Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 2534.14dc: \SystemRoot\System32\ntdll.dll:
- 2534.14dc: CreationTime: 2025-03-12T17:32:50.955934500Z
- 2534.14dc: LastWriteTime: 2025-03-12T17:32:51.017206900Z
- 2534.14dc: ChangeTime: 2025-03-13T22:19:28.355125000Z
- 2534.14dc: FileAttributes: 0x20
- 2534.14dc: Size: 0x216038
- 2534.14dc: NT Headers: 0xe8
- 2534.14dc: Timestamp: 0x36d7bcf8
- 2534.14dc: Machine: 0x8664 - amd64
- 2534.14dc: Timestamp: 0x36d7bcf8
- 2534.14dc: Image Version: 10.0
- 2534.14dc: SizeOfImage: 0x217000 (2191360)
- 2534.14dc: Resource Dir: 0x1a0000 LB 0x759a8
- 2534.14dc: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 2534.14dc: [Raw version resource data: 0x1a00f0 LB 0x380, codepage 0x0 (reserved 0x0)]
- 2534.14dc: ProductName: Microsoft® Windows® Operating System
- 2534.14dc: ProductVersion: 10.0.22621.4974
- 2534.14dc: FileVersion: 10.0.22621.4974 (WinBuild.160101.0800)
- 2534.14dc: FileDescription: NT Layer DLL
- 2534.14dc: \SystemRoot\System32\kernel32.dll:
- 2534.14dc: CreationTime: 2025-03-12T17:32:50.494392400Z
- 2534.14dc: LastWriteTime: 2025-03-12T17:32:50.522189500Z
- 2534.14dc: ChangeTime: 2025-03-13T22:20:04.067768600Z
- 2534.14dc: FileAttributes: 0x20
- 2534.14dc: Size: 0xc7188
- 2534.14dc: NT Headers: 0xe8
- 2534.14dc: Timestamp: 0x8c0b1418
- 2534.14dc: Machine: 0x8664 - amd64
- 2534.14dc: Timestamp: 0x8c0b1418
- 2534.14dc: Image Version: 10.0
- 2534.14dc: SizeOfImage: 0xc4000 (802816)
- 2534.14dc: Resource Dir: 0xc2000 LB 0x520
- 2534.14dc: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 2534.14dc: [Raw version resource data: 0xc20b0 LB 0x3a4, codepage 0x0 (reserved 0x0)]
- 2534.14dc: ProductName: Microsoft® Windows® Operating System
- 2534.14dc: ProductVersion: 10.0.22621.4974
- 2534.14dc: FileVersion: 10.0.22621.4974 (WinBuild.160101.0800)
- 2534.14dc: FileDescription: Windows NT BASE API Client DLL
- 2534.14dc: \SystemRoot\System32\KernelBase.dll:
- 2534.14dc: CreationTime: 2025-03-12T17:32:51.859758200Z
- 2534.14dc: LastWriteTime: 2025-03-12T17:32:52.063051800Z
- 2534.14dc: ChangeTime: 2025-03-13T22:20:04.207799700Z
- 2534.14dc: FileAttributes: 0x20
- 2534.14dc: Size: 0x3d7f18
- 2534.14dc: NT Headers: 0xf8
- 2534.14dc: Timestamp: 0xa29a3610
- 2534.14dc: Machine: 0x8664 - amd64
- 2534.14dc: Timestamp: 0xa29a3610
- 2534.14dc: Image Version: 10.0
- 2534.14dc: SizeOfImage: 0x3d1000 (4001792)
- 2534.14dc: Resource Dir: 0x3a0000 LB 0x548
- 2534.14dc: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 2534.14dc: [Raw version resource data: 0x3a00b0 LB 0x3bc, codepage 0x0 (reserved 0x0)]
- 2534.14dc: ProductName: Microsoft® Windows® Operating System
- 2534.14dc: ProductVersion: 10.0.22621.5037
- 2534.14dc: FileVersion: 10.0.22621.5037 (WinBuild.160101.0800)
- 2534.14dc: FileDescription: Windows NT BASE API Client DLL
- 2534.14dc: \SystemRoot\System32\apisetschema.dll:
- 2534.14dc: CreationTime: 2024-08-18T12:47:44.848835500Z
- 2534.14dc: LastWriteTime: 2024-08-18T12:47:44.854356200Z
- 2534.14dc: ChangeTime: 2025-03-12T17:34:36.442764200Z
- 2534.14dc: FileAttributes: 0x20
- 2534.14dc: Size: 0x245e0
- 2534.14dc: NT Headers: 0xc8
- 2534.14dc: Timestamp: 0x8f476251
- 2534.14dc: Machine: 0x8664 - amd64
- 2534.14dc: Timestamp: 0x8f476251
- 2534.14dc: Image Version: 10.0
- 2534.14dc: SizeOfImage: 0x23000 (143360)
- 2534.14dc: Resource Dir: 0x22000 LB 0x408
- 2534.14dc: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 2534.14dc: [Raw version resource data: 0x22060 LB 0x3a8, codepage 0x0 (reserved 0x0)]
- 2534.14dc: ProductName: Microsoft® Windows® Operating System
- 2534.14dc: ProductVersion: 10.0.22621.3958
- 2534.14dc: FileVersion: 10.0.22621.3958 (WinBuild.160101.0800)
- 2534.14dc: FileDescription: ApiSet Schema DLL
- 2534.14dc: NtOpenDirectoryObject failed on \Driver: 0xc0000022
- 2534.14dc: supR3HardenedWinFindAdversaries: 0x0
- 2534.14dc: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox'
- 2534.14dc: Calling main()
- 2534.14dc: SUPR3HardenedMain: pszProgName=VirtualBoxVM fFlags=0x2
- 2534.14dc: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox'
- 2534.14dc: SUPR3HardenedMain: Respawn #1
- 2534.14dc: System32: \Device\HarddiskVolume5\Windows\System32
- 2534.14dc: WinSxS: \Device\HarddiskVolume5\Windows\WinSxS
- 2534.14dc: KnownDllPath: C:\Windows\System32
- 2534.14dc: supR3HardenedWinInit: Performing a limited self purification...
- 2534.14dc: supHardNtVpScanVirtualMemory: enmKind=SELF_PURIFICATION
- 2534.14dc: *0000000000000000-000000007ffdffff 0x0001/0x0000 0x0000000
- 2534.14dc: *000000007ffe0000-000000007ffe0fff 0x0002/0x0002 0x0020000
- 2534.14dc: 000000007ffe1000-000000007ffe8fff 0x0001/0x0000 0x0000000
- 2534.14dc: *000000007ffe9000-000000007ffe9fff 0x0002/0x0002 0x0020000
- 2534.14dc: 000000007ffea000-000000ace888ffff 0x0001/0x0000 0x0000000
- 2534.14dc: *000000ace8890000-000000ace8948fff 0x0000/0x0004 0x0020000
- 2534.14dc: 000000ace8949000-000000ace894bfff 0x0104/0x0004 0x0020000
- 2534.14dc: 000000ace894c000-000000ace898ffff 0x0004/0x0004 0x0020000
- 2534.14dc: 000000ace8990000-000000ace89fffff 0x0001/0x0000 0x0000000
- 2534.14dc: *000000ace8a00000-000000ace8a47fff 0x0000/0x0004 0x0020000
- 2534.14dc: 000000ace8a48000-000000ace8a4afff 0x0004/0x0004 0x0020000
- 2534.14dc: 000000ace8a4b000-000000ace8bfffff 0x0000/0x0004 0x0020000
- 2534.14dc: 000000ace8c00000-000002893cbfffff 0x0001/0x0000 0x0000000
- 2534.14dc: *000002893cc00000-000002893cc0ffff 0x0004/0x0004 0x0040000
- 2534.14dc: *000002893cc10000-000002893cc12fff 0x0002/0x0002 0x0040000
- 2534.14dc: 000002893cc13000-000002893cc1ffff 0x0001/0x0000 0x0000000
- 2534.14dc: *000002893cc20000-000002893cc3efff 0x0002/0x0002 0x0040000
- 2534.14dc: 000002893cc3f000-000002893cc3ffff 0x0001/0x0000 0x0000000
- 2534.14dc: *000002893cc40000-000002893cc43fff 0x0002/0x0002 0x0040000
- 2534.14dc: 000002893cc44000-000002893cc4ffff 0x0001/0x0000 0x0000000
- 2534.14dc: *000002893cc50000-000002893cc50fff 0x0002/0x0002 0x0040000
- 2534.14dc: 000002893cc51000-000002893cc5ffff 0x0001/0x0000 0x0000000
- 2534.14dc: *000002893cc60000-000002893cc61fff 0x0004/0x0004 0x0020000
- 2534.14dc: 000002893cc62000-000002893cc6ffff 0x0001/0x0000 0x0000000
- 2534.14dc: *000002893cc70000-000002893cc72fff 0x0002/0x0002 0x0040000
- 2534.14dc: 000002893cc73000-000002893cc7ffff 0x0001/0x0000 0x0000000
- 2534.14dc: *000002893cc80000-000002893cc81fff 0x0004/0x0004 0x0020000
- 2534.14dc: 000002893cc82000-000002893cce1fff 0x0000/0x0004 0x0020000
- 2534.14dc: 000002893cce2000-000002893cceffff 0x0001/0x0000 0x0000000
- 2534.14dc: *000002893ccf0000-000002893ccf3fff 0x0002/0x0002 0x0040000
- 2534.14dc: 000002893ccf4000-000002893ccfffff 0x0001/0x0000 0x0000000
- 2534.14dc: *000002893cd00000-000002893cd03fff 0x0002/0x0002 0x0040000
- 2534.14dc: 000002893cd04000-000002893cd0ffff 0x0001/0x0000 0x0000000
- 2534.14dc: *000002893cd10000-000002893cd10fff 0x0002/0x0002 0x0040000
- 2534.14dc: 000002893cd11000-000002893cd2ffff 0x0001/0x0000 0x0000000
- 2534.14dc: *000002893cd30000-000002893cd39fff 0x0004/0x0004 0x0020000
- 2534.14dc: 000002893cd3a000-000002893ce2ffff 0x0000/0x0004 0x0020000
- 2534.14dc: *000002893ce30000-000002893cefdfff 0x0002/0x0002 0x0040000
- 2534.14dc: 000002893cefe000-000002893cefffff 0x0001/0x0000 0x0000000
- 2534.14dc: *000002893cf00000-000002893cf01fff 0x0004/0x0004 0x0020000
- 2534.14dc: 000002893cf02000-000002893cf61fff 0x0000/0x0004 0x0020000
- 2534.14dc: 000002893cf62000-000002893cf6ffff 0x0001/0x0000 0x0000000
- 2534.14dc: *000002893cf70000-000002893cf7efff 0x0004/0x0004 0x0020000
- 2534.14dc: 000002893cf7f000-000002893cf7ffff 0x0000/0x0004 0x0020000
- 2534.14dc: *000002893cf80000-000002893cf88fff 0x0000/0x0004 0x0020000
- 2534.14dc: 000002893cf89000-000002893d1a0fff 0x0004/0x0004 0x0020000
- 2534.14dc: 000002893d1a1000-000002893d1a1fff 0x0000/0x0004 0x0020000
- 2534.14dc: 000002893d1a2000-000002893d1affff 0x0001/0x0000 0x0000000
- 2534.14dc: *000002893d1b0000-000002893d1e0fff 0x0004/0x0004 0x0020000
- 2534.14dc: 000002893d1e1000-000002893d2affff 0x0000/0x0004 0x0020000
- 2534.14dc: 000002893d2b0000-00007df46695ffff 0x0001/0x0000 0x0000000
- 2534.14dc: *00007df466960000-00007df466964fff 0x0002/0x0002 0x0040000
- 2534.14dc: 00007df466965000-00007df466a5ffff 0x0000/0x0002 0x0040000
- 2534.14dc: *00007df466a60000-00007df566a7ffff 0x0000/0x0004 0x0020000
- 2534.14dc: *00007df566a80000-00007df568a7ffff 0x0000/0x0004 0x0020000
- 2534.14dc: 00007df568a80000-00007df568a80fff 0x0004/0x0004 0x0020000
- 2534.14dc: 00007df568a81000-00007df568a8ffff 0x0001/0x0000 0x0000000
- 2534.14dc: *00007df568a90000-00007df568a90fff 0x0002/0x0002 0x0040000
- 2534.14dc: 00007df568a91000-00007df568a9ffff 0x0001/0x0000 0x0000000
- 2534.14dc: *00007df568aa0000-00007df569f22fff 0x0000/0x0001 0x0040000
- 2534.14dc: 00007df569f23000-00007df569ff1fff 0x0001/0x0001 0x0040000
- 2534.14dc: 00007df569ff2000-00007df56a886fff 0x0000/0x0001 0x0040000
- 2534.14dc: 00007df56a887000-00007df56a887fff 0x0001/0x0001 0x0040000
- 2534.14dc: 00007df56a888000-00007ff54127ffff 0x0000/0x0001 0x0040000
- 2534.14dc: 00007ff541280000-00007ff541284fff 0x0002/0x0001 0x0040000
- 2534.14dc: 00007ff541285000-00007ff5543d0fff 0x0000/0x0001 0x0040000
- 2534.14dc: 00007ff5543d1000-00007ff558018fff 0x0001/0x0001 0x0040000
- 2534.14dc: 00007ff558019000-00007ff558028fff 0x0002/0x0001 0x0040000
- 2534.14dc: 00007ff558029000-00007ff558080fff 0x0001/0x0001 0x0040000
- 2534.14dc: 00007ff558081000-00007ff558084fff 0x0002/0x0001 0x0040000
- 2534.14dc: 00007ff558085000-00007ff5580d3fff 0x0001/0x0001 0x0040000
- 2534.14dc: 00007ff5580d4000-00007ff5580dcfff 0x0002/0x0001 0x0040000
- 2534.14dc: 00007ff5580dd000-00007ff568a9ffff 0x0000/0x0001 0x0040000
- 2534.14dc: 00007ff568aa0000-00007ff61f80ffff 0x0001/0x0000 0x0000000
- 2534.14dc: *00007ff61f810000-00007ff61f810fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 2534.14dc: 00007ff61f811000-00007ff61f87bfff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 2534.14dc: 00007ff61f87c000-00007ff61f87cfff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 2534.14dc: 00007ff61f87d000-00007ff61f8d1fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 2534.14dc: 00007ff61f8d2000-00007ff61f8d4fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 2534.14dc: 00007ff61f8d5000-00007ff61f8d7fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 2534.14dc: 00007ff61f8d8000-00007ff61f8ddfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 2534.14dc: 00007ff61f8de000-00007ff61f8defff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 2534.14dc: 00007ff61f8df000-00007ff61f919fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 2534.14dc: 00007ff61f91a000-00007ffbd5e4ffff 0x0001/0x0000 0x0000000
- 2534.14dc: *00007ffbd5e50000-00007ffbd5e50fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\KernelBase.dll
- 2534.14dc: 00007ffbd5e51000-00007ffbd6004fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\KernelBase.dll
- 2534.14dc: 00007ffbd6005000-00007ffbd61cdfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\KernelBase.dll
- 2534.14dc: 00007ffbd61ce000-00007ffbd61d2fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\KernelBase.dll
- 2534.14dc: 00007ffbd61d3000-00007ffbd61d3fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\KernelBase.dll
- 2534.14dc: 00007ffbd61d4000-00007ffbd6220fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\KernelBase.dll
- 2534.14dc: 00007ffbd6221000-00007ffbd786ffff 0x0001/0x0000 0x0000000
- 2534.14dc: *00007ffbd7870000-00007ffbd7870fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\kernel32.dll
- 2534.14dc: 00007ffbd7871000-00007ffbd78f1fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\kernel32.dll
- 2534.14dc: 00007ffbd78f2000-00007ffbd7928fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\kernel32.dll
- 2534.14dc: 00007ffbd7929000-00007ffbd7929fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\kernel32.dll
- 2534.14dc: 00007ffbd792a000-00007ffbd792afff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\kernel32.dll
- 2534.14dc: 00007ffbd792b000-00007ffbd7933fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\kernel32.dll
- 2534.14dc: 00007ffbd7934000-00007ffbd8d0ffff 0x0001/0x0000 0x0000000
- 2534.14dc: *00007ffbd8d10000-00007ffbd8d10fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\ntdll.dll
- 2534.14dc: 00007ffbd8d11000-00007ffbd8e41fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\ntdll.dll
- 2534.14dc: 00007ffbd8e42000-00007ffbd8e8ffff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\ntdll.dll
- 2534.14dc: 00007ffbd8e90000-00007ffbd8e90fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\ntdll.dll
- 2534.14dc: 00007ffbd8e91000-00007ffbd8e92fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\ntdll.dll
- 2534.14dc: 00007ffbd8e93000-00007ffbd8e9bfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\ntdll.dll
- 2534.14dc: 00007ffbd8e9c000-00007ffbd8f26fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\ntdll.dll
- 2534.14dc: 00007ffbd8f27000-00007ffffffeffff 0x0001/0x0000 0x0000000
- 2534.14dc: kernel32.dll: timestamp 0x8c0b1418 (rc=VINF_SUCCESS)
- 2534.14dc: kernelbase.dll: timestamp 0xa29a3610 (rc=VINF_SUCCESS)
- 2534.14dc: VirtualBoxVM.exe: timestamp 0x678f9dd6 (rc=VINF_SUCCESS)
- 2534.14dc: '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
- 2534.14dc: VirtualBoxVM.exe: Differences in section #7 (.00cfg) between file and memory:
- 2534.14dc: 00007ff61f8e6000 / 0x00d6000: 00 != 70
- 2534.14dc: 00007ff61f8e6001 / 0x00d6001: e7 != f2
- 2534.14dc: 00007ff61f8e6002 / 0x00d6002: 82 != d9
- 2534.14dc: 00007ff61f8e6003 / 0x00d6003: 1f != d8
- 2534.14dc: 00007ff61f8e6004 / 0x00d6004: f6 != fb
- 2534.14dc: 00007ff61f8e6008 / 0x00d6008: 00 != 70
- 2534.14dc: 00007ff61f8e6009 / 0x00d6009: e7 != f2
- 2534.14dc: 00007ff61f8e600a / 0x00d600a: 82 != d9
- 2534.14dc: 00007ff61f8e600b / 0x00d600b: 1f != d8
- 2534.14dc: 00007ff61f8e600c / 0x00d600c: f6 != fb
- 2534.14dc: 00007ff61f8e6010 / 0x00d6010: f0 != b0
- 2534.14dc: 00007ff61f8e6011 / 0x00d6011: b4 != f3
- 2534.14dc: 00007ff61f8e6012 / 0x00d6012: 87 != d9
- 2534.14dc: 00007ff61f8e6013 / 0x00d6013: 1f != d8
- 2534.14dc: 00007ff61f8e6014 / 0x00d6014: f6 != fb
- 2534.14dc: 00007ff61f8e6018 / 0x00d6018: 10 != b0
- 2534.14dc: 00007ff61f8e6019 / 0x00d6019: b5 != f3
- 2534.14dc: 00007ff61f8e601a / 0x00d601a: 87 != d9
- 2534.14dc: 00007ff61f8e601b / 0x00d601b: 1f != d8
- 2534.14dc: 00007ff61f8e601c / 0x00d601c: f6 != fb
- 2534.14dc: 00007ff61f8e6020 / 0x00d6020: 10 != b0
- 2534.14dc: 00007ff61f8e6021 / 0x00d6021: b5 != f3
- 2534.14dc: 00007ff61f8e6022 / 0x00d6022: 87 != d9
- 2534.14dc: 00007ff61f8e6023 / 0x00d6023: 1f != d8
- 2534.14dc: 00007ff61f8e6024 / 0x00d6024: f6 != fb
- 2534.14dc: Restored 0x28 bytes of original file content at 00007ff61f8e6000
- 2534.14dc: VirtualBoxVM.exe: Differences in section #8 (.rsrc) between file and memory:
- 2534.14dc: 00007ff61f917b28 / 0x0107b28: 00 != 50
- 2534.14dc: 00007ff61f917b29 / 0x0107b29: 00 != 41
- 2534.14dc: 00007ff61f917b2a / 0x0107b2a: 00 != 44
- 2534.14dc: 00007ff61f917b2b / 0x0107b2b: 00 != 44
- 2534.14dc: 00007ff61f917b2c / 0x0107b2c: 00 != 49
- 2534.14dc: 00007ff61f917b2d / 0x0107b2d: 00 != 4e
- 2534.14dc: 00007ff61f917b2e / 0x0107b2e: 00 != 47
- 2534.14dc: 00007ff61f917b2f / 0x0107b2f: 00 != 58
- 2534.14dc: 00007ff61f917b30 / 0x0107b30: 00 != 58
- 2534.14dc: 00007ff61f917b31 / 0x0107b31: 00 != 50
- 2534.14dc: 00007ff61f917b32 / 0x0107b32: 00 != 41
- 2534.14dc: 00007ff61f917b33 / 0x0107b33: 00 != 44
- 2534.14dc: 00007ff61f917b34 / 0x0107b34: 00 != 44
