell\DW WLAN Card;C:\Ruby-install\bin;C:\Windows\System32\WindowsPowerShell\v1.0;C:\Program Files (x86)\Common Files\Adobe\AGL;C:\Program Files\Microsoft SQL Server\110\Tools\Binn;C:\Program Files\WIDCOMM\Bluetooth Software;C:\Program Files\WIDCOMM\Bluetooth Software\syswow64;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit;E:\apps\CMake\bin;E:\apps\PDFtk\bin;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5\Doctrine extensions for PHP;C:\adb;E:\apps\Tesseract-OCR;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x64;E:\apps\NodeJS\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;E:\apps\python;E:\apps\Python\Scripts\;E:\apps\Python\;C:\Users\TouchOdeath\AppData\Roaming\npm [calling]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefda70000 'C:\Windows\system32\CRYPT32.dll'
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'advapi32.dll'.
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\imagehlp.dll)
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\imagehlp.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\imagehlp.dll (Input=imagehlp.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000695c50:E:\apps\virtualbox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;E:\apps\Iridium Browser;C:\Program Files (x86)\Google\Chrome\Application;C:\Windows\system32;C:\Windows;C:\Windows\system32\wbem;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\Dell\DW WLAN Card;C:\Ruby-install\bin;C:\Windows\System32\WindowsPowerShell\v1.0;C:\Program Files (x86)\Common Files\Adobe\AGL;C:\Program Files\Microsoft SQL Server\110\Tools\Binn;C:\Program Files\WIDCOMM\Bluetooth Software;C:\Program Files\WIDCOMM\Bluetooth Software\syswow64;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit;E:\apps\CMake\bin;E:\apps\PDFtk\bin;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5\Doctrine extensions for PHP;C:\adb;E:\apps\Tesseract-OCR;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x64;E:\apps\NodeJS\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;E:\apps\python;E:\apps\Python\Scripts\;E:\apps\Python\;C:\Users\TouchOdeath\AppData\Roaming\npm [calling]
- 1db4.1c50: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\imagehlp.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 000007fefe1a0000 LB 0x00019000 C:\Windows\system32\imagehlp.dll [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\imagehlp.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe1a0000 'C:\Windows\system32\imagehlp.dll'
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptsp.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTSP.dll (Input=CRYPTSP.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000695c50:E:\apps\virtualbox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;E:\apps\Iridium Browser;C:\Program Files (x86)\Google\Chrome\Application;C:\Windows\system32;C:\Windows;C:\Windows\system32\wbem;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\Dell\DW WLAN Card;C:\Ruby-install\bin;C:\Windows\System32\WindowsPowerShell\v1.0;C:\Program Files (x86)\Common Files\Adobe\AGL;C:\Program Files\Microsoft SQL Server\110\Tools\Binn;C:\Program Files\WIDCOMM\Bluetooth Software;C:\Program Files\WIDCOMM\Bluetooth Software\syswow64;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit;E:\apps\CMake\bin;E:\apps\PDFtk\bin;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5\Doctrine extensions for PHP;C:\adb;E:\apps\Tesseract-OCR;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x64;E:\apps\NodeJS\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;E:\apps\python;E:\apps\Python\Scripts\;E:\apps\Python\;C:\Users\TouchOdeath\AppData\Roaming\npm [calling]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd0c0000 'C:\Windows\system32\CRYPTSP.dll'
- 1db4.1c50: \Device\HarddiskVolume2\Windows\System32\user32.dll: Owner is not trusted installer (01 05 00 00 00 00 00 05 15 00 00 00 ae 4d ef 8d ed db df fd 54 89 01 57 e8 03 00 00)
- 1db4.1c50: \Device\HarddiskVolume2\Windows\System32\user32.dll: Relaxing the TrustedInstaller requirement for this DLL (it's in system32).
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\user32.dll)
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\user32.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'lpk.dll'.
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\gdi32.dll)
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\gdi32.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'lpk.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'lpk.dll' -> '\Device\HarddiskVolume2\Windows\System32\lpk.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'gdi32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'user32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'usp10.dll'.
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\lpk.dll)
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\lpk.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'usp10.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'usp10.dll' -> '\Device\HarddiskVolume2\Windows\System32\usp10.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'gdi32.dll'.
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\usp10.dll)
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\usp10.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\USER32.dll (Input=USER32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000695c50:E:\apps\virtualbox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;E:\apps\Iridium Browser;C:\Program Files (x86)\Google\Chrome\Application;C:\Windows\system32;C:\Windows;C:\Windows\system32\wbem;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\Dell\DW WLAN Card;C:\Ruby-install\bin;C:\Windows\System32\WindowsPowerShell\v1.0;C:\Program Files (x86)\Common Files\Adobe\AGL;C:\Program Files\Microsoft SQL Server\110\Tools\Binn;C:\Program Files\WIDCOMM\Bluetooth Software;C:\Program Files\WIDCOMM\Bluetooth Software\syswow64;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit;E:\apps\CMake\bin;E:\apps\PDFtk\bin;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5\Doctrine extensions for PHP;C:\adb;E:\apps\Tesseract-OCR;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x64;E:\apps\NodeJS\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;E:\apps\python;E:\apps\Python\Scripts\;E:\apps\Python\;C:\Users\TouchOdeath\AppData\Roaming\npm [calling]
- 1db4.1c50: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 0000000077890000 LB 0x000fa000 C:\Windows\system32\USER32.dll [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 000007fefe130000 LB 0x00067000 C:\Windows\system32\GDI32.dll [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 000007fefe470000 LB 0x0000e000 C:\Windows\system32\LPK.dll [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\lpk.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 000007feff4c0000 LB 0x000c9000 C:\Windows\system32\USP10.dll [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\usp10.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\gdi32.dll (Input=gdi32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000695c50:E:\apps\virtualbox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;E:\apps\Iridium Browser;C:\Program Files (x86)\Google\Chrome\Application;C:\Windows\system32;C:\Windows;C:\Windows\system32\wbem;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\Dell\DW WLAN Card;C:\Ruby-install\bin;C:\Windows\System32\WindowsPowerShell\v1.0;C:\Program Files (x86)\Common Files\Adobe\AGL;C:\Program Files\Microsoft SQL Server\110\Tools\Binn;C:\Program Files\WIDCOMM\Bluetooth Software;C:\Program Files\WIDCOMM\Bluetooth Software\syswow64;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit;E:\apps\CMake\bin;E:\apps\PDFtk\bin;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5\Doctrine extensions for PHP;C:\adb;E:\apps\Tesseract-OCR;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x64;E:\apps\NodeJS\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;E:\apps\python;E:\apps\Python\Scripts\;E:\apps\Python\;C:\Users\TouchOdeath\AppData\Roaming\npm [calling]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe130000 'C:\Windows\system32\gdi32.dll'
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'user32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msctf.dll'.
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\imm32.dll)
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\imm32.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msctf.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'msctf.dll' -> '\Device\HarddiskVolume2\Windows\System32\msctf.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'gdi32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'imm32.dll'.
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\msctf.dll)
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msctf.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume2\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\imm32.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\IMM32.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000695c50:E:\apps\virtualbox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;E:\apps\Iridium Browser;C:\Program Files (x86)\Google\Chrome\Application;C:\Windows\system32;C:\Windows;C:\Windows\system32\wbem;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\Dell\DW WLAN Card;C:\Ruby-install\bin;C:\Windows\System32\WindowsPowerShell\v1.0;C:\Program Files (x86)\Common Files\Adobe\AGL;C:\Program Files\Microsoft SQL Server\110\Tools\Binn;C:\Program Files\WIDCOMM\Bluetooth Software;C:\Program Files\WIDCOMM\Bluetooth Software\syswow64;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit;E:\apps\CMake\bin;E:\apps\PDFtk\bin;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5\Doctrine extensions for PHP;C:\adb;E:\apps\Tesseract-OCR;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x64;E:\apps\NodeJS\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;E:\apps\python;E:\apps\Python\Scripts\;E:\apps\Python\;C:\Users\TouchOdeath\AppData\Roaming\npm [calling]
- 1db4.1c50: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\imm32.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 000007feff770000 LB 0x0002e000 C:\Windows\system32\IMM32.DLL [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\imm32.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 000007fefdd60000 LB 0x00109000 C:\Windows\system32\MSCTF.dll [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msctf.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff770000 'C:\Windows\system32\IMM32.DLL'
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077890000 'C:\Windows\system32\USER32.dll'
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'bcrypt.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msasn1.dll'.
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\ncrypt.dll)
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ncrypt.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msasn1.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'msasn1.dll' -> '\Device\HarddiskVolume2\Windows\System32\msasn1.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume2\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ncrypt.dll (Input=ncrypt.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000695c50:E:\apps\virtualbox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;E:\apps\Iridium Browser;C:\Program Files (x86)\Google\Chrome\Application;C:\Windows\system32;C:\Windows;C:\Windows\system32\wbem;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\Dell\DW WLAN Card;C:\Ruby-install\bin;C:\Windows\System32\WindowsPowerShell\v1.0;C:\Program Files (x86)\Common Files\Adobe\AGL;C:\Program Files\Microsoft SQL Server\110\Tools\Binn;C:\Program Files\WIDCOMM\Bluetooth Software;C:\Program Files\WIDCOMM\Bluetooth Software\syswow64;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit;E:\apps\CMake\bin;E:\apps\PDFtk\bin;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5\Doctrine extensions for PHP;C:\adb;E:\apps\Tesseract-OCR;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x64;E:\apps\NodeJS\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;E:\apps\python;E:\apps\Python\Scripts\;E:\apps\Python\;C:\Users\TouchOdeath\AppData\Roaming\npm [calling]
- 1db4.1c50: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\ncrypt.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 000007fefd240000 LB 0x0004d000 C:\Windows\system32\ncrypt.dll [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\ncrypt.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd240000 'C:\Windows\system32\ncrypt.dll'
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\bcrypt.dll (Input=bcrypt.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000695c50:E:\apps\virtualbox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;E:\apps\Iridium Browser;C:\Program Files (x86)\Google\Chrome\Application;C:\Windows\system32;C:\Windows;C:\Windows\system32\wbem;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\Dell\DW WLAN Card;C:\Ruby-install\bin;C:\Windows\System32\WindowsPowerShell\v1.0;C:\Program Files (x86)\Common Files\Adobe\AGL;C:\Program Files\Microsoft SQL Server\110\Tools\Binn;C:\Program Files\WIDCOMM\Bluetooth Software;C:\Program Files\WIDCOMM\Bluetooth Software\syswow64;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit;E:\apps\CMake\bin;E:\apps\PDFtk\bin;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5\Doctrine extensions for PHP;C:\adb;E:\apps\Tesseract-OCR;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x64;E:\apps\NodeJS\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;E:\apps\python;E:\apps\Python\Scripts\;E:\apps\Python\;C:\Users\TouchOdeath\AppData\Roaming\npm [calling]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd210000 'C:\Windows\system32\bcrypt.dll'
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'rpcrt4.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'profapi.dll'.
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\userenv.dll)
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\userenv.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'profapi.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'profapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\profapi.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\profapi.dll)
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\profapi.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\USERENV.dll (Input=USERENV.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000695c50:E:\apps\virtualbox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;E:\apps\Iridium Browser;C:\Program Files (x86)\Google\Chrome\Application;C:\Windows\system32;C:\Windows;C:\Windows\system32\wbem;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\Dell\DW WLAN Card;C:\Ruby-install\bin;C:\Windows\System32\WindowsPowerShell\v1.0;C:\Program Files (x86)\Common Files\Adobe\AGL;C:\Program Files\Microsoft SQL Server\110\Tools\Binn;C:\Program Files\WIDCOMM\Bluetooth Software;C:\Program Files\WIDCOMM\Bluetooth Software\syswow64;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit;E:\apps\CMake\bin;E:\apps\PDFtk\bin;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5\Doctrine extensions for PHP;C:\adb;E:\apps\Tesseract-OCR;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x64;E:\apps\NodeJS\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;E:\apps\python;E:\apps\Python\Scripts\;E:\apps\Python\;C:\Users\TouchOdeath\AppData\Roaming\npm [calling]
- 1db4.1c50: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\userenv.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 000007fefda50000 LB 0x0001e000 C:\Windows\system32\USERENV.dll [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\userenv.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 000007fefd8c0000 LB 0x0000f000 C:\Windows\system32\profapi.dll [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\profapi.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefda50000 'C:\Windows\system32\USERENV.dll'
- 1db4.1c50: supR3HardenedIsApiSetDll: '<NULL>' -> true
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000695c50:E:\apps\virtualbox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;E:\apps\Iridium Browser;C:\Program Files (x86)\Google\Chrome\Application;C:\Windows\system32;C:\Windows;C:\Windows\system32\wbem;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\Dell\DW WLAN Card;C:\Ruby-install\bin;C:\Windows\System32\WindowsPowerShell\v1.0;C:\Program Files (x86)\Common Files\Adobe\AGL;C:\Program Files\Microsoft SQL Server\110\Tools\Binn;C:\Program Files\WIDCOMM\Bluetooth Software;C:\Program Files\WIDCOMM\Bluetooth Software\syswow64;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit;E:\apps\CMake\bin;E:\apps\PDFtk\bin;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5\Doctrine extensions for PHP;C:\adb;E:\apps\Tesseract-OCR;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x64;E:\apps\NodeJS\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;E:\apps\python;E:\apps\Python\Scripts\;E:\apps\Python\;C:\Users\TouchOdeath\AppData\Roaming\npm [calling]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe110000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
- 1db4.1c50: supR3HardenedIsApiSetDll: '<NULL>' -> true
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000695c50:E:\apps\virtualbox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;E:\apps\Iridium Browser;C:\Program Files (x86)\Google\Chrome\Application;C:\Windows\system32;C:\Windows;C:\Windows\system32\wbem;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\Dell\DW WLAN Card;C:\Ruby-install\bin;C:\Windows\System32\WindowsPowerShell\v1.0;C:\Program Files (x86)\Common Files\Adobe\AGL;C:\Program Files\Microsoft SQL Server\110\Tools\Binn;C:\Program Files\WIDCOMM\Bluetooth Software;C:\Program Files\WIDCOMM\Bluetooth Software\syswow64;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit;E:\apps\CMake\bin;E:\apps\PDFtk\bin;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5\Doctrine extensions for PHP;C:\adb;E:\apps\Tesseract-OCR;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x64;E:\apps\NodeJS\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;E:\apps\python;E:\apps\Python\Scripts\;E:\apps\Python\;C:\Users\TouchOdeath\AppData\Roaming\npm [calling]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe110000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'rpcrt4.dll'.