- 2534.14dc: 00007ff61f917b35 / 0x0107b35: 00 != 49
- 2534.14dc: 00007ff61f917b36 / 0x0107b36: 00 != 4e
- 2534.14dc: 00007ff61f917b37 / 0x0107b37: 00 != 47
- 2534.14dc: 00007ff61f917b38 / 0x0107b38: 00 != 50
- 2534.14dc: 00007ff61f917b39 / 0x0107b39: 00 != 41
- 2534.14dc: 00007ff61f917b3a / 0x0107b3a: 00 != 44
- 2534.14dc: 00007ff61f917b3b / 0x0107b3b: 00 != 44
- 2534.14dc: 00007ff61f917b3c / 0x0107b3c: 00 != 49
- 2534.14dc: 00007ff61f917b3d / 0x0107b3d: 00 != 4e
- 2534.14dc: 00007ff61f917b3e / 0x0107b3e: 00 != 47
- 2534.14dc: 00007ff61f917b3f / 0x0107b3f: 00 != 58
- 2534.14dc: 00007ff61f917b40 / 0x0107b40: 00 != 58
- 2534.14dc: 00007ff61f917b41 / 0x0107b41: 00 != 50
- 2534.14dc: 00007ff61f917b42 / 0x0107b42: 00 != 41
- 2534.14dc: 00007ff61f917b43 / 0x0107b43: 00 != 44
- 2534.14dc: 00007ff61f917b44 / 0x0107b44: 00 != 44
- 2534.14dc: 00007ff61f917b45 / 0x0107b45: 00 != 49
- 2534.14dc: 00007ff61f917b46 / 0x0107b46: 00 != 4e
- 2534.14dc: 00007ff61f917b47 / 0x0107b47: 00 != 47
- 2534.14dc: 00007ff61f917b48 / 0x0107b48: 00 != 50
- 2534.14dc: 00007ff61f917b49 / 0x0107b49: 00 != 41
- 2534.14dc: 00007ff61f917b4a / 0x0107b4a: 00 != 44
- 2534.14dc: 00007ff61f917b4b / 0x0107b4b: 00 != 44
- 2534.14dc: 00007ff61f917b4c / 0x0107b4c: 00 != 49
- 2534.14dc: 00007ff61f917b4d / 0x0107b4d: 00 != 4e
- 2534.14dc: 00007ff61f917b4e / 0x0107b4e: 00 != 47
- 2534.14dc: 00007ff61f917b4f / 0x0107b4f: 00 != 58
- 2534.14dc: 00007ff61f917b50 / 0x0107b50: 00 != 58
- 2534.14dc: 00007ff61f917b51 / 0x0107b51: 00 != 50
- 2534.14dc: 00007ff61f917b52 / 0x0107b52: 00 != 41
- 2534.14dc: 00007ff61f917b53 / 0x0107b53: 00 != 44
- 2534.14dc: 00007ff61f917b54 / 0x0107b54: 00 != 44
- 2534.14dc: 00007ff61f917b55 / 0x0107b55: 00 != 49
- 2534.14dc: 00007ff61f917b56 / 0x0107b56: 00 != 4e
- 2534.14dc: 00007ff61f917b57 / 0x0107b57: 00 != 47
- 2534.14dc: 00007ff61f917b58 / 0x0107b58: 00 != 50
- 2534.14dc: 00007ff61f917b59 / 0x0107b59: 00 != 41
- 2534.14dc: 00007ff61f917b5a / 0x0107b5a: 00 != 44
- 2534.14dc: 00007ff61f917b5b / 0x0107b5b: 00 != 44
- 2534.14dc: 00007ff61f917b5c / 0x0107b5c: 00 != 49
- 2534.14dc: 00007ff61f917b5d / 0x0107b5d: 00 != 4e
- 2534.14dc: 00007ff61f917b5e / 0x0107b5e: 00 != 47
- 2534.14dc: 00007ff61f917b5f / 0x0107b5f: 00 != 58
- 2534.14dc: 00007ff61f917b60 / 0x0107b60: 00 != 58
- 2534.14dc: 00007ff61f917b61 / 0x0107b61: 00 != 50
- 2534.14dc: 00007ff61f917b62 / 0x0107b62: 00 != 41
- 2534.14dc: 00007ff61f917b63 / 0x0107b63: 00 != 44
- 2534.14dc: 00007ff61f917b64 / 0x0107b64: 00 != 44
- 2534.14dc: 00007ff61f917b65 / 0x0107b65: 00 != 49
- 2534.14dc: 00007ff61f917b66 / 0x0107b66: 00 != 4e
- 2534.14dc: 00007ff61f917b67 / 0x0107b67: 00 != 47
- 2534.14dc: 00007ff61f917b68 / 0x0107b68: 00 != 50
- 2534.14dc: 00007ff61f917b69 / 0x0107b69: 00 != 41
- 2534.14dc: 00007ff61f917b6a / 0x0107b6a: 00 != 44
- 2534.14dc: 00007ff61f917b6b / 0x0107b6b: 00 != 44
- 2534.14dc: 00007ff61f917b6c / 0x0107b6c: 00 != 49
- 2534.14dc: 00007ff61f917b6d / 0x0107b6d: 00 != 4e
- 2534.14dc: 00007ff61f917b6e / 0x0107b6e: 00 != 47
- 2534.14dc: 00007ff61f917b6f / 0x0107b6f: 00 != 58
- 2534.14dc: 00007ff61f917b70 / 0x0107b70: 00 != 58
- 2534.14dc: 00007ff61f917b71 / 0x0107b71: 00 != 50
- 2534.14dc: 00007ff61f917b72 / 0x0107b72: 00 != 41
- 2534.14dc: 00007ff61f917b73 / 0x0107b73: 00 != 44
- 2534.14dc: 00007ff61f917b74 / 0x0107b74: 00 != 44
- 2534.14dc: 00007ff61f917b75 / 0x0107b75: 00 != 49
- 2534.14dc: 00007ff61f917b76 / 0x0107b76: 00 != 4e
- 2534.14dc: 00007ff61f917b77 / 0x0107b77: 00 != 47
- 2534.14dc: 00007ff61f917b78 / 0x0107b78: 00 != 50
- 2534.14dc: 00007ff61f917b79 / 0x0107b79: 00 != 41
- 2534.14dc: 00007ff61f917b7a / 0x0107b7a: 00 != 44
- 2534.14dc: 00007ff61f917b7b / 0x0107b7b: 00 != 44
- 2534.14dc: 00007ff61f917b7c / 0x0107b7c: 00 != 49
- 2534.14dc: 00007ff61f917b7d / 0x0107b7d: 00 != 4e
- 2534.14dc: 00007ff61f917b7e / 0x0107b7e: 00 != 47
- 2534.14dc: 00007ff61f917b7f / 0x0107b7f: 00 != 58
- 2534.14dc: 00007ff61f917b80 / 0x0107b80: 00 != 58
- 2534.14dc: 00007ff61f917b81 / 0x0107b81: 00 != 50
- 2534.14dc: 00007ff61f917b82 / 0x0107b82: 00 != 41
- 2534.14dc: 00007ff61f917b83 / 0x0107b83: 00 != 44
- 2534.14dc: 00007ff61f917b84 / 0x0107b84: 00 != 44
- 2534.14dc: 00007ff61f917b85 / 0x0107b85: 00 != 49
- 2534.14dc: 00007ff61f917b86 / 0x0107b86: 00 != 4e
- 2534.14dc: 00007ff61f917b87 / 0x0107b87: 00 != 47
- 2534.14dc: 00007ff61f917b88 / 0x0107b88: 00 != 50
- 2534.14dc: 00007ff61f917b89 / 0x0107b89: 00 != 41
- 2534.14dc: 00007ff61f917b8a / 0x0107b8a: 00 != 44
- 2534.14dc: 00007ff61f917b8b / 0x0107b8b: 00 != 44
- 2534.14dc: 00007ff61f917b8c / 0x0107b8c: 00 != 49
- 2534.14dc: 00007ff61f917b8d / 0x0107b8d: 00 != 4e
- 2534.14dc: 00007ff61f917b8e / 0x0107b8e: 00 != 47
- 2534.14dc: 00007ff61f917b8f / 0x0107b8f: 00 != 58
- 2534.14dc: 00007ff61f917b90 / 0x0107b90: 00 != 58
- 2534.14dc: 00007ff61f917b91 / 0x0107b91: 00 != 50
- 2534.14dc: 00007ff61f917b92 / 0x0107b92: 00 != 41
- 2534.14dc: 00007ff61f917b93 / 0x0107b93: 00 != 44
- 2534.14dc: 00007ff61f917b94 / 0x0107b94: 00 != 44
- 2534.14dc: 00007ff61f917b95 / 0x0107b95: 00 != 49
- 2534.14dc: 00007ff61f917b96 / 0x0107b96: 00 != 4e
- 2534.14dc: 00007ff61f917b97 / 0x0107b97: 00 != 47
- 2534.14dc: 00007ff61f917b98 / 0x0107b98: 00 != 50
- 2534.14dc: 00007ff61f917b99 / 0x0107b99: 00 != 41
- 2534.14dc: 00007ff61f917b9a / 0x0107b9a: 00 != 44
- 2534.14dc: 00007ff61f917b9b / 0x0107b9b: 00 != 44
- 2534.14dc: 00007ff61f917b9c / 0x0107b9c: 00 != 49
- 2534.14dc: 00007ff61f917b9d / 0x0107b9d: 00 != 4e
- 2534.14dc: 00007ff61f917b9e / 0x0107b9e: 00 != 47
- 2534.14dc: 00007ff61f917b9f / 0x0107b9f: 00 != 58
- 2534.14dc: 00007ff61f917ba0 / 0x0107ba0: 00 != 58
- 2534.14dc: 00007ff61f917ba1 / 0x0107ba1: 00 != 50
- 2534.14dc: 00007ff61f917ba2 / 0x0107ba2: 00 != 41
- 2534.14dc: 00007ff61f917ba3 / 0x0107ba3: 00 != 44
- 2534.14dc: 00007ff61f917ba4 / 0x0107ba4: 00 != 44
- 2534.14dc: 00007ff61f917ba5 / 0x0107ba5: 00 != 49
- 2534.14dc: 00007ff61f917ba6 / 0x0107ba6: 00 != 4e
- 2534.14dc: 00007ff61f917ba7 / 0x0107ba7: 00 != 47
- 2534.14dc: 00007ff61f917ba8 / 0x0107ba8: 00 != 50
- 2534.14dc: 00007ff61f917ba9 / 0x0107ba9: 00 != 41
- 2534.14dc: 00007ff61f917baa / 0x0107baa: 00 != 44
- 2534.14dc: 00007ff61f917bab / 0x0107bab: 00 != 44
- 2534.14dc: 00007ff61f917bac / 0x0107bac: 00 != 49
- 2534.14dc: 00007ff61f917bad / 0x0107bad: 00 != 4e
- 2534.14dc: 00007ff61f917bae / 0x0107bae: 00 != 47
- 2534.14dc: 00007ff61f917baf / 0x0107baf: 00 != 58
- 2534.14dc: 00007ff61f917bb0 / 0x0107bb0: 00 != 58
- 2534.14dc: 00007ff61f917bb1 / 0x0107bb1: 00 != 50
- 2534.14dc: 00007ff61f917bb2 / 0x0107bb2: 00 != 41
- 2534.14dc: 00007ff61f917bb3 / 0x0107bb3: 00 != 44
- 2534.14dc: 00007ff61f917bb4 / 0x0107bb4: 00 != 44
- 2534.14dc: 00007ff61f917bb5 / 0x0107bb5: 00 != 49
- 2534.14dc: 00007ff61f917bb6 / 0x0107bb6: 00 != 4e
- 2534.14dc: 00007ff61f917bb7 / 0x0107bb7: 00 != 47
- 2534.14dc: 00007ff61f917bb8 / 0x0107bb8: 00 != 50
- 2534.14dc: 00007ff61f917bb9 / 0x0107bb9: 00 != 41
- 2534.14dc: 00007ff61f917bba / 0x0107bba: 00 != 44
- 2534.14dc: 00007ff61f917bbb / 0x0107bbb: 00 != 44
- 2534.14dc: 00007ff61f917bbc / 0x0107bbc: 00 != 49
- 2534.14dc: 00007ff61f917bbd / 0x0107bbd: 00 != 4e
- 2534.14dc: 00007ff61f917bbe / 0x0107bbe: 00 != 47
- 2534.14dc: 00007ff61f917bbf / 0x0107bbf: 00 != 58
- 2534.14dc: 00007ff61f917bc0 / 0x0107bc0: 00 != 58
- 2534.14dc: 00007ff61f917bc1 / 0x0107bc1: 00 != 50
- 2534.14dc: 00007ff61f917bc2 / 0x0107bc2: 00 != 41
- 2534.14dc: 00007ff61f917bc3 / 0x0107bc3: 00 != 44
- 2534.14dc: 00007ff61f917bc4 / 0x0107bc4: 00 != 44
- 2534.14dc: 00007ff61f917bc5 / 0x0107bc5: 00 != 49
- 2534.14dc: 00007ff61f917bc6 / 0x0107bc6: 00 != 4e
- 2534.14dc: 00007ff61f917bc7 / 0x0107bc7: 00 != 47
- 2534.14dc: 00007ff61f917bc8 / 0x0107bc8: 00 != 50
- 2534.14dc: 00007ff61f917bc9 / 0x0107bc9: 00 != 41
- 2534.14dc: 00007ff61f917bca / 0x0107bca: 00 != 44
- 2534.14dc: 00007ff61f917bcb / 0x0107bcb: 00 != 44
- 2534.14dc: 00007ff61f917bcc / 0x0107bcc: 00 != 49
- 2534.14dc: 00007ff61f917bcd / 0x0107bcd: 00 != 4e
- 2534.14dc: 00007ff61f917bce / 0x0107bce: 00 != 47
- 2534.14dc: 00007ff61f917bcf / 0x0107bcf: 00 != 58
- 2534.14dc: 00007ff61f917bd0 / 0x0107bd0: 00 != 58
- 2534.14dc: 00007ff61f917bd1 / 0x0107bd1: 00 != 50
- 2534.14dc: 00007ff61f917bd2 / 0x0107bd2: 00 != 41
- 2534.14dc: 00007ff61f917bd3 / 0x0107bd3: 00 != 44
- 2534.14dc: 00007ff61f917bd4 / 0x0107bd4: 00 != 44
- 2534.14dc: 00007ff61f917bd5 / 0x0107bd5: 00 != 49
- 2534.14dc: 00007ff61f917bd6 / 0x0107bd6: 00 != 4e
- 2534.14dc: 00007ff61f917bd7 / 0x0107bd7: 00 != 47
- 2534.14dc: 00007ff61f917bd8 / 0x0107bd8: 00 != 50
- 2534.14dc: 00007ff61f917bd9 / 0x0107bd9: 00 != 41
- 2534.14dc: 00007ff61f917bda / 0x0107bda: 00 != 44
- 2534.14dc: 00007ff61f917bdb / 0x0107bdb: 00 != 44
- 2534.14dc: 00007ff61f917bdc / 0x0107bdc: 00 != 49
- 2534.14dc: 00007ff61f917bdd / 0x0107bdd: 00 != 4e
- 2534.14dc: 00007ff61f917bde / 0x0107bde: 00 != 47
- 2534.14dc: 00007ff61f917bdf / 0x0107bdf: 00 != 58
- 2534.14dc: 00007ff61f917be0 / 0x0107be0: 00 != 58
- 2534.14dc: 00007ff61f917be1 / 0x0107be1: 00 != 50
- 2534.14dc: 00007ff61f917be2 / 0x0107be2: 00 != 41
- 2534.14dc: 00007ff61f917be3 / 0x0107be3: 00 != 44
- 2534.14dc: 00007ff61f917be4 / 0x0107be4: 00 != 44
- 2534.14dc: 00007ff61f917be5 / 0x0107be5: 00 != 49
- 2534.14dc: 00007ff61f917be6 / 0x0107be6: 00 != 4e
- 2534.14dc: 00007ff61f917be7 / 0x0107be7: 00 != 47
- 2534.14dc: 00007ff61f917be8 / 0x0107be8: 00 != 50
- 2534.14dc: 00007ff61f917be9 / 0x0107be9: 00 != 41
- 2534.14dc: 00007ff61f917bea / 0x0107bea: 00 != 44
- 2534.14dc: 00007ff61f917beb / 0x0107beb: 00 != 44
- 2534.14dc: 00007ff61f917bec / 0x0107bec: 00 != 49
- 2534.14dc: 00007ff61f917bed / 0x0107bed: 00 != 4e
- 2534.14dc: 00007ff61f917bee / 0x0107bee: 00 != 47
- 2534.14dc: 00007ff61f917bef / 0x0107bef: 00 != 58
- 2534.14dc: 00007ff61f917bf0 / 0x0107bf0: 00 != 58
- 2534.14dc: 00007ff61f917bf1 / 0x0107bf1: 00 != 50
- 2534.14dc: 00007ff61f917bf2 / 0x0107bf2: 00 != 41
- 2534.14dc: 00007ff61f917bf3 / 0x0107bf3: 00 != 44
- 2534.14dc: 00007ff61f917bf4 / 0x0107bf4: 00 != 44
- 2534.14dc: 00007ff61f917bf5 / 0x0107bf5: 00 != 49
- 2534.14dc: 00007ff61f917bf6 / 0x0107bf6: 00 != 4e
- 2534.14dc: 00007ff61f917bf7 / 0x0107bf7: 00 != 47
- 2534.14dc: 00007ff61f917bf8 / 0x0107bf8: 00 != 50
- 2534.14dc: 00007ff61f917bf9 / 0x0107bf9: 00 != 41
- 2534.14dc: 00007ff61f917bfa / 0x0107bfa: 00 != 44
- 2534.14dc: 00007ff61f917bfb / 0x0107bfb: 00 != 44
- 2534.14dc: 00007ff61f917bfc / 0x0107bfc: 00 != 49
- 2534.14dc: 00007ff61f917bfd / 0x0107bfd: 00 != 4e
- 2534.14dc: 00007ff61f917bfe / 0x0107bfe: 00 != 47
- 2534.14dc: 00007ff61f917bff / 0x0107bff: 00 != 58
- 2534.14dc: Restored 0x4d8 bytes of original file content at 00007ff61f917b28
- 2534.14dc: '\Device\HarddiskVolume5\Windows\System32\ntdll.dll' has no imports
- 2534.14dc: ntdll.dll: Differences in section #9 (.00cfg) between file and memory:
- 2534.14dc: 00007ffbd8eaf000 / 0x019f000: 90 != b0
- 2534.14dc: 00007ffbd8eaf001 / 0x019f001: 40 != f3
- 2534.14dc: 00007ffbd8eaf002 / 0x019f002: db != d9
- 2534.14dc: 00007ffbd8eaf008 / 0x019f008: 60 != 70
- 2534.14dc: 00007ffbd8eaf009 / 0x019f009: f1 != f2
- 2534.14dc: 00007ffbd8eaf011 / 0x019f011: 40 != f3
- 2534.14dc: 00007ffbd8eaf012 / 0x019f012: db != d9
- 2534.14dc: 00007ffbd8eaf019 / 0x019f019: 40 != f3
- 2534.14dc: 00007ffbd8eaf01a / 0x019f01a: db != d9
- 2534.14dc: Restored 0x28 bytes of original file content at 00007ffbd8eaf000
- 2534.14dc: kernel32.dll: Differences in section #2 (.rdata) between file and memory:
- 2534.14dc: 00007ffbd78f66d8 / 0x00866d8: 10 != 70
- 2534.14dc: 00007ffbd78f66d9 / 0x00866d9: 01 != f2
- 2534.14dc: 00007ffbd78f66da / 0x00866da: 89 != d9
- 2534.14dc: 00007ffbd78f66db / 0x00866db: d7 != d8
- 2534.14dc: 00007ffbd78f66e0 / 0x00866e0: f0 != b0
- 2534.14dc: 00007ffbd78f66e1 / 0x00866e1: 42 != f3
- 2534.14dc: 00007ffbd78f66e2 / 0x00866e2: 89 != d9
- 2534.14dc: 00007ffbd78f66e3 / 0x00866e3: d7 != d8
- 2534.14dc: 00007ffbd78f66e8 / 0x00866e8: 10 != 70
- 2534.14dc: 00007ffbd78f66e9 / 0x00866e9: 01 != f2
- 2534.14dc: 00007ffbd78f66ea / 0x00866ea: 89 != d9
- 2534.14dc: 00007ffbd78f66eb / 0x00866eb: d7 != d8
- 2534.14dc: 00007ffbd78f66f0 / 0x00866f0: 10 != b0
- 2534.14dc: 00007ffbd78f66f1 / 0x00866f1: 43 != f3
- 2534.14dc: 00007ffbd78f66f2 / 0x00866f2: 89 != d9
- 2534.14dc: 00007ffbd78f66f3 / 0x00866f3: d7 != d8
- 2534.14dc: 00007ffbd78f66f8 / 0x00866f8: 10 != b0
- 2534.14dc: 00007ffbd78f66f9 / 0x00866f9: 43 != f3
- 2534.14dc: 00007ffbd78f66fa / 0x00866fa: 89 != d9
- 2534.14dc: 00007ffbd78f66fb / 0x00866fb: d7 != d8
- 2534.14dc: Restored 0x2000 bytes of original file content at 00007ffbd78f6000
- 2534.14dc: kernelbase.dll: Differences in section #2 (.rdata) between file and memory:
- 2534.14dc: 00007ffbd60d5f88 / 0x0285f88: a0 != 70
- 2534.14dc: 00007ffbd60d5f89 / 0x0285f89: 25 != f2
- 2534.14dc: 00007ffbd60d5f8a / 0x0285f8a: f4 != d9
- 2534.14dc: 00007ffbd60d5f8b / 0x0285f8b: d5 != d8
- 2534.14dc: 00007ffbd60d5f90 / 0x0285f90: 50 != b0
- 2534.14dc: 00007ffbd60d5f91 / 0x0285f91: 29 != f3
- 2534.14dc: 00007ffbd60d5f92 / 0x0285f92: f4 != d9
- 2534.14dc: 00007ffbd60d5f93 / 0x0285f93: d5 != d8
- 2534.14dc: 00007ffbd60d5f98 / 0x0285f98: a0 != 70
- 2534.14dc: 00007ffbd60d5f99 / 0x0285f99: 25 != f2
- 2534.14dc: 00007ffbd60d5f9a / 0x0285f9a: f4 != d9
- 2534.14dc: 00007ffbd60d5f9b / 0x0285f9b: d5 != d8
- 2534.14dc: 00007ffbd60d5fa0 / 0x0285fa0: 70 != b0
- 2534.14dc: 00007ffbd60d5fa1 / 0x0285fa1: 29 != f3
- 2534.14dc: 00007ffbd60d5fa2 / 0x0285fa2: f4 != d9
- 2534.14dc: 00007ffbd60d5fa3 / 0x0285fa3: d5 != d8
- 2534.14dc: 00007ffbd60d5fa8 / 0x0285fa8: 70 != b0
- 2534.14dc: 00007ffbd60d5fa9 / 0x0285fa9: 29 != f3
- 2534.14dc: 00007ffbd60d5faa / 0x0285faa: f4 != d9
- 2534.14dc: 00007ffbd60d5fab / 0x0285fab: d5 != d8
- 2534.14dc: Restored 0x2000 bytes of original file content at 00007ffbd60d5000
- 2534.14dc: supHardNtVpCheckHandles:
- 2534.14dc: supR3HardenedWinInit: SUPHARDNTVPKIND_SELF_PURIFICATION_LIMITED -> VINF_SUCCESS, cFixes=5
- 2534.14dc: '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
- 2534.14dc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe)
- 2534.14dc: supR3HardNtEnableThreadCreationEx:
- 2534.14dc: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffbd8d84440 pvNtTerminateThread=00007ffbd8db0e30
- 2534.14dc: supR3HardenedWinDoReSpawn(1): New child 46ec.54b0 [kernel32].
- 2534.14dc: supR3HardNtChildGatherData: PebBaseAddress=000000af28088000 cbPeb=0x388
- 2534.14dc: supR3HardNtPuChFindNtdll: uNtDllParentAddr=00007ffbd8d10000 uNtDllChildAddr=00007ffbd8d10000
- 2534.14dc: supR3HardenedWinSetupChildInit: uLdrInitThunk=00007ffbd8d84440
- 2534.14dc: supR3HardenedWinSetupChildInit: Initial context:
- rax=0000000000000000 rbx=0000000000000000 rcx=00007ff61f81b850 rdx=000000af28088000
- rsi=0000000000000000 rdi=0000000000000000 r8 =0000000000000000 r9 =0000000000000000
- r10=0000000000000000 r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
- r14=0000000000000000 r15=0000000000000000 P1=0000000000000000 P2=0000000000000000
- rip=00007ffbd8d6af10 rsp=000000af27fffef8 rbp=0000000000000000 ctxflags=0010001b
- cs=0033 ss=002b ds=0000 es=0000 fs=0000 gs=0000 eflags=00000200 mxcrx=00001f80
- P3=0000000000000000 P4=0000000000000000 P5=0000000000000000 P6=0000000000000000
- dr0=0000000000000000 dr1=0000000000000000 dr2=0000000000000000 dr3=0000000000000000
- dr6=0000000000000000 dr7=0000000000000000 vcr=0000000000000000 dcr=0000000000000000
- lbt=0000000000000000 lbf=0000000000000000 lxt=0000000000000000 lxf=0000000000000000
- 2534.14dc: supR3HardenedWinSetupChildInit: Start child.
- 2534.14dc: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
- 2534.14dc: supR3HardNtChildPurify: Startup delay kludge #1/0: 258 ms, 16 sleeps
- 2534.14dc: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
- 2534.14dc: *0000000000000000-000000007ffdffff 0x0001/0x0000 0x0000000
- 2534.14dc: *000000007ffe0000-000000007ffe0fff 0x0002/0x0002 0x0020000
- 2534.14dc: 000000007ffe1000-000000007ffe8fff 0x0001/0x0000 0x0000000
- 2534.14dc: *000000007ffe9000-000000007ffe9fff 0x0002/0x0002 0x0020000
- 2534.14dc: 000000007ffea000-000000af27efffff 0x0001/0x0000 0x0000000
- 2534.14dc: *000000af27f00000-000000af27ffafff 0x0000/0x0004 0x0020000
- 2534.14dc: 000000af27ffb000-000000af27ffdfff 0x0104/0x0004 0x0020000
- 2534.14dc: 000000af27ffe000-000000af27ffffff 0x0004/0x0004 0x0020000
- 2534.14dc: *000000af28000000-000000af28087fff 0x0000/0x0004 0x0020000
- 2534.14dc: 000000af28088000-000000af2808afff 0x0004/0x0004 0x0020000
- 2534.14dc: 000000af2808b000-000000af281fffff 0x0000/0x0004 0x0020000
- 2534.14dc: 000000af28200000-000002855f25ffff 0x0001/0x0000 0x0000000
- 2534.14dc: *000002855f260000-000002855f27ffff 0x0004/0x0004 0x0020000
- 2534.14dc: *000002855f280000-000002855f29efff 0x0002/0x0002 0x0040000
- 2534.14dc: 000002855f29f000-000002855f29ffff 0x0001/0x0000 0x0000000
- 2534.14dc: *000002855f2a0000-000002855f2a3fff 0x0002/0x0002 0x0040000
- 2534.14dc: 000002855f2a4000-000002855f2affff 0x0001/0x0000 0x0000000
- 2534.14dc: *000002855f2b0000-000002855f2b0fff 0x0002/0x0002 0x0040000
- 2534.14dc: 000002855f2b1000-000002855f2bffff 0x0001/0x0000 0x0000000
- 2534.14dc: *000002855f2c0000-000002855f2c1fff 0x0004/0x0004 0x0020000
- 2534.14dc: 000002855f2c2000-00007df54badffff 0x0001/0x0000 0x0000000
- 2534.14dc: *00007df54bae0000-00007df54bae0fff 0x0002/0x0002 0x0040000
- 2534.14dc: 00007df54bae1000-00007df54baeffff 0x0001/0x0000 0x0000000
- 2534.14dc: *00007df54baf0000-00007df54cf72fff 0x0000/0x0001 0x0040000
- 2534.14dc: 00007df54cf73000-00007df54d041fff 0x0001/0x0001 0x0040000
- 2534.14dc: 00007df54d042000-00007df54d8d6fff 0x0000/0x0001 0x0040000
- 2534.14dc: 00007df54d8d7000-00007df54d8d7fff 0x0001/0x0001 0x0040000
- 2534.14dc: 00007df54d8d8000-00007ff5242cffff 0x0000/0x0001 0x0040000
- 2534.14dc: 00007ff5242d0000-00007ff5242d4fff 0x0002/0x0001 0x0040000
- 2534.14dc: 00007ff5242d5000-00007ff537420fff 0x0000/0x0001 0x0040000
- 2534.14dc: 00007ff537421000-00007ff53b123fff 0x0001/0x0001 0x0040000
- 2534.14dc: 00007ff53b124000-00007ff53b12cfff 0x0002/0x0001 0x0040000
- 2534.14dc: 00007ff53b12d000-00007ff54baeffff 0x0000/0x0001 0x0040000
- 2534.14dc: 00007ff54baf0000-00007ff61f80ffff 0x0001/0x0000 0x0000000
- 2534.14dc: *00007ff61f810000-00007ff61f810fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 2534.14dc: 00007ff61f811000-00007ff61f87bfff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 2534.14dc: 00007ff61f87c000-00007ff61f87cfff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 2534.14dc: 00007ff61f87d000-00007ff61f8d1fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 2534.14dc: 00007ff61f8d2000-00007ff61f8d2fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 2534.14dc: 00007ff61f8d3000-00007ff61f8d3fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 2534.14dc: 00007ff61f8d4000-00007ff61f8d8fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 2534.14dc: 00007ff61f8d9000-00007ff61f8defff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 2534.14dc: 00007ff61f8df000-00007ff61f919fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 2534.14dc: 00007ff61f91a000-00007ffbd8d0ffff 0x0001/0x0000 0x0000000
- 2534.14dc: *00007ffbd8d10000-00007ffbd8d10fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\ntdll.dll
- 2534.14dc: 00007ffbd8d11000-00007ffbd8e41fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\ntdll.dll
- 2534.14dc: 00007ffbd8e42000-00007ffbd8e8ffff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\ntdll.dll
- 2534.14dc: 00007ffbd8e90000-00007ffbd8e9bfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\ntdll.dll
- 2534.14dc: 00007ffbd8e9c000-00007ffbd8eaafff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\ntdll.dll
- 2534.14dc: 00007ffbd8eab000-00007ffbd8eabfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\ntdll.dll
- 2534.14dc: 00007ffbd8eac000-00007ffbd8eaefff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\ntdll.dll
- 2534.14dc: 00007ffbd8eaf000-00007ffbd8f26fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\ntdll.dll
- 2534.14dc: 00007ffbd8f27000-00007ffffffeffff 0x0001/0x0000 0x0000000
- 2534.14dc: VirtualBoxVM.exe: Differences in section #8 (.rsrc) between file and memory:
- 2534.14dc: 00007ff61f917b28 / 0x0107b28: 00 != 50
- 2534.14dc: 00007ff61f917b29 / 0x0107b29: 00 != 41
- 2534.14dc: 00007ff61f917b2a / 0x0107b2a: 00 != 44
- 2534.14dc: 00007ff61f917b2b / 0x0107b2b: 00 != 44
- 2534.14dc: 00007ff61f917b2c / 0x0107b2c: 00 != 49
- 2534.14dc: 00007ff61f917b2d / 0x0107b2d: 00 != 4e
- 2534.14dc: 00007ff61f917b2e / 0x0107b2e: 00 != 47
- 2534.14dc: 00007ff61f917b2f / 0x0107b2f: 00 != 58
- 2534.14dc: 00007ff61f917b30 / 0x0107b30: 00 != 58
- 2534.14dc: 00007ff61f917b31 / 0x0107b31: 00 != 50
- 2534.14dc: 00007ff61f917b32 / 0x0107b32: 00 != 41
- 2534.14dc: 00007ff61f917b33 / 0x0107b33: 00 != 44
- 2534.14dc: 00007ff61f917b34 / 0x0107b34: 00 != 44
- 2534.14dc: 00007ff61f917b35 / 0x0107b35: 00 != 49
- 2534.14dc: 00007ff61f917b36 / 0x0107b36: 00 != 4e
- 2534.14dc: 00007ff61f917b37 / 0x0107b37: 00 != 47
- 2534.14dc: 00007ff61f917b38 / 0x0107b38: 00 != 50
- 2534.14dc: 00007ff61f917b39 / 0x0107b39: 00 != 41
- 2534.14dc: 00007ff61f917b3a / 0x0107b3a: 00 != 44
- 2534.14dc: 00007ff61f917b3b / 0x0107b3b: 00 != 44
- 2534.14dc: 00007ff61f917b3c / 0x0107b3c: 00 != 49
- 2534.14dc: 00007ff61f917b3d / 0x0107b3d: 00 != 4e
- 2534.14dc: 00007ff61f917b3e / 0x0107b3e: 00 != 47
- 2534.14dc: 00007ff61f917b3f / 0x0107b3f: 00 != 58
- 2534.14dc: 00007ff61f917b40 / 0x0107b40: 00 != 58
- 2534.14dc: 00007ff61f917b41 / 0x0107b41: 00 != 50
- 2534.14dc: 00007ff61f917b42 / 0x0107b42: 00 != 41
- 2534.14dc: 00007ff61f917b43 / 0x0107b43: 00 != 44
- 2534.14dc: 00007ff61f917b44 / 0x0107b44: 00 != 44
- 2534.14dc: 00007ff61f917b45 / 0x0107b45: 00 != 49
- 2534.14dc: 00007ff61f917b46 / 0x0107b46: 00 != 4e
- 2534.14dc: 00007ff61f917b47 / 0x0107b47: 00 != 47
- 2534.14dc: 00007ff61f917b48 / 0x0107b48: 00 != 50
- 2534.14dc: 00007ff61f917b49 / 0x0107b49: 00 != 41
- 2534.14dc: 00007ff61f917b4a / 0x0107b4a: 00 != 44
- 2534.14dc: 00007ff61f917b4b / 0x0107b4b: 00 != 44
- 2534.14dc: 00007ff61f917b4c / 0x0107b4c: 00 != 49
- 2534.14dc: 00007ff61f917b4d / 0x0107b4d: 00 != 4e
- 2534.14dc: 00007ff61f917b4e / 0x0107b4e: 00 != 47
- 2534.14dc: 00007ff61f917b4f / 0x0107b4f: 00 != 58
- 2534.14dc: 00007ff61f917b50 / 0x0107b50: 00 != 58
- 2534.14dc: 00007ff61f917b51 / 0x0107b51: 00 != 50
- 2534.14dc: 00007ff61f917b52 / 0x0107b52: 00 != 41
- 2534.14dc: 00007ff61f917b53 / 0x0107b53: 00 != 44
- 2534.14dc: 00007ff61f917b54 / 0x0107b54: 00 != 44
- 2534.14dc: 00007ff61f917b55 / 0x0107b55: 00 != 49
- 2534.14dc: 00007ff61f917b56 / 0x0107b56: 00 != 4e
- 2534.14dc: 00007ff61f917b57 / 0x0107b57: 00 != 47
- 2534.14dc: 00007ff61f917b58 / 0x0107b58: 00 != 50
- 2534.14dc: 00007ff61f917b59 / 0x0107b59: 00 != 41
- 2534.14dc: 00007ff61f917b5a / 0x0107b5a: 00 != 44
- 2534.14dc: 00007ff61f917b5b / 0x0107b5b: 00 != 44
- 2534.14dc: 00007ff61f917b5c / 0x0107b5c: 00 != 49
- 2534.14dc: 00007ff61f917b5d / 0x0107b5d: 00 != 4e
- 2534.14dc: 00007ff61f917b5e / 0x0107b5e: 00 != 47
- 2534.14dc: 00007ff61f917b5f / 0x0107b5f: 00 != 58
- 2534.14dc: 00007ff61f917b60 / 0x0107b60: 00 != 58
- 2534.14dc: 00007ff61f917b61 / 0x0107b61: 00 != 50
- 2534.14dc: 00007ff61f917b62 / 0x0107b62: 00 != 41
- 2534.14dc: 00007ff61f917b63 / 0x0107b63: 00 != 44
- 2534.14dc: 00007ff61f917b64 / 0x0107b64: 00 != 44
- 2534.14dc: 00007ff61f917b65 / 0x0107b65: 00 != 49
- 2534.14dc: 00007ff61f917b66 / 0x0107b66: 00 != 4e
- 2534.14dc: 00007ff61f917b67 / 0x0107b67: 00 != 47
- 2534.14dc: 00007ff61f917b68 / 0x0107b68: 00 != 50
- 2534.14dc: 00007ff61f917b69 / 0x0107b69: 00 != 41
- 2534.14dc: 00007ff61f917b6a / 0x0107b6a: 00 != 44
- 2534.14dc: 00007ff61f917b6b / 0x0107b6b: 00 != 44
- 2534.14dc: 00007ff61f917b6c / 0x0107b6c: 00 != 49
- 2534.14dc: 00007ff61f917b6d / 0x0107b6d: 00 != 4e
- 2534.14dc: 00007ff61f917b6e / 0x0107b6e: 00 != 47
- 2534.14dc: 00007ff61f917b6f / 0x0107b6f: 00 != 58
- 2534.14dc: 00007ff61f917b70 / 0x0107b70: 00 != 58
- 2534.14dc: 00007ff61f917b71 / 0x0107b71: 00 != 50
- 2534.14dc: 00007ff61f917b72 / 0x0107b72: 00 != 41
- 2534.14dc: 00007ff61f917b73 / 0x0107b73: 00 != 44
- 2534.14dc: 00007ff61f917b74 / 0x0107b74: 00 != 44
- 2534.14dc: 00007ff61f917b75 / 0x0107b75: 00 != 49
- 2534.14dc: 00007ff61f917b76 / 0x0107b76: 00 != 4e
- 2534.14dc: 00007ff61f917b77 / 0x0107b77: 00 != 47
- 2534.14dc: 00007ff61f917b78 / 0x0107b78: 00 != 50
- 2534.14dc: 00007ff61f917b79 / 0x0107b79: 00 != 41
- 2534.14dc: 00007ff61f917b7a / 0x0107b7a: 00 != 44
- 2534.14dc: 00007ff61f917b7b / 0x0107b7b: 00 != 44
- 2534.14dc: 00007ff61f917b7c / 0x0107b7c: 00 != 49
- 2534.14dc: 00007ff61f917b7d / 0x0107b7d: 00 != 4e
- 2534.14dc: 00007ff61f917b7e / 0x0107b7e: 00 != 47
- 2534.14dc: 00007ff61f917b7f / 0x0107b7f: 00 != 58
- 2534.14dc: 00007ff61f917b80 / 0x0107b80: 00 != 58
- 2534.14dc: 00007ff61f917b81 / 0x0107b81: 00 != 50
- 2534.14dc: 00007ff61f917b82 / 0x0107b82: 00 != 41
- 2534.14dc: 00007ff61f917b83 / 0x0107b83: 00 != 44
- 2534.14dc: 00007ff61f917b84 / 0x0107b84: 00 != 44
- 2534.14dc: 00007ff61f917b85 / 0x0107b85: 00 != 49
- 2534.14dc: 00007ff61f917b86 / 0x0107b86: 00 != 4e
- 2534.14dc: 00007ff61f917b87 / 0x0107b87: 00 != 47
- 2534.14dc: 00007ff61f917b88 / 0x0107b88: 00 != 50
- 2534.14dc: 00007ff61f917b89 / 0x0107b89: 00 != 41
- 2534.14dc: 00007ff61f917b8a / 0x0107b8a: 00 != 44
- 2534.14dc: 00007ff61f917b8b / 0x0107b8b: 00 != 44
- 2534.14dc: 00007ff61f917b8c / 0x0107b8c: 00 != 49
- 2534.14dc: 00007ff61f917b8d / 0x0107b8d: 00 != 4e
- 2534.14dc: 00007ff61f917b8e / 0x0107b8e: 00 != 47
- 2534.14dc: 00007ff61f917b8f / 0x0107b8f: 00 != 58
- 2534.14dc: 00007ff61f917b90 / 0x0107b90: 00 != 58
- 2534.14dc: 00007ff61f917b91 / 0x0107b91: 00 != 50
- 2534.14dc: 00007ff61f917b92 / 0x0107b92: 00 != 41
- 2534.14dc: 00007ff61f917b93 / 0x0107b93: 00 != 44
- 2534.14dc: 00007ff61f917b94 / 0x0107b94: 00 != 44
- 2534.14dc: 00007ff61f917b95 / 0x0107b95: 00 != 49
- 2534.14dc: 00007ff61f917b96 / 0x0107b96: 00 != 4e
- 2534.14dc: 00007ff61f917b97 / 0x0107b97: 00 != 47
- 2534.14dc: 00007ff61f917b98 / 0x0107b98: 00 != 50
- 2534.14dc: 00007ff61f917b99 / 0x0107b99: 00 != 41
- 2534.14dc: 00007ff61f917b9a / 0x0107b9a: 00 != 44
- 2534.14dc: 00007ff61f917b9b / 0x0107b9b: 00 != 44
- 2534.14dc: 00007ff61f917b9c / 0x0107b9c: 00 != 49
- 2534.14dc: 00007ff61f917b9d / 0x0107b9d: 00 != 4e
- 2534.14dc: 00007ff61f917b9e / 0x0107b9e: 00 != 47
- 2534.14dc: 00007ff61f917b9f / 0x0107b9f: 00 != 58
- 2534.14dc: 00007ff61f917ba0 / 0x0107ba0: 00 != 58
- 2534.14dc: 00007ff61f917ba1 / 0x0107ba1: 00 != 50
- 2534.14dc: 00007ff61f917ba2 / 0x0107ba2: 00 != 41
- 2534.14dc: 00007ff61f917ba3 / 0x0107ba3: 00 != 44
- 2534.14dc: 00007ff61f917ba4 / 0x0107ba4: 00 != 44
- 2534.14dc: 00007ff61f917ba5 / 0x0107ba5: 00 != 49
- 2534.14dc: 00007ff61f917ba6 / 0x0107ba6: 00 != 4e
- 2534.14dc: 00007ff61f917ba7 / 0x0107ba7: 00 != 47
- 2534.14dc: 00007ff61f917ba8 / 0x0107ba8: 00 != 50
- 2534.14dc: 00007ff61f917ba9 / 0x0107ba9: 00 != 41
- 2534.14dc: 00007ff61f917baa / 0x0107baa: 00 != 44
- 2534.14dc: 00007ff61f917bab / 0x0107bab: 00 != 44
- 2534.14dc: 00007ff61f917bac / 0x0107bac: 00 != 49
- 2534.14dc: 00007ff61f917bad / 0x0107bad: 00 != 4e
- 2534.14dc: 00007ff61f917bae / 0x0107bae: 00 != 47
- 2534.14dc: 00007ff61f917baf / 0x0107baf: 00 != 58
- 2534.14dc: 00007ff61f917bb0 / 0x0107bb0: 00 != 58
- 2534.14dc: 00007ff61f917bb1 / 0x0107bb1: 00 != 50
- 2534.14dc: 00007ff61f917bb2 / 0x0107bb2: 00 != 41
- 2534.14dc: 00007ff61f917bb3 / 0x0107bb3: 00 != 44
- 2534.14dc: 00007ff61f917bb4 / 0x0107bb4: 00 != 44
- 2534.14dc: 00007ff61f917bb5 / 0x0107bb5: 00 != 49
- 2534.14dc: 00007ff61f917bb6 / 0x0107bb6: 00 != 4e
- 2534.14dc: 00007ff61f917bb7 / 0x0107bb7: 00 != 47
- 2534.14dc: 00007ff61f917bb8 / 0x0107bb8: 00 != 50
- 2534.14dc: 00007ff61f917bb9 / 0x0107bb9: 00 != 41
- 2534.14dc: 00007ff61f917bba / 0x0107bba: 00 != 44
- 2534.14dc: 00007ff61f917bbb / 0x0107bbb: 00 != 44
- 2534.14dc: 00007ff61f917bbc / 0x0107bbc: 00 != 49
- 2534.14dc: 00007ff61f917bbd / 0x0107bbd: 00 != 4e
- 2534.14dc: 00007ff61f917bbe / 0x0107bbe: 00 != 47
- 2534.14dc: 00007ff61f917bbf / 0x0107bbf: 00 != 58
- 2534.14dc: 00007ff61f917bc0 / 0x0107bc0: 00 != 58
- 2534.14dc: 00007ff61f917bc1 / 0x0107bc1: 00 != 50
- 2534.14dc: 00007ff61f917bc2 / 0x0107bc2: 00 != 41
- 2534.14dc: 00007ff61f917bc3 / 0x0107bc3: 00 != 44
- 2534.14dc: 00007ff61f917bc4 / 0x0107bc4: 00 != 44
- 2534.14dc: 00007ff61f917bc5 / 0x0107bc5: 00 != 49
- 2534.14dc: 00007ff61f917bc6 / 0x0107bc6: 00 != 4e
- 2534.14dc: 00007ff61f917bc7 / 0x0107bc7: 00 != 47
- 2534.14dc: 00007ff61f917bc8 / 0x0107bc8: 00 != 50
- 2534.14dc: 00007ff61f917bc9 / 0x0107bc9: 00 != 41
- 2534.14dc: 00007ff61f917bca / 0x0107bca: 00 != 44
- 2534.14dc: 00007ff61f917bcb / 0x0107bcb: 00 != 44
- 2534.14dc: 00007ff61f917bcc / 0x0107bcc: 00 != 49
- 2534.14dc: 00007ff61f917bcd / 0x0107bcd: 00 != 4e
- 2534.14dc: 00007ff61f917bce / 0x0107bce: 00 != 47
- 2534.14dc: 00007ff61f917bcf / 0x0107bcf: 00 != 58
- 2534.14dc: 00007ff61f917bd0 / 0x0107bd0: 00 != 58
- 2534.14dc: 00007ff61f917bd1 / 0x0107bd1: 00 != 50
- 2534.14dc: 00007ff61f917bd2 / 0x0107bd2: 00 != 41
- 2534.14dc: 00007ff61f917bd3 / 0x0107bd3: 00 != 44
- 2534.14dc: 00007ff61f917bd4 / 0x0107bd4: 00 != 44
- 2534.14dc: 00007ff61f917bd5 / 0x0107bd5: 00 != 49
- 2534.14dc: 00007ff61f917bd6 / 0x0107bd6: 00 != 4e
- 2534.14dc: 00007ff61f917bd7 / 0x0107bd7: 00 != 47
- 2534.14dc: 00007ff61f917bd8 / 0x0107bd8: 00 != 50
- 2534.14dc: 00007ff61f917bd9 / 0x0107bd9: 00 != 41
- 2534.14dc: 00007ff61f917bda / 0x0107bda: 00 != 44
- 2534.14dc: 00007ff61f917bdb / 0x0107bdb: 00 != 44
- 2534.14dc: 00007ff61f917bdc / 0x0107bdc: 00 != 49
- 2534.14dc: 00007ff61f917bdd / 0x0107bdd: 00 != 4e
- 2534.14dc: 00007ff61f917bde / 0x0107bde: 00 != 47
- 2534.14dc: 00007ff61f917bdf / 0x0107bdf: 00 != 58
- 2534.14dc: 00007ff61f917be0 / 0x0107be0: 00 != 58
- 2534.14dc: 00007ff61f917be1 / 0x0107be1: 00 != 50
- 2534.14dc: 00007ff61f917be2 / 0x0107be2: 00 != 41
- 2534.14dc: 00007ff61f917be3 / 0x0107be3: 00 != 44
- 2534.14dc: 00007ff61f917be4 / 0x0107be4: 00 != 44
- 2534.14dc: 00007ff61f917be5 / 0x0107be5: 00 != 49
- 2534.14dc: 00007ff61f917be6 / 0x0107be6: 00 != 4e
- 2534.14dc: 00007ff61f917be7 / 0x0107be7: 00 != 47
- 2534.14dc: 00007ff61f917be8 / 0x0107be8: 00 != 50
- 2534.14dc: 00007ff61f917be9 / 0x0107be9: 00 != 41
- 2534.14dc: 00007ff61f917bea / 0x0107bea: 00 != 44
- 2534.14dc: 00007ff61f917beb / 0x0107beb: 00 != 44
- 2534.14dc: 00007ff61f917bec / 0x0107bec: 00 != 49
- 2534.14dc: 00007ff61f917bed / 0x0107bed: 00 != 4e
- 2534.14dc: 00007ff61f917bee / 0x0107bee: 00 != 47
- 2534.14dc: 00007ff61f917bef / 0x0107bef: 00 != 58
- 2534.14dc: 00007ff61f917bf0 / 0x0107bf0: 00 != 58
- 2534.14dc: 00007ff61f917bf1 / 0x0107bf1: 00 != 50
- 2534.14dc: 00007ff61f917bf2 / 0x0107bf2: 00 != 41
- 2534.14dc: 00007ff61f917bf3 / 0x0107bf3: 00 != 44
- 2534.14dc: 00007ff61f917bf4 / 0x0107bf4: 00 != 44
- 2534.14dc: 00007ff61f917bf5 / 0x0107bf5: 00 != 49
- 2534.14dc: 00007ff61f917bf6 / 0x0107bf6: 00 != 4e
- 2534.14dc: 00007ff61f917bf7 / 0x0107bf7: 00 != 47
- 2534.14dc: 00007ff61f917bf8 / 0x0107bf8: 00 != 50
- 2534.14dc: 00007ff61f917bf9 / 0x0107bf9: 00 != 41
- 2534.14dc: 00007ff61f917bfa / 0x0107bfa: 00 != 44
- 2534.14dc: 00007ff61f917bfb / 0x0107bfb: 00 != 44
- 2534.14dc: 00007ff61f917bfc / 0x0107bfc: 00 != 49
- 2534.14dc: 00007ff61f917bfd / 0x0107bfd: 00 != 4e
- 2534.14dc: 00007ff61f917bfe / 0x0107bfe: 00 != 47
- 2534.14dc: 00007ff61f917bff / 0x0107bff: 00 != 58
- 2534.14dc: Restored 0x4d8 bytes of original file content at 00007ff61f917b28
- 2534.14dc: supR3HardNtChildPurify: cFixes=1 g_fSupAdversaries=0x80000000
- 2534.14dc: supR3HardNtChildPurify: Startup delay kludge #1/1: 524 ms, 33 sleeps
- 2534.14dc: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
- 2534.14dc: *0000000000000000-000000007ffdffff 0x0001/0x0000 0x0000000
- 2534.14dc: *000000007ffe0000-000000007ffe0fff 0x0002/0x0002 0x0020000
- 2534.14dc: 000000007ffe1000-000000007ffe8fff 0x0001/0x0000 0x0000000
- 2534.14dc: *000000007ffe9000-000000007ffe9fff 0x0002/0x0002 0x0020000
- 2534.14dc: 000000007ffea000-000000af27efffff 0x0001/0x0000 0x0000000
- 2534.14dc: *000000af27f00000-000000af27ffafff 0x0000/0x0004 0x0020000
- 2534.14dc: 000000af27ffb000-000000af27ffdfff 0x0104/0x0004 0x0020000
- 2534.14dc: 000000af27ffe000-000000af27ffffff 0x0004/0x0004 0x0020000
- 2534.14dc: *000000af28000000-000000af28087fff 0x0000/0x0004 0x0020000
- 2534.14dc: 000000af28088000-000000af2808afff 0x0004/0x0004 0x0020000
- 2534.14dc: 000000af2808b000-000000af281fffff 0x0000/0x0004 0x0020000
- 2534.14dc: 000000af28200000-000002855f25ffff 0x0001/0x0000 0x0000000
- 2534.14dc: *000002855f260000-000002855f27ffff 0x0004/0x0004 0x0020000
- 2534.14dc: *000002855f280000-000002855f29efff 0x0002/0x0002 0x0040000
- 2534.14dc: 000002855f29f000-000002855f29ffff 0x0001/0x0000 0x0000000
- 2534.14dc: *000002855f2a0000-000002855f2a3fff 0x0002/0x0002 0x0040000
- 2534.14dc: 000002855f2a4000-000002855f2affff 0x0001/0x0000 0x0000000
- 2534.14dc: *000002855f2b0000-000002855f2b0fff 0x0002/0x0002 0x0040000
- 2534.14dc: 000002855f2b1000-000002855f2bffff 0x0001/0x0000 0x0000000
- 2534.14dc: *000002855f2c0000-000002855f2c1fff 0x0004/0x0004 0x0020000
- 2534.14dc: 000002855f2c2000-00007df54badffff 0x0001/0x0000 0x0000000
- 2534.14dc: *00007df54bae0000-00007df54bae0fff 0x0002/0x0002 0x0040000
- 2534.14dc: 00007df54bae1000-00007df54baeffff 0x0001/0x0000 0x0000000
- 2534.14dc: *00007df54baf0000-00007df54cf72fff 0x0000/0x0001 0x0040000
- 2534.14dc: 00007df54cf73000-00007df54d041fff 0x0001/0x0001 0x0040000
- 2534.14dc: 00007df54d042000-00007df54d8d6fff 0x0000/0x0001 0x0040000
- 2534.14dc: 00007df54d8d7000-00007df54d8d7fff 0x0001/0x0001 0x0040000
- 2534.14dc: 00007df54d8d8000-00007ff5242cffff 0x0000/0x0001 0x0040000
- 2534.14dc: 00007ff5242d0000-00007ff5242d4fff 0x0002/0x0001 0x0040000
- 2534.14dc: 00007ff5242d5000-00007ff537420fff 0x0000/0x0001 0x0040000
- 2534.14dc: 00007ff537421000-00007ff53b123fff 0x0001/0x0001 0x0040000
- 2534.14dc: 00007ff53b124000-00007ff53b12cfff 0x0002/0x0001 0x0040000
- 2534.14dc: 00007ff53b12d000-00007ff54baeffff 0x0000/0x0001 0x0040000
- 2534.14dc: 00007ff54baf0000-00007ff61f80ffff 0x0001/0x0000 0x0000000
- 2534.14dc: *00007ff61f810000-00007ff61f810fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 2534.14dc: 00007ff61f811000-00007ff61f87bfff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 2534.14dc: 00007ff61f87c000-00007ff61f87cfff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 2534.14dc: 00007ff61f87d000-00007ff61f8d1fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 2534.14dc: 00007ff61f8d2000-00007ff61f8ddfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 2534.14dc: 00007ff61f8de000-00007ff61f8defff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 2534.14dc: 00007ff61f8df000-00007ff61f919fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 2534.14dc: 00007ff61f91a000-00007ffbd8d0ffff 0x0001/0x0000 0x0000000
- 2534.14dc: *00007ffbd8d10000-00007ffbd8d10fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\ntdll.dll
- 2534.14dc: 00007ffbd8d11000-00007ffbd8e41fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\ntdll.dll
- 2534.14dc: 00007ffbd8e42000-00007ffbd8e8ffff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\ntdll.dll
- 2534.14dc: 00007ffbd8e90000-00007ffbd8e93fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\ntdll.dll
- 2534.14dc: 00007ffbd8e94000-00007ffbd8e9bfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\ntdll.dll
- 2534.14dc: 00007ffbd8e9c000-00007ffbd8eaafff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\ntdll.dll
- 2534.14dc: 00007ffbd8eab000-00007ffbd8eabfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\ntdll.dll
- 2534.14dc: 00007ffbd8eac000-00007ffbd8eaefff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\ntdll.dll
- 2534.14dc: 00007ffbd8eaf000-00007ffbd8f26fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\ntdll.dll
- 2534.14dc: 00007ffbd8f27000-00007ffffffeffff 0x0001/0x0000 0x0000000
- 2534.14dc: supR3HardNtChildPurify: Done after 794 ms and 1 fixes (loop #1).