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\gpapi.dll)
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\gpapi.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\GPAPI.dll (Input=GPAPI.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000695c50:E:\apps\virtualbox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;E:\apps\Iridium Browser;C:\Program Files (x86)\Google\Chrome\Application;C:\Windows\system32;C:\Windows;C:\Windows\system32\wbem;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\Dell\DW WLAN Card;C:\Ruby-install\bin;C:\Windows\System32\WindowsPowerShell\v1.0;C:\Program Files (x86)\Common Files\Adobe\AGL;C:\Program Files\Microsoft SQL Server\110\Tools\Binn;C:\Program Files\WIDCOMM\Bluetooth Software;C:\Program Files\WIDCOMM\Bluetooth Software\syswow64;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit;E:\apps\CMake\bin;E:\apps\PDFtk\bin;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5\Doctrine extensions for PHP;C:\adb;E:\apps\Tesseract-OCR;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x64;E:\apps\NodeJS\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;E:\apps\python;E:\apps\Python\Scripts\;E:\apps\Python\;C:\Users\TouchOdeath\AppData\Roaming\npm [calling]
- 1db4.1c50: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gpapi.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 000007fefcb80000 LB 0x0001b000 C:\Windows\system32\GPAPI.dll [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gpapi.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefcb80000 'C:\Windows\system32\GPAPI.dll'
- 1db4.1c50: supR3HardenedIsApiSetDll: '<NULL>' -> true
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-Management-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000695c50:E:\apps\virtualbox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;E:\apps\Iridium Browser;C:\Program Files (x86)\Google\Chrome\Application;C:\Windows\system32;C:\Windows;C:\Windows\system32\wbem;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\Dell\DW WLAN Card;C:\Ruby-install\bin;C:\Windows\System32\WindowsPowerShell\v1.0;C:\Program Files (x86)\Common Files\Adobe\AGL;C:\Program Files\Microsoft SQL Server\110\Tools\Binn;C:\Program Files\WIDCOMM\Bluetooth Software;C:\Program Files\WIDCOMM\Bluetooth Software\syswow64;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit;E:\apps\CMake\bin;E:\apps\PDFtk\bin;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5\Doctrine extensions for PHP;C:\adb;E:\apps\Tesseract-OCR;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x64;E:\apps\NodeJS\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;E:\apps\python;E:\apps\Python\Scripts\;E:\apps\Python\;C:\Users\TouchOdeath\AppData\Roaming\npm [calling]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe110000 'API-MS-WIN-Service-Management-L1-1-0.dll'
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rpcrt4.dll (Input=rpcrt4.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000695c50:E:\apps\virtualbox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;E:\apps\Iridium Browser;C:\Program Files (x86)\Google\Chrome\Application;C:\Windows\system32;C:\Windows;C:\Windows\system32\wbem;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\Dell\DW WLAN Card;C:\Ruby-install\bin;C:\Windows\System32\WindowsPowerShell\v1.0;C:\Program Files (x86)\Common Files\Adobe\AGL;C:\Program Files\Microsoft SQL Server\110\Tools\Binn;C:\Program Files\WIDCOMM\Bluetooth Software;C:\Program Files\WIDCOMM\Bluetooth Software\syswow64;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit;E:\apps\CMake\bin;E:\apps\PDFtk\bin;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5\Doctrine extensions for PHP;C:\adb;E:\apps\Tesseract-OCR;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x64;E:\apps\NodeJS\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;E:\apps\python;E:\apps\Python\Scripts\;E:\apps\Python\;C:\Users\TouchOdeath\AppData\Roaming\npm [calling]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feffc90000 'C:\Windows\system32\rpcrt4.dll'
- 1db4.1c50: supR3HardenedIsApiSetDll: '<NULL>' -> true
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-Management-L2-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000695c50:E:\apps\virtualbox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;E:\apps\Iridium Browser;C:\Program Files (x86)\Google\Chrome\Application;C:\Windows\system32;C:\Windows;C:\Windows\system32\wbem;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\Dell\DW WLAN Card;C:\Ruby-install\bin;C:\Windows\System32\WindowsPowerShell\v1.0;C:\Program Files (x86)\Common Files\Adobe\AGL;C:\Program Files\Microsoft SQL Server\110\Tools\Binn;C:\Program Files\WIDCOMM\Bluetooth Software;C:\Program Files\WIDCOMM\Bluetooth Software\syswow64;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit;E:\apps\CMake\bin;E:\apps\PDFtk\bin;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5\Doctrine extensions for PHP;C:\adb;E:\apps\Tesseract-OCR;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x64;E:\apps\NodeJS\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;E:\apps\python;E:\apps\Python\Scripts\;E:\apps\Python\;C:\Users\TouchOdeath\AppData\Roaming\npm [calling]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe110000 'API-MS-WIN-Service-Management-L2-1-0.dll'
- 1db4.1c50: supR3HardenedIsApiSetDll: '<NULL>' -> true
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000695c50:E:\apps\virtualbox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;E:\apps\Iridium Browser;C:\Program Files (x86)\Google\Chrome\Application;C:\Windows\system32;C:\Windows;C:\Windows\system32\wbem;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\Dell\DW WLAN Card;C:\Ruby-install\bin;C:\Windows\System32\WindowsPowerShell\v1.0;C:\Program Files (x86)\Common Files\Adobe\AGL;C:\Program Files\Microsoft SQL Server\110\Tools\Binn;C:\Program Files\WIDCOMM\Bluetooth Software;C:\Program Files\WIDCOMM\Bluetooth Software\syswow64;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit;E:\apps\CMake\bin;E:\apps\PDFtk\bin;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5\Doctrine extensions for PHP;C:\adb;E:\apps\Tesseract-OCR;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x64;E:\apps\NodeJS\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;E:\apps\python;E:\apps\Python\Scripts\;E:\apps\Python\;C:\Users\TouchOdeath\AppData\Roaming\npm [calling]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe110000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'advapi32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'crypt32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'wldap32.dll'.
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\cryptnet.dll)
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cryptnet.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wldap32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'wldap32.dll' -> '\Device\HarddiskVolume2\Windows\System32\wldap32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\Wldap32.dll)
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\Wldap32.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume2\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (Input=cryptnet.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000695c50:E:\apps\virtualbox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;E:\apps\Iridium Browser;C:\Program Files (x86)\Google\Chrome\Application;C:\Windows\system32;C:\Windows;C:\Windows\system32\wbem;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\Dell\DW WLAN Card;C:\Ruby-install\bin;C:\Windows\System32\WindowsPowerShell\v1.0;C:\Program Files (x86)\Common Files\Adobe\AGL;C:\Program Files\Microsoft SQL Server\110\Tools\Binn;C:\Program Files\WIDCOMM\Bluetooth Software;C:\Program Files\WIDCOMM\Bluetooth Software\syswow64;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit;E:\apps\CMake\bin;E:\apps\PDFtk\bin;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5\Doctrine extensions for PHP;C:\adb;E:\apps\Tesseract-OCR;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x64;E:\apps\NodeJS\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;E:\apps\python;E:\apps\Python\Scripts\;E:\apps\Python\;C:\Users\TouchOdeath\AppData\Roaming\npm [calling]
- 1db4.1c50: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 000007fefa690000 LB 0x00027000 C:\Windows\system32\cryptnet.dll [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 000007fefe210000 LB 0x00052000 C:\Windows\system32\WLDAP32.dll [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\Wldap32.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=0000000000695c50:E:\apps\virtualbox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;E:\apps\Iridium Browser;C:\Program Files (x86)\Google\Chrome\Application;C:\Windows\system32;C:\Windows;C:\Windows\system32\wbem;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\Dell\DW WLAN Card;C:\Ruby-install\bin;C:\Windows\System32\WindowsPowerShell\v1.0;C:\Program Files (x86)\Common Files\Adobe\AGL;C:\Program Files\Microsoft SQL Server\110\Tools\Binn;C:\Program Files\WIDCOMM\Bluetooth Software;C:\Program Files\WIDCOMM\Bluetooth Software\syswow64;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit;E:\apps\CMake\bin;E:\apps\PDFtk\bin;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5\Doctrine extensions for PHP;C:\adb;E:\apps\Tesseract-OCR;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x64;E:\apps\NodeJS\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;E:\apps\python;E:\apps\Python\Scripts\;E:\apps\Python\;C:\Users\TouchOdeath\AppData\Roaming\npm [calling]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa690000 'C:\Windows\system32\cryptnet.dll'
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=0000000000695c50:E:\apps\virtualbox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;E:\apps\Iridium Browser;C:\Program Files (x86)\Google\Chrome\Application;C:\Windows\system32;C:\Windows;C:\Windows\system32\wbem;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\Dell\DW WLAN Card;C:\Ruby-install\bin;C:\Windows\System32\WindowsPowerShell\v1.0;C:\Program Files (x86)\Common Files\Adobe\AGL;C:\Program Files\Microsoft SQL Server\110\Tools\Binn;C:\Program Files\WIDCOMM\Bluetooth Software;C:\Program Files\WIDCOMM\Bluetooth Software\syswow64;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit;E:\apps\CMake\bin;E:\apps\PDFtk\bin;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5\Doctrine extensions for PHP;C:\adb;E:\apps\Tesseract-OCR;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x64;E:\apps\NodeJS\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;E:\apps\python;E:\apps\Python\Scripts\;E:\apps\Python\;C:\Users\TouchOdeath\AppData\Roaming\npm [calling]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa690000 'C:\Windows\system32\cryptnet.dll'
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=0000000000695c50:E:\apps\virtualbox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;E:\apps\Iridium Browser;C:\Program Files (x86)\Google\Chrome\Application;C:\Windows\system32;C:\Windows;C:\Windows\system32\wbem;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\Dell\DW WLAN Card;C:\Ruby-install\bin;C:\Windows\System32\WindowsPowerShell\v1.0;C:\Program Files (x86)\Common Files\Adobe\AGL;C:\Program Files\Microsoft SQL Server\110\Tools\Binn;C:\Program Files\WIDCOMM\Bluetooth Software;C:\Program Files\WIDCOMM\Bluetooth Software\syswow64;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit;E:\apps\CMake\bin;E:\apps\PDFtk\bin;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5\Doctrine extensions for PHP;C:\adb;E:\apps\Tesseract-OCR;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x64;E:\apps\NodeJS\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;E:\apps\python;E:\apps\Python\Scripts\;E:\apps\Python\;C:\Users\TouchOdeath\AppData\Roaming\npm [calling]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa690000 'C:\Windows\system32\cryptnet.dll'
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=0000000000695c50:E:\apps\virtualbox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;E:\apps\Iridium Browser;C:\Program Files (x86)\Google\Chrome\Application;C:\Windows\system32;C:\Windows;C:\Windows\system32\wbem;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\Dell\DW WLAN Card;C:\Ruby-install\bin;C:\Windows\System32\WindowsPowerShell\v1.0;C:\Program Files (x86)\Common Files\Adobe\AGL;C:\Program Files\Microsoft SQL Server\110\Tools\Binn;C:\Program Files\WIDCOMM\Bluetooth Software;C:\Program Files\WIDCOMM\Bluetooth Software\syswow64;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit;E:\apps\CMake\bin;E:\apps\PDFtk\bin;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5\Doctrine extensions for PHP;C:\adb;E:\apps\Tesseract-OCR;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x64;E:\apps\NodeJS\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;E:\apps\python;E:\apps\Python\Scripts\;E:\apps\Python\;C:\Users\TouchOdeath\AppData\Roaming\npm [calling]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa690000 'C:\Windows\system32\cryptnet.dll'
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=0000000000695c50:E:\apps\virtualbox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;E:\apps\Iridium Browser;C:\Program Files (x86)\Google\Chrome\Application;C:\Windows\system32;C:\Windows;C:\Windows\system32\wbem;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\Dell\DW WLAN Card;C:\Ruby-install\bin;C:\Windows\System32\WindowsPowerShell\v1.0;C:\Program Files (x86)\Common Files\Adobe\AGL;C:\Program Files\Microsoft SQL Server\110\Tools\Binn;C:\Program Files\WIDCOMM\Bluetooth Software;C:\Program Files\WIDCOMM\Bluetooth Software\syswow64;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit;E:\apps\CMake\bin;E:\apps\PDFtk\bin;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5\Doctrine extensions for PHP;C:\adb;E:\apps\Tesseract-OCR;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x64;E:\apps\NodeJS\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;E:\apps\python;E:\apps\Python\Scripts\;E:\apps\Python\;C:\Users\TouchOdeath\AppData\Roaming\npm [calling]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa690000 'C:\Windows\system32\cryptnet.dll'
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=0000000000695c50:E:\apps\virtualbox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;E:\apps\Iridium Browser;C:\Program Files (x86)\Google\Chrome\Application;C:\Windows\system32;C:\Windows;C:\Windows\system32\wbem;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\Dell\DW WLAN Card;C:\Ruby-install\bin;C:\Windows\System32\WindowsPowerShell\v1.0;C:\Program Files (x86)\Common Files\Adobe\AGL;C:\Program Files\Microsoft SQL Server\110\Tools\Binn;C:\Program Files\WIDCOMM\Bluetooth Software;C:\Program Files\WIDCOMM\Bluetooth Software\syswow64;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit;E:\apps\CMake\bin;E:\apps\PDFtk\bin;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5\Doctrine extensions for PHP;C:\adb;E:\apps\Tesseract-OCR;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x64;E:\apps\NodeJS\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;E:\apps\python;E:\apps\Python\Scripts\;E:\apps\Python\;C:\Users\TouchOdeath\AppData\Roaming\npm [calling]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa690000 'C:\Windows\system32\cryptnet.dll'
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa690000 'C:\Windows\system32\cryptnet.dll'
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa690000 'C:\Windows\system32\cryptnet.dll'
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa690000 'C:\Windows\system32\cryptnet.dll'
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa690000 'C:\Windows\system32\cryptnet.dll'
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa690000 'C:\Windows\system32\cryptnet.dll'
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa690000 'C:\Windows\system32\cryptnet.dll'
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa690000 'C:\Windows\system32\cryptnet.dll'
- 1db4.1c50: supR3HardenedIsApiSetDll: '<NULL>' -> true
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000695c50:E:\apps\virtualbox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;E:\apps\Iridium Browser;C:\Program Files (x86)\Google\Chrome\Application;C:\Windows\system32;C:\Windows;C:\Windows\system32\wbem;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\Dell\DW WLAN Card;C:\Ruby-install\bin;C:\Windows\System32\WindowsPowerShell\v1.0;C:\Program Files (x86)\Common Files\Adobe\AGL;C:\Program Files\Microsoft SQL Server\110\Tools\Binn;C:\Program Files\WIDCOMM\Bluetooth Software;C:\Program Files\WIDCOMM\Bluetooth Software\syswow64;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit;E:\apps\CMake\bin;E:\apps\PDFtk\bin;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5\Doctrine extensions for PHP;C:\adb;E:\apps\Tesseract-OCR;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x64;E:\apps\NodeJS\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;E:\apps\python;E:\apps\Python\Scripts\;E:\apps\Python\;C:\Users\TouchOdeath\AppData\Roaming\npm [calling]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe110000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\profapi.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\profapi.dll (Input=profapi.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000695c50:E:\apps\virtualbox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;E:\apps\Iridium Browser;C:\Program Files (x86)\Google\Chrome\Application;C:\Windows\system32;C:\Windows;C:\Windows\system32\wbem;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\Dell\DW WLAN Card;C:\Ruby-install\bin;C:\Windows\System32\WindowsPowerShell\v1.0;C:\Program Files (x86)\Common Files\Adobe\AGL;C:\Program Files\Microsoft SQL Server\110\Tools\Binn;C:\Program Files\WIDCOMM\Bluetooth Software;C:\Program Files\WIDCOMM\Bluetooth Software\syswow64;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit;E:\apps\CMake\bin;E:\apps\PDFtk\bin;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5\Doctrine extensions for PHP;C:\adb;E:\apps\Tesseract-OCR;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x64;E:\apps\NodeJS\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;E:\apps\python;E:\apps\Python\Scripts\;E:\apps\Python\;C:\Users\TouchOdeath\AppData\Roaming\npm [calling]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd8c0000 'C:\Windows\system32\profapi.dll'
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msvcrt.dll'.