- 46ec.54b0: supR3HardenedVmProcessInit: uNtDllAddr=00007ffbd8d10000 g_uNtVerCombined=0xa0586700 (stack ~000000af27ffecc0)
- 46ec.54b0: ntdll.dll: timestamp 0x36d7bcf8 (rc=VINF_SUCCESS)
- 46ec.54b0: New simple heap: #1 000002855f3d0000 LB 0x800000 (for 2191360 allocation)
- 2534.14dc: supR3HardNtEnableThreadCreationEx:
- 46ec.54b0: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox'
- 46ec.54b0: System32: \Device\HarddiskVolume5\Windows\System32
- 46ec.54b0: WinSxS: \Device\HarddiskVolume5\Windows\WinSxS
- 46ec.54b0: KnownDllPath: C:\Windows\System32
- 46ec.54b0: supR3HardenedVmProcessInit: Opening vboxsup stub...
- 46ec.54b0: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
- 46ec.54b0: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
- 46ec.54b0: Registered Dll notification callback with NTDLL.
- 46ec.54b0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\kernel32.dll)
- 46ec.54b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\kernel32.dll
- 46ec.54b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\KERNEL32.DLL (Input=KERNEL32.DLL, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000004001:<flags> [calling]
- 46ec.54b0: supR3HardenedDllNotificationCallback: load 00007ffbd5e50000 LB 0x003d1000 C:\Windows\System32\KERNELBASE.dll [fFlags=0x0]
- 46ec.54b0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\KernelBase.dll)
- 46ec.54b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\KernelBase.dll
- 46ec.54b0: supR3HardenedDllNotificationCallback: load 00007ffbd7870000 LB 0x000c4000 C:\Windows\System32\KERNEL32.DLL [fFlags=0x0]
- 46ec.54b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
- 46ec.54b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7870000 'C:\Windows\System32\KERNEL32.DLL'
- 46ec.54b0: supR3HardenedDllNotificationCallback: load 00007ff61f810000 LB 0x0010a000 C:\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe [fFlags=0x0]
- 46ec.54b0: '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
- 46ec.54b0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe)
- 46ec.54b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 46ec.54b0: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffbd8d84440 pvNtTerminateThread=00007ffbd8db0e30
- 2534.14dc: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 75 ms.
- 46ec.54b0: \SystemRoot\System32\ntdll.dll:
- 46ec.54b0: CreationTime: 2025-03-12T17:32:50.955934500Z
- 46ec.54b0: LastWriteTime: 2025-03-12T17:32:51.017206900Z
- 46ec.54b0: ChangeTime: 2025-03-13T22:19:28.355125000Z
- 46ec.54b0: FileAttributes: 0x20
- 46ec.54b0: Size: 0x216038
- 46ec.54b0: NT Headers: 0xe8
- 46ec.54b0: Timestamp: 0x36d7bcf8
- 46ec.54b0: Machine: 0x8664 - amd64
- 46ec.54b0: Timestamp: 0x36d7bcf8
- 46ec.54b0: Image Version: 10.0
- 46ec.54b0: SizeOfImage: 0x217000 (2191360)
- 46ec.54b0: Resource Dir: 0x1a0000 LB 0x759a8
- 46ec.54b0: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 46ec.54b0: [Raw version resource data: 0x1a00f0 LB 0x380, codepage 0x0 (reserved 0x0)]
- 46ec.54b0: ProductName: Microsoft® Windows® Operating System
- 46ec.54b0: ProductVersion: 10.0.22621.4974
- 46ec.54b0: FileVersion: 10.0.22621.4974 (WinBuild.160101.0800)
- 46ec.54b0: FileDescription: NT Layer DLL
- 46ec.54b0: \SystemRoot\System32\kernel32.dll:
- 46ec.54b0: CreationTime: 2025-03-12T17:32:50.494392400Z
- 46ec.54b0: LastWriteTime: 2025-03-12T17:32:50.522189500Z
- 46ec.54b0: ChangeTime: 2025-03-13T22:20:04.067768600Z
- 46ec.54b0: FileAttributes: 0x20
- 46ec.54b0: Size: 0xc7188
- 46ec.54b0: NT Headers: 0xe8
- 46ec.54b0: Timestamp: 0x8c0b1418
- 46ec.54b0: Machine: 0x8664 - amd64
- 46ec.54b0: Timestamp: 0x8c0b1418
- 46ec.54b0: Image Version: 10.0
- 46ec.54b0: SizeOfImage: 0xc4000 (802816)
- 46ec.54b0: Resource Dir: 0xc2000 LB 0x520
- 46ec.54b0: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 46ec.54b0: [Raw version resource data: 0xc20b0 LB 0x3a4, codepage 0x0 (reserved 0x0)]
- 46ec.54b0: ProductName: Microsoft® Windows® Operating System
- 46ec.54b0: ProductVersion: 10.0.22621.4974
- 46ec.54b0: FileVersion: 10.0.22621.4974 (WinBuild.160101.0800)
- 46ec.54b0: FileDescription: Windows NT BASE API Client DLL
- 46ec.54b0: \SystemRoot\System32\KernelBase.dll:
- 46ec.54b0: CreationTime: 2025-03-12T17:32:51.859758200Z
- 46ec.54b0: LastWriteTime: 2025-03-12T17:32:52.063051800Z
- 46ec.54b0: ChangeTime: 2025-03-13T22:20:04.207799700Z
- 46ec.54b0: FileAttributes: 0x20
- 46ec.54b0: Size: 0x3d7f18
- 46ec.54b0: NT Headers: 0xf8
- 46ec.54b0: Timestamp: 0xa29a3610
- 46ec.54b0: Machine: 0x8664 - amd64
- 46ec.54b0: Timestamp: 0xa29a3610
- 46ec.54b0: Image Version: 10.0
- 46ec.54b0: SizeOfImage: 0x3d1000 (4001792)
- 46ec.54b0: Resource Dir: 0x3a0000 LB 0x548
- 46ec.54b0: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 46ec.54b0: [Raw version resource data: 0x3a00b0 LB 0x3bc, codepage 0x0 (reserved 0x0)]
- 46ec.54b0: ProductName: Microsoft® Windows® Operating System
- 46ec.54b0: ProductVersion: 10.0.22621.5037
- 46ec.54b0: FileVersion: 10.0.22621.5037 (WinBuild.160101.0800)
- 46ec.54b0: FileDescription: Windows NT BASE API Client DLL
- 46ec.54b0: \SystemRoot\System32\apisetschema.dll:
- 46ec.54b0: CreationTime: 2024-08-18T12:47:44.848835500Z
- 46ec.54b0: LastWriteTime: 2024-08-18T12:47:44.854356200Z
- 46ec.54b0: ChangeTime: 2025-03-12T17:34:36.442764200Z
- 46ec.54b0: FileAttributes: 0x20
- 46ec.54b0: Size: 0x245e0
- 46ec.54b0: NT Headers: 0xc8
- 46ec.54b0: Timestamp: 0x8f476251
- 46ec.54b0: Machine: 0x8664 - amd64
- 46ec.54b0: Timestamp: 0x8f476251
- 46ec.54b0: Image Version: 10.0
- 46ec.54b0: SizeOfImage: 0x23000 (143360)
- 46ec.54b0: Resource Dir: 0x22000 LB 0x408
- 46ec.54b0: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 46ec.54b0: [Raw version resource data: 0x22060 LB 0x3a8, codepage 0x0 (reserved 0x0)]
- 46ec.54b0: ProductName: Microsoft® Windows® Operating System
- 46ec.54b0: ProductVersion: 10.0.22621.3958
- 46ec.54b0: FileVersion: 10.0.22621.3958 (WinBuild.160101.0800)
- 46ec.54b0: FileDescription: ApiSet Schema DLL
- 46ec.54b0: NtOpenDirectoryObject failed on \Driver: 0xc0000022
- 46ec.54b0: supR3HardenedWinFindAdversaries: 0x0
- 46ec.54b0: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox'
- 46ec.54b0: Calling main()
- 46ec.54b0: SUPR3HardenedMain: pszProgName=VirtualBoxVM fFlags=0x2
- 46ec.54b0: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox'
- 46ec.54b0: '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
- 46ec.54b0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe)
- 46ec.54b0: SUPR3HardenedMain: Respawn #2
- 46ec.54b0: supR3HardNtEnableThreadCreationEx:
- 46ec.54b0: supR3HardenedDllNotificationCallback: load 00007ffbd6350000 LB 0x00028000 C:\Windows\System32\bcrypt.dll [fFlags=0x0]
- 46ec.54b0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\bcrypt.dll)
- 46ec.54b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\bcrypt.dll
- 46ec.54b0: supR3HardenedDllNotificationCallback: load 00007ffbd6b90000 LB 0x000a7000 C:\Windows\System32\sechost.dll [fFlags=0x0]
- 46ec.54b0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #24 'bcrypt.dll'.
- 46ec.54b0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\sechost.dll)
- 46ec.54b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\sechost.dll
- 46ec.54b0: '\Device\HarddiskVolume5\Windows\System32\ntdll.dll' has no imports
- 46ec.54b0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\ntdll.dll)
- 46ec.54b0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\ntdll.dll
- 46ec.54b0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
- 46ec.54b0: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume5\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
- 46ec.54b0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
- 46ec.54b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\ntdll.dll (Input=ntdll.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 46ec.54b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd8d10000 'C:\Windows\System32\ntdll.dll'
- 46ec.54b0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\KernelBase.dll [lacks WinVerifyTrust]
- 46ec.54b0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\KernelBase.dll (Input=KernelBase, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 46ec.54b0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd5e50000 'C:\Windows\System32\KernelBase.dll'
- 46ec.54b0: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffbd8d84440 pvNtTerminateThread=00007ffbd8db0e30
- 46ec.54b0: supR3HardenedWinDoReSpawn(2): New child 3f24.31ac [kernel32].
- 46ec.54b0: supR3HardenedWinReSpawn: NtSetInformationThread/ThreadHideFromDebugger failed: 0xc0000022 (harmless)
- 46ec.54b0: supR3HardNtChildGatherData: PebBaseAddress=000000b0eb44c000 cbPeb=0x388
- 46ec.54b0: supR3HardNtPuChFindNtdll: uNtDllParentAddr=00007ffbd8d10000 uNtDllChildAddr=00007ffbd8d10000
- 46ec.54b0: supR3HardenedWinSetupChildInit: uLdrInitThunk=00007ffbd8d84440
- 46ec.54b0: supR3HardenedWinSetupChildInit: Initial context:
- rax=0000000000000000 rbx=0000000000000000 rcx=00007ff61f81b850 rdx=000000b0eb44c000
- rsi=0000000000000000 rdi=0000000000000000 r8 =0000000000000000 r9 =0000000000000000
- r10=0000000000000000 r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
- r14=0000000000000000 r15=0000000000000000 P1=0000000000000000 P2=0000000000000000
- rip=00007ffbd8d6af10 rsp=000000b0eb6fffb8 rbp=0000000000000000 ctxflags=0010001b
- cs=0033 ss=002b ds=0000 es=0000 fs=0000 gs=0000 eflags=00000200 mxcrx=00001f80
- P3=0000000000000000 P4=0000000000000000 P5=0000000000000000 P6=0000000000000000
- dr0=0000000000000000 dr1=0000000000000000 dr2=0000000000000000 dr3=0000000000000000
- dr6=0000000000000000 dr7=0000000000000000 vcr=0000000000000000 dcr=0000000000000000
- lbt=0000000000000000 lbf=0000000000000000 lxt=0000000000000000 lxf=0000000000000000
- 46ec.54b0: kernel32.dll: timestamp 0x8c0b1418 (rc=VINF_SUCCESS)
- 46ec.54b0: supR3HardenedWinSetupChildInit: Start child.