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\shlwapi.dll)
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\shlwapi.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\user32.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\SHLWAPI.dll (Input=SHLWAPI.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000695c50:E:\apps\virtualbox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;E:\apps\Iridium Browser;C:\Program Files (x86)\Google\Chrome\Application;C:\Windows\system32;C:\Windows;C:\Windows\system32\wbem;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\Dell\DW WLAN Card;C:\Ruby-install\bin;C:\Windows\System32\WindowsPowerShell\v1.0;C:\Program Files (x86)\Common Files\Adobe\AGL;C:\Program Files\Microsoft SQL Server\110\Tools\Binn;C:\Program Files\WIDCOMM\Bluetooth Software;C:\Program Files\WIDCOMM\Bluetooth Software\syswow64;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit;E:\apps\CMake\bin;E:\apps\PDFtk\bin;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5\Doctrine extensions for PHP;C:\adb;E:\apps\Tesseract-OCR;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x64;E:\apps\NodeJS\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;E:\apps\python;E:\apps\Python\Scripts\;E:\apps\Python\;C:\Users\TouchOdeath\AppData\Roaming\npm [calling]
- 1db4.1c50: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 000007fefe270000 LB 0x00071000 C:\Windows\system32\SHLWAPI.dll [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe270000 'C:\Windows\system32\SHLWAPI.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000000 pwszName=\SystemRoot\System32\ntdll.dll
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: New context 00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=771D512B7B1C39F0393BD4EF9FC62F442783FB35
- 1db4.1c50: supR3HardenedIsApiSetDll: '<NULL>' -> true
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000695c50:E:\apps\virtualbox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;E:\apps\Iridium Browser;C:\Program Files (x86)\Google\Chrome\Application;C:\Windows\system32;C:\Windows;C:\Windows\system32\wbem;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\Dell\DW WLAN Card;C:\Ruby-install\bin;C:\Windows\System32\WindowsPowerShell\v1.0;C:\Program Files (x86)\Common Files\Adobe\AGL;C:\Program Files\Microsoft SQL Server\110\Tools\Binn;C:\Program Files\WIDCOMM\Bluetooth Software;C:\Program Files\WIDCOMM\Bluetooth Software\syswow64;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit;E:\apps\CMake\bin;E:\apps\PDFtk\bin;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5\Doctrine extensions for PHP;C:\adb;E:\apps\Tesseract-OCR;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x64;E:\apps\NodeJS\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;E:\apps\python;E:\apps\Python\Scripts\;E:\apps\Python\;C:\Users\TouchOdeath\AppData\Roaming\npm [calling]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe110000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
- 1db4.1c50: supR3HardenedIsApiSetDll: '<NULL>' -> true
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-Management-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000695c50:E:\apps\virtualbox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;E:\apps\Iridium Browser;C:\Program Files (x86)\Google\Chrome\Application;C:\Windows\system32;C:\Windows;C:\Windows\system32\wbem;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\Dell\DW WLAN Card;C:\Ruby-install\bin;C:\Windows\System32\WindowsPowerShell\v1.0;C:\Program Files (x86)\Common Files\Adobe\AGL;C:\Program Files\Microsoft SQL Server\110\Tools\Binn;C:\Program Files\WIDCOMM\Bluetooth Software;C:\Program Files\WIDCOMM\Bluetooth Software\syswow64;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit;E:\apps\CMake\bin;E:\apps\PDFtk\bin;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5\Doctrine extensions for PHP;C:\adb;E:\apps\Tesseract-OCR;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x64;E:\apps\NodeJS\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;E:\apps\python;E:\apps\Python\Scripts\;E:\apps\Python\;C:\Users\TouchOdeath\AppData\Roaming\npm [calling]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe110000 'API-MS-WIN-Service-Management-L1-1-0.dll'
- 1db4.1c50: supR3HardenedIsApiSetDll: '<NULL>' -> true
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-winsvc-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000695c50:E:\apps\virtualbox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;E:\apps\Iridium Browser;C:\Program Files (x86)\Google\Chrome\Application;C:\Windows\system32;C:\Windows;C:\Windows\system32\wbem;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\Dell\DW WLAN Card;C:\Ruby-install\bin;C:\Windows\System32\WindowsPowerShell\v1.0;C:\Program Files (x86)\Common Files\Adobe\AGL;C:\Program Files\Microsoft SQL Server\110\Tools\Binn;C:\Program Files\WIDCOMM\Bluetooth Software;C:\Program Files\WIDCOMM\Bluetooth Software\syswow64;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit;E:\apps\CMake\bin;E:\apps\PDFtk\bin;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5\Doctrine extensions for PHP;C:\adb;E:\apps\Tesseract-OCR;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x64;E:\apps\NodeJS\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;E:\apps\python;E:\apps\Python\Scripts\;E:\apps\Python\;C:\Users\TouchOdeath\AppData\Roaming\npm [calling]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe110000 'API-MS-WIN-Service-winsvc-L1-1-0.dll'
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll [lacks WinVerifyTrust]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ADVAPI32.dll (Input=ADVAPI32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000695c50:E:\apps\virtualbox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;E:\apps\Iridium Browser;C:\Program Files (x86)\Google\Chrome\Application;C:\Windows\system32;C:\Windows;C:\Windows\system32\wbem;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\Dell\DW WLAN Card;C:\Ruby-install\bin;C:\Windows\System32\WindowsPowerShell\v1.0;C:\Program Files (x86)\Common Files\Adobe\AGL;C:\Program Files\Microsoft SQL Server\110\Tools\Binn;C:\Program Files\WIDCOMM\Bluetooth Software;C:\Program Files\WIDCOMM\Bluetooth Software\syswow64;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit;E:\apps\CMake\bin;E:\apps\PDFtk\bin;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5\Doctrine extensions for PHP;C:\adb;E:\apps\Tesseract-OCR;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x64;E:\apps\NodeJS\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;E:\apps\python;E:\apps\Python\Scripts\;E:\apps\Python\;C:\Users\TouchOdeath\AppData\Roaming\npm [calling]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefde70000 'C:\Windows\system32\ADVAPI32.dll'
- 1db4.1c50: supR3HardenedIsApiSetDll: '<NULL>' -> true
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-LSALookup-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000695c50:E:\apps\virtualbox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;E:\apps\Iridium Browser;C:\Program Files (x86)\Google\Chrome\Application;C:\Windows\system32;C:\Windows;C:\Windows\system32\wbem;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\Dell\DW WLAN Card;C:\Ruby-install\bin;C:\Windows\System32\WindowsPowerShell\v1.0;C:\Program Files (x86)\Common Files\Adobe\AGL;C:\Program Files\Microsoft SQL Server\110\Tools\Binn;C:\Program Files\WIDCOMM\Bluetooth Software;C:\Program Files\WIDCOMM\Bluetooth Software\syswow64;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit;E:\apps\CMake\bin;E:\apps\PDFtk\bin;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5\Doctrine extensions for PHP;C:\adb;E:\apps\Tesseract-OCR;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x64;E:\apps\NodeJS\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;E:\apps\python;E:\apps\Python\Scripts\;E:\apps\Python\;C:\Users\TouchOdeath\AppData\Roaming\npm [calling]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe110000 'API-MS-Win-Security-LSALookup-L1-1-0.dll'
- 1db4.1c50: supR3HardenedIsApiSetDll: '<NULL>' -> true
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-LSALookup-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000695c50:E:\apps\virtualbox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;E:\apps\Iridium Browser;C:\Program Files (x86)\Google\Chrome\Application;C:\Windows\system32;C:\Windows;C:\Windows\system32\wbem;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\Dell\DW WLAN Card;C:\Ruby-install\bin;C:\Windows\System32\WindowsPowerShell\v1.0;C:\Program Files (x86)\Common Files\Adobe\AGL;C:\Program Files\Microsoft SQL Server\110\Tools\Binn;C:\Program Files\WIDCOMM\Bluetooth Software;C:\Program Files\WIDCOMM\Bluetooth Software\syswow64;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit;E:\apps\CMake\bin;E:\apps\PDFtk\bin;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5\Doctrine extensions for PHP;C:\adb;E:\apps\Tesseract-OCR;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x64;E:\apps\NodeJS\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;E:\apps\python;E:\apps\Python\Scripts\;E:\apps\Python\;C:\Users\TouchOdeath\AppData\Roaming\npm [calling]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe110000 'API-MS-Win-Security-LSALookup-L1-1-0.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_5_for_KB2882822~31bf3856ad364e35~amd64~~6.1.1.2.cat'; file='\SystemRoot\System32\ntdll.dll'
- 1db4.1c50: g_pfnWinVerifyTrust=000007fefd981010
- 1db4.1c50: supR3HardenedScreenImage/preload: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll [redoing WinVerifyTrust]
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000e0 pwszName=\Device\HarddiskVolume2\Windows\System32\crypt32.dll
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=CF258E1DA85AD69891395F6F7501E1D54F2DFED8
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_112_for_KB2868626~31bf3856ad364e35~amd64~~6.1.1.2.cat'; file='\Device\HarddiskVolume2\Windows\System32\crypt32.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.1c50: supR3HardenedScreenImage/preload: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\crypt32.dll'
- 1db4.1c50: supR3HardenedScreenImage/preload: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll [redoing WinVerifyTrust]
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000d4 pwszName=\Device\HarddiskVolume2\Windows\System32\wintrust.dll
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=80662AB761CF56CEC7909E5D03289BC65B4457A8
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_75_for_KB2862966~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\wintrust.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.1c50: supR3HardenedScreenImage/preload: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\wintrust.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000388 pwszName=\Device\HarddiskVolume2\Windows\System32\shlwapi.dll
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=0AB8D9C9D3E1FC95D01F9A984B16ED031BB40CD8
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\shlwapi.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000380 pwszName=\Device\HarddiskVolume2\Windows\System32\Wldap32.dll
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=87E73086F2528CF31D3AD5F0D71E04F8B942D5D8
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\Wldap32.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\Wldap32.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000037c pwszName=\Device\HarddiskVolume2\Windows\System32\cryptnet.dll
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=C1C670A9871F2BD448B2F0FA6127AC7A486B8D8F
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_75_for_KB2862966~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\cryptnet.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\cryptnet.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000258 pwszName=\Device\HarddiskVolume2\Windows\System32\gpapi.dll
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=470795C189226F7BDB8E50F42104CC34488B9340
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\gpapi.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\gpapi.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000001c4 pwszName=\Device\HarddiskVolume2\Windows\System32\profapi.dll
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2449672745D9BA339420451D13FA0380AA768231
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\profapi.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\profapi.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000001c0 pwszName=\Device\HarddiskVolume2\Windows\System32\userenv.dll
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=D3E1A2CC7367F751C19EBF4E6EDF5E9A10E47313
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\userenv.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\userenv.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000001ac pwszName=\Device\HarddiskVolume2\Windows\System32\ncrypt.dll
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=79EA9CBEF21789D2261F797DD2A1624A054306AB
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_52_for_KB2973337~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\Windows\System32\ncrypt.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\ncrypt.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000194 pwszName=\Device\HarddiskVolume2\Windows\System32\msctf.dll
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=803AF52F95A9EFDFDA06C595023831EE36ACD3A8
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\msctf.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\msctf.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000190 pwszName=\Device\HarddiskVolume2\Windows\System32\imm32.dll
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=6EEE1AB3B6D79AFF857940FF5F51ED27698153EC
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\imm32.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\imm32.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000018c pwszName=\Device\HarddiskVolume2\Windows\System32\usp10.dll
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=1F1AA8340DE02FC1B6341EE2706E55D56EDF63B8
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB2957509~31bf3856ad364e35~amd64~~6.1.1.2.cat'; file='\Device\HarddiskVolume2\Windows\System32\usp10.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\usp10.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000188 pwszName=\Device\HarddiskVolume2\Windows\System32\lpk.dll
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=6FCA4D678614C8615E6E5C082BF3A4562FCF14EB
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB2847311~31bf3856ad364e35~amd64~~6.1.1.2.cat'; file='\Device\HarddiskVolume2\Windows\System32\lpk.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\lpk.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000184 pwszName=\Device\HarddiskVolume2\Windows\System32\gdi32.dll
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=7AEB59C2353484ADF282BEA358113ABD82C223B9
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB2993651~31bf3856ad364e35~amd64~~6.1.1.3.cat'; file='\Device\HarddiskVolume2\Windows\System32\gdi32.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\gdi32.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000180 pwszName=\Device\HarddiskVolume2\Windows\System32\user32.dll
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B723D1B8AD72750B0CF5F6BEC66171B1254ED879
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\user32.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\user32.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000017c pwszName=\Device\HarddiskVolume2\Windows\System32\imagehlp.dll
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2702EE05F1B717B0F2CE0FBE32784A47B8419DCA
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_2_for_KB2893294~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\imagehlp.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\imagehlp.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000130 pwszName=\Device\HarddiskVolume2\Windows\System32\cryptbase.dll
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=A965CC5DB13A5FB23BBB1B6B5FA6D400DC49462F
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\cryptbase.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\cryptbase.dll'
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\rsaenh.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000012c pwszName=\Device\HarddiskVolume2\Windows\System32\cryptsp.dll
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=40667EDBA9045D4A4BE1D4844665D3B88F8CD0E0
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\cryptsp.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\cryptsp.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000120 pwszName=\Device\HarddiskVolume2\Windows\System32\sechost.dll
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=3FA2A014BF360CDC0E203A174FFC9DC5343C5323
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\sechost.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\sechost.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000011c pwszName=\Device\HarddiskVolume2\Windows\System32\advapi32.dll
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=7C0A1C638CE7C1160F49C473EC1420BD3AB693C4
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_5_for_KB2882822~31bf3856ad364e35~amd64~~6.1.1.2.cat'; file='\Device\HarddiskVolume2\Windows\System32\advapi32.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\advapi32.dll'
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\bcryptprimitives.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000104 pwszName=\Device\HarddiskVolume2\Windows\System32\bcrypt.dll
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=62E377A1F0AD0C2EDC0A73CB3EFF841FF18D00D2
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\bcrypt.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\bcrypt.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000e4 pwszName=\Device\HarddiskVolume2\Windows\System32\msvcrt.dll
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2CA2FD632B264C063162F71474266E3615B6420C
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB2654428~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\Windows\System32\msvcrt.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000dc pwszName=\Device\HarddiskVolume2\Windows\System32\msasn1.dll
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=F2FF57DC30D774F93061607060DAA0DD15E39CCE
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\msasn1.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\msasn1.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000000d8 pwszName=\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=03E871CFC4A3E7194619AFC99CEEA1EC75982D12
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB2978668~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll'
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume7\apps\virtualbox\VBoxSupLib.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000028 pwszName=\Device\HarddiskVolume2\Windows\System32\KernelBase.dll
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=57EB6F834C5A5D9585A660D91756134028A3B089
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_54_for_KB2871997~31bf3856ad364e35~amd64~~6.1.2.5.cat'; file='\Device\HarddiskVolume2\Windows\System32\KernelBase.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\KernelBase.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000020 pwszName=\Device\HarddiskVolume2\Windows\System32\kernel32.dll
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=5349346AE66DA4E3A7206628F484AC3B3AA43776
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_54_for_KB2871997~31bf3856ad364e35~amd64~~6.1.2.5.cat'; file='\Device\HarddiskVolume2\Windows\System32\kernel32.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume2\Windows\System32\kernel32.dll'
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\crypt32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000028bf310:C:\Windows\system32 [calling]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefda70000 'C:\Windows\system32\crypt32.dll'
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0x3d98ab22bb04a300 C=IE, O=Baltimore, OU=CyberTrust, CN=Baltimore CyberTrust Root
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0x5ad46780fa5df300 DC=com, DC=microsoft, CN=Microsoft Root Certificate Authority
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0xca2de669f55ba200 C=US, O=Symantec Corporation, CN=Symantec Root 2005 CA
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0xea5386456178582b C=ZA, ST=Western Cape, L=Durbanville, O=Thawte, OU=Thawte Certification, CN=Thawte Timestamping CA
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0x3be670c1bd02a900 OU=Copyright (c) 1997 Microsoft Corp., OU=Microsoft Corporation, CN=Microsoft Root Authority
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0x4d3835aa4180b200 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2011
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0x6864e162ceb5d900 CN=UniversalADB
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0x646e3fe3ba08df00 C=US, O=MSFT, CN=Microsoft Authenticode(tm) Root Authority
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0x3423e6c7a208b400 O=Symantec Corporation, CN=Symantec Root CA
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0xfa9d9f76947289ee CN=NGO
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0xd4fbe673e5ccc600 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0xa45b257adbbeb200 CN=127.0.0.1
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0xece4e4289e08b900 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0x722f7e828a308acb CN=libusb-win32 (WorldCup_Device.inf) [Self]
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0x43a9cc371ff5385a O=Microsoft Trust Network, OU=Microsoft Corporation, OU=Microsoft Time Stamping Service Root, OU=Copyright (c) 1997 Microsoft Corp.
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0x2e2d2c7c68f0202e O=VeriSign Trust Network, OU=VeriSign, Inc., OU=VeriSign Time Stamping Service Root, OU=NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0xa12b07674f1bf600 C=US, O=AffirmTrust, CN=AffirmTrust Commercial
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0xd8dbfb2c27bfb200 C=US, O=thawte, Inc., OU=Certification Services Division, OU=(c) 2008 thawte, Inc. - For authorized use only, CN=thawte Primary Root CA - G3
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0x91e3728b8b40d000 C=GB, ST=Greater Manchester, L=Salford, O=COMODO CA Limited, CN=COMODO Certification Authority
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0x61a3a33f81aace00 C=US, ST=UT, L=Salt Lake City, O=The USERTRUST Network, OU=http://www.usertrust.com, CN=UTN-USERFirst-Object
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0x6b7bdc34cd37bb00 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root G2
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0x57ba5395b561bf00 C=BM, O=QuoVadis Limited, OU=Root Certification Authority, CN=QuoVadis Root Certification Authority
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0xf4fd306318ccda00 C=US, O=GeoTrust Inc., CN=GeoTrust Global CA
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0x83085097e9afdf00 O=Digital Signature Trust Co., CN=DST Root CA X3
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0xe248b7eeee4af00 C=CH, O=SwissSign AG, CN=SwissSign Gold CA - G2
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0x780679907625cc00 OU=GlobalSign Root CA - R3, O=GlobalSign, CN=GlobalSign
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0x3d98ab22bb04a300 C=IE, O=Baltimore, OU=CyberTrust, CN=Baltimore CyberTrust Root
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0xa0ee62086758b15d C=US, O=Equifax, OU=Equifax Secure Certificate Authority
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0x9403a4b8727eb000 C=TW, O=TAIWAN-CA, OU=Root CA, CN=TWCA Root Certification Authority
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0xd944bca189a00 C=BM, O=QuoVadis Limited, CN=QuoVadis Root CA 2
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0x8ff6fc03c1edbd00 C=US, ST=Arizona, L=Scottsdale, O=Starfield Technologies, Inc., CN=Starfield Root Certificate Authority - G2
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0xc6fa4243b695b600 C=US, O=Entrust, Inc., OU=www.entrust.net/CPS is incorporated by reference, OU=(c) 2006 Entrust, Inc., CN=Entrust Root Certification Authority
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0xa3ce8d99e60eda00 C=BE, O=GlobalSign nv-sa, OU=Root CA, CN=GlobalSign Root CA
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0x560ad29254e89100 C=GB, ST=Greater Manchester, L=Salford, O=COMODO CA Limited, CN=COMODO RSA Certification Authority
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0xa671e9fec832b700 C=US, O=Starfield Technologies, Inc., OU=Starfield Class 2 Certification Authority
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0xa8de7211e13be200 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root CA
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0x7ae89c50f0b6a00f C=US, O=GTE Corporation, OU=GTE CyberTrust Solutions, Inc., CN=GTE CyberTrust Global Root
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0xd45980fbf0a0ac00 C=US, O=thawte, Inc., OU=Certification Services Division, OU=(c) 2006 thawte, Inc. - For authorized use only, CN=thawte Primary Root CA
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0x4d3835aa4180b200 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2011
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0xc9edb72b684ba00 C=US, O=Entrust, Inc., OU=See www.entrust.net/legal-terms, OU=(c) 2009 Entrust, Inc. - for authorized use only, CN=Entrust Root Certification Authority - G2
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0xf5cd95e581a4ab00 C=US, O=SecureTrust Corporation, CN=SecureTrust CA
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0x298be035a30bab00 C=DE, O=Deutsche Telekom AG, OU=T-TeleSec Trust Center, CN=Deutsche Telekom Root CA 2
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0xabd0695c5d11d15e C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority - G2, OU=(c) 1998 VeriSign, Inc. - For authorized use only, OU=VeriSign Trust Network
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0x802b3770cb00af00 C=EU, L=Madrid (see current address at www.camerfirma.com/address), SRN=A82743287, O=AC Camerfirma S.A., CN=Chambers of Commerce Root - 2008
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0x6f2ebe0e24cfa600 OU=GlobalSign Root CA - R2, O=GlobalSign, CN=GlobalSign
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0x14018a1bf29e595c C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0x35f812d09650dc00 C=FR, O=Certplus, CN=Class 2 Primary CA
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0x9e5bc2d78b6a3636 C=ZA, ST=Western Cape, L=Cape Town, O=Thawte Consulting cc, OU=Certification Services Division, CN=Thawte Premium Server CA, Email=premium-server@thawte.com
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0x7c4fd32ec1b1ce00 C=PL, O=Unizeto Sp. z o.o., CN=Certum CA
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0xd4fbe673e5ccc600 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0x16e64d2a56ccf200 C=US, ST=Arizona, L=Scottsdale, O=Starfield Technologies, Inc., OU=http://certificates.starfieldtech.com/repository/, CN=Starfield Services Root Certificate Authority
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0xb28612a94b4dad00 O=Entrust.net, OU=www.entrust.net/CPS_2048 incorp. by ref. (limits liab.), OU=(c) 1999 Entrust.net Limited, CN=Entrust.net Certification Authority (2048)
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0x357a29080824af00 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2006 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G5
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0x59faf1086271bf00 C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com, Inc., CN=Go Daddy Root Certificate Authority - G2
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0x466cbc09db88c100 C=IL, O=StartCom Ltd., OU=Secure Digital Certificate Signing, CN=StartCom Certification Authority
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0xece4e4289e08b900 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0x30669a4e82fa800 C=US, O=America Online Inc., CN=America Online Root Certification Authority 1
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0x3401b15e3761c700 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2008 VeriSign, Inc. - For authorized use only, CN=VeriSign Universal Root Certification Authority
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0x7cd4ff7b15b8be00 C=US, O=GeoTrust Inc., CN=GeoTrust Primary Certification Authority
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0x20b7075b3689b600 C=IL, O=StartCom Ltd., CN=StartCom Certification Authority G2
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0x491857ead79dde00 C=US, O=The Go Daddy Group, Inc., OU=Go Daddy Class 2 Certification Authority
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0xab549401526569d3 L=Internet, O=VeriSign, Inc., OU=VeriSign Commercial Software Publishers CA
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0x92ac5ed85c2d0e9b C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2007 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G4
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0x1f78fc529cbacb00 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 1999 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G3
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0xdc1801b225aea100 C=BM, O=QuoVadis Limited, CN=QuoVadis Root CA 2 G3
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0xc2ba72a37dfbe300 C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Trusted Network CA
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0x8043e4ce150ead00 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID Root CA
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0xa8b43f38c3f7b100 C=US, ST=UT, L=Salt Lake City, O=The USERTRUST Network, OU=http://www.usertrust.com, CN=UTN-USERFirst-Hardware
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0x331d58625ee2dc00 C=US, O=GeoTrust Inc., OU=(c) 2008 GeoTrust Inc. - For authorized use only, CN=GeoTrust Primary Certification Authority - G3
- 1db4.1c50: supR3HardenedWinIsDesiredRootCA: Adding 0xf2e6331af7b700 C=SE, O=AddTrust AB, OU=AddTrust External TTP Network, CN=AddTrust External CA Root
- 1db4.1c50: supR3HardenedWinRetrieveTrustedRootCAs: cAdded=70
- 1db4.1c50: SUPR3HardenedMain: Load Runtime...
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ws2_32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'rpcrt4.dll'.
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume7\apps\virtualbox\VBoxRT.dll) WinVerifyTrust
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume7\apps\virtualbox\VBoxRT.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000003f8 pwszName=\Device\HarddiskVolume2\Windows\System32\ws2_32.dll
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=3EF3BDC1E84DFA17EA056313214EE88EC3E66F79
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\ws2_32.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'rpcrt4.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'nsi.dll'.
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ws2_32.dll) WinVerifyTrust
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\msvcp100.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume7\apps\virtualbox\msvcp100.dll) WinVerifyTrust
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume7\apps\virtualbox\msvcp100.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume7\apps\virtualbox\msvcr100.dll) WinVerifyTrust
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume7\apps\virtualbox\msvcr100.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\msvcr100.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume2\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000440 pwszName=\Device\HarddiskVolume2\Windows\System32\nsi.dll
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=7AFD8538945F2D05BC1AF949B9B19B7D2D9FBBF8
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\nsi.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\nsi.dll) WinVerifyTrust
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\nsi.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=E:\apps\virtualbox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000781d20:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.1c50: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\VBoxRT.dll
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 000007fee6c60000 LB 0x00590000 E:\apps\virtualbox\VBoxRT.dll [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\VBoxRT.dll
- 1db4.1c50: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\msvcr100.dll
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 0000000066480000 LB 0x000d2000 E:\apps\virtualbox\MSVCR100.dll [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\msvcr100.dll
- 1db4.1c50: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\msvcp100.dll
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 00000000663e0000 LB 0x00098000 E:\apps\virtualbox\MSVCP100.dll [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\msvcp100.dll
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 000007fefe1c0000 LB 0x0004d000 C:\Windows\system32\WS2_32.dll [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 000007fefe460000 LB 0x00008000 C:\Windows\system32\NSI.dll [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\nsi.dll
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\VBoxRT.dll
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=E:\apps\virtualbox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000695c50:E:\apps\virtualbox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;E:\apps\Iridium Browser;C:\Program Files (x86)\Google\Chrome\Application;C:\Windows\system32;C:\Windows;C:\Windows\system32\wbem;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\Dell\DW WLAN Card;C:\Ruby-install\bin;C:\Windows\System32\WindowsPowerShell\v1.0;C:\Program Files (x86)\Common Files\Adobe\AGL;C:\Program Files\Microsoft SQL Server\110\Tools\Binn;C:\Program Files\WIDCOMM\Bluetooth Software;C:\Program Files\WIDCOMM\Bluetooth Software\syswow64;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit;E:\apps\CMake\bin;E:\apps\PDFtk\bin;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5\Doctrine extensions for PHP;C:\adb;E:\apps\Tesseract-OCR;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x64;E:\apps\NodeJS\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;E:\apps\python;E:\apps\Python\Scripts\;E:\apps\Python\;C:\Users\TouchOdeath\AppData\Roaming\npm [calling]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee6c60000 'E:\apps\virtualbox\VBoxRT.dll'
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\VBoxRT.dll
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=E:\apps\virtualbox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000695c50:E:\apps\virtualbox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;E:\apps\Iridium Browser;C:\Program Files (x86)\Google\Chrome\Application;C:\Windows\system32;C:\Windows;C:\Windows\system32\wbem;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\Dell\DW WLAN Card;C:\Ruby-install\bin;C:\Windows\System32\WindowsPowerShell\v1.0;C:\Program Files (x86)\Common Files\Adobe\AGL;C:\Program Files\Microsoft SQL Server\110\Tools\Binn;C:\Program Files\WIDCOMM\Bluetooth Software;C:\Program Files\WIDCOMM\Bluetooth Software\syswow64;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit;E:\apps\CMake\bin;E:\apps\PDFtk\bin;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5\Doctrine extensions for PHP;C:\adb;E:\apps\Tesseract-OCR;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x64;E:\apps\NodeJS\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;E:\apps\python;E:\apps\Python\Scripts\;E:\apps\Python\;C:\Users\TouchOdeath\AppData\Roaming\npm [calling]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee6c60000 'E:\apps\virtualbox\VBoxRT.dll'
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\VBoxRT.dll
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=E:\apps\virtualbox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000695c50:E:\apps\virtualbox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;E:\apps\Iridium Browser;C:\Program Files (x86)\Google\Chrome\Application;C:\Windows\system32;C:\Windows;C:\Windows\system32\wbem;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\Dell\DW WLAN Card;C:\Ruby-install\bin;C:\Windows\System32\WindowsPowerShell\v1.0;C:\Program Files (x86)\Common Files\Adobe\AGL;C:\Program Files\Microsoft SQL Server\110\Tools\Binn;C:\Program Files\WIDCOMM\Bluetooth Software;C:\Program Files\WIDCOMM\Bluetooth Software\syswow64;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit;E:\apps\CMake\bin;E:\apps\PDFtk\bin;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5\Doctrine extensions for PHP;C:\adb;E:\apps\Tesseract-OCR;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x64;E:\apps\NodeJS\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;E:\apps\python;E:\apps\Python\Scripts\;E:\apps\Python\;C:\Users\TouchOdeath\AppData\Roaming\npm [calling]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee6c60000 'E:\apps\virtualbox\VBoxRT.dll'
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\VBoxRT.dll
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=E:\apps\virtualbox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000695c50:E:\apps\virtualbox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;E:\apps\Iridium Browser;C:\Program Files (x86)\Google\Chrome\Application;C:\Windows\system32;C:\Windows;C:\Windows\system32\wbem;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\Dell\DW WLAN Card;C:\Ruby-install\bin;C:\Windows\System32\WindowsPowerShell\v1.0;C:\Program Files (x86)\Common Files\Adobe\AGL;C:\Program Files\Microsoft SQL Server\110\Tools\Binn;C:\Program Files\WIDCOMM\Bluetooth Software;C:\Program Files\WIDCOMM\Bluetooth Software\syswow64;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit;E:\apps\CMake\bin;E:\apps\PDFtk\bin;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5\Doctrine extensions for PHP;C:\adb;E:\apps\Tesseract-OCR;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x64;E:\apps\NodeJS\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;E:\apps\python;E:\apps\Python\Scripts\;E:\apps\Python\;C:\Users\TouchOdeath\AppData\Roaming\npm [calling]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee6c60000 'E:\apps\virtualbox\VBoxRT.dll'
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\VBoxRT.dll
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=E:\apps\virtualbox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000695c50:E:\apps\virtualbox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;E:\apps\Iridium Browser;C:\Program Files (x86)\Google\Chrome\Application;C:\Windows\system32;C:\Windows;C:\Windows\system32\wbem;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\Dell\DW WLAN Card;C:\Ruby-install\bin;C:\Windows\System32\WindowsPowerShell\v1.0;C:\Program Files (x86)\Common Files\Adobe\AGL;C:\Program Files\Microsoft SQL Server\110\Tools\Binn;C:\Program Files\WIDCOMM\Bluetooth Software;C:\Program Files\WIDCOMM\Bluetooth Software\syswow64;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit;E:\apps\CMake\bin;E:\apps\PDFtk\bin;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5\Doctrine extensions for PHP;C:\adb;E:\apps\Tesseract-OCR;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x64;E:\apps\NodeJS\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;E:\apps\python;E:\apps\Python\Scripts\;E:\apps\Python\;C:\Users\TouchOdeath\AppData\Roaming\npm [calling]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee6c60000 'E:\apps\virtualbox\VBoxRT.dll'
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\VBoxRT.dll
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=E:\apps\virtualbox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000695c50:E:\apps\virtualbox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;E:\apps\Iridium Browser;C:\Program Files (x86)\Google\Chrome\Application;C:\Windows\system32;C:\Windows;C:\Windows\system32\wbem;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\Dell\DW WLAN Card;C:\Ruby-install\bin;C:\Windows\System32\WindowsPowerShell\v1.0;C:\Program Files (x86)\Common Files\Adobe\AGL;C:\Program Files\Microsoft SQL Server\110\Tools\Binn;C:\Program Files\WIDCOMM\Bluetooth Software;C:\Program Files\WIDCOMM\Bluetooth Software\syswow64;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit;E:\apps\CMake\bin;E:\apps\PDFtk\bin;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5\Doctrine extensions for PHP;C:\adb;E:\apps\Tesseract-OCR;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x64;E:\apps\NodeJS\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;E:\apps\python;E:\apps\Python\Scripts\;E:\apps\Python\;C:\Users\TouchOdeath\AppData\Roaming\npm [calling]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee6c60000 'E:\apps\virtualbox\VBoxRT.dll'
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee6c60000 'E:\apps\virtualbox\VBoxRT.dll'
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee6c60000 'E:\apps\virtualbox\VBoxRT.dll'
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee6c60000 'E:\apps\virtualbox\VBoxRT.dll'
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee6c60000 'E:\apps\virtualbox\VBoxRT.dll'
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee6c60000 'E:\apps\virtualbox\VBoxRT.dll'
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee6c60000 'E:\apps\virtualbox\VBoxRT.dll'
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee6c60000 'E:\apps\virtualbox\VBoxRT.dll'
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\VBoxRT.dll
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=E:\apps\virtualbox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000695c50:E:\apps\virtualbox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;E:\apps\Iridium Browser;C:\Program Files (x86)\Google\Chrome\Application;C:\Windows\system32;C:\Windows;C:\Windows\system32\wbem;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\Dell\DW WLAN Card;C:\Ruby-install\bin;C:\Windows\System32\WindowsPowerShell\v1.0;C:\Program Files (x86)\Common Files\Adobe\AGL;C:\Program Files\Microsoft SQL Server\110\Tools\Binn;C:\Program Files\WIDCOMM\Bluetooth Software;C:\Program Files\WIDCOMM\Bluetooth Software\syswow64;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit;E:\apps\CMake\bin;E:\apps\PDFtk\bin;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5\Doctrine extensions for PHP;C:\adb;E:\apps\Tesseract-OCR;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x64;E:\apps\NodeJS\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;E:\apps\python;E:\apps\Python\Scripts\;E:\apps\Python\;C:\Users\TouchOdeath\AppData\Roaming\npm [calling]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee6c60000 'E:\apps\virtualbox\VBoxRT.dll'
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee6c60000 'E:\apps\virtualbox\VBoxRT.dll'
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee6c60000 'E:\apps\virtualbox\VBoxRT.dll'
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee6c60000 'E:\apps\virtualbox\VBoxRT.dll'
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee6c60000 'E:\apps\virtualbox\VBoxRT.dll'
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee6c60000 'E:\apps\virtualbox\VBoxRT.dll'
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee6c60000 'E:\apps\virtualbox\VBoxRT.dll'
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee6c60000 'E:\apps\virtualbox\VBoxRT.dll'
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee6c60000 'E:\apps\virtualbox\VBoxRT.dll'
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee6c60000 'E:\apps\virtualbox\VBoxRT.dll'
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee6c60000 'E:\apps\virtualbox\VBoxRT.dll'
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee6c60000 'E:\apps\virtualbox\VBoxRT.dll'
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee6c60000 'E:\apps\virtualbox\VBoxRT.dll'
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee6c60000 'E:\apps\virtualbox\VBoxRT.dll'
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee6c60000 'E:\apps\virtualbox\VBoxRT.dll'
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee6c60000 'E:\apps\virtualbox\VBoxRT.dll'
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\VBoxRT.dll
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=E:\apps\virtualbox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000695c50:E:\apps\virtualbox;C:\Windows\system32;C:\Windows\system;C:\Windows;.;E:\apps\Iridium Browser;C:\Program Files (x86)\Google\Chrome\Application;C:\Windows\system32;C:\Windows;C:\Windows\system32\wbem;C:\ProgramData\Oracle\Java\javapath;C:\Program Files\Dell\DW WLAN Card;C:\Ruby-install\bin;C:\Windows\System32\WindowsPowerShell\v1.0;C:\Program Files (x86)\Common Files\Adobe\AGL;C:\Program Files\Microsoft SQL Server\110\Tools\Binn;C:\Program Files\WIDCOMM\Bluetooth Software;C:\Program Files\WIDCOMM\Bluetooth Software\syswow64;C:\Program Files (x86)\Windows Kits\8.1\Windows Performance Toolkit;E:\apps\CMake\bin;E:\apps\PDFtk\bin;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5;E:\apps\MySQL\MySQL Fabric 1.5 ^& MySQL Utilities 1.5\Doctrine extensions for PHP;C:\adb;E:\apps\Tesseract-OCR;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x64;E:\apps\NodeJS\;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;E:\apps\python;E:\apps\Python\Scripts\;E:\apps\Python\;C:\Users\TouchOdeath\AppData\Roaming\npm [calling]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee6c60000 'E:\apps\virtualbox\VBoxRT.dll'
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee6c60000 'E:\apps\virtualbox\VBoxRT.dll'
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee6c60000 'E:\apps\virtualbox\VBoxRT.dll'
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee6c60000 'E:\apps\virtualbox\VBoxRT.dll'
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000028d9530:C:\Windows\system32 [calling]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd980000 'C:\Windows\system32\Wintrust.dll'
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\crypt32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000028d9530:C:\Windows\system32 [calling]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefda70000 'C:\Windows\system32\crypt32.dll'
- 1db4.1c50: SUPR3HardenedMain: Load TrustedMain...