- 46ec.54b0: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
- 46ec.54b0: supR3HardNtChildPurify: Startup delay kludge #1/0: 263 ms, 17 sleeps
- 46ec.54b0: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
- 46ec.54b0: *0000000000000000-000000007ffdffff 0x0001/0x0000 0x0000000
- 46ec.54b0: *000000007ffe0000-000000007ffe0fff 0x0002/0x0002 0x0020000
- 46ec.54b0: 000000007ffe1000-000000007ffe8fff 0x0001/0x0000 0x0000000
- 46ec.54b0: *000000007ffe9000-000000007ffe9fff 0x0002/0x0002 0x0020000
- 46ec.54b0: 000000007ffea000-000000b0eb3fffff 0x0001/0x0000 0x0000000
- 46ec.54b0: *000000b0eb400000-000000b0eb44bfff 0x0000/0x0004 0x0020000
- 46ec.54b0: 000000b0eb44c000-000000b0eb44efff 0x0004/0x0004 0x0020000
- 46ec.54b0: 000000b0eb44f000-000000b0eb5fffff 0x0000/0x0004 0x0020000
- 46ec.54b0: *000000b0eb600000-000000b0eb6fafff 0x0000/0x0004 0x0020000
- 46ec.54b0: 000000b0eb6fb000-000000b0eb6fdfff 0x0104/0x0004 0x0020000
- 46ec.54b0: 000000b0eb6fe000-000000b0eb6fffff 0x0004/0x0004 0x0020000
- 46ec.54b0: 000000b0eb700000-000002440d71ffff 0x0001/0x0000 0x0000000
- 46ec.54b0: *000002440d720000-000002440d73ffff 0x0004/0x0004 0x0020000
- 46ec.54b0: *000002440d740000-000002440d75efff 0x0002/0x0002 0x0040000
- 46ec.54b0: 000002440d75f000-000002440d75ffff 0x0001/0x0000 0x0000000
- 46ec.54b0: *000002440d760000-000002440d763fff 0x0002/0x0002 0x0040000
- 46ec.54b0: 000002440d764000-000002440d76ffff 0x0001/0x0000 0x0000000
- 46ec.54b0: *000002440d770000-000002440d770fff 0x0002/0x0002 0x0040000
- 46ec.54b0: 000002440d771000-000002440d77ffff 0x0001/0x0000 0x0000000
- 46ec.54b0: *000002440d780000-000002440d781fff 0x0004/0x0004 0x0020000
- 46ec.54b0: 000002440d782000-00007df542f5ffff 0x0001/0x0000 0x0000000
- 46ec.54b0: *00007df542f60000-00007df542f60fff 0x0002/0x0002 0x0040000
- 46ec.54b0: 00007df542f61000-00007df542f6ffff 0x0001/0x0000 0x0000000
- 46ec.54b0: *00007df542f70000-00007df5443f2fff 0x0000/0x0001 0x0040000
- 46ec.54b0: 00007df5443f3000-00007df5444c1fff 0x0001/0x0001 0x0040000
- 46ec.54b0: 00007df5444c2000-00007df544d56fff 0x0000/0x0001 0x0040000
- 46ec.54b0: 00007df544d57000-00007df544d57fff 0x0001/0x0001 0x0040000
- 46ec.54b0: 00007df544d58000-00007ff51b74ffff 0x0000/0x0001 0x0040000
- 46ec.54b0: 00007ff51b750000-00007ff51b754fff 0x0002/0x0001 0x0040000
- 46ec.54b0: 00007ff51b755000-00007ff52e8a0fff 0x0000/0x0001 0x0040000
- 46ec.54b0: 00007ff52e8a1000-00007ff5325a3fff 0x0001/0x0001 0x0040000
- 46ec.54b0: 00007ff5325a4000-00007ff5325acfff 0x0002/0x0001 0x0040000
- 46ec.54b0: 00007ff5325ad000-00007ff542f6ffff 0x0000/0x0001 0x0040000
- 46ec.54b0: 00007ff542f70000-00007ff61f80ffff 0x0001/0x0000 0x0000000
- 46ec.54b0: *00007ff61f810000-00007ff61f810fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 46ec.54b0: 00007ff61f811000-00007ff61f87bfff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 46ec.54b0: 00007ff61f87c000-00007ff61f87cfff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 46ec.54b0: 00007ff61f87d000-00007ff61f8d1fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 46ec.54b0: 00007ff61f8d2000-00007ff61f8d2fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 46ec.54b0: 00007ff61f8d3000-00007ff61f8d3fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 46ec.54b0: 00007ff61f8d4000-00007ff61f8d8fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 46ec.54b0: 00007ff61f8d9000-00007ff61f8defff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 46ec.54b0: 00007ff61f8df000-00007ff61f919fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 46ec.54b0: 00007ff61f91a000-00007ffbd8d0ffff 0x0001/0x0000 0x0000000
- 46ec.54b0: *00007ffbd8d10000-00007ffbd8d10fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\ntdll.dll
- 46ec.54b0: 00007ffbd8d11000-00007ffbd8e41fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\ntdll.dll
- 46ec.54b0: 00007ffbd8e42000-00007ffbd8e8ffff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\ntdll.dll
- 46ec.54b0: 00007ffbd8e90000-00007ffbd8e9bfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\ntdll.dll
- 46ec.54b0: 00007ffbd8e9c000-00007ffbd8eaafff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\ntdll.dll
- 46ec.54b0: 00007ffbd8eab000-00007ffbd8eabfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\ntdll.dll
- 46ec.54b0: 00007ffbd8eac000-00007ffbd8eaefff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\ntdll.dll
- 46ec.54b0: 00007ffbd8eaf000-00007ffbd8f26fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\ntdll.dll
- 46ec.54b0: 00007ffbd8f27000-00007ffffffeffff 0x0001/0x0000 0x0000000
- 46ec.54b0: VirtualBoxVM.exe: timestamp 0x678f9dd6 (rc=VINF_SUCCESS)
- 46ec.54b0: '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
- 46ec.54b0: VirtualBoxVM.exe: Differences in section #8 (.rsrc) between file and memory:
- 46ec.54b0: 00007ff61f917b28 / 0x0107b28: 00 != 50
- 46ec.54b0: 00007ff61f917b29 / 0x0107b29: 00 != 41
- 46ec.54b0: 00007ff61f917b2a / 0x0107b2a: 00 != 44
- 46ec.54b0: 00007ff61f917b2b / 0x0107b2b: 00 != 44
- 46ec.54b0: 00007ff61f917b2c / 0x0107b2c: 00 != 49
- 46ec.54b0: 00007ff61f917b2d / 0x0107b2d: 00 != 4e
- 46ec.54b0: 00007ff61f917b2e / 0x0107b2e: 00 != 47
- 46ec.54b0: 00007ff61f917b2f / 0x0107b2f: 00 != 58
- 46ec.54b0: 00007ff61f917b30 / 0x0107b30: 00 != 58
- 46ec.54b0: 00007ff61f917b31 / 0x0107b31: 00 != 50
- 46ec.54b0: 00007ff61f917b32 / 0x0107b32: 00 != 41
- 46ec.54b0: 00007ff61f917b33 / 0x0107b33: 00 != 44
- 46ec.54b0: 00007ff61f917b34 / 0x0107b34: 00 != 44
- 46ec.54b0: 00007ff61f917b35 / 0x0107b35: 00 != 49
- 46ec.54b0: 00007ff61f917b36 / 0x0107b36: 00 != 4e
- 46ec.54b0: 00007ff61f917b37 / 0x0107b37: 00 != 47
- 46ec.54b0: 00007ff61f917b38 / 0x0107b38: 00 != 50
- 46ec.54b0: 00007ff61f917b39 / 0x0107b39: 00 != 41
- 46ec.54b0: 00007ff61f917b3a / 0x0107b3a: 00 != 44
- 46ec.54b0: 00007ff61f917b3b / 0x0107b3b: 00 != 44
- 46ec.54b0: 00007ff61f917b3c / 0x0107b3c: 00 != 49
- 46ec.54b0: 00007ff61f917b3d / 0x0107b3d: 00 != 4e
- 46ec.54b0: 00007ff61f917b3e / 0x0107b3e: 00 != 47
- 46ec.54b0: 00007ff61f917b3f / 0x0107b3f: 00 != 58
- 46ec.54b0: 00007ff61f917b40 / 0x0107b40: 00 != 58
- 46ec.54b0: 00007ff61f917b41 / 0x0107b41: 00 != 50
- 46ec.54b0: 00007ff61f917b42 / 0x0107b42: 00 != 41
- 46ec.54b0: 00007ff61f917b43 / 0x0107b43: 00 != 44
- 46ec.54b0: 00007ff61f917b44 / 0x0107b44: 00 != 44
- 46ec.54b0: 00007ff61f917b45 / 0x0107b45: 00 != 49
- 46ec.54b0: 00007ff61f917b46 / 0x0107b46: 00 != 4e
- 46ec.54b0: 00007ff61f917b47 / 0x0107b47: 00 != 47
- 46ec.54b0: 00007ff61f917b48 / 0x0107b48: 00 != 50
- 46ec.54b0: 00007ff61f917b49 / 0x0107b49: 00 != 41
- 46ec.54b0: 00007ff61f917b4a / 0x0107b4a: 00 != 44
- 46ec.54b0: 00007ff61f917b4b / 0x0107b4b: 00 != 44
- 46ec.54b0: 00007ff61f917b4c / 0x0107b4c: 00 != 49
- 46ec.54b0: 00007ff61f917b4d / 0x0107b4d: 00 != 4e
- 46ec.54b0: 00007ff61f917b4e / 0x0107b4e: 00 != 47
- 46ec.54b0: 00007ff61f917b4f / 0x0107b4f: 00 != 58
- 46ec.54b0: 00007ff61f917b50 / 0x0107b50: 00 != 58
- 46ec.54b0: 00007ff61f917b51 / 0x0107b51: 00 != 50
- 46ec.54b0: 00007ff61f917b52 / 0x0107b52: 00 != 41
- 46ec.54b0: 00007ff61f917b53 / 0x0107b53: 00 != 44
- 46ec.54b0: 00007ff61f917b54 / 0x0107b54: 00 != 44
- 46ec.54b0: 00007ff61f917b55 / 0x0107b55: 00 != 49
- 46ec.54b0: 00007ff61f917b56 / 0x0107b56: 00 != 4e
- 46ec.54b0: 00007ff61f917b57 / 0x0107b57: 00 != 47
- 46ec.54b0: 00007ff61f917b58 / 0x0107b58: 00 != 50
- 46ec.54b0: 00007ff61f917b59 / 0x0107b59: 00 != 41
- 46ec.54b0: 00007ff61f917b5a / 0x0107b5a: 00 != 44
- 46ec.54b0: 00007ff61f917b5b / 0x0107b5b: 00 != 44
- 46ec.54b0: 00007ff61f917b5c / 0x0107b5c: 00 != 49
- 46ec.54b0: 00007ff61f917b5d / 0x0107b5d: 00 != 4e
- 46ec.54b0: 00007ff61f917b5e / 0x0107b5e: 00 != 47
- 46ec.54b0: 00007ff61f917b5f / 0x0107b5f: 00 != 58
- 46ec.54b0: 00007ff61f917b60 / 0x0107b60: 00 != 58
- 46ec.54b0: 00007ff61f917b61 / 0x0107b61: 00 != 50
- 46ec.54b0: 00007ff61f917b62 / 0x0107b62: 00 != 41
- 46ec.54b0: 00007ff61f917b63 / 0x0107b63: 00 != 44
- 46ec.54b0: 00007ff61f917b64 / 0x0107b64: 00 != 44
- 46ec.54b0: 00007ff61f917b65 / 0x0107b65: 00 != 49
- 46ec.54b0: 00007ff61f917b66 / 0x0107b66: 00 != 4e
- 46ec.54b0: 00007ff61f917b67 / 0x0107b67: 00 != 47
- 46ec.54b0: 00007ff61f917b68 / 0x0107b68: 00 != 50
- 46ec.54b0: 00007ff61f917b69 / 0x0107b69: 00 != 41
- 46ec.54b0: 00007ff61f917b6a / 0x0107b6a: 00 != 44
- 46ec.54b0: 00007ff61f917b6b / 0x0107b6b: 00 != 44
- 46ec.54b0: 00007ff61f917b6c / 0x0107b6c: 00 != 49
- 46ec.54b0: 00007ff61f917b6d / 0x0107b6d: 00 != 4e
- 46ec.54b0: 00007ff61f917b6e / 0x0107b6e: 00 != 47
- 46ec.54b0: 00007ff61f917b6f / 0x0107b6f: 00 != 58
- 46ec.54b0: 00007ff61f917b70 / 0x0107b70: 00 != 58
- 46ec.54b0: 00007ff61f917b71 / 0x0107b71: 00 != 50
- 46ec.54b0: 00007ff61f917b72 / 0x0107b72: 00 != 41
- 46ec.54b0: 00007ff61f917b73 / 0x0107b73: 00 != 44
- 46ec.54b0: 00007ff61f917b74 / 0x0107b74: 00 != 44
- 46ec.54b0: 00007ff61f917b75 / 0x0107b75: 00 != 49
- 46ec.54b0: 00007ff61f917b76 / 0x0107b76: 00 != 4e
- 46ec.54b0: 00007ff61f917b77 / 0x0107b77: 00 != 47
- 46ec.54b0: 00007ff61f917b78 / 0x0107b78: 00 != 50
- 46ec.54b0: 00007ff61f917b79 / 0x0107b79: 00 != 41
- 46ec.54b0: 00007ff61f917b7a / 0x0107b7a: 00 != 44
- 46ec.54b0: 00007ff61f917b7b / 0x0107b7b: 00 != 44
- 46ec.54b0: 00007ff61f917b7c / 0x0107b7c: 00 != 49
- 46ec.54b0: 00007ff61f917b7d / 0x0107b7d: 00 != 4e
- 46ec.54b0: 00007ff61f917b7e / 0x0107b7e: 00 != 47
- 46ec.54b0: 00007ff61f917b7f / 0x0107b7f: 00 != 58
- 46ec.54b0: 00007ff61f917b80 / 0x0107b80: 00 != 58
- 46ec.54b0: 00007ff61f917b81 / 0x0107b81: 00 != 50
- 46ec.54b0: 00007ff61f917b82 / 0x0107b82: 00 != 41
- 46ec.54b0: 00007ff61f917b83 / 0x0107b83: 00 != 44
- 46ec.54b0: 00007ff61f917b84 / 0x0107b84: 00 != 44
- 46ec.54b0: 00007ff61f917b85 / 0x0107b85: 00 != 49
- 46ec.54b0: 00007ff61f917b86 / 0x0107b86: 00 != 4e
- 46ec.54b0: 00007ff61f917b87 / 0x0107b87: 00 != 47
- 46ec.54b0: 00007ff61f917b88 / 0x0107b88: 00 != 50
- 46ec.54b0: 00007ff61f917b89 / 0x0107b89: 00 != 41
- 46ec.54b0: 00007ff61f917b8a / 0x0107b8a: 00 != 44
- 46ec.54b0: 00007ff61f917b8b / 0x0107b8b: 00 != 44
- 46ec.54b0: 00007ff61f917b8c / 0x0107b8c: 00 != 49
- 46ec.54b0: 00007ff61f917b8d / 0x0107b8d: 00 != 4e
- 46ec.54b0: 00007ff61f917b8e / 0x0107b8e: 00 != 47
- 46ec.54b0: 00007ff61f917b8f / 0x0107b8f: 00 != 58
- 46ec.54b0: 00007ff61f917b90 / 0x0107b90: 00 != 58
- 46ec.54b0: 00007ff61f917b91 / 0x0107b91: 00 != 50
- 46ec.54b0: 00007ff61f917b92 / 0x0107b92: 00 != 41
- 46ec.54b0: 00007ff61f917b93 / 0x0107b93: 00 != 44
- 46ec.54b0: 00007ff61f917b94 / 0x0107b94: 00 != 44
- 46ec.54b0: 00007ff61f917b95 / 0x0107b95: 00 != 49
- 46ec.54b0: 00007ff61f917b96 / 0x0107b96: 00 != 4e
- 46ec.54b0: 00007ff61f917b97 / 0x0107b97: 00 != 47
- 46ec.54b0: 00007ff61f917b98 / 0x0107b98: 00 != 50
- 46ec.54b0: 00007ff61f917b99 / 0x0107b99: 00 != 41
- 46ec.54b0: 00007ff61f917b9a / 0x0107b9a: 00 != 44
- 46ec.54b0: 00007ff61f917b9b / 0x0107b9b: 00 != 44
- 46ec.54b0: 00007ff61f917b9c / 0x0107b9c: 00 != 49
- 46ec.54b0: 00007ff61f917b9d / 0x0107b9d: 00 != 4e
- 46ec.54b0: 00007ff61f917b9e / 0x0107b9e: 00 != 47
- 46ec.54b0: 00007ff61f917b9f / 0x0107b9f: 00 != 58
- 46ec.54b0: 00007ff61f917ba0 / 0x0107ba0: 00 != 58
- 46ec.54b0: 00007ff61f917ba1 / 0x0107ba1: 00 != 50
- 46ec.54b0: 00007ff61f917ba2 / 0x0107ba2: 00 != 41
- 46ec.54b0: 00007ff61f917ba3 / 0x0107ba3: 00 != 44
- 46ec.54b0: 00007ff61f917ba4 / 0x0107ba4: 00 != 44
- 46ec.54b0: 00007ff61f917ba5 / 0x0107ba5: 00 != 49
- 46ec.54b0: 00007ff61f917ba6 / 0x0107ba6: 00 != 4e
- 46ec.54b0: 00007ff61f917ba7 / 0x0107ba7: 00 != 47
- 46ec.54b0: 00007ff61f917ba8 / 0x0107ba8: 00 != 50
- 46ec.54b0: 00007ff61f917ba9 / 0x0107ba9: 00 != 41
- 46ec.54b0: 00007ff61f917baa / 0x0107baa: 00 != 44
- 46ec.54b0: 00007ff61f917bab / 0x0107bab: 00 != 44
- 46ec.54b0: 00007ff61f917bac / 0x0107bac: 00 != 49
- 46ec.54b0: 00007ff61f917bad / 0x0107bad: 00 != 4e
- 46ec.54b0: 00007ff61f917bae / 0x0107bae: 00 != 47
- 46ec.54b0: 00007ff61f917baf / 0x0107baf: 00 != 58
- 46ec.54b0: 00007ff61f917bb0 / 0x0107bb0: 00 != 58
- 46ec.54b0: 00007ff61f917bb1 / 0x0107bb1: 00 != 50
- 46ec.54b0: 00007ff61f917bb2 / 0x0107bb2: 00 != 41
- 46ec.54b0: 00007ff61f917bb3 / 0x0107bb3: 00 != 44
- 46ec.54b0: 00007ff61f917bb4 / 0x0107bb4: 00 != 44
- 46ec.54b0: 00007ff61f917bb5 / 0x0107bb5: 00 != 49
- 46ec.54b0: 00007ff61f917bb6 / 0x0107bb6: 00 != 4e
- 46ec.54b0: 00007ff61f917bb7 / 0x0107bb7: 00 != 47
- 46ec.54b0: 00007ff61f917bb8 / 0x0107bb8: 00 != 50
- 46ec.54b0: 00007ff61f917bb9 / 0x0107bb9: 00 != 41
- 46ec.54b0: 00007ff61f917bba / 0x0107bba: 00 != 44
- 46ec.54b0: 00007ff61f917bbb / 0x0107bbb: 00 != 44
- 46ec.54b0: 00007ff61f917bbc / 0x0107bbc: 00 != 49
- 46ec.54b0: 00007ff61f917bbd / 0x0107bbd: 00 != 4e
- 46ec.54b0: 00007ff61f917bbe / 0x0107bbe: 00 != 47
- 46ec.54b0: 00007ff61f917bbf / 0x0107bbf: 00 != 58
- 46ec.54b0: 00007ff61f917bc0 / 0x0107bc0: 00 != 58
- 46ec.54b0: 00007ff61f917bc1 / 0x0107bc1: 00 != 50
- 46ec.54b0: 00007ff61f917bc2 / 0x0107bc2: 00 != 41
- 46ec.54b0: 00007ff61f917bc3 / 0x0107bc3: 00 != 44
- 46ec.54b0: 00007ff61f917bc4 / 0x0107bc4: 00 != 44
- 46ec.54b0: 00007ff61f917bc5 / 0x0107bc5: 00 != 49
- 46ec.54b0: 00007ff61f917bc6 / 0x0107bc6: 00 != 4e
- 46ec.54b0: 00007ff61f917bc7 / 0x0107bc7: 00 != 47
- 46ec.54b0: 00007ff61f917bc8 / 0x0107bc8: 00 != 50
- 46ec.54b0: 00007ff61f917bc9 / 0x0107bc9: 00 != 41
- 46ec.54b0: 00007ff61f917bca / 0x0107bca: 00 != 44
- 46ec.54b0: 00007ff61f917bcb / 0x0107bcb: 00 != 44
- 46ec.54b0: 00007ff61f917bcc / 0x0107bcc: 00 != 49
- 46ec.54b0: 00007ff61f917bcd / 0x0107bcd: 00 != 4e
- 46ec.54b0: 00007ff61f917bce / 0x0107bce: 00 != 47
- 46ec.54b0: 00007ff61f917bcf / 0x0107bcf: 00 != 58
- 46ec.54b0: 00007ff61f917bd0 / 0x0107bd0: 00 != 58
- 46ec.54b0: 00007ff61f917bd1 / 0x0107bd1: 00 != 50
- 46ec.54b0: 00007ff61f917bd2 / 0x0107bd2: 00 != 41
- 46ec.54b0: 00007ff61f917bd3 / 0x0107bd3: 00 != 44
- 46ec.54b0: 00007ff61f917bd4 / 0x0107bd4: 00 != 44
- 46ec.54b0: 00007ff61f917bd5 / 0x0107bd5: 00 != 49
- 46ec.54b0: 00007ff61f917bd6 / 0x0107bd6: 00 != 4e
- 46ec.54b0: 00007ff61f917bd7 / 0x0107bd7: 00 != 47
- 46ec.54b0: 00007ff61f917bd8 / 0x0107bd8: 00 != 50
- 46ec.54b0: 00007ff61f917bd9 / 0x0107bd9: 00 != 41
- 46ec.54b0: 00007ff61f917bda / 0x0107bda: 00 != 44
- 46ec.54b0: 00007ff61f917bdb / 0x0107bdb: 00 != 44
- 46ec.54b0: 00007ff61f917bdc / 0x0107bdc: 00 != 49
- 46ec.54b0: 00007ff61f917bdd / 0x0107bdd: 00 != 4e
- 46ec.54b0: 00007ff61f917bde / 0x0107bde: 00 != 47
- 46ec.54b0: 00007ff61f917bdf / 0x0107bdf: 00 != 58
- 46ec.54b0: 00007ff61f917be0 / 0x0107be0: 00 != 58
- 46ec.54b0: 00007ff61f917be1 / 0x0107be1: 00 != 50
- 46ec.54b0: 00007ff61f917be2 / 0x0107be2: 00 != 41
- 46ec.54b0: 00007ff61f917be3 / 0x0107be3: 00 != 44
- 46ec.54b0: 00007ff61f917be4 / 0x0107be4: 00 != 44
- 46ec.54b0: 00007ff61f917be5 / 0x0107be5: 00 != 49
- 46ec.54b0: 00007ff61f917be6 / 0x0107be6: 00 != 4e
- 46ec.54b0: 00007ff61f917be7 / 0x0107be7: 00 != 47
- 46ec.54b0: 00007ff61f917be8 / 0x0107be8: 00 != 50
- 46ec.54b0: 00007ff61f917be9 / 0x0107be9: 00 != 41
- 46ec.54b0: 00007ff61f917bea / 0x0107bea: 00 != 44
- 46ec.54b0: 00007ff61f917beb / 0x0107beb: 00 != 44
- 46ec.54b0: 00007ff61f917bec / 0x0107bec: 00 != 49
- 46ec.54b0: 00007ff61f917bed / 0x0107bed: 00 != 4e
- 46ec.54b0: 00007ff61f917bee / 0x0107bee: 00 != 47
- 46ec.54b0: 00007ff61f917bef / 0x0107bef: 00 != 58
- 46ec.54b0: 00007ff61f917bf0 / 0x0107bf0: 00 != 58
- 46ec.54b0: 00007ff61f917bf1 / 0x0107bf1: 00 != 50
- 46ec.54b0: 00007ff61f917bf2 / 0x0107bf2: 00 != 41
- 46ec.54b0: 00007ff61f917bf3 / 0x0107bf3: 00 != 44
- 46ec.54b0: 00007ff61f917bf4 / 0x0107bf4: 00 != 44
- 46ec.54b0: 00007ff61f917bf5 / 0x0107bf5: 00 != 49
- 46ec.54b0: 00007ff61f917bf6 / 0x0107bf6: 00 != 4e
- 46ec.54b0: 00007ff61f917bf7 / 0x0107bf7: 00 != 47
- 46ec.54b0: 00007ff61f917bf8 / 0x0107bf8: 00 != 50
- 46ec.54b0: 00007ff61f917bf9 / 0x0107bf9: 00 != 41
- 46ec.54b0: 00007ff61f917bfa / 0x0107bfa: 00 != 44
- 46ec.54b0: 00007ff61f917bfb / 0x0107bfb: 00 != 44
- 46ec.54b0: 00007ff61f917bfc / 0x0107bfc: 00 != 49
- 46ec.54b0: 00007ff61f917bfd / 0x0107bfd: 00 != 4e
- 46ec.54b0: 00007ff61f917bfe / 0x0107bfe: 00 != 47
- 46ec.54b0: 00007ff61f917bff / 0x0107bff: 00 != 58
- 46ec.54b0: Restored 0x4d8 bytes of original file content at 00007ff61f917b28
- 46ec.54b0: '\Device\HarddiskVolume5\Windows\System32\ntdll.dll' has no imports
- 46ec.54b0: supR3HardNtChildPurify: cFixes=1 g_fSupAdversaries=0x80000000
- 46ec.54b0: supR3HardNtChildPurify: Startup delay kludge #1/1: 515 ms, 33 sleeps
- 46ec.54b0: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
- 46ec.54b0: *0000000000000000-000000007ffdffff 0x0001/0x0000 0x0000000
- 46ec.54b0: *000000007ffe0000-000000007ffe0fff 0x0002/0x0002 0x0020000
- 46ec.54b0: 000000007ffe1000-000000007ffe8fff 0x0001/0x0000 0x0000000
- 46ec.54b0: *000000007ffe9000-000000007ffe9fff 0x0002/0x0002 0x0020000
- 46ec.54b0: 000000007ffea000-000000b0eb3fffff 0x0001/0x0000 0x0000000
- 46ec.54b0: *000000b0eb400000-000000b0eb44bfff 0x0000/0x0004 0x0020000
- 46ec.54b0: 000000b0eb44c000-000000b0eb44efff 0x0004/0x0004 0x0020000
- 46ec.54b0: 000000b0eb44f000-000000b0eb5fffff 0x0000/0x0004 0x0020000
- 46ec.54b0: *000000b0eb600000-000000b0eb6fafff 0x0000/0x0004 0x0020000
- 46ec.54b0: 000000b0eb6fb000-000000b0eb6fdfff 0x0104/0x0004 0x0020000
- 46ec.54b0: 000000b0eb6fe000-000000b0eb6fffff 0x0004/0x0004 0x0020000
- 46ec.54b0: 000000b0eb700000-000002440d71ffff 0x0001/0x0000 0x0000000
- 46ec.54b0: *000002440d720000-000002440d73ffff 0x0004/0x0004 0x0020000
- 46ec.54b0: *000002440d740000-000002440d75efff 0x0002/0x0002 0x0040000
- 46ec.54b0: 000002440d75f000-000002440d75ffff 0x0001/0x0000 0x0000000
- 46ec.54b0: *000002440d760000-000002440d763fff 0x0002/0x0002 0x0040000
- 46ec.54b0: 000002440d764000-000002440d76ffff 0x0001/0x0000 0x0000000
- 46ec.54b0: *000002440d770000-000002440d770fff 0x0002/0x0002 0x0040000
- 46ec.54b0: 000002440d771000-000002440d77ffff 0x0001/0x0000 0x0000000
- 46ec.54b0: *000002440d780000-000002440d781fff 0x0004/0x0004 0x0020000
- 46ec.54b0: 000002440d782000-00007df542f5ffff 0x0001/0x0000 0x0000000
- 46ec.54b0: *00007df542f60000-00007df542f60fff 0x0002/0x0002 0x0040000
- 46ec.54b0: 00007df542f61000-00007df542f6ffff 0x0001/0x0000 0x0000000
- 46ec.54b0: *00007df542f70000-00007df5443f2fff 0x0000/0x0001 0x0040000
- 46ec.54b0: 00007df5443f3000-00007df5444c1fff 0x0001/0x0001 0x0040000
- 46ec.54b0: 00007df5444c2000-00007df544d56fff 0x0000/0x0001 0x0040000
- 46ec.54b0: 00007df544d57000-00007df544d57fff 0x0001/0x0001 0x0040000
- 46ec.54b0: 00007df544d58000-00007ff51b74ffff 0x0000/0x0001 0x0040000
- 46ec.54b0: 00007ff51b750000-00007ff51b754fff 0x0002/0x0001 0x0040000
- 46ec.54b0: 00007ff51b755000-00007ff52e8a0fff 0x0000/0x0001 0x0040000
- 46ec.54b0: 00007ff52e8a1000-00007ff5325a3fff 0x0001/0x0001 0x0040000
- 46ec.54b0: 00007ff5325a4000-00007ff5325acfff 0x0002/0x0001 0x0040000
- 46ec.54b0: 00007ff5325ad000-00007ff542f6ffff 0x0000/0x0001 0x0040000
- 46ec.54b0: 00007ff542f70000-00007ff61f80ffff 0x0001/0x0000 0x0000000
- 46ec.54b0: *00007ff61f810000-00007ff61f810fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 46ec.54b0: 00007ff61f811000-00007ff61f87bfff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 46ec.54b0: 00007ff61f87c000-00007ff61f87cfff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 46ec.54b0: 00007ff61f87d000-00007ff61f8d1fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 46ec.54b0: 00007ff61f8d2000-00007ff61f8ddfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 46ec.54b0: 00007ff61f8de000-00007ff61f8defff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 46ec.54b0: 00007ff61f8df000-00007ff61f919fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 46ec.54b0: 00007ff61f91a000-00007ffbd8d0ffff 0x0001/0x0000 0x0000000
- 46ec.54b0: *00007ffbd8d10000-00007ffbd8d10fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\ntdll.dll
- 46ec.54b0: 00007ffbd8d11000-00007ffbd8e41fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\ntdll.dll
- 46ec.54b0: 00007ffbd8e42000-00007ffbd8e8ffff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\ntdll.dll
- 46ec.54b0: 00007ffbd8e90000-00007ffbd8e93fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\ntdll.dll
- 46ec.54b0: 00007ffbd8e94000-00007ffbd8e9bfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\ntdll.dll
- 46ec.54b0: 00007ffbd8e9c000-00007ffbd8eaafff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\ntdll.dll
- 46ec.54b0: 00007ffbd8eab000-00007ffbd8eabfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\ntdll.dll
- 46ec.54b0: 00007ffbd8eac000-00007ffbd8eaefff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\ntdll.dll
- 46ec.54b0: 00007ffbd8eaf000-00007ffbd8f26fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume5\Windows\System32\ntdll.dll
- 46ec.54b0: 00007ffbd8f27000-00007ffffffeffff 0x0001/0x0000 0x0000000
- 46ec.54b0: supR3HardNtChildPurify: Done after 814 ms and 1 fixes (loop #1).