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'opengl32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msvcp100.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcr100.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qt5corevbox.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'qt5guivbox.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'qt5widgetsvbox.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'qt5printsupportvbox.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'qt5openglvbox.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'user32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'advapi32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'shell32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'ole32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'oleaut32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #15 'winmm.dll'.
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume7\apps\virtualbox\VirtualBox.dll) WinVerifyTrust
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume7\apps\virtualbox\VirtualBox.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000480 pwszName=\Device\HarddiskVolume2\Windows\System32\winmm.dll
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=82E2B2A7826F88BEB98FFF0540C9BDB0A12F001A
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\winmm.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\winmm.dll) WinVerifyTrust
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\winmm.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000460 pwszName=\Device\HarddiskVolume2\Windows\System32\oleaut32.dll
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=C1D7CC9111C6B5A59641FA11BE0A6A1841FEBBCD
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB2564958~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\oleaut32.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ole32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'user32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'gdi32.dll'.
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\oleaut32.dll) WinVerifyTrust
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000048c pwszName=\Device\HarddiskVolume2\Windows\System32\ole32.dll
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2E64AE329BD5124592BC8CB0B327AA3B95DC65B7
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\ole32.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'gdi32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'user32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'rpcrt4.dll'.
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ole32.dll) WinVerifyTrust
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ole32.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000498 pwszName=\Device\HarddiskVolume2\Windows\System32\shell32.dll
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=8D11B9B481EE916E64C94F8ECA71C2995A2999B7
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_2_for_KB2980245~31bf3856ad364e35~amd64~~6.1.1.0.cat'; file='\Device\HarddiskVolume2\Windows\System32\shell32.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #21 'shlwapi.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'user32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #24 'gdi32.dll'.
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\shell32.dll) WinVerifyTrust
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\shell32.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5openglvbox.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5openglvbox.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\qt5openglvbox.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'qt5widgetsvbox.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'qt5guivbox.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5corevbox.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcr100.dll'.
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume7\apps\virtualbox\Qt5OpenGLVBox.dll) WinVerifyTrust
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume7\apps\virtualbox\Qt5OpenGLVBox.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5printsupportvbox.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5printsupportvbox.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\qt5printsupportvbox.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5widgetsvbox.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qt5guivbox.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qt5corevbox.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'winspool.drv'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'comdlg32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'msvcr100.dll'.
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume7\apps\virtualbox\Qt5PrintSupportVBox.dll) WinVerifyTrust
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume7\apps\virtualbox\Qt5PrintSupportVBox.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5guivbox.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qt5corevbox.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'shell32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcp100.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msvcr100.dll'.
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume7\apps\virtualbox\Qt5WidgetsVBox.dll) WinVerifyTrust
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume7\apps\virtualbox\Qt5WidgetsVBox.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ole32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'opengl32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qt5corevbox.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcp100.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msvcr100.dll'.
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume7\apps\virtualbox\Qt5GuiVBox.dll) WinVerifyTrust
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume7\apps\virtualbox\Qt5GuiVBox.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'shell32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ole32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ws2_32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'mpr.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'msvcp100.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'msvcr100.dll'.
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume7\apps\virtualbox\Qt5CoreVBox.dll) WinVerifyTrust
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume7\apps\virtualbox\Qt5CoreVBox.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\msvcr100.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\msvcp100.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\msvcp100.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\vboxrt.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004b8 pwszName=\Device\HarddiskVolume2\Windows\System32\opengl32.dll
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=608AC397FCC42B9FBAE25CB8C25EAF4C19AA384D
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\opengl32.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'gdi32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'glu32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'ddraw.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'user32.dll'.
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\opengl32.dll) WinVerifyTrust
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\opengl32.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ddraw.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'ddraw.dll' -> '\Device\HarddiskVolume2\Windows\System32\ddraw.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004ac pwszName=\Device\HarddiskVolume2\Windows\System32\ddraw.dll
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=24C763EA54CD792A0F1618411061DC356EE31FF6
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\ddraw.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'dciman32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'setupapi.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'dwmapi.dll'.
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ddraw.dll) WinVerifyTrust
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ddraw.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'glu32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'glu32.dll' -> '\Device\HarddiskVolume2\Windows\System32\glu32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004b4 pwszName=\Device\HarddiskVolume2\Windows\System32\glu32.dll
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=60E45AB914E06A11F44EA76C6EF750AF892F9EA2
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\glu32.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'opengl32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\glu32.dll) WinVerifyTrust
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\glu32.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\msvcr100.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\msvcp100.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\msvcp100.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mpr.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'mpr.dll' -> '\Device\HarddiskVolume2\Windows\System32\mpr.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004c8 pwszName=\Device\HarddiskVolume2\Windows\System32\mpr.dll
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=F84FE9BA047B24E7694C9E0C349B48B9FD5F925B
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\mpr.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\mpr.dll) WinVerifyTrust
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\mpr.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\msvcr100.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\msvcp100.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\msvcp100.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\Qt5CoreVBox.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\msvcr100.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\msvcp100.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\msvcp100.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\Qt5CoreVBox.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\Qt5GuiVBox.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\msvcr100.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comdlg32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'comdlg32.dll' -> '\Device\HarddiskVolume2\Windows\System32\comdlg32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004d4 pwszName=\Device\HarddiskVolume2\Windows\System32\comdlg32.dll
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=66EE5BDFFA413AEA9E1FE7838A08646E94136DA5
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\comdlg32.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'shlwapi.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'gdi32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'comctl32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'shell32.dll'.
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\comdlg32.dll) WinVerifyTrust
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\comdlg32.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winspool.drv'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'winspool.drv' -> '\Device\HarddiskVolume2\Windows\System32\winspool.drv' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004d8 pwszName=\Device\HarddiskVolume2\Windows\System32\winspool.drv
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=C89A2ED7B99A056D78CA6BAC9CCAB8B1FF119A14
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\winspool.drv'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\winspool.drv) WinVerifyTrust
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\winspool.drv
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\Qt5CoreVBox.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\Qt5GuiVBox.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\Qt5WidgetsVBox.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\Qt5CoreVBox.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\Qt5GuiVBox.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\Qt5WidgetsVBox.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comctl32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'comctl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\comctl32.dll' [rcNtRedir=0x0]
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004cc pwszName=\Device\HarddiskVolume2\Windows\System32\comctl32.dll
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=5A2FB6B10717AFC03CD9FE6E8F1337A8EA94BF9B
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB2864058~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\comctl32.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'advapi32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\comctl32.dll) WinVerifyTrust
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\comctl32.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\gdi32.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume2\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dwmapi.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'dwmapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\dwmapi.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004e0 pwszName=\Device\HarddiskVolume2\Windows\System32\dwmapi.dll
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B79EE7B5AD74EF51A849809202E043183A2C727E
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\dwmapi.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\dwmapi.dll) WinVerifyTrust
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\dwmapi.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004e8 pwszName=\Device\HarddiskVolume2\Windows\System32\setupapi.dll
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=1499C4FEA6E143F9BEC35B4FFA098917D3A6EBF2
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\setupapi.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'cfgmgr32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msvcrt.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'gdi32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'user32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'oleaut32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'devobj.dll'.
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\setupapi.dll) WinVerifyTrust
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\setupapi.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dciman32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'dciman32.dll' -> '\Device\HarddiskVolume2\Windows\System32\dciman32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000484 pwszName=\Device\HarddiskVolume2\Windows\System32\dciman32.dll
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=F097BF0B081F54722F0A01EF1CC13AECA64B12F0
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB2847311~31bf3856ad364e35~amd64~~6.1.1.2.cat'; file='\Device\HarddiskVolume2\Windows\System32\dciman32.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'gdi32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\dciman32.dll) WinVerifyTrust
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\dciman32.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'devobj.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'devobj.dll' -> '\Device\HarddiskVolume2\Windows\System32\devobj.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004f4 pwszName=\Device\HarddiskVolume2\Windows\System32\devobj.dll
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B410A095222E69F0ECE7D66E4AC27A7125D2EB5A
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\devobj.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'cfgmgr32.dll'.
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\devobj.dll) WinVerifyTrust
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\devobj.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004fc pwszName=\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=8F731777EFC4BC982C1E1467FBF29A74CC14D93A
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'rpcrt4.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll) WinVerifyTrust
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=E:\apps\virtualbox\VirtualBox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000781d20:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.1c50: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\VirtualBox.dll
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 000007fed6410000 LB 0x00a06000 E:\apps\virtualbox\VirtualBox.dll [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\VirtualBox.dll
- 1db4.1c50: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 000007fee74f0000 LB 0x0011d000 C:\Windows\system32\OPENGL32.dll [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\opengl32.dll
- 1db4.1c50: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\glu32.dll
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 000007fee7b70000 LB 0x0002d000 C:\Windows\system32\GLU32.dll [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\glu32.dll
- 1db4.1c50: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ddraw.dll
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 000007fee73f0000 LB 0x000f1000 C:\Windows\system32\DDRAW.dll [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ddraw.dll
- 1db4.1c50: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dciman32.dll
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 000007feed660000 LB 0x00008000 C:\Windows\system32\DCIMAN32.dll [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dciman32.dll
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 000007feff590000 LB 0x001d7000 C:\Windows\system32\SETUPAPI.dll [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\setupapi.dll
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 000007fefd8e0000 LB 0x00036000 C:\Windows\system32\CFGMGR32.dll [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 000007fefdc80000 LB 0x000d7000 C:\Windows\system32\OLEAUT32.dll [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 000007feff2b0000 LB 0x00203000 C:\Windows\system32\ole32.dll [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 000007fefd9c0000 LB 0x0001a000 C:\Windows\system32\DEVOBJ.dll [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\devobj.dll
- 1db4.1c50: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dwmapi.dll
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 000007fefbc10000 LB 0x00018000 C:\Windows\system32\dwmapi.dll [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dwmapi.dll
- 1db4.1c50: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\Qt5CoreVBox.dll
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 0000000065ce0000 LB 0x00565000 E:\apps\virtualbox\Qt5CoreVBox.dll [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\Qt5CoreVBox.dll
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 000007fefe480000 LB 0x00d88000 C:\Windows\system32\SHELL32.dll [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
- 1db4.1c50: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\mpr.dll
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 000007fefc7c0000 LB 0x00018000 C:\Windows\system32\MPR.dll [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\mpr.dll
- 1db4.1c50: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\Qt5GuiVBox.dll
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 000007fee6660000 LB 0x005f7000 E:\apps\virtualbox\Qt5GuiVBox.dll [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\Qt5GuiVBox.dll
- 1db4.1c50: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\Qt5WidgetsVBox.dll
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 0000000055a20000 LB 0x00561000 E:\apps\virtualbox\Qt5WidgetsVBox.dll [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\Qt5WidgetsVBox.dll
- 1db4.1c50: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\Qt5PrintSupportVBox.dll
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 000007fee7860000 LB 0x00051000 E:\apps\virtualbox\Qt5PrintSupportVBox.dll [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\Qt5PrintSupportVBox.dll
- 1db4.1c50: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winspool.drv
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 000007fefb950000 LB 0x00071000 C:\Windows\system32\WINSPOOL.DRV [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winspool.drv
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 000007fefdf50000 LB 0x00097000 C:\Windows\system32\COMDLG32.dll [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\comdlg32.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'advapi32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18201_none_a4d3b9377117c3df\comctl32.dll)
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18201_none_a4d3b9377117c3df\comctl32.dll
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 000007fee63d0000 LB 0x000a0000 C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18201_none_a4d3b9377117c3df\COMCTL32.dll [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18201_none_a4d3b9377117c3df\comctl32.dll [avoiding WinVerifyTrust]
- 1db4.1c50: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\Qt5OpenGLVBox.dll
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 0000000066380000 LB 0x00054000 E:\apps\virtualbox\Qt5OpenGLVBox.dll [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\Qt5OpenGLVBox.dll
- 1db4.1c50: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 000007fef75c0000 LB 0x0003b000 C:\Windows\system32\WINMM.dll [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
- 1db4.1c50: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume2\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18201_none_a4d3b9377117c3df\comctl32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume2\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18201_none_a4d3b9377117c3df\comctl32.dll' [rescheduled]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\imm32.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\imm32.dll (Input=imm32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000006f5250:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff770000 'C:\Windows\system32\imm32.dll'
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefde70000 'C:\Windows\system32\ADVAPI32.DLL'
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cryptbase.dll
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\cryptbase.dll (Input=cryptbase.dll, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd6c0000 'C:\Windows\system32\cryptbase.dll'
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fed6410000 'E:\apps\virtualbox\VirtualBox.dll'
- 1db4.1c50: SUPR3HardenedMain: Calling TrustedMain (000007fed64114f0)...