- 3f24.31ac: supR3HardenedVmProcessInit: uNtDllAddr=00007ffbd8d10000 g_uNtVerCombined=0xa0586700 (stack ~000000b0eb6fed80)
- 46ec.54b0: supR3HardenedEarlyCompact: Removed heap 1 (0x0002855f3d0000 LB 0x800000)
- 46ec.54b0: supR3HardNtEnableThreadCreationEx:
- 3f24.31ac: ntdll.dll: timestamp 0x36d7bcf8 (rc=VINF_SUCCESS)
- 3f24.31ac: New simple heap: #1 000002440d890000 LB 0x800000 (for 2191360 allocation)
- 3f24.31ac: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox'
- 3f24.31ac: System32: \Device\HarddiskVolume5\Windows\System32
- 3f24.31ac: WinSxS: \Device\HarddiskVolume5\Windows\WinSxS
- 3f24.31ac: KnownDllPath: C:\Windows\System32
- 3f24.31ac: supR3HardenedVmProcessInit: Opening vboxsup...
- 3f24.31ac: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
- 3f24.31ac: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
- 3f24.31ac: Registered Dll notification callback with NTDLL.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\kernel32.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\kernel32.dll
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\KERNEL32.DLL (Input=KERNEL32.DLL, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000004001:<flags> [calling]
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbd5e50000 LB 0x003d1000 C:\Windows\System32\KERNELBASE.dll [fFlags=0x0]
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\KernelBase.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\KernelBase.dll
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbd7870000 LB 0x000c4000 C:\Windows\System32\KERNEL32.DLL [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7870000 'C:\Windows\System32\KERNEL32.DLL'
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ff61f810000 LB 0x0010a000 C:\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe [fFlags=0x0]
- 3f24.31ac: '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 3f24.31ac: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffbd8d84440 pvNtTerminateThread=00007ffbd8db0e30
- 46ec.54b0: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 92 ms.
- 3f24.31ac: \SystemRoot\System32\ntdll.dll:
- 3f24.31ac: CreationTime: 2025-03-12T17:32:50.955934500Z
- 3f24.31ac: LastWriteTime: 2025-03-12T17:32:51.017206900Z
- 3f24.31ac: ChangeTime: 2025-03-13T22:19:28.355125000Z
- 3f24.31ac: FileAttributes: 0x20
- 3f24.31ac: Size: 0x216038
- 3f24.31ac: NT Headers: 0xe8
- 3f24.31ac: Timestamp: 0x36d7bcf8
- 3f24.31ac: Machine: 0x8664 - amd64
- 3f24.31ac: Timestamp: 0x36d7bcf8
- 3f24.31ac: Image Version: 10.0
- 3f24.31ac: SizeOfImage: 0x217000 (2191360)
- 3f24.31ac: Resource Dir: 0x1a0000 LB 0x759a8
- 3f24.31ac: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 3f24.31ac: [Raw version resource data: 0x1a00f0 LB 0x380, codepage 0x0 (reserved 0x0)]
- 3f24.31ac: ProductName: Microsoft® Windows® Operating System
- 3f24.31ac: ProductVersion: 10.0.22621.4974
- 3f24.31ac: FileVersion: 10.0.22621.4974 (WinBuild.160101.0800)
- 3f24.31ac: FileDescription: NT Layer DLL
- 3f24.31ac: \SystemRoot\System32\kernel32.dll:
- 3f24.31ac: CreationTime: 2025-03-12T17:32:50.494392400Z
- 3f24.31ac: LastWriteTime: 2025-03-12T17:32:50.522189500Z
- 3f24.31ac: ChangeTime: 2025-03-13T22:20:04.067768600Z
- 3f24.31ac: FileAttributes: 0x20
- 3f24.31ac: Size: 0xc7188
- 3f24.31ac: NT Headers: 0xe8
- 3f24.31ac: Timestamp: 0x8c0b1418
- 3f24.31ac: Machine: 0x8664 - amd64
- 3f24.31ac: Timestamp: 0x8c0b1418
- 3f24.31ac: Image Version: 10.0
- 3f24.31ac: SizeOfImage: 0xc4000 (802816)
- 3f24.31ac: Resource Dir: 0xc2000 LB 0x520
- 3f24.31ac: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 3f24.31ac: [Raw version resource data: 0xc20b0 LB 0x3a4, codepage 0x0 (reserved 0x0)]
- 3f24.31ac: ProductName: Microsoft® Windows® Operating System
- 3f24.31ac: ProductVersion: 10.0.22621.4974
- 3f24.31ac: FileVersion: 10.0.22621.4974 (WinBuild.160101.0800)
- 3f24.31ac: FileDescription: Windows NT BASE API Client DLL
- 3f24.31ac: \SystemRoot\System32\KernelBase.dll:
- 3f24.31ac: CreationTime: 2025-03-12T17:32:51.859758200Z
- 3f24.31ac: LastWriteTime: 2025-03-12T17:32:52.063051800Z
- 3f24.31ac: ChangeTime: 2025-03-13T22:20:04.207799700Z
- 3f24.31ac: FileAttributes: 0x20
- 3f24.31ac: Size: 0x3d7f18
- 3f24.31ac: NT Headers: 0xf8
- 3f24.31ac: Timestamp: 0xa29a3610
- 3f24.31ac: Machine: 0x8664 - amd64
- 3f24.31ac: Timestamp: 0xa29a3610
- 3f24.31ac: Image Version: 10.0
- 3f24.31ac: SizeOfImage: 0x3d1000 (4001792)
- 3f24.31ac: Resource Dir: 0x3a0000 LB 0x548
- 3f24.31ac: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 3f24.31ac: [Raw version resource data: 0x3a00b0 LB 0x3bc, codepage 0x0 (reserved 0x0)]
- 3f24.31ac: ProductName: Microsoft® Windows® Operating System
- 3f24.31ac: ProductVersion: 10.0.22621.5037
- 3f24.31ac: FileVersion: 10.0.22621.5037 (WinBuild.160101.0800)
- 3f24.31ac: FileDescription: Windows NT BASE API Client DLL
- 3f24.31ac: \SystemRoot\System32\apisetschema.dll:
- 3f24.31ac: CreationTime: 2024-08-18T12:47:44.848835500Z
- 3f24.31ac: LastWriteTime: 2024-08-18T12:47:44.854356200Z
- 3f24.31ac: ChangeTime: 2025-03-12T17:34:36.442764200Z
- 3f24.31ac: FileAttributes: 0x20
- 3f24.31ac: Size: 0x245e0
- 3f24.31ac: NT Headers: 0xc8
- 3f24.31ac: Timestamp: 0x8f476251
- 3f24.31ac: Machine: 0x8664 - amd64
- 3f24.31ac: Timestamp: 0x8f476251
- 3f24.31ac: Image Version: 10.0
- 3f24.31ac: SizeOfImage: 0x23000 (143360)
- 3f24.31ac: Resource Dir: 0x22000 LB 0x408
- 3f24.31ac: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 3f24.31ac: [Raw version resource data: 0x22060 LB 0x3a8, codepage 0x0 (reserved 0x0)]
- 3f24.31ac: ProductName: Microsoft® Windows® Operating System
- 3f24.31ac: ProductVersion: 10.0.22621.3958
- 3f24.31ac: FileVersion: 10.0.22621.3958 (WinBuild.160101.0800)
- 3f24.31ac: FileDescription: ApiSet Schema DLL
- 3f24.31ac: NtOpenDirectoryObject failed on \Driver: 0xc0000022
- 3f24.31ac: supR3HardenedWinFindAdversaries: 0x0
- 3f24.31ac: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox'
- 3f24.31ac: Calling main()
- 3f24.31ac: SUPR3HardenedMain: pszProgName=VirtualBoxVM fFlags=0x2
- 3f24.31ac: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox'
- 3f24.31ac: '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe)
- 3f24.31ac: SUPR3HardenedMain: Final process, opening VBoxDrv...
- 3f24.31ac: supR3HardenedEarlyCompact: Removed heap 1 (0x0002440d890000 LB 0x800000)
- 3f24.31ac: supR3HardNtEnableThreadCreationEx:
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxSupLib.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxSupLib.dll
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 3f24.31ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbc9e10000 LB 0x00005000 C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbc9e10000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbc9e10000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbc9e10000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #30 'rpcrt4.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\wintrust.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\wintrust.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume5\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\rpcrt4.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\rpcrt4.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\msvcrt.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\msvcrt.dll
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbd89e0000 LB 0x000a7000 C:\Windows\System32\msvcrt.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbd8bb0000 LB 0x00114000 C:\Windows\System32\RPCRT4.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbd65c0000 LB 0x00072000 C:\Windows\System32\Wintrust.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbd68c0000 LB 0x00111000 C:\Windows\System32\ucrtbase.dll [fFlags=0x0]
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\ucrtbase.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\ucrtbase.dll
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbd6450000 LB 0x00166000 C:\Windows\System32\CRYPT32.dll [fFlags=0x0]
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\crypt32.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\crypt32.dll
- 3f24.31ac: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd5e50000 'api-ms-win-core-synch-l1-2-0'
- 3f24.31ac: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-fibers-l1-1-1) -> 0x0, fPresent=1
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd5e50000 'api-ms-win-core-fibers-l1-1-1'
- 3f24.31ac: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd5e50000 'api-ms-win-core-synch-l1-2-0'
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\msasn1.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\msasn1.dll
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbd5af0000 LB 0x00012000 C:\Windows\SYSTEM32\MSASN1.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd65c0000 'C:\Windows\system32\Wintrust.dll'
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\bcrypt.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\bcrypt.dll
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\bcrypt.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbd6350000 LB 0x00028000 C:\Windows\System32\bcrypt.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6350000 'C:\Windows\system32\bcrypt.dll'
- 3f24.31ac: bcrypt.dll loaded at 00007ffbd6350000, BCryptOpenAlgorithmProvider at 00007ffbd6354520, preloading providers:
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\bcryptprimitives.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\bcryptprimitives.dll
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\bcryptprimitives.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbd6640000 LB 0x0007b000 C:\Windows\System32\bcryptprimitives.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6640000 'C:\Windows\system32\bcryptprimitives.dll'
- 3f24.31ac: BCryptOpenAlgorithmProvider(,'MD2',0,0) -> 0x0 (hAlgo=000002440e1f0fe0)
- 3f24.31ac: BCryptOpenAlgorithmProvider(,'MD4',0,0) -> 0x0 (hAlgo=000002440e1f1db0)
- 3f24.31ac: BCryptOpenAlgorithmProvider(,'MD5',0,0) -> 0x0 (hAlgo=000002440e1f2100)
- 3f24.31ac: BCryptOpenAlgorithmProvider(,'SHA1',0,0) -> 0x0 (hAlgo=000002440e1f2450)
- 3f24.31ac: BCryptOpenAlgorithmProvider(,'SHA256',0,0) -> 0x0 (hAlgo=000002440e1f27a0)
- 3f24.31ac: BCryptOpenAlgorithmProvider(,'SHA512',0,0) -> 0x0 (hAlgo=000002440e1f2af0)
- 3f24.31ac: BCryptOpenAlgorithmProvider(,'RSA',0,0) -> 0x0 (hAlgo=000002440e1f2eb0)
- 3f24.31ac: BCryptOpenAlgorithmProvider(,'DSA',0,0) -> 0x0 (hAlgo=000002440e1f3200)
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\cryptsp.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\cryptsp.dll
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbd5700000 LB 0x0001b000 C:\Windows\SYSTEM32\CRYPTSP.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\cryptsp.dll [lacks WinVerifyTrust]
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\rsaenh.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\rsaenh.dll
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.31ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbd4e30000 LB 0x00037000 C:\Windows\system32\rsaenh.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\cryptbase.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\cryptbase.dll
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbd56e0000 LB 0x0000c000 C:\Windows\SYSTEM32\CRYPTBASE.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\cryptbase.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7870000 'C:\Windows\System32\kernel32.dll'
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (Input=WINTRUST.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd65c0000 'C:\Windows\System32\WINTRUST.DLL'
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\CRYPT32.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\CRYPT32.dll'
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbd8b10000 LB 0x0001f000 C:\Windows\System32\imagehlp.dll [fFlags=0x0]
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\imagehlp.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\imagehlp.dll
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbd6b90000 LB 0x000a7000 C:\Windows\System32\sechost.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #24 'bcrypt.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\sechost.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\sechost.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'rpcrt4.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\gpapi.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\gpapi.dll
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbd5420000 LB 0x00026000 C:\Windows\SYSTEM32\gpapi.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\gpapi.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'crypt32.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\cryptnet.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\cryptnet.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume5\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume5\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcrypt.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcrypt.dll' -> '\Device\HarddiskVolume5\Windows\System32\bcrypt.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.31ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbd09b0000 LB 0x00032000 C:\Windows\System32\cryptnet.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd09b0000 'C:\Windows\System32\cryptnet.dll'
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd09b0000 'C:\Windows\System32\cryptnet.dll'
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd09b0000 'C:\Windows\System32\cryptnet.dll'
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd09b0000 'C:\Windows\System32\cryptnet.dll'
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd09b0000 'C:\Windows\System32\cryptnet.dll'
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd09b0000 'C:\Windows\System32\cryptnet.dll'
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd09b0000 'C:\Windows\System32\cryptnet.dll'
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd09b0000 'C:\Windows\System32\cryptnet.dll'
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd09b0000 'C:\Windows\System32\cryptnet.dll'
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd09b0000 'C:\Windows\System32\cryptnet.dll'
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd09b0000 'C:\Windows\System32\cryptnet.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd09b0000 'C:\Windows\System32\cryptnet.dll'
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\profapi.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\profapi.dll
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbd5d80000 LB 0x0002b000 C:\Windows\SYSTEM32\profapi.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\profapi.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbd7a40000 LB 0x000b1000 C:\Windows\System32\advapi32.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'sechost.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #28 'rpcrt4.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\advapi32.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\advapi32.dll
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume5\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'sechost.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'sechost.dll' -> '\Device\HarddiskVolume5\Windows\System32\sechost.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\sechost.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000000 pwszName=\SystemRoot\System32\ntdll.dll
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: New context 000002440e2782e0
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000002440e2782e0
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=28BF5815E2C1F3D73DA234D7D82F1EA0BD0523D3
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\rpcrt4.dll (Input=rpcrt4.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd8bb0000 'C:\Windows\System32\rpcrt4.dll'
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package051420~31bf3856ad364e35~amd64~~10.0.22621.5039.cat'; file='\SystemRoot\System32\ntdll.dll'
- 3f24.31ac: g_pfnWinVerifyTrust=00007ffbd65d24c0
- 3f24.31ac: supR3HardenedScreenImage/preload: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\crypt32.dll [redoing WinVerifyTrust]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedScreenImage/preload: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedScreenImage/preload: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\wintrust.dll [redoing WinVerifyTrust]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\crypt32.dll
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedScreenImage/preload: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\wintrust.dll'
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\advapi32.dll'
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\profapi.dll'
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\cryptnet.dll'
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\gpapi.dll'
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\sechost.dll'
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\imagehlp.dll'
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\cryptbase.dll'
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\crypt32.dll
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\rsaenh.dll'
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\rsaenh.dll
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\cryptsp.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\bcryptprimitives.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\bcrypt.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\msasn1.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\ucrtbase.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\rpcrt4.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxSupLib.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\KernelBase.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\kernel32.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\system32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0xf56e5244680e8400 CN=DYMO Root CA (for localhost), O=DYMO, OU=Dev, C=USA, L=Atlanta, ST=GA
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0xa70df29e51fc4095 C=LT, O=NordVPN S.A., CN=NordVPN S.A. -ThreatProtection
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0x5ad46780fa5df300 DC=com, DC=microsoft, CN=Microsoft Root Certificate Authority
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0xea5386456178582b C=ZA, ST=Western Cape, L=Durbanville, O=Thawte, OU=Thawte Certification, CN=Thawte Timestamping CA
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0x3be670c1bd02a900 OU=Copyright (c) 1997 Microsoft Corp., OU=Microsoft Corporation, CN=Microsoft Root Authority
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0xe991ee72b03db500 C=US, O=Symantec Corporation, CN=Symantec Enterprise Mobile Root for Microsoft
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0x4d3835aa4180b200 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2011
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0x646e3fe3ba08df00 C=US, O=MSFT, CN=Microsoft Authenticode(tm) Root Authority
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0x66dda7496ebabd00 CN=USB\VID_0BDA&PID_2838&MI_00 (libwdi autogenerated)
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0xece4e4289e08b900 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0xf3bb4d7e894b420 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft ECC TS Root Certificate Authority 2018
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0x43a9cc371ff5385a O=Microsoft Trust Network, OU=Microsoft Corporation, OU=Microsoft Time Stamping Service Root, OU=Copyright (c) 1997 Microsoft Corp.
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0x2e2d2c7c68f0202e O=VeriSign Trust Network, OU=VeriSign, Inc., OU=VeriSign Time Stamping Service Root, OU=NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0xcec3d46562b9be8e C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft ECC Product Root Certificate Authority 2018
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0xca58a05dd401ae00 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Time Stamp Root Certificate Authority 2014
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0x670683072a91b300 C=US, O=Microsoft Corporation, CN=Microsoft Identity Verification Root Certificate Authority 2020
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0xa1e31e8b0211b600 C=US, O=Google Trust Services LLC, CN=GTS Root R1
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0x61a3a33f81aace00 C=US, ST=UT, L=Salt Lake City, O=The USERTRUST Network, OU=http://www.usertrust.com, CN=UTN-USERFirst-Object
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0x3d993fde1950a700 C=US, O=IdenTrust, CN=IdenTrust Commercial Root CA 1
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0x6b7bdc34cd37bb00 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root G2
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0x57ba5395b561bf00 C=BM, O=QuoVadis Limited, OU=Root Certification Authority, CN=QuoVadis Root Certification Authority
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0xbbde687390e6bf00 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Trusted Root G4
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0x83085097e9afdf00 O=Digital Signature Trust Co., CN=DST Root CA X3
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0x780679907625cc00 OU=GlobalSign Root CA - R3, O=GlobalSign, CN=GlobalSign
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0x3d98ab22bb04a300 C=IE, O=Baltimore, OU=CyberTrust, CN=Baltimore CyberTrust Root
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0x80d5e6f878f9bd00 C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Trusted Network CA 2
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0xeae16ef49d40be00 C=GB, ST=Greater Manchester, L=Salford, O=Comodo CA Limited, CN=AAA Certificate Services
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0xc6536f24d57ae723 C=US, ST=New Jersey, L=Jersey City, O=The USERTRUST Network, CN=USERTrust ECC Certification Authority
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0x2404221294e78d00 C=GB, O=Sectigo Limited, CN=Sectigo Public Code Signing Root R46
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0x3714f47324e8ad00 C=US, O=Internet Security Research Group, CN=ISRG Root X1
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0xcb7d2ba3dd0ff900 C=US, ST=Texas, L=Houston, O=SSL Corporation, CN=SSL.com Root Certification Authority RSA
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0x8ff6fc03c1edbd00 C=US, ST=Arizona, L=Scottsdale, O=Starfield Technologies, Inc., CN=Starfield Root Certificate Authority - G2
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0xa3ce8d99e60eda00 C=BE, O=GlobalSign nv-sa, OU=Root CA, CN=GlobalSign Root CA
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0x560ad29254e89100 C=GB, ST=Greater Manchester, L=Salford, O=COMODO CA Limited, CN=COMODO RSA Certification Authority
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0xa671e9fec832b700 C=US, O=Starfield Technologies, Inc., OU=Starfield Class 2 Certification Authority
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0xa8de7211e13be200 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root CA
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0x2fba703484f19900 C=DE, O=D-Trust GmbH, CN=D-TRUST Root Class 3 CA 2 EV 2009
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0x4ef92ac43a0cd500 C=US, ST=Arizona, L=Scottsdale, O=Starfield Technologies, Inc., CN=Starfield Services Root Certificate Authority - G2
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0xd45980fbf0a0ac00 C=US, O=thawte, Inc., OU=Certification Services Division, OU=(c) 2006 thawte, Inc. - For authorized use only, CN=thawte Primary Root CA
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0xc9edb72b684ba00 C=US, O=Entrust, Inc., OU=See www.entrust.net/legal-terms, OU=(c) 2009 Entrust, Inc. - for authorized use only, CN=Entrust Root Certification Authority - G2
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0xf5cd95e581a4ab00 C=US, O=SecureTrust Corporation, CN=SecureTrust CA
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0xf966ca73e8079500 OU=GlobalSign Root CA - R6, O=GlobalSign, CN=GlobalSign
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0xbebef0d2217f0bfb C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root G3
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0x4dd6e14065368f00 C=US, ST=Texas, L=Houston, O=SSL Corporation, CN=SSL.com EV Root Certification Authority RSA R2
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0x14018a1bf29e595c C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0x298c3394be5bca00 C=US, O=Microsoft Corporation, CN=Microsoft RSA Root Certificate Authority 2017
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0xa4031c19392e9f0e OU=GlobalSign ECC Root CA - R4, O=GlobalSign, CN=GlobalSign
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0xd4fbe673e5ccc600 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0xb352b1523915d000 C=JP, O=SECOM Trust Systems CO.,LTD., OU=Security Communication RootCA2
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0x362d8807333b600 C=US, O=DigiCert, Inc., CN=DigiCert CS RSA4096 Root G5
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0xb28612a94b4dad00 O=Entrust.net, OU=www.entrust.net/CPS_2048 incorp. by ref. (limits liab.), OU=(c) 1999 Entrust.net Limited, CN=Entrust.net Certification Authority (2048)
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0xe87add30c52db600 C=BE, O=GlobalSign nv-sa, CN=GlobalSign Code Signing Root R45
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0x357a29080824af00 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2006 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G5
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0x59faf1086271bf00 C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com, Inc., CN=Go Daddy Root Certificate Authority - G2
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0x466cbc09db88c100 C=IL, O=StartCom Ltd., OU=Secure Digital Certificate Signing, CN=StartCom Certification Authority
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0x3401b15e3761c700 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2008 VeriSign, Inc. - For authorized use only, CN=VeriSign Universal Root Certification Authority
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0xc30e361765128000 C=US, ST=New Jersey, L=Jersey City, O=The USERTRUST Network, CN=USERTrust RSA Certification Authority
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0x491857ead79dde00 C=US, O=The Go Daddy Group, Inc., OU=Go Daddy Class 2 Certification Authority
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0x665f55ebd06ce27b C=US, O=Entrust, Inc., OU=See www.entrust.net/legal-terms, OU=(c) 2012 Entrust, Inc. - for authorized use only, CN=Entrust Root Certification Authority - EC1
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0xb9ff821d139e9bf OU=GlobalSign ECC Root CA - R5, O=GlobalSign, CN=GlobalSign
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0xdc1801b225aea100 C=BM, O=QuoVadis Limited, CN=QuoVadis Root CA 2 G3
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0xc2ba72a37dfbe300 C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Trusted Network CA
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0x8043e4ce150ead00 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID Root CA
- 3f24.31ac: supR3HardenedWinIsDesiredRootCA: Adding 0xf2e6331af7b700 C=SE, O=AddTrust AB, OU=AddTrust External TTP Network, CN=AddTrust External CA Root
- 3f24.31ac: supR3HardenedWinRetrieveTrustedRootCAs: cAdded=64
- 3f24.31ac: SUPR3HardenedMain: Load Runtime...
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'vcruntime140.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msvcp140.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'mpr.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'rpcrt4.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'ws2_32.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxRT.dll) WinVerifyTrust
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxRT.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume5\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'rpcrt4.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\ws2_32.dll) WinVerifyTrust
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\ws2_32.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume5\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\rpcrt4.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mpr.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'mpr.dll' -> '\Device\HarddiskVolume5\Windows\System32\mpr.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume5\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\rpcrt4.dll
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\mpr.dll) WinVerifyTrust
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\mpr.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp140.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp140.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcp140.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\crypt32.dll
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'vcruntime140.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vcruntime140_1.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\msvcp140.dll) WinVerifyTrust
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\msvcp140.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140_1.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140_1.dll' -> '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140_1.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140_1.dll' -> '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vcruntime140.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140.dll' -> '\Device\HarddiskVolume5\Windows\System32\vcruntime140.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\vcruntime140.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\vcruntime140.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140.dll' -> '\Device\HarddiskVolume5\Windows\System32\vcruntime140.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\vcruntime140.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vcruntime140.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll) WinVerifyTrust
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140.dll' -> '\Device\HarddiskVolume5\Windows\System32\vcruntime140.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\vcruntime140.dll [redoing WinVerifyTrust]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\rsaenh.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140.dll' -> '\Device\HarddiskVolume5\Windows\System32\vcruntime140.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\vcruntime140.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000a01:<flags> [calling]
- 3f24.31ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxRT.dll
- 3f24.31ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\vcruntime140.dll
- 3f24.31ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll [avoiding WinVerifyTrust]
- 3f24.31ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\msvcp140.dll
- 3f24.31ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\mpr.dll
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbb5c80000 LB 0x0001e000 C:\Windows\SYSTEM32\VCRUNTIME140.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\vcruntime140.dll
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbb7a10000 LB 0x0000c000 C:\Windows\SYSTEM32\VCRUNTIME140_1.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll [avoiding WinVerifyTrust]
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbb5bf0000 LB 0x0008d000 C:\Windows\SYSTEM32\MSVCP140.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\msvcp140.dll
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbb97a0000 LB 0x0001e000 C:\Windows\SYSTEM32\MPR.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\mpr.dll
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbd8a90000 LB 0x00071000 C:\Windows\System32\WS2_32.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\ws2_32.dll
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffb25590000 LB 0x006f5000 C:\Program Files\Oracle\VirtualBox\VBoxRT.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxRT.dll
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd5e50000 'api-ms-win-core-synch-l1-2-0'
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-fibers-l1-1-1) -> 0x0, fPresent=1
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd5e50000 'api-ms-win-core-fibers-l1-1-1'
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd5e50000 'api-ms-win-core-synch-l1-2-0'
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-fibers-l1-1-1) -> 0x0, fPresent=1
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd5e50000 'api-ms-win-core-fibers-l1-1-1'
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\kernel32.dll
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\kernel32.dll (Input=kernel32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7870000 'C:\Windows\System32\kernel32.dll'
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-string-l1-1-0) -> 0x0, fPresent=1
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-string-l1-1-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd5e50000 'api-ms-win-core-string-l1-1-0'
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-l1-2-1) -> 0x0, fPresent=1
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-l1-2-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd5e50000 'api-ms-win-core-localization-l1-2-1'
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-datetime-l1-1-1) -> 0x0, fPresent=1
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-datetime-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd5e50000 'api-ms-win-core-datetime-l1-1-1'
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-obsolete-l1-2-0) -> 0x0, fPresent=1
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-obsolete-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd5e50000 'api-ms-win-core-localization-obsolete-l1-2-0'
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxRT.dll
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb25590000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxRT.dll
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb25590000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxRT.dll
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb25590000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxRT.dll
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb25590000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxRT.dll
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb25590000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxRT.dll
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb25590000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb25590000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb25590000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb25590000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb25590000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb25590000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb25590000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb25590000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxRT.dll
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb25590000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb25590000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb25590000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb25590000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb25590000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb25590000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb25590000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb25590000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb25590000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb25590000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb25590000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb25590000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb25590000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb25590000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb25590000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb25590000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxRT.dll
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb25590000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb25590000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb25590000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rescheduled]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb25590000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll'
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\wintrust.dll
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd65c0000 'C:\Windows\system32\Wintrust.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\system32\crypt32.dll'
- 3f24.31ac: SUPR3HardenedMain: Load TrustedMain...
- 3f24.5d60: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-appmodel-runtime-l1-1-2) -> 0x0, fPresent=1
- 3f24.5d60: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-appmodel-runtime-l1-1-2 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 3f24.5d60: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'msvcrt.dll'.
- 3f24.5d60: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\kernel.appcore.dll)
- 3f24.5d60: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\kernel.appcore.dll
- 3f24.5d60: supR3HardenedDllNotificationCallback: load 00007ffbd4e70000 LB 0x00018000 C:\Windows\SYSTEM32\kernel.appcore.dll [fFlags=0x0]
- 3f24.5d60: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\kernel.appcore.dll [avoiding WinVerifyTrust]
- 3f24.5d60: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e70000 'api-ms-win-appmodel-runtime-l1-1-2'
- 3f24.5d60: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 3f24.5d60: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 3f24.5d60: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\msvcrt.dll
- 3f24.5d60: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.5d60: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.5d60: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\kernel.appcore.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'uicommon.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vcruntime140.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msvcp140.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'qt6corevbox.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'qt6guivbox.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'qt6widgetsvbox.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'user32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'advapi32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'ole32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'oleaut32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'winmm.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll) WinVerifyTrust
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume5\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\winmm.dll) WinVerifyTrust
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\winmm.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume5\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'combase.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'rpcrt4.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\oleaut32.dll) WinVerifyTrust
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\oleaut32.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume5\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume5\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\rpcrt4.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume5\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\combase.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rpcrt4.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\combase.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\combase.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\msvcp_win.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\msvcp_win.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\msvcp_win.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume5\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\rpcrt4.dll
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #44 'gdi32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #45 'user32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #46 'combase.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\ole32.dll) WinVerifyTrust
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\ole32.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume5\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\advapi32.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume5\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume5\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\combase.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume5\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\user32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'win32u.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #39 'gdi32.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\user32.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\user32.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume5\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\gdi32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'win32u.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\gdi32.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\gdi32.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\msvcp_win.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume5\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\win32u.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\win32u.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\win32u.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume5\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume5\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\win32u.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'win32u.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #39 'gdi32.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\user32.dll) WinVerifyTrust
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt6widgetsvbox.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt6widgetsvbox.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\qt6widgetsvbox.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume5\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume5\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\win32u.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'dwmapi.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'uxtheme.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt6guivbox.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qt6corevbox.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'user32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'gdi32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'msvcp140.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'msvcp140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'vcruntime140.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'vcruntime140_1.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\Qt6WidgetsVBox.dll) WinVerifyTrust
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\Qt6WidgetsVBox.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt6guivbox.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt6guivbox.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\qt6guivbox.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140_1.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140_1.dll' -> '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140.dll' -> '\Device\HarddiskVolume5\Windows\System32\vcruntime140.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\vcruntime140.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp140_1.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp140_1.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcp140_1.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\msvcp140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp140.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vcruntime140.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\msvcp140_1.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\msvcp140_1.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp140.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp140.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcp140.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\msvcp140.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume5\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume5\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\user32.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt6corevbox.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt6corevbox.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\qt6corevbox.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\Qt6CoreVBox.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'mpr.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'userenv.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'authz.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'netapi32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'ole32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'shell32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'user32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'version.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'winmm.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'ws2_32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'msvcp140.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'msvcp140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #15 'vcruntime140.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'vcruntime140_1.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\Qt6CoreVBox.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\Qt6CoreVBox.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt6guivbox.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt6guivbox.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\qt6guivbox.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\Qt6GuiVBox.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'd3d11.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'dxgi.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ole32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'shell32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'user32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'dwrite.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'qt6corevbox.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'msvcp140.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'msvcp140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'msvcp140_2.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'vcruntime140.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'vcruntime140_1.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\Qt6GuiVBox.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\Qt6GuiVBox.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'uxtheme.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'uxtheme.dll' -> '\Device\HarddiskVolume5\Windows\System32\uxtheme.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: Detected WinVerifyTrust recursion: rc=22900 '\Device\HarddiskVolume5\Windows\System32\uxtheme.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #39 'gdi32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #40 'user32.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume5\Windows\System32\uxtheme.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\uxtheme.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dwmapi.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'dwmapi.dll' -> '\Device\HarddiskVolume5\Windows\System32\dwmapi.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\dwmapi.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #24 'win32u.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'user32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'gdi32.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\dwmapi.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\dwmapi.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume5\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume5\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\user32.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume5\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\win32u.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume5\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\user32.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume5\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140_1.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140_1.dll' -> '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140.dll' -> '\Device\HarddiskVolume5\Windows\System32\vcruntime140.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\vcruntime140.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp140_2.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp140_2.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcp140_2.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\msvcp140_2.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp140.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vcruntime140.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vcruntime140_1.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\msvcp140_2.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\msvcp140_2.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp140_1.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp140_1.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcp140_1.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\msvcp140_1.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp140.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp140.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcp140.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\msvcp140.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt6corevbox.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt6corevbox.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\qt6corevbox.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\Qt6CoreVBox.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dwrite.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'dwrite.dll' -> '\Device\HarddiskVolume5\Windows\System32\dwrite.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: Detected WinVerifyTrust recursion: rc=22900 '\Device\HarddiskVolume5\Windows\System32\DWrite.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'rpcrt4.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume5\Windows\System32\DWrite.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\DWrite.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume5\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\user32.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume5\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\shell32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #74 'user32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #76 'gdi32.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\shell32.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\shell32.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume5\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\ole32.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume5\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dxgi.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'dxgi.dll' -> '\Device\HarddiskVolume5\Windows\System32\dxgi.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\dxgi.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'win32u.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\dxgi.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\dxgi.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'd3d11.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'd3d11.dll' -> '\Device\HarddiskVolume5\Windows\System32\d3d11.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\d3d11.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #28 'dxgi.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #30 'win32u.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\d3d11.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\d3d11.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140_1.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140_1.dll' -> '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140.dll' -> '\Device\HarddiskVolume5\Windows\System32\vcruntime140.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\vcruntime140.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp140_1.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp140_1.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcp140_1.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\msvcp140_1.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp140.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp140.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcp140.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\msvcp140.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume5\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\ws2_32.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume5\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\winmm.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'version.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'version.dll' -> '\Device\HarddiskVolume5\Windows\System32\version.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\version.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\version.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\version.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume5\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\user32.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume5\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\shell32.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume5\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\ole32.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'netapi32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'netapi32.dll' -> '\Device\HarddiskVolume5\Windows\System32\netapi32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\netapi32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\netapi32.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\netapi32.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'authz.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'authz.dll' -> '\Device\HarddiskVolume5\Windows\System32\authz.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: Detected WinVerifyTrust recursion: rc=22900 '\Device\HarddiskVolume5\Windows\System32\authz.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume5\Windows\System32\authz.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\authz.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume5\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\advapi32.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'userenv.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'userenv.dll' -> '\Device\HarddiskVolume5\Windows\System32\userenv.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\userenv.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #15 'rpcrt4.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\userenv.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\userenv.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mpr.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'mpr.dll' -> '\Device\HarddiskVolume5\Windows\System32\mpr.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\mpr.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140.dll' -> '\Device\HarddiskVolume5\Windows\System32\vcruntime140.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp140.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp140.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcp140.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\msvcp140.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume5\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\msvcrt.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\msvcrt.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume5\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\win32u.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dxgi.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'dxgi.dll' -> '\Device\HarddiskVolume5\Windows\System32\dxgi.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\dxgi.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\msvcp_win.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume5\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\win32u.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\msvcp_win.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume5\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume5\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\user32.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\msvcp_win.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume5\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\msvcrt.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140_1.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140_1.dll' -> '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140.dll' -> '\Device\HarddiskVolume5\Windows\System32\vcruntime140.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp140.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp140.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcp140.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\msvcp140.dll
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'd3d11.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'dxgi.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ole32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'shell32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'user32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'dwrite.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'qt6corevbox.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'msvcp140.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'msvcp140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'msvcp140_2.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'vcruntime140.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'vcruntime140_1.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\Qt6GuiVBox.dll) WinVerifyTrust
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt6corevbox.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt6corevbox.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\qt6corevbox.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\Qt6CoreVBox.dll [redoing WinVerifyTrust]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140_1.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140_1.dll' -> '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140.dll' -> '\Device\HarddiskVolume5\Windows\System32\vcruntime140.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp140_2.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp140_2.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcp140_2.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\msvcp140_2.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp140_1.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp140_1.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcp140_1.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\msvcp140_1.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp140.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp140.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcp140.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\msvcp140.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt6corevbox.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt6corevbox.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\qt6corevbox.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\Qt6CoreVBox.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dwrite.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'dwrite.dll' -> '\Device\HarddiskVolume5\Windows\System32\dwrite.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (22900) on \Device\HarddiskVolume5\Windows\System32\DWrite.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume5\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\user32.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume5\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\shell32.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume5\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\ole32.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume5\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dxgi.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'dxgi.dll' -> '\Device\HarddiskVolume5\Windows\System32\dxgi.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\dxgi.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'd3d11.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'd3d11.dll' -> '\Device\HarddiskVolume5\Windows\System32\d3d11.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\d3d11.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\Qt6CoreVBox.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp140.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp140.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcp140.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140_1.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140_1.dll' -> '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140.dll' -> '\Device\HarddiskVolume5\Windows\System32\vcruntime140.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'uicommon.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'uicommon.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\uicommon.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'vboxrt.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vcruntime140.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vcruntime140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcp140.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qt6corevbox.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'qt6guivbox.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'qt6widgetsvbox.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'qt6helpvbox.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'qt6statemachinevbox.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #15 'user32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'advapi32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'ole32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'oleaut32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #19 'rpcrt4.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\UICommon.dll) WinVerifyTrust
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\UICommon.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume5\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume5\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\oleaut32.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume5\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\ole32.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume5\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\advapi32.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume5\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\user32.dll [redoing WinVerifyTrust]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\user32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt6statemachinevbox.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt6statemachinevbox.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\qt6statemachinevbox.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'qt6guivbox.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'qt6corevbox.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vcruntime140.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\Qt6StateMachineVBox.dll) WinVerifyTrust
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\Qt6StateMachineVBox.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt6helpvbox.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt6helpvbox.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\qt6helpvbox.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140.dll' -> '\Device\HarddiskVolume5\Windows\System32\vcruntime140.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt6corevbox.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt6corevbox.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\qt6corevbox.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\Qt6CoreVBox.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt6guivbox.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt6guivbox.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\qt6guivbox.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\Qt6GuiVBox.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'qt6sqlvbox.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'qt6widgetsvbox.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt6guivbox.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qt6corevbox.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msvcp140.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'vcruntime140.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'vcruntime140_1.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\Qt6HelpVBox.dll) WinVerifyTrust
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\Qt6HelpVBox.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt6widgetsvbox.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt6widgetsvbox.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\qt6widgetsvbox.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\Qt6WidgetsVBox.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt6guivbox.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt6guivbox.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\qt6guivbox.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\Qt6GuiVBox.dll [redoing WinVerifyTrust]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140_1.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140_1.dll' -> '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140.dll' -> '\Device\HarddiskVolume5\Windows\System32\vcruntime140.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp140.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp140.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcp140.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt6corevbox.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt6corevbox.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\qt6corevbox.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\Qt6CoreVBox.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt6guivbox.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt6guivbox.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\qt6guivbox.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\Qt6GuiVBox.dll [lacks WinVerifyTrust]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt6widgetsvbox.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt6widgetsvbox.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\qt6widgetsvbox.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\Qt6WidgetsVBox.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt6sqlvbox.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt6sqlvbox.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\qt6sqlvbox.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\Qt6SqlVBox.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'qt6corevbox.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp140.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vcruntime140.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vcruntime140_1.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\Qt6SqlVBox.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\Qt6SqlVBox.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140_1.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140_1.dll' -> '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140.dll' -> '\Device\HarddiskVolume5\Windows\System32\vcruntime140.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp140.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp140.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcp140.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt6corevbox.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt6corevbox.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\qt6corevbox.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\Qt6CoreVBox.dll
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedScreenImage/Imports: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\Qt6GuiVBox.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt6corevbox.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt6corevbox.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\qt6corevbox.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\Qt6CoreVBox.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp140.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp140.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcp140.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140_1.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140_1.dll' -> '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140.dll' -> '\Device\HarddiskVolume5\Windows\System32\vcruntime140.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\vcruntime140.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000a01:<flags> [calling]
- 3f24.31ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll
- 3f24.31ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\UICommon.dll
- 3f24.31ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\Qt6CoreVBox.dll
- 3f24.31ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\Qt6GuiVBox.dll
- 3f24.31ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\Qt6WidgetsVBox.dll
- 3f24.31ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\winmm.dll
- 3f24.31ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\Qt6HelpVBox.dll
- 3f24.31ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\Qt6StateMachineVBox.dll
- 3f24.31ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\userenv.dll [avoiding WinVerifyTrust]
- 3f24.31ac: supR3HardenedScreenImage/NtCreateSection: cache hit (22900) on \Device\HarddiskVolume5\Windows\System32\authz.dll [avoiding WinVerifyTrust]
- 3f24.31ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\netapi32.dll [avoiding WinVerifyTrust]
- 3f24.31ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\version.dll [avoiding WinVerifyTrust]
- 3f24.31ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\msvcp140_1.dll [avoiding WinVerifyTrust]
- 3f24.31ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\d3d11.dll [avoiding WinVerifyTrust]
- 3f24.31ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\dxgi.dll [avoiding WinVerifyTrust]
- 3f24.31ac: supR3HardenedScreenImage/NtCreateSection: cache hit (22900) on \Device\HarddiskVolume5\Windows\System32\DWrite.dll [avoiding WinVerifyTrust]
- 3f24.31ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\msvcp140_2.dll [avoiding WinVerifyTrust]
- 3f24.31ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\dwmapi.dll [avoiding WinVerifyTrust]
- 3f24.31ac: supR3HardenedScreenImage/NtCreateSection: cache hit (22900) on \Device\HarddiskVolume5\Windows\System32\uxtheme.dll [avoiding WinVerifyTrust]
- 3f24.31ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\Qt6SqlVBox.dll [avoiding WinVerifyTrust]
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\netutils.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\netutils.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rpcrt4.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\srvcli.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\srvcli.dll
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbd5450000 LB 0x00028000 C:\Windows\SYSTEM32\USERENV.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\userenv.dll [avoiding WinVerifyTrust]
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbd4a50000 LB 0x00050000 C:\Windows\SYSTEM32\AUTHZ.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (22900) on \Device\HarddiskVolume5\Windows\System32\authz.dll [avoiding WinVerifyTrust]
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbc7330000 LB 0x00019000 C:\Windows\SYSTEM32\NETAPI32.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\netapi32.dll [avoiding WinVerifyTrust]
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbd63b0000 LB 0x0009a000 C:\Windows\System32\msvcp_win.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\msvcp_win.dll [avoiding WinVerifyTrust]
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbd6380000 LB 0x00026000 C:\Windows\System32\win32u.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\win32u.dll [avoiding WinVerifyTrust]
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbd71d0000 LB 0x001b1000 C:\Windows\System32\USER32.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbd6230000 LB 0x0011b000 C:\Windows\System32\gdi32full.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #39 'gdi32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #42 'user32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #43 'win32u.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\gdi32full.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\gdi32full.dll
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbd6e00000 LB 0x00029000 C:\Windows\System32\GDI32.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\gdi32.dll [avoiding WinVerifyTrust]
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbd6e30000 LB 0x00390000 C:\Windows\System32\combase.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\combase.dll [avoiding WinVerifyTrust]
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbd76c0000 LB 0x001a1000 C:\Windows\System32\ole32.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\ole32.dll
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbd66c0000 LB 0x0013f000 C:\Windows\System32\wintypes.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'combase.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\WinTypes.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\WinTypes.dll
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbd8150000 LB 0x00888000 C:\Windows\System32\SHELL32.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\shell32.dll [avoiding WinVerifyTrust]
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbd0a20000 LB 0x0000a000 C:\Windows\SYSTEM32\VERSION.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\version.dll [avoiding WinVerifyTrust]
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbcf410000 LB 0x00034000 C:\Windows\SYSTEM32\WINMM.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\winmm.dll
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbb1540000 LB 0x00009000 C:\Windows\SYSTEM32\MSVCP140_1.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\msvcp140_1.dll [avoiding WinVerifyTrust]
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbd48c0000 LB 0x0000c000 C:\Windows\SYSTEM32\NETUTILS.DLL [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\netutils.dll [avoiding WinVerifyTrust]
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbc7bf0000 LB 0x00028000 C:\Windows\SYSTEM32\SRVCLI.DLL [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\srvcli.dll [avoiding WinVerifyTrust]
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffb89520000 LB 0x00588000 C:\Program Files\Oracle\VirtualBox\Qt6CoreVBox.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbd35d0000 LB 0x000f7000 C:\Windows\SYSTEM32\dxgi.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\dxgi.dll [avoiding WinVerifyTrust]
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbd1b10000 LB 0x00257000 C:\Windows\SYSTEM32\d3d11.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\d3d11.dll [avoiding WinVerifyTrust]
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbd1220000 LB 0x00273000 C:\Windows\SYSTEM32\DWrite.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (22900) on \Device\HarddiskVolume5\Windows\System32\DWrite.dll [avoiding WinVerifyTrust]
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffb43290000 LB 0x00041000 C:\Windows\SYSTEM32\MSVCP140_2.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\msvcp140_2.dll [avoiding WinVerifyTrust]
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffb88da0000 LB 0x00773000 C:\Program Files\Oracle\VirtualBox\Qt6GuiVBox.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\Qt6GuiVBox.dll
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbd37e0000 LB 0x0002b000 C:\Windows\SYSTEM32\dwmapi.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\dwmapi.dll [avoiding WinVerifyTrust]
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbd3470000 LB 0x000b3000 C:\Windows\SYSTEM32\UxTheme.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (22900) on \Device\HarddiskVolume5\Windows\System32\uxtheme.dll [avoiding WinVerifyTrust]
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffb24fc0000 LB 0x005c1000 C:\Program Files\Oracle\VirtualBox\Qt6WidgetsVBox.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\Qt6WidgetsVBox.dll
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbc9ee0000 LB 0x00047000 C:\Program Files\Oracle\VirtualBox\Qt6SqlVBox.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\Qt6SqlVBox.dll [avoiding WinVerifyTrust]
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbc9c40000 LB 0x0008b000 C:\Program Files\Oracle\VirtualBox\Qt6HelpVBox.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\Qt6HelpVBox.dll
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbd2720000 LB 0x0004f000 C:\Program Files\Oracle\VirtualBox\Qt6StateMachineVBox.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\Qt6StateMachineVBox.dll
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbd75e0000 LB 0x000d7000 C:\Windows\System32\OLEAUT32.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\oleaut32.dll
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffaed540000 LB 0x01b4a000 C:\Program Files\Oracle\VirtualBox\UICommon.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\UICommon.dll
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffb2ffc0000 LB 0x00154000 C:\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'win32u.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\imm32.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\imm32.dll
- 3f24.31ac: supR3HardenedMonitor_NtCreateSection: NtMapViewOfSection failed on 00000000000005b0 (hFile=0000000000000580) with 0xc0000022 -> STATUS_TRUST_FAILURE
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\imm32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\imm32.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\WinTypes.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\WinTypes.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\gdi32full.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\gdi32full.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\srvcli.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\srvcli.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\netutils.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\netutils.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\Qt6SqlVBox.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\Qt6SqlVBox.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\userenv.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\userenv.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=22900 '\Device\HarddiskVolume5\Windows\System32\authz.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\authz.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\netapi32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\netapi32.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\version.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\version.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\d3d11.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\d3d11.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\dxgi.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\dxgi.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\shell32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\shell32.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=22900 '\Device\HarddiskVolume5\Windows\System32\DWrite.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\DWrite.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\msvcp140_2.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\msvcp140_2.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\dwmapi.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\dwmapi.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=22900 '\Device\HarddiskVolume5\Windows\System32\uxtheme.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\uxtheme.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\msvcp140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\msvcp140_1.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\win32u.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\win32u.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\gdi32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\gdi32.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\msvcp_win.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\msvcp_win.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\combase.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\combase.dll' [rescheduled]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\imm32.dll [redoing WinVerifyTrust]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\imm32.dll'.