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ole32.dll (Input=ole32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000781d20:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff2b0000 'C:\Windows\system32\ole32.dll'
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefde70000 'C:\Windows\system32\ADVAPI32.dll'
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\profapi.dll
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\profapi.dll (Input=profapi.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000781d20:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd8c0000 'C:\Windows\system32\profapi.dll'
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'ole32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'imm32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'winmm.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'oleaut32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'shell32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'advapi32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'qt5guivbox.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'qt5corevbox.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'msvcr100.dll'.
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume7\apps\virtualbox\platforms\qwindows.dll) WinVerifyTrust
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume7\apps\virtualbox\platforms\qwindows.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\Qt5CoreVBox.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\Qt5GuiVBox.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume2\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume2\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\imm32.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=E:\apps\virtualbox\platforms\qwindows.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000781d20:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.1c50: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\platforms\qwindows.dll
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 000007fee6530000 LB 0x0012e000 E:\apps\virtualbox\platforms\qwindows.dll [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\platforms\qwindows.dll
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee6530000 'E:\apps\virtualbox\platforms\qwindows.dll'
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cryptbase.dll
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTBASE.dll (Input=CRYPTBASE.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000781d20:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd6c0000 'C:\Windows\system32\CRYPTBASE.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000058c pwszName=\Device\HarddiskVolume2\Windows\System32\uxtheme.dll
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=936D45CC7026757A151F62882B557DD75D5FCB21
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\uxtheme.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'gdi32.dll'.
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\uxtheme.dll) WinVerifyTrust
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000737d00:C:\Windows\system32;E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.1c50: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 000007fefbfc0000 LB 0x00056000 C:\Windows\system32\uxtheme.dll [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbfc0000 'C:\Windows\system32\uxtheme.dll'
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000737d00:C:\Windows\system32;E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbfc0000 'C:\Windows\system32\uxtheme.dll'
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000737d00:C:\Windows\system32;E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbfc0000 'C:\Windows\system32\uxtheme.dll'
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000737d00:C:\Windows\system32;E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbfc0000 'C:\Windows\system32\uxtheme.dll'
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077890000 'C:\Windows\system32\user32.dll'
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000006f53a0:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe480000 'C:\Windows\system32\shell32.dll'
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: error opening 'C:\Windows\system32\wintab32.dll': 0 (NtPath=\??\C:\Windows\system32\wintab32.dll; Input=C:\Windows\system32\wintab32.dll; rcNtGetDll=0x0
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000034 'C:\Windows\system32\wintab32.dll'
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\winmm.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000006f53a0:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\winmm.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000006f53a0:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000006f53a0:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe480000 'C:\Windows\system32\shell32.dll'
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\uxtheme.dll
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000006f53a0:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbfc0000 'C:\Windows\system32\uxtheme.dll'
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefde70000 'C:\Windows\system32\advapi32.dll'
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\userenv.dll
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\userenv.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000006f53a0:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefda50000 'C:\Windows\system32\userenv.dll'
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (Input=kernel32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000006f53a0:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077990000 'C:\Windows\system32\kernel32.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000594 pwszName=\Device\HarddiskVolume2\Windows\System32\clbcatq.dll
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B01469787CE9D8C6FEE98FB207652B88B8494526
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\clbcatq.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'ole32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'oleaut32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'rpcrt4.dll'.
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\clbcatq.dll) WinVerifyTrust
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\clbcatq.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\advapi32.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msvcrt.dll
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CLBCatQ.DLL (Input=CLBCatQ.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000006f53a0:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.1c50: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\clbcatq.dll
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 000007fefdff0000 LB 0x00099000 C:\Windows\system32\CLBCatQ.DLL [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\clbcatq.dll
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdff0000 'C:\Windows\system32\CLBCatQ.DLL'
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefde70000 'C:\Windows\system32\ADVAPI32.dll'
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cryptsp.dll
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPTSP.dll (Input=CRYPTSP.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000006f5640:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd0c0000 'C:\Windows\system32\CRYPTSP.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000005dc pwszName=\Device\HarddiskVolume2\Windows\System32\RpcRtRemote.dll
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=DFC4A7C7E103D324218E6EF5D219B953746D6EC1
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\RpcRtRemote.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'rpcrt4.dll'.
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\RpcRtRemote.dll) WinVerifyTrust
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\RpcRtRemote.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\RpcRtRemote.dll (Input=RpcRtRemote.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000006f56b0:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.1c50: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\RpcRtRemote.dll
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 000007fefd810000 LB 0x00014000 C:\Windows\system32\RpcRtRemote.dll [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\RpcRtRemote.dll
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd810000 'C:\Windows\system32\RpcRtRemote.dll'
- 1db4.fec: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
- 1db4.fec: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
- 1db4.fec: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
- 1db4.fec: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
- 1db4.fec: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ole32.dll'.
- 1db4.fec: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'oleaut32.dll'.
- 1db4.fec: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume7\apps\virtualbox\VBoxC.dll) WinVerifyTrust
- 1db4.fec: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume7\apps\virtualbox\VBoxC.dll
- 1db4.fec: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
- 1db4.fec: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
- 1db4.fec: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
- 1db4.fec: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
- 1db4.fec: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
- 1db4.fec: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
- 1db4.fec: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
- 1db4.fec: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
- 1db4.fec: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
- 1db4.fec: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\vboxrt.dll' [rcNtRedir=0xc0150008]
- 1db4.fec: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
- 1db4.fec: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\msvcp100.dll' [rcNtRedir=0xc0150008]
- 1db4.fec: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\msvcp100.dll
- 1db4.fec: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
- 1db4.fec: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
- 1db4.fec: supR3HardenedMonitor_LdrLoadDll: pName=E:\apps\virtualbox\VBoxC.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000738720:E:\apps\virtualbox;E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.fec: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\VBoxC.dll
- 1db4.fec: supR3HardenedDllNotificationCallback: load 000007fedc0c0000 LB 0x00545000 E:\apps\virtualbox\VBoxC.dll [fFlags=0x0]
- 1db4.fec: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\VBoxC.dll
- 1db4.fec: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fedc0c0000 'E:\apps\virtualbox\VBoxC.dll'
- 1db4.fec: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
- 1db4.fec: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
- 1db4.fec: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
- 1db4.fec: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'shlwapi.dll'.
- 1db4.fec: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ole32.dll'.
- 1db4.fec: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'oleaut32.dll'.
- 1db4.fec: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
- 1db4.fec: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume7\apps\virtualbox\VBoxProxyStub.dll) WinVerifyTrust
- 1db4.fec: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume7\apps\virtualbox\VBoxProxyStub.dll
- 1db4.fec: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 1db4.fec: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 1db4.fec: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
- 1db4.fec: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
- 1db4.fec: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
- 1db4.fec: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
- 1db4.fec: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
- 1db4.fec: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
- 1db4.fec: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
- 1db4.fec: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll
- 1db4.fec: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
- 1db4.fec: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
- 1db4.fec: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
- 1db4.fec: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\vboxrt.dll' [rcNtRedir=0xc0150008]
- 1db4.fec: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
- 1db4.fec: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
- 1db4.fec: supR3HardenedMonitor_LdrLoadDll: pName=E:\apps\virtualbox\VBoxProxyStub.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007388d0:E:\apps\virtualbox;E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.fec: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\VBoxProxyStub.dll
- 1db4.fec: supR3HardenedDllNotificationCallback: load 000007fee6470000 LB 0x000ba000 E:\apps\virtualbox\VBoxProxyStub.dll [fFlags=0x0]
- 1db4.fec: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\VBoxProxyStub.dll
- 1db4.fec: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee6470000 'E:\apps\virtualbox\VBoxProxyStub.dll'
- 1db4.fec: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
- 1db4.fec: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\oleaut32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=00000000007388d0:C:\Windows\system32;E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.fec: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdc80000 'C:\Windows\system32\oleaut32.dll'
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefde70000 'C:\Windows\system32\ADVAPI32.dll'
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe130000 'C:\Windows\system32\gdi32.dll'
- 1db4.7ec: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
- 1db4.7ec: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
- 1db4.7ec: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume7\apps\virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMainVM.dll) WinVerifyTrust
- 1db4.7ec: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume7\apps\virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMainVM.dll
- 1db4.7ec: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
- 1db4.7ec: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\vboxrt.dll' [rcNtRedir=0xc0150008]
- 1db4.7ec: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
- 1db4.7ec: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
- 1db4.7ec: supR3HardenedMonitor_LdrLoadDll: pName=E:\apps\virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMainVM.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000002f9f340:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.7ec: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMainVM.dll
- 1db4.7ec: supR3HardenedDllNotificationCallback: load 000007fefc030000 LB 0x0000e000 E:\apps\virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMainVM.DLL [fFlags=0x0]
- 1db4.7ec: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMainVM.dll
- 1db4.7ec: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc030000 'E:\apps\virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxPuelMainVM.DLL'
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shell32.dll
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003001d70:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe480000 'C:\Windows\system32\shell32.dll'
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dwmapi.dll
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\dwmapi.dll (Input=dwmapi.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8e590:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefbc10000 'C:\Windows\system32\dwmapi.dll'
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefde70000 'C:\Windows\system32\ADVAPI32.dll'
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff2b0000 'C:\Windows\system32\ole32.dll'
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff2b0000 'C:\Windows\system32\ole32.dll'
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\OLEAUT32.dll (Input=OLEAUT32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8e830:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdc80000 'C:\Windows\system32\OLEAUT32.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000097c pwszName=\Device\HarddiskVolume2\Windows\System32\wbem\wbemprox.dll
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=41D7AA7A9ECA84ABF6801478BA3134174B21C472
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\wbem\wbemprox.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'wbemcomn.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'oleaut32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'ole32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'ws2_32.dll'.
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\wbem\wbemprox.dll) WinVerifyTrust
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wbem\wbemprox.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wbemcomn.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'wbemcomn.dll' -> '\Device\HarddiskVolume2\Windows\System32\wbemcomn.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000980 pwszName=\Device\HarddiskVolume2\Windows\System32\wbemcomn.dll
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=03D0A77E5195AA70198FDE6C2FAC2C76FF200674
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\wbemcomn.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'oleaut32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'ole32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'ws2_32.dll'.
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\wbemcomn.dll) WinVerifyTrust
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wbemcomn.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\user32.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wbem\wbemprox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000002930f40:C:\Windows\system32\wbem;E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.1c50: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbem\wbemprox.dll
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 000007fef6b40000 LB 0x0000f000 C:\Windows\system32\wbem\wbemprox.dll [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbem\wbemprox.dll
- 1db4.1c50: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbemcomn.dll
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 000007fef6dc0000 LB 0x00086000 C:\Windows\system32\wbemcomn.dll [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbemcomn.dll
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef6b40000 'C:\Windows\system32\wbem\wbemprox.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000009a8 pwszName=\Device\HarddiskVolume2\Windows\System32\wbem\wbemsvc.dll
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=83AB88529BF28CFF670EA617E0B9C376CFE28B0F
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\wbem\wbemsvc.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'rpcrt4.dll'.
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\wbem\wbemsvc.dll) WinVerifyTrust
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wbem\wbemsvc.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\rpcrt4.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wbem\wbemsvc.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000002931080:C:\Windows\system32\wbem;E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.1c50: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbem\wbemsvc.dll
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 000007feed4a0000 LB 0x00014000 C:\Windows\system32\wbem\wbemsvc.dll [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbem\wbemsvc.dll
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed4a0000 'C:\Windows\system32\wbem\wbemsvc.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000009ac pwszName=\Device\HarddiskVolume2\Windows\System32\wbem\fastprox.dll
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=391AD7580DBA8EA6A4190F5A010E834B8C320D79
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\wbem\fastprox.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'wbemcomn.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'advapi32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'oleaut32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ole32.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ntdsapi.dll'.
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\wbem\fastprox.dll) WinVerifyTrust
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wbem\fastprox.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ntdsapi.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'ntdsapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\ntdsapi.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000098c pwszName=\Device\HarddiskVolume2\Windows\System32\ntdsapi.dll
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=67C74E045820FCAB3FC8AD5C180928A20C1F11CE
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\ntdsapi.dll'
- 1db4.1c50: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'rpcrt4.dll'.
- 1db4.1c50: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'ws2_32.dll'.
- 1db4.1c50: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ntdsapi.dll) WinVerifyTrust
- 1db4.1c50: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ntdsapi.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wbemcomn.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'wbemcomn.dll' -> '\Device\HarddiskVolume2\Windows\System32\wbemcomn.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbemcomn.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 1db4.1c50: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wbem\fastprox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000002931080:C:\Windows\system32\wbem;E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.1c50: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbem\fastprox.dll
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 000007fef6b50000 LB 0x000e2000 C:\Windows\system32\wbem\fastprox.dll [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wbem\fastprox.dll
- 1db4.1c50: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ntdsapi.dll
- 1db4.1c50: supR3HardenedDllNotificationCallback: load 000007fef6d50000 LB 0x00027000 C:\Windows\system32\NTDSAPI.dll [fFlags=0x0]
- 1db4.1c50: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ntdsapi.dll
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef6b50000 'C:\Windows\system32\wbem\fastprox.dll'
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdc80000 'C:\Windows\system32\OLEAUT32.dll'
- 1db4.18d0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
- 1db4.18d0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrem.dll'.
- 1db4.18d0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
- 1db4.18d0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume7\apps\virtualbox\VBoxVMM.dll) WinVerifyTrust
- 1db4.18d0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume7\apps\virtualbox\VBoxVMM.dll
- 1db4.18d0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
- 1db4.18d0: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\vboxrt.dll' [rcNtRedir=0xc0150008]
- 1db4.18d0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrem.dll'...
- 1db4.18d0: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrem.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\vboxrem.dll' [rcNtRedir=0xc0150008]
- 1db4.18d0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'vboxrt.dll'.
- 1db4.18d0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
- 1db4.18d0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcrt.dll'.