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume5\Windows\System32\imm32.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume5\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\win32u.dll [redoing WinVerifyTrust]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\win32u.dll'.
- 3f24.31ac: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume5\Windows\System32\win32u.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume5\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\combase.dll [redoing WinVerifyTrust]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\combase.dll'.
- 3f24.31ac: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume5\Windows\System32\combase.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume5\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\win32u.dll [redoing WinVerifyTrust]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\win32u.dll'.
- 3f24.31ac: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume5\Windows\System32\win32u.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume5\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume5\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\gdi32.dll [redoing WinVerifyTrust]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\gdi32.dll'.
- 3f24.31ac: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume5\Windows\System32\gdi32.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\msvcp_win.dll [redoing WinVerifyTrust]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\msvcp_win.dll'.
- 3f24.31ac: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume5\Windows\System32\msvcp_win.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume5\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\IMM32.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbd7940000 LB 0x00031000 C:\Windows\System32\IMM32.DLL [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\imm32.dll [avoiding WinVerifyTrust]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7940000 'C:\Windows\system32\IMM32.DLL'
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\imm32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\imm32.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\WinTypes.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\WinTypes.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\gdi32full.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\gdi32full.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\srvcli.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\srvcli.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\netutils.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\netutils.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\Qt6SqlVBox.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\Qt6SqlVBox.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\userenv.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\userenv.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=22900 '\Device\HarddiskVolume5\Windows\System32\authz.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\authz.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\netapi32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\netapi32.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\version.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\version.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\d3d11.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\d3d11.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\dxgi.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\dxgi.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\shell32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\shell32.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=22900 '\Device\HarddiskVolume5\Windows\System32\DWrite.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\DWrite.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\msvcp140_2.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\msvcp140_2.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\dwmapi.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\dwmapi.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=22900 '\Device\HarddiskVolume5\Windows\System32\uxtheme.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\uxtheme.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\msvcp140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\msvcp140_1.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\win32u.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\win32u.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\gdi32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\gdi32.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\msvcp_win.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\msvcp_win.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\combase.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\combase.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\imm32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\imm32.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\WinTypes.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\WinTypes.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\gdi32full.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\gdi32full.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\srvcli.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\srvcli.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\netutils.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\netutils.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\Qt6SqlVBox.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\Qt6SqlVBox.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\userenv.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\userenv.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=22900 '\Device\HarddiskVolume5\Windows\System32\authz.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\authz.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\netapi32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\netapi32.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\version.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\version.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\d3d11.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\d3d11.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\dxgi.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\dxgi.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\shell32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\shell32.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=22900 '\Device\HarddiskVolume5\Windows\System32\DWrite.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\DWrite.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\msvcp140_2.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\msvcp140_2.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\dwmapi.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\dwmapi.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=22900 '\Device\HarddiskVolume5\Windows\System32\uxtheme.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\uxtheme.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\msvcp140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\msvcp140_1.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\win32u.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\win32u.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\gdi32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\gdi32.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\msvcp_win.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\msvcp_win.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\combase.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\combase.dll' [rescheduled]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\gdi32.dll [redoing WinVerifyTrust]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\gdi32.dll'.
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume5\Windows\System32\gdi32.dll
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6e00000 'C:\Windows\System32\gdi32.dll'
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\imm32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\imm32.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\WinTypes.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\WinTypes.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\gdi32full.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\gdi32full.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\srvcli.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\srvcli.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\netutils.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\netutils.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\Qt6SqlVBox.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\Qt6SqlVBox.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\userenv.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\userenv.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=22900 '\Device\HarddiskVolume5\Windows\System32\authz.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\authz.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\netapi32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\netapi32.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\version.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\version.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\d3d11.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\d3d11.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\dxgi.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\dxgi.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\shell32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\shell32.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=22900 '\Device\HarddiskVolume5\Windows\System32\DWrite.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\DWrite.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\msvcp140_2.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\msvcp140_2.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\dwmapi.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\dwmapi.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=22900 '\Device\HarddiskVolume5\Windows\System32\uxtheme.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\uxtheme.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\msvcp140_1.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\msvcp140_1.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\win32u.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\win32u.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\gdi32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\gdi32.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\msvcp_win.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\msvcp_win.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\combase.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\combase.dll' [rescheduled]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb2ffc0000 'C:\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\imm32.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\WinTypes.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\gdi32full.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\srvcli.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\netutils.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\Qt6SqlVBox.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\userenv.dll'
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000050c pwszName=\Device\HarddiskVolume5\Windows\System32\authz.dll
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000002440e2782e0
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000002440e2782e0
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=35A08DD1CF3C7ACA286DE00029F21D5B286CF85E
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package05142030~31bf3856ad364e35~amd64~~10.0.22621.5039.cat'; file='\Device\HarddiskVolume5\Windows\System32\authz.dll'
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\authz.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\netapi32.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\version.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\d3d11.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\crypt32.dll
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\dxgi.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\shell32.dll'
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000045c pwszName=\Device\HarddiskVolume5\Windows\System32\DWrite.dll
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000002440e2782e0
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000002440e2782e0
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=3A14F493351233539FC8E1DDF869B897830701F4
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package051021~31bf3856ad364e35~amd64~~10.0.22621.5039.cat'; file='\Device\HarddiskVolume5\Windows\System32\DWrite.dll'
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\DWrite.dll'
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\rsaenh.dll
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\msvcp140_2.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\dwmapi.dll'
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000041c pwszName=\Device\HarddiskVolume5\Windows\System32\uxtheme.dll
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000002440e2782e0
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000002440e2782e0
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=39A793A611F3CBD0CA1BB792D98180D7E9E0E443
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package05~31bf3856ad364e35~amd64~~10.0.22621.5039.cat'; file='\Device\HarddiskVolume5\Windows\System32\uxtheme.dll'
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\uxtheme.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\msvcp140_1.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\win32u.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\gdi32.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\msvcp_win.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\combase.dll'
- 3f24.31ac: SUPR3HardenedMain: Calling TrustedMain (00007ffb2ffc19a0)...
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #31 'combase.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #32 'msvcp_win.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\windows.storage.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\windows.storage.dll
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbd3d60000 LB 0x0090d000 C:\Windows\SYSTEM32\windows.storage.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\windows.storage.dll [avoiding WinVerifyTrust]
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbd7fd0000 LB 0x0010a000 C:\Windows\System32\SHCORE.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\SHCore.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\SHCore.dll
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbd7580000 LB 0x0005e000 C:\Windows\System32\shlwapi.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\shlwapi.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\shlwapi.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\msvcp_win.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\msvcp_win.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume5\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\combase.dll
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\shlwapi.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\SHCore.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\windows.storage.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'advapi32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'dwmapi.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'imm32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ole32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'oleaut32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'setupapi.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'shell32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'shlwapi.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'user32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'winmm.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'wtsapi32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'comdlg32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'd3d9.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'qt6guivbox.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #18 'qt6corevbox.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #20 'msvcp140.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #21 'vcruntime140.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #22 'vcruntime140_1.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\platforms\qwindowsVBox.dll) WinVerifyTrust
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\platforms\qwindowsVBox.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140_1.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140_1.dll' -> '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140.dll' -> '\Device\HarddiskVolume5\Windows\System32\vcruntime140.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp140.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp140.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcp140.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt6corevbox.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt6corevbox.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\qt6corevbox.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt6guivbox.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt6guivbox.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\qt6guivbox.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\Qt6GuiVBox.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'd3d9.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'd3d9.dll' -> '\Device\HarddiskVolume5\Windows\System32\d3d9.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'win32u.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'gdi32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'dwmapi.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\d3d9.dll) WinVerifyTrust
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\d3d9.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comdlg32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'comdlg32.dll' -> '\Device\HarddiskVolume5\Windows\System32\comdlg32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000770 pwszName=\Device\HarddiskVolume5\Windows\System32\comdlg32.dll
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000002440e2782e0
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000002440e2782e0
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2A8CA960FAC4C7D072818494CB78FA226758A25C
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dwmapi.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'dwmapi.dll' -> '\Device\HarddiskVolume5\Windows\System32\dwmapi.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\dwmapi.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume5\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume5\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume5\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package05114~31bf3856ad364e35~amd64~~10.0.22621.5037.cat'; file='\Device\HarddiskVolume5\Windows\System32\comdlg32.dll'
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'rpcrt4.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #43 'user32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #61 'shlwapi.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #62 'gdi32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #63 'comctl32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #64 'shell32.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\comdlg32.dll) WinVerifyTrust
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\comdlg32.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wtsapi32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'wtsapi32.dll' -> '\Device\HarddiskVolume5\Windows\System32\wtsapi32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume5\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\shell32.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'comctl32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'comctl32.dll' -> '\Device\HarddiskVolume5\Windows\System32\comctl32.dll' [rcNtRedir=0x0]
- 3f24.31ac: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\comctl32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'advapi32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\comctl32.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\comctl32.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume5\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume5\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\shlwapi.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume5\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume5\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume5\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume5\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume5\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\advapi32.dll
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\wtsapi32.dll) WinVerifyTrust
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\wtsapi32.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume5\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\winmm.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume5\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume5\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\shlwapi.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume5\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\shell32.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume5\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\setupapi.dll) WinVerifyTrust
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\setupapi.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume5\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\oleaut32.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume5\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\ole32.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume5\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\imm32.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume5\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'dwmapi.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'dwmapi.dll' -> '\Device\HarddiskVolume5\Windows\System32\dwmapi.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\dwmapi.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume5\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\advapi32.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\platforms\qwindowsVBox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.31ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\platforms\qwindowsVBox.dll
- 3f24.31ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\wtsapi32.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'advapi32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.22621.3527_none_b43b7f4b638cc64f\comctl32.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.22621.3527_none_b43b7f4b638cc64f\comctl32.dll
- 3f24.31ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\d3d9.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'win32u.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\DXCore.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\DXCore.dll
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbd7b50000 LB 0x00474000 C:\Windows\System32\SETUPAPI.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\setupapi.dll
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbd4c90000 LB 0x00014000 C:\Windows\SYSTEM32\WTSAPI32.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\wtsapi32.dll
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbc02e0000 LB 0x000b3000 C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.22621.3527_none_b43b7f4b638cc64f\COMCTL32.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.22621.3527_none_b43b7f4b638cc64f\comctl32.dll [avoiding WinVerifyTrust]
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbd6a10000 LB 0x00102000 C:\Windows\System32\COMDLG32.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\comdlg32.dll
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbd3590000 LB 0x00037000 C:\Windows\SYSTEM32\dxcore.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\DXCore.dll [avoiding WinVerifyTrust]
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbb6cc0000 LB 0x001a8000 C:\Windows\SYSTEM32\d3d9.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\d3d9.dll
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffb88cd0000 LB 0x000cd000 C:\Program Files\Oracle\VirtualBox\platforms\qwindowsVBox.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\platforms\qwindowsVBox.dll
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\DXCore.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\DXCore.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.22621.3527_none_b43b7f4b638cc64f\comctl32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.22621.3527_none_b43b7f4b638cc64f\comctl32.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\comctl32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\comctl32.dll' [rescheduled]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\imm32.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume5\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume5\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume5\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\gdi32.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume5\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\advapi32.dll
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\imm32.dll (Input=imm32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7940000 'C:\Windows\System32\imm32.dll'
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\DXCore.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\DXCore.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.22621.3527_none_b43b7f4b638cc64f\comctl32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.22621.3527_none_b43b7f4b638cc64f\comctl32.dll' [rescheduled]
- 3f24.31ac: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume5\Windows\System32\comctl32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume5\Windows\System32\comctl32.dll' [rescheduled]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb88cd0000 'C:\Program Files\Oracle\VirtualBox\platforms\qwindowsVBox.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\DXCore.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.22621.3527_none_b43b7f4b638cc64f\comctl32.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\comctl32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'rpcrt4.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #38 'bcryptprimitives.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #51 'combase.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #52 'msvcp_win.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume5\Windows\System32\rpcss.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\rpcss.dll
- 3f24.31ac: supR3HardenedMonitor_NtCreateSection: NtMapViewOfSection failed on 00000000000006b4 (hFile=00000000000006bc) with 0xc0000022 -> STATUS_TRUST_FAILURE
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000006c0 pwszName=\Device\HarddiskVolume5\Windows\System32\rpcss.dll
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000002440e2782e0
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000002440e2782e0
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=EE801CC70F2DB8C5D1D7E0C1FC570B58BEF5FA59
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume5\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\combase.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcryptprimitives.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcryptprimitives.dll' -> '\Device\HarddiskVolume5\Windows\System32\bcryptprimitives.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\bcryptprimitives.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume5\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package05142030~31bf3856ad364e35~amd64~~10.0.22621.5039.cat'; file='\Device\HarddiskVolume5\Windows\System32\rpcss.dll'
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\rpcss.dll'
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\uxtheme.dll
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd3470000 'C:\Windows\system32\uxtheme.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'rpcrt4.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\powrprof.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\powrprof.dll
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbd5100000 LB 0x0004d000 C:\Windows\SYSTEM32\powrprof.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\powrprof.dll [avoiding WinVerifyTrust]
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\umpdc.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\umpdc.dll
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbd4ff0000 LB 0x00013000 C:\Windows\SYSTEM32\UMPDC.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\umpdc.dll [avoiding WinVerifyTrust]
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbd7390000 LB 0x0015d000 C:\Windows\System32\MSCTF.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\msctf.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\msctf.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume5\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\msctf.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\umpdc.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\powrprof.dll'
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\user32.dll
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\USER32.dll (Input=USER32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd71d0000 'C:\Windows\System32\USER32.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #19 'cfgmgr32.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\devobj.dll) WinVerifyTrust
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\devobj.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume5\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\cfgmgr32.dll) WinVerifyTrust
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\cfgmgr32.dll
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\DEVOBJ.dll (Input=DEVOBJ.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.31ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\devobj.dll
- 3f24.31ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\cfgmgr32.dll
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbd5b40000 LB 0x0004e000 C:\Windows\SYSTEM32\cfgmgr32.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\cfgmgr32.dll
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbd5b10000 LB 0x0002c000 C:\Windows\System32\DEVOBJ.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\devobj.dll
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd5b10000 'C:\Windows\System32\DEVOBJ.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'uxtheme.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qt6widgetsvbox.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qt6guivbox.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'qt6corevbox.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'vcruntime140.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'vcruntime140_1.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\styles\qwindowsvistastyleVBox.dll) WinVerifyTrust
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\styles\qwindowsvistastyleVBox.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140_1.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140_1.dll' -> '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140.dll' -> '\Device\HarddiskVolume5\Windows\System32\vcruntime140.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt6corevbox.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt6corevbox.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\qt6corevbox.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt6guivbox.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt6guivbox.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\qt6guivbox.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\Qt6GuiVBox.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt6widgetsvbox.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt6widgetsvbox.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\qt6widgetsvbox.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\Qt6WidgetsVBox.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'uxtheme.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'uxtheme.dll' -> '\Device\HarddiskVolume5\Windows\System32\uxtheme.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\uxtheme.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume5\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume5\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\styles\qwindowsvistastyleVBox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.31ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\styles\qwindowsvistastyleVBox.dll
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbc9c10000 LB 0x00025000 C:\Program Files\Oracle\VirtualBox\styles\qwindowsvistastyleVBox.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\styles\qwindowsvistastyleVBox.dll
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbc9c10000 'C:\Program Files\Oracle\VirtualBox\styles\qwindowsvistastyleVBox.dll'
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\uxtheme.dll
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\uxtheme.dll (Input=uxtheme.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd3470000 'C:\Windows\System32\uxtheme.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #39 'gdi32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #40 'user32.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.22621.4830_none_270fe7d773858e80\comctl32.dll) WinVerifyTrust
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.22621.4830_none_270fe7d773858e80\comctl32.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume5\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume5\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.22621.4830_none_270fe7d773858e80\comctl32.dll (Input=comctl32.dll, rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000004001:<flags> [calling]
- 3f24.31ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.22621.4830_none_270fe7d773858e80\comctl32.dll
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbc19f0000 LB 0x00292000 C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.22621.4830_none_270fe7d773858e80\comctl32.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.22621.4830_none_270fe7d773858e80\comctl32.dll
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbc19f0000 'C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.22621.4830_none_270fe7d773858e80\comctl32.dll'
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.22621.4830_none_270fe7d773858e80\comctl32.dll
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.22621.4830_none_270fe7d773858e80\comctl32.dll (Input=comctl32.dll, rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000004001:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbc19f0000 'C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.22621.4830_none_270fe7d773858e80\comctl32.dll'
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\WindowsCodecs.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\WindowsCodecs.dll
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbd3240000 LB 0x001b0000 C:\Windows\SYSTEM32\WindowsCodecs.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\WindowsCodecs.dll [avoiding WinVerifyTrust]
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbd7980000 LB 0x000b0000 C:\Windows\System32\clbcatq.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #30 'rpcrt4.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\clbcatq.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\clbcatq.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume5\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\rpcrt4.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\clbcatq.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\WindowsCodecs.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #39 'msvcp_win.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\thumbcache.dll) WinVerifyTrust
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\thumbcache.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\thumbcache.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
- 3f24.31ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\thumbcache.dll
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffb9d270000 LB 0x0006a000 C:\Windows\System32\thumbcache.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\thumbcache.dll
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb9d270000 'C:\Windows\System32\thumbcache.dll'
- 3f24.31ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\rpcss.dll
- 3f24.31ac: supR3HardenedMonitor_NtCreateSection: NtMapViewOfSection failed on 0000000000000880 (hFile=0000000000000874) with 0xc0000022 -> STATUS_TRUST_FAILURE
- 3f24.10b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.10b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.10b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'vcruntime140.dll'.
- 3f24.10b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vcruntime140_1.dll'.
- 3f24.10b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msvcp140.dll'.
- 3f24.10b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vboxrt.dll'.
- 3f24.10b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'advapi32.dll'.
- 3f24.10b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'ole32.dll'.
- 3f24.10b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #15 'oleaut32.dll'.
- 3f24.10b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxC.dll) WinVerifyTrust
- 3f24.10b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxC.dll
- 3f24.10b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
- 3f24.10b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume5\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
- 3f24.10b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\oleaut32.dll
- 3f24.10b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
- 3f24.10b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume5\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
- 3f24.10b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\ole32.dll
- 3f24.10b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
- 3f24.10b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume5\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
- 3f24.10b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\advapi32.dll
- 3f24.10b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
- 3f24.10b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
- 3f24.10b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp140.dll'...
- 3f24.10b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp140.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcp140.dll' [rcNtRedir=0xc0150008]
- 3f24.10b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140_1.dll'...
- 3f24.10b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140_1.dll' -> '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rcNtRedir=0xc0150008]
- 3f24.10b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140.dll'...
- 3f24.10b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140.dll' -> '\Device\HarddiskVolume5\Windows\System32\vcruntime140.dll' [rcNtRedir=0xc0150008]
- 3f24.10b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxC.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
- 3f24.10b4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxC.dll
- 3f24.10b4: supR3HardenedDllNotificationCallback: load 00007ffb721e0000 LB 0x003f6000 C:\Program Files\Oracle\VirtualBox\VBoxC.dll [fFlags=0x0]
- 3f24.10b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxC.dll
- 3f24.10b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb721e0000 'C:\Program Files\Oracle\VirtualBox\VBoxC.dll'
- 3f24.10b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.10b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.10b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'vcruntime140.dll'.
- 3f24.10b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
- 3f24.10b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'advapi32.dll'.
- 3f24.10b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'shlwapi.dll'.
- 3f24.10b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'ole32.dll'.
- 3f24.10b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'oleaut32.dll'.
- 3f24.10b4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'rpcrt4.dll'.
- 3f24.10b4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll) WinVerifyTrust
- 3f24.10b4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll
- 3f24.10b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 3f24.10b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume5\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 3f24.10b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
- 3f24.10b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume5\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
- 3f24.10b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\oleaut32.dll
- 3f24.10b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
- 3f24.10b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume5\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
- 3f24.10b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\ole32.dll
- 3f24.10b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
- 3f24.10b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume5\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
- 3f24.10b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\shlwapi.dll
- 3f24.10b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
- 3f24.10b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume5\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
- 3f24.10b4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\advapi32.dll
- 3f24.10b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
- 3f24.10b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
- 3f24.10b4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140.dll'...
- 3f24.10b4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140.dll' -> '\Device\HarddiskVolume5\Windows\System32\vcruntime140.dll' [rcNtRedir=0xc0150008]
- 3f24.10b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
- 3f24.10b4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll
- 3f24.10b4: supR3HardenedDllNotificationCallback: load 00007ffb88be0000 LB 0x000e9000 C:\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll [fFlags=0x0]
- 3f24.10b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll
- 3f24.10b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb88be0000 'C:\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll'
- 3f24.10b4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\oleaut32.dll
- 3f24.10b4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\oleaut32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
- 3f24.10b4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd75e0000 'C:\Windows\System32\oleaut32.dll'
- 3f24.31ac: '\Device\HarddiskVolume5\Windows\System32\tzres.dll' has no imports
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume5\Windows\System32\tzres.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\tzres.dll
- 3f24.31ac: supR3HardenedMonitor_NtCreateSection: NtMapViewOfSection failed on 00000000000009ec (hFile=00000000000009bc) with 0xc0000022 -> STATUS_TRUST_FAILURE
- 3f24.31ac: supR3HardenedScreenImage/NtCreateSection: cache hit (22900) on \Device\HarddiskVolume5\Windows\System32\tzres.dll [avoiding WinVerifyTrust]
- 3f24.31ac: supR3HardenedMonitor_NtCreateSection: NtMapViewOfSection failed on 00000000000009bc (hFile=00000000000009ec) with 0xc0000022 -> STATUS_TRUST_FAILURE
- 3f24.4918: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000009e8 pwszName=\Device\HarddiskVolume5\Windows\System32\tzres.dll
- 3f24.4918: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000002440e2782e0
- 3f24.4918: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000002440e2782e0
- 3f24.4918: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=C937369FF20DE75362318875CB965C74D59448F3
- 3f24.4918: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.4918: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.4918: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package051420~31bf3856ad364e35~amd64~~10.0.22621.5039.cat'; file='\Device\HarddiskVolume5\Windows\System32\tzres.dll'
- 3f24.4918: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 3f24.4918: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\tzres.dll'
- 3f24.4918: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.4918: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.4918: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'vcruntime140.dll'.
- 3f24.4918: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vcruntime140_1.dll'.
- 3f24.4918: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
- 3f24.4918: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxVMM.dll) WinVerifyTrust
- 3f24.4918: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxVMM.dll
- 3f24.4918: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
- 3f24.4