- 1db4.18d0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume7\apps\virtualbox\VBoxREM.dll) WinVerifyTrust
- 1db4.18d0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume7\apps\virtualbox\VBoxREM.dll
- 1db4.18d0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
- 1db4.18d0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
- 1db4.18d0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 1db4.18d0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 1db4.18d0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
- 1db4.18d0: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\vboxvmm.dll' [rcNtRedir=0xc0150008]
- 1db4.18d0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\VBoxVMM.dll
- 1db4.18d0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
- 1db4.18d0: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\vboxrt.dll' [rcNtRedir=0xc0150008]
- 1db4.18d0: supR3HardenedMonitor_LdrLoadDll: pName=E:\apps\virtualbox\VBoxVMM.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8ea60:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.18d0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\VBoxVMM.dll
- 1db4.18d0: supR3HardenedDllNotificationCallback: load 000007fedab50000 LB 0x002c9000 E:\apps\virtualbox\VBoxVMM.DLL [fFlags=0x0]
- 1db4.18d0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\VBoxVMM.dll
- 1db4.18d0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\VBoxREM.dll
- 1db4.18d0: supR3HardenedDllNotificationCallback: load 0000000057430000 LB 0x0010b000 E:\apps\virtualbox\VBoxREM.dll [fFlags=0x0]
- 1db4.18d0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\VBoxREM.dll
- 1db4.18d0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fedab50000 'E:\apps\virtualbox\VBoxVMM.DLL'
- 1db4.1e00: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
- 1db4.1e00: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
- 1db4.1e00: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
- 1db4.1e00: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
- 1db4.1e00: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume7\apps\virtualbox\VBoxSharedClipboard.dll) WinVerifyTrust
- 1db4.1e00: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume7\apps\virtualbox\VBoxSharedClipboard.dll
- 1db4.1e00: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 1db4.1e00: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 1db4.1e00: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
- 1db4.1e00: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\vboxrt.dll' [rcNtRedir=0xc0150008]
- 1db4.1e00: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
- 1db4.1e00: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\vboxvmm.dll' [rcNtRedir=0xc0150008]
- 1db4.1e00: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\VBoxVMM.dll
- 1db4.1e00: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
- 1db4.1e00: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
- 1db4.1e00: supR3HardenedMonitor_LdrLoadDll: pName=E:\apps\virtualbox\VBoxSharedClipboard.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8fbe0:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.1e00: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\VBoxSharedClipboard.dll
- 1db4.1e00: supR3HardenedDllNotificationCallback: load 000007feed910000 LB 0x0000b000 E:\apps\virtualbox\VBoxSharedClipboard.DLL [fFlags=0x0]
- 1db4.1e00: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\VBoxSharedClipboard.dll
- 1db4.1e00: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed910000 'E:\apps\virtualbox\VBoxSharedClipboard.DLL'
- 1db4.1e00: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077890000 'C:\Windows\system32\User32.dll'
- 1db4.12cc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
- 1db4.12cc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
- 1db4.12cc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
- 1db4.12cc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume7\apps\virtualbox\VBoxDragAndDropSvc.dll) WinVerifyTrust
- 1db4.12cc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume7\apps\virtualbox\VBoxDragAndDropSvc.dll
- 1db4.12cc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
- 1db4.12cc: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\vboxrt.dll' [rcNtRedir=0xc0150008]
- 1db4.12cc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
- 1db4.12cc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\msvcp100.dll' [rcNtRedir=0xc0150008]
- 1db4.12cc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\msvcp100.dll
- 1db4.12cc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
- 1db4.12cc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
- 1db4.12cc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\msvcr100.dll
- 1db4.12cc: supR3HardenedMonitor_LdrLoadDll: pName=E:\apps\virtualbox\VBoxDragAndDropSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8fbe0:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.12cc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\VBoxDragAndDropSvc.dll
- 1db4.12cc: supR3HardenedDllNotificationCallback: load 000007feed900000 LB 0x0000d000 E:\apps\virtualbox\VBoxDragAndDropSvc.DLL [fFlags=0x0]
- 1db4.12cc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\VBoxDragAndDropSvc.dll
- 1db4.12cc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed900000 'E:\apps\virtualbox\VBoxDragAndDropSvc.DLL'
- 1db4.560: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
- 1db4.560: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
- 1db4.560: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
- 1db4.560: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume7\apps\virtualbox\VBoxGuestPropSvc.dll) WinVerifyTrust
- 1db4.560: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume7\apps\virtualbox\VBoxGuestPropSvc.dll
- 1db4.560: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
- 1db4.560: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\vboxrt.dll' [rcNtRedir=0xc0150008]
- 1db4.560: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
- 1db4.560: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\msvcp100.dll' [rcNtRedir=0xc0150008]
- 1db4.560: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
- 1db4.560: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
- 1db4.560: supR3HardenedMonitor_LdrLoadDll: pName=E:\apps\virtualbox\VBoxGuestPropSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8fbe0:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.560: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\VBoxGuestPropSvc.dll
- 1db4.560: supR3HardenedDllNotificationCallback: load 000007feed8f0000 LB 0x0000c000 E:\apps\virtualbox\VBoxGuestPropSvc.DLL [fFlags=0x0]
- 1db4.560: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\VBoxGuestPropSvc.dll
- 1db4.560: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed8f0000 'E:\apps\virtualbox\VBoxGuestPropSvc.DLL'
- 1db4.1954: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
- 1db4.1954: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
- 1db4.1954: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
- 1db4.1954: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume7\apps\virtualbox\VBoxGuestControlSvc.dll) WinVerifyTrust
- 1db4.1954: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume7\apps\virtualbox\VBoxGuestControlSvc.dll
- 1db4.1954: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
- 1db4.1954: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\vboxrt.dll' [rcNtRedir=0xc0150008]
- 1db4.1954: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
- 1db4.1954: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\msvcp100.dll' [rcNtRedir=0xc0150008]
- 1db4.1954: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
- 1db4.1954: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
- 1db4.1954: supR3HardenedMonitor_LdrLoadDll: pName=E:\apps\virtualbox\VBoxGuestControlSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8fd30:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.1954: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\VBoxGuestControlSvc.dll
- 1db4.1954: supR3HardenedDllNotificationCallback: load 000007feed8e0000 LB 0x0000b000 E:\apps\virtualbox\VBoxGuestControlSvc.DLL [fFlags=0x0]
- 1db4.1954: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\VBoxGuestControlSvc.dll
- 1db4.1954: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed8e0000 'E:\apps\virtualbox\VBoxGuestControlSvc.DLL'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe480000 'C:\Windows\system32\Shell32.dll'
- 1db4.e4c: supR3HardenedIsApiSetDll: '<NULL>' -> true
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Security-SDDL-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000003d8fd30:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe110000 'API-MS-Win-Security-SDDL-L1-1-0.dll'
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\VBoxVMM.dll
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: pName=E:\apps\virtualbox\VBoxVMM.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8f080:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fedab50000 'E:\apps\virtualbox\VBoxVMM.DLL'
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ole32.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'oleaut32.dll'.
- 1db4.e4c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume7\apps\virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll) WinVerifyTrust
- 1db4.e4c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume7\apps\virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\vboxrt.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: pName=E:\apps\virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8f080:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.e4c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
- 1db4.e4c: supR3HardenedDllNotificationCallback: load 000007feeb310000 LB 0x00041000 E:\apps\virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL [fFlags=0x0]
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeb310000 'E:\apps\virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL'
- 1db4.e4c: supR3HardenedDllNotificationCallback: Unload 000007feeb310000 LB 0x00041000 E:\apps\virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL [flags=0x0]
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vboxddu.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'vboxdd2.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'setupapi.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'ws2_32.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'ole32.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'iphlpapi.dll'.
- 1db4.e4c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume7\apps\virtualbox\VBoxDD.dll) WinVerifyTrust
- 1db4.e4c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume7\apps\virtualbox\VBoxDD.dll
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'iphlpapi.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'iphlpapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\iphlpapi.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000bf4 pwszName=\Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=3BDC72529DA09BA841BE702C4C902C8AA1242642
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL'
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'nsi.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'winnsi.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'rpcrt4.dll'.
- 1db4.e4c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL) WinVerifyTrust
- 1db4.e4c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ole32.dll
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\setupapi.dll
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxdd2.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxdd2.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\vboxdd2.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
- 1db4.e4c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume7\apps\virtualbox\VBoxDD2.dll) WinVerifyTrust
- 1db4.e4c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume7\apps\virtualbox\VBoxDD2.dll
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxddu.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxddu.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\vboxddu.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'setupapi.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'advapi32.dll'.
- 1db4.e4c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume7\apps\virtualbox\VBoxDDU.dll) WinVerifyTrust
- 1db4.e4c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume7\apps\virtualbox\VBoxDDU.dll
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\vboxrt.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\vboxvmm.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\VBoxVMM.dll
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\setupapi.dll
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\vboxrt.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\vboxrt.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winnsi.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'winnsi.dll' -> '\Device\HarddiskVolume2\Windows\System32\winnsi.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000be0 pwszName=\Device\HarddiskVolume2\Windows\System32\winnsi.dll
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B28F3E0DF5586B9FB3AEAC48E4ECCA0AFB6ABD91
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\winnsi.dll'
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'rpcrt4.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'nsi.dll'.
- 1db4.e4c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\winnsi.dll) WinVerifyTrust
- 1db4.e4c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\winnsi.dll
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume2\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\nsi.dll
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume2\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\nsi.dll
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: pName=E:\apps\virtualbox\VBoxDD.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8ea60:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.e4c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\VBoxDD.dll
- 1db4.e4c: supR3HardenedDllNotificationCallback: load 000007fed57b0000 LB 0x009c3000 E:\apps\virtualbox\VBoxDD.DLL [fFlags=0x0]
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\VBoxDD.dll
- 1db4.e4c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\VBoxDDU.dll
- 1db4.e4c: supR3HardenedDllNotificationCallback: load 000007fee76d0000 LB 0x00063000 E:\apps\virtualbox\VBoxDDU.dll [fFlags=0x0]
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\VBoxDDU.dll
- 1db4.e4c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\VBoxDD2.dll
- 1db4.e4c: supR3HardenedDllNotificationCallback: load 000007feeb300000 LB 0x0005d000 E:\apps\virtualbox\VBoxDD2.dll [fFlags=0x0]
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\VBoxDD2.dll
- 1db4.e4c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL
- 1db4.e4c: supR3HardenedDllNotificationCallback: load 000007fefb3a0000 LB 0x00027000 C:\Windows\system32\IPHLPAPI.DLL [fFlags=0x0]
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL
- 1db4.e4c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winnsi.dll
- 1db4.e4c: supR3HardenedDllNotificationCallback: load 000007fefb300000 LB 0x0000b000 C:\Windows\system32\WINNSI.DLL [fFlags=0x0]
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winnsi.dll
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fed57b0000 'E:\apps\virtualbox\VBoxDD.DLL'
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: pName=E:\apps\virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8ea60:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.e4c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
- 1db4.e4c: supR3HardenedDllNotificationCallback: load 000007fee7be0000 LB 0x00041000 E:\apps\virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL [fFlags=0x0]
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.dll
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7be0000 'E:\apps\virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxHostWebcam.DLL'
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\VBoxC.dll
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: pName=E:\apps\virtualbox\VBoxC.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8ea60:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fedc0c0000 'E:\apps\virtualbox\VBoxC.DLL'
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\VBoxDD2.dll
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: pName=E:\apps\virtualbox\VBoxDD2.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8ea60:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeb300000 'E:\apps\virtualbox\VBoxDD2.DLL'
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
- 1db4.e4c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume7\apps\virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.dll) WinVerifyTrust
- 1db4.e4c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume7\apps\virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.dll
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\vboxrt.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: pName=E:\apps\virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8ea60:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.e4c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.dll
- 1db4.e4c: supR3HardenedDllNotificationCallback: load 000007feed8c0000 LB 0x0001f000 E:\apps\virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.DLL [fFlags=0x0]
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.dll
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feed8c0000 'E:\apps\virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxEhciR3.DLL'
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
- 1db4.e4c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume7\apps\virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.dll) WinVerifyTrust
- 1db4.e4c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume7\apps\virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.dll
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\vboxrt.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: pName=E:\apps\virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8ea60:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.e4c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.dll
- 1db4.e4c: supR3HardenedDllNotificationCallback: load 000007feeb2e0000 LB 0x00018000 E:\apps\virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.DLL [fFlags=0x0]
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.dll
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeb2e0000 'E:\apps\virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxNvmeR3.DLL'
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
- 1db4.e4c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume7\apps\virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.dll) WinVerifyTrust
- 1db4.e4c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume7\apps\virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.dll
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\vboxrt.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: pName=E:\apps\virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8ea60:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.e4c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.dll
- 1db4.e4c: supR3HardenedDllNotificationCallback: load 000007feeb2c0000 LB 0x00018000 E:\apps\virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.DLL [fFlags=0x0]
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.dll
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeb2c0000 'E:\apps\virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbCardReaderR3.DLL'
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
- 1db4.e4c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume7\apps\virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.dll) WinVerifyTrust
- 1db4.e4c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume7\apps\virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.dll
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\vboxrt.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: pName=E:\apps\virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8ea60:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.e4c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.dll
- 1db4.e4c: supR3HardenedDllNotificationCallback: load 000007feeb250000 LB 0x00019000 E:\apps\virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.DLL [fFlags=0x0]
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.dll
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeb250000 'E:\apps\virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VBoxUsbWebcamR3.DLL'
- 1db4.1d4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
- 1db4.1d4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
- 1db4.1d4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
- 1db4.1d4c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume7\apps\virtualbox\VBoxSharedFolders.dll) WinVerifyTrust
- 1db4.1d4c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume7\apps\virtualbox\VBoxSharedFolders.dll
- 1db4.1d4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
- 1db4.1d4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\vboxrt.dll' [rcNtRedir=0xc0150008]
- 1db4.1d4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
- 1db4.1d4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\vboxvmm.dll' [rcNtRedir=0xc0150008]
- 1db4.1d4c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\VBoxVMM.dll
- 1db4.1d4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
- 1db4.1d4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
- 1db4.1d4c: supR3HardenedMonitor_LdrLoadDll: pName=E:\apps\virtualbox\VBoxSharedFolders.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8ea60:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.1d4c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\VBoxSharedFolders.dll
- 1db4.1d4c: supR3HardenedDllNotificationCallback: load 000007feeb240000 LB 0x0000d000 E:\apps\virtualbox\VBoxSharedFolders.DLL [fFlags=0x0]
- 1db4.1d4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\VBoxSharedFolders.dll
- 1db4.1d4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeb240000 'E:\apps\virtualbox\VBoxSharedFolders.DLL'
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ws2_32.dll'.
- 1db4.e4c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume7\apps\virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.dll) WinVerifyTrust
- 1db4.e4c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume7\apps\virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.dll
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\vboxrt.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume7\apps\virtualbox\msvcr100.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: pName=E:\apps\virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8ea60:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.e4c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.dll
- 1db4.e4c: supR3HardenedDllNotificationCallback: load 000007fee6300000 LB 0x000cc000 E:\apps\virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.DLL [fFlags=0x0]
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume7\apps\virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.dll
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee6300000 'E:\apps\virtualbox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.amd64\VDPluginCrypt.DLL'
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\Iphlpapi.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8ea60:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefb3a0000 'C:\Windows\system32\Iphlpapi.dll'
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000d44 pwszName=\Device\HarddiskVolume2\Windows\System32\dhcpcsvc6.dll
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=A719769A21133C3F89F7BEA09AB706365F35DF8F
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_26_for_KB2763523~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\dhcpcsvc6.dll'
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'rpcrt4.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ws2_32.dll'.
- 1db4.e4c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\dhcpcsvc6.dll) WinVerifyTrust
- 1db4.e4c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\dhcpcsvc6.dll
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ws2_32.dll
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\dhcpcsvc6.DLL (Input=dhcpcsvc6.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8e7c0:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.e4c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dhcpcsvc6.dll
- 1db4.e4c: supR3HardenedDllNotificationCallback: load 000007fef8f30000 LB 0x00011000 C:\Windows\system32\dhcpcsvc6.DLL [fFlags=0x0]
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dhcpcsvc6.dll
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef8f30000 'C:\Windows\system32\dhcpcsvc6.DLL'
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\IPHLPAPI.DLL (Input=IPHLPAPI.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8e7c0:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefb3a0000 'C:\Windows\system32\IPHLPAPI.DLL'
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000d68 pwszName=\Device\HarddiskVolume2\Windows\System32\dhcpcsvc.dll
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=D89E2D6AED9A19082ECA108BEEF81A904C7A9756
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\dhcpcsvc.dll'
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'rpcrt4.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ws2_32.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'nsi.dll'.
- 1db4.e4c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\dhcpcsvc.dll) WinVerifyTrust
- 1db4.e4c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\dhcpcsvc.dll
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume2\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\nsi.dll
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\dhcpcsvc.DLL (Input=dhcpcsvc.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8e7c0:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.e4c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dhcpcsvc.dll
- 1db4.e4c: supR3HardenedDllNotificationCallback: load 000007fef8e00000 LB 0x00018000 C:\Windows\system32\dhcpcsvc.DLL [fFlags=0x0]
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dhcpcsvc.dll
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef8e00000 'C:\Windows\system32\dhcpcsvc.DLL'
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\IPHLPAPI.DLL
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\IPHLPAPI.DLL (Input=IPHLPAPI.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8e7c0:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefb3a0000 'C:\Windows\system32\IPHLPAPI.DLL'
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000dd8 pwszName=\Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=704F97298D44B8146C54067788F597E0BF365197
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll'
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'user32.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'rpcrt4.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'propsys.dll'.
- 1db4.e4c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll) WinVerifyTrust
- 1db4.e4c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'propsys.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'propsys.dll' -> '\Device\HarddiskVolume2\Windows\System32\propsys.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000ddc pwszName=\Device\HarddiskVolume2\Windows\System32\propsys.dll
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=6A1594E841359779EF7EA7EBCF775D89F55388D3
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\propsys.dll'
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ole32.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'oleaut32.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'user32.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'rpcrt4.dll'.
- 1db4.e4c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\propsys.dll) WinVerifyTrust
- 1db4.e4c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\propsys.dll
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\MMDevApi.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000002fa0df0:C:\Windows\System32;E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.e4c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
- 1db4.e4c: supR3HardenedDllNotificationCallback: load 000007fefc040000 LB 0x0004b000 C:\Windows\System32\MMDevApi.dll [fFlags=0x0]
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
- 1db4.e4c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\propsys.dll
- 1db4.e4c: supR3HardenedDllNotificationCallback: load 000007fefc170000 LB 0x0012c000 C:\Windows\System32\PROPSYS.dll [fFlags=0x0]
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\propsys.dll
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefde70000 'C:\Windows\system32\ADVAPI32.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc040000 'C:\Windows\System32\MMDevApi.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff2b0000 'C:\Windows\system32\ole32.dll'
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\setupapi.dll
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\SETUPAPI.dll (Input=SETUPAPI.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8f080:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff590000 'C:\Windows\system32\SETUPAPI.dll'
- 1db4.c88: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\cfgmgr32.dll
- 1db4.c88: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CFGMGR32.dll (Input=CFGMGR32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8f080:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.c88: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd8e0000 'C:\Windows\system32\CFGMGR32.dll'
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000e40 pwszName=\Device\HarddiskVolume2\Windows\System32\dsound.dll
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=F6C3E3D9F8B48D816E52C31576FFFD4AF86AB813
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\dsound.dll'
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ole32.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'winmm.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'powrprof.dll'.
- 1db4.e4c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\dsound.dll) WinVerifyTrust
- 1db4.e4c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\dsound.dll
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'powrprof.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'powrprof.dll' -> '\Device\HarddiskVolume2\Windows\System32\powrprof.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000e44 pwszName=\Device\HarddiskVolume2\Windows\System32\powrprof.dll
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=E0B7DE18787DB24DAD3580634869A9A8FF4AB48F
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\powrprof.dll'
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'rpcrt4.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'setupapi.dll'.
- 1db4.e4c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\powrprof.dll) WinVerifyTrust
- 1db4.e4c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\powrprof.dll
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\setupapi.dll
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000002fa0df0:C:\Windows\System32;E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.e4c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dsound.dll
- 1db4.e4c: supR3HardenedDllNotificationCallback: load 000007fee7360000 LB 0x00088000 C:\Windows\System32\dsound.dll [fFlags=0x0]
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dsound.dll
- 1db4.e4c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\powrprof.dll
- 1db4.e4c: supR3HardenedDllNotificationCallback: load 000007fefc090000 LB 0x0002c000 C:\Windows\System32\POWRPROF.dll [fFlags=0x0]
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\powrprof.dll
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dsound.dll
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8f1d0:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\System32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\System32\dsound.dll'
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dsound.dll
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8f1d0:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\shlwapi.dll
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\SHLWAPI.dll (Input=SHLWAPI.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8f1d0:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe270000 'C:\Windows\system32\SHLWAPI.dll'
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\MMDEVAPI.DLL (Input=MMDEVAPI.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8f1d0:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc040000 'C:\Windows\system32\MMDEVAPI.DLL'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff2b0000 'C:\Windows\system32\ole32.dll'
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\winmm.dll (Input=winmm.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8f1d0:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedIsApiSetDll: '<NULL>' -> true
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-Management-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000003d8f1d0:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe110000 'API-MS-WIN-Service-Management-L1-1-0.dll'
- 1db4.e4c: supR3HardenedIsApiSetDll: '<NULL>' -> true
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-WIN-Service-winsvc-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000003d8f1d0:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe110000 'API-MS-WIN-Service-winsvc-L1-1-0.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feffc90000 'C:\Windows\system32\RPCRT4.dll'
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\MMDevAPI.DLL (Input=MMDevAPI.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8f1d0:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefc040000 'C:\Windows\system32\MMDevAPI.DLL'
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000e50 pwszName=\Device\HarddiskVolume2\Windows\System32\wdmaud.drv
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=4B64306F5558D2DEC53CF11AAF17F02438929FDD
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\wdmaud.drv'
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ole32.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'user32.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'winmm.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'ksuser.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'mmdevapi.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'avrt.dll'.
- 1db4.e4c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\wdmaud.drv) WinVerifyTrust
- 1db4.e4c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'avrt.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'avrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\avrt.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000e7c pwszName=\Device\HarddiskVolume2\Windows\System32\avrt.dll
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=1362C343929DD08AB918B38DE195D1A11B1D1365
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\avrt.dll'
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.e4c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\avrt.dll) WinVerifyTrust
- 1db4.e4c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\avrt.dll
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mmdevapi.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'mmdevapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\mmdevapi.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ksuser.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ksuser.dll' -> '\Device\HarddiskVolume2\Windows\System32\ksuser.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000e80 pwszName=\Device\HarddiskVolume2\Windows\System32\ksuser.dll
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=EC3873F9ACBE279185D3540F02128F42D21D0856
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\ksuser.dll'
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 1db4.e4c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\ksuser.dll) WinVerifyTrust
- 1db4.e4c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\ksuser.dll
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8f1d0:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.e4c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
- 1db4.e4c: supR3HardenedDllNotificationCallback: load 000007fee7a70000 LB 0x0003b000 C:\Windows\system32\wdmaud.drv [fFlags=0x0]
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
- 1db4.e4c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ksuser.dll
- 1db4.e4c: supR3HardenedDllNotificationCallback: load 0000000071710000 LB 0x00006000 C:\Windows\system32\ksuser.dll [fFlags=0x0]
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\ksuser.dll
- 1db4.e4c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\avrt.dll
- 1db4.e4c: supR3HardenedDllNotificationCallback: load 000007fefbfb0000 LB 0x00009000 C:\Windows\system32\AVRT.dll [fFlags=0x0]
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\avrt.dll
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7a70000 'C:\Windows\system32\wdmaud.drv'
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8f1d0:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7a70000 'C:\Windows\system32\wdmaud.drv'
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8f1d0:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7a70000 'C:\Windows\system32\wdmaud.drv'
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8f1d0:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7a70000 'C:\Windows\system32\wdmaud.drv'
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8f1d0:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7a70000 'C:\Windows\system32\wdmaud.drv'
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000ea8 pwszName=\Device\HarddiskVolume2\Windows\System32\AudioSes.dll
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=1B5BCEE9F60F75E176D19C778D9B6CD5DBEB84BB
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Foundation-Package~31bf3856ad364e35~amd64~~6.1.7601.17514.cat'; file='\Device\HarddiskVolume2\Windows\System32\AudioSes.dll'
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ole32.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'oleaut32.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'mmdevapi.dll'.
- 1db4.e4c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\AudioSes.dll) WinVerifyTrust
- 1db4.e4c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\AudioSes.dll
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mmdevapi.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'mmdevapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\mmdevapi.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume2\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\AUDIOSES.DLL (Input=AUDIOSES.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8f1d0:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.e4c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\AudioSes.dll
- 1db4.e4c: supR3HardenedDllNotificationCallback: load 000007feece80000 LB 0x0004f000 C:\Windows\system32\AUDIOSES.DLL [fFlags=0x0]
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\AudioSes.dll
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feece80000 'C:\Windows\system32\AUDIOSES.DLL'
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8f0f0:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7a70000 'C:\Windows\system32\wdmaud.drv'
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wdmaud.drv
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wdmaud.drv (Input=wdmaud.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8f0f0:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7a70000 'C:\Windows\system32\wdmaud.drv'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7a70000 'C:\Windows\system32\wdmaud.drv'
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000e88 pwszName=\Device\HarddiskVolume2\Windows\System32\msacm32.drv
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=522563F5384AD4C93CF5CF4EEA899D3267552328
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\msacm32.drv'
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'winmm.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msacm32.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'mmdevapi.dll'.
- 1db4.e4c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\msacm32.drv) WinVerifyTrust
- 1db4.e4c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msacm32.drv
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mmdevapi.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'mmdevapi.dll' -> '\Device\HarddiskVolume2\Windows\System32\mmdevapi.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\MMDevAPI.dll
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msacm32.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msacm32.dll' -> '\Device\HarddiskVolume2\Windows\System32\msacm32.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000eb4 pwszName=\Device\HarddiskVolume2\Windows\System32\msacm32.dll
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=DCA0A8AEE81B82C402AA72A300B2C8D2DC17C1DA
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\msacm32.dll'
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'gdi32.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'winmm.dll'.
- 1db4.e4c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\msacm32.dll) WinVerifyTrust
- 1db4.e4c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\msacm32.dll
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume2\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8f0f0:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.e4c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
- 1db4.e4c: supR3HardenedDllNotificationCallback: load 000007feeb210000 LB 0x0000a000 C:\Windows\system32\msacm32.drv [fFlags=0x0]
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
- 1db4.e4c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.dll
- 1db4.e4c: supR3HardenedDllNotificationCallback: load 000007fee7a50000 LB 0x00018000 C:\Windows\system32\MSACM32.dll [fFlags=0x0]
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.dll
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeb210000 'C:\Windows\system32\msacm32.drv'
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8f0f0:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeb210000 'C:\Windows\system32\msacm32.drv'
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8f0f0:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeb210000 'C:\Windows\system32\msacm32.drv'
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8f0f0:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeb210000 'C:\Windows\system32\msacm32.drv'
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8f0f0:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeb210000 'C:\Windows\system32\msacm32.drv'
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8f0f0:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeb210000 'C:\Windows\system32\msacm32.drv'
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\msacm32.drv
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\msacm32.drv (Input=msacm32.drv, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8f0f0:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeb210000 'C:\Windows\system32\msacm32.drv'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeb210000 'C:\Windows\system32\msacm32.drv'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeb210000 'C:\Windows\system32\msacm32.drv'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feeb210000 'C:\Windows\system32\msacm32.drv'
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000e98 pwszName=\Device\HarddiskVolume2\Windows\System32\midimap.dll
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=43116C5C719A4751DA70B12932084D73D7AACEA3
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat'; file='\Device\HarddiskVolume2\Windows\System32\midimap.dll'
- 1db4.e4c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
- 1db4.e4c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'winmm.dll'.
- 1db4.e4c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\midimap.dll) WinVerifyTrust
- 1db4.e4c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\midimap.dll
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume2\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 1db4.e4c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8f0f0:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.e4c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\midimap.dll
- 1db4.e4c: supR3HardenedDllNotificationCallback: load 000007fee7bd0000 LB 0x00009000 C:\Windows\system32\midimap.dll [fFlags=0x0]
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\midimap.dll
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7bd0000 'C:\Windows\system32\midimap.dll'
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\midimap.dll
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8f0f0:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7bd0000 'C:\Windows\system32\midimap.dll'
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\midimap.dll
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8f0f0:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7bd0000 'C:\Windows\system32\midimap.dll'
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\midimap.dll
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\midimap.dll (Input=midimap.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8f0f0:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7bd0000 'C:\Windows\system32\midimap.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007feff2b0000 'C:\Windows\system32\ole32.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\winmm.dll (Input=winmm.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8f0f0:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dsound.dll
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8f0f0:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.18d0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\oleaut32.dll
- 1db4.18d0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\OLEAUT32.dll (Input=OLEAUT32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8ed00:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.18d0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefdc80000 'C:\Windows\system32\OLEAUT32.dll'
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe480000 'C:\Windows\system32\shell32.dll'
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefe480000 'C:\Windows\system32\shell32.dll'
- 1db4.1c50: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\WINMM.dll'
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dsound.dll
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8e2f0:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dsound.dll
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8e2f0:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dsound.dll
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8e2f0:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dsound.dll
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8e2f0:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\winmm.dll (Input=winmm.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8e2f0:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.1f7c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000001040 pwszName=\Device\HarddiskVolume2\Windows\System32\mswsock.dll
- 1db4.1f7c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.1f7c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.1f7c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\wintrust.dll
- 1db4.1f7c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\WINTRUST.DLL (Input=WINTRUST.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8e280:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.1f7c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd980000 'C:\Windows\system32\WINTRUST.DLL'
- 1db4.1f7c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\crypt32.dll
- 1db4.1f7c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\CRYPT32.dll (rcNtResolve=0xc0150008) *pfFlags=0x1002 pwszSearchPath=0000000003d8e280:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.1f7c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefda70000 'C:\Windows\system32\CRYPT32.dll'
- 1db4.1f7c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=C8E5754748E0E000AB425BF2AEB177780FB43945
- 1db4.1f7c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefa690000 'C:\Windows\system32\cryptnet.dll'
- 1db4.1f7c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_3_for_KB2888049~31bf3856ad364e35~amd64~~6.1.1.1.cat'; file='\Device\HarddiskVolume2\Windows\System32\mswsock.dll'
- 1db4.1f7c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.1f7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 1db4.1f7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
- 1db4.1f7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rpcrt4.dll'.
- 1db4.1f7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ws2_32.dll'.
- 1db4.1f7c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\mswsock.dll) WinVerifyTrust
- 1db4.1f7c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\mswsock.dll
- 1db4.1f7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
- 1db4.1f7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
- 1db4.1f7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 1db4.1f7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume2\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 1db4.1f7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 1db4.1f7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume2\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 1db4.1f7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 1db4.1f7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume2\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 1db4.1f7c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\mswsock.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8e2f0:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.1f7c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\mswsock.dll
- 1db4.1f7c: supR3HardenedDllNotificationCallback: load 000007fefd060000 LB 0x00055000 C:\Windows\system32\mswsock.dll [fFlags=0x0]
- 1db4.1f7c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\mswsock.dll
- 1db4.1f7c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefd060000 'C:\Windows\system32\mswsock.dll'
- 1db4.1f7c: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000001060 pwszName=\Device\HarddiskVolume2\Windows\System32\WSHTCPIP.DLL
- 1db4.1f7c: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 00000000006d6b20
- 1db4.1f7c: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=00000000006d6b20
- 1db4.1f7c: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=1EFFE58BB9FD8A94FD1609B7F82A43C8E09D98AA
- 1db4.1f7c: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntpe.cat'; file='\Device\HarddiskVolume2\Windows\System32\WSHTCPIP.DLL'
- 1db4.1f7c: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 1db4.1f7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'ws2_32.dll'.
- 1db4.1f7c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\WSHTCPIP.DLL) WinVerifyTrust
- 1db4.1f7c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\WSHTCPIP.DLL
- 1db4.1f7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
- 1db4.1f7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume2\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
- 1db4.1f7c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\wshtcpip.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8e2f0:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.1f7c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\WSHTCPIP.DLL
- 1db4.1f7c: supR3HardenedDllNotificationCallback: load 000007fefca80000 LB 0x00007000 C:\Windows\System32\wshtcpip.dll [fFlags=0x0]
- 1db4.1f7c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\WSHTCPIP.DLL
- 1db4.1f7c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fefca80000 'C:\Windows\System32\wshtcpip.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dsound.dll
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8e280:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\winmm.dll
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\winmm.dll (Input=winmm.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8e750:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\dsound.dll
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\dsound.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000003d8e280:E:\apps\virtualbox;C:\Windows\system32 [calling]
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fee7360000 'C:\Windows\system32\dsound.dll'
- 1db4.e4c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=000007fef75c0000 'C:\Windows\system32\winmm.dll'
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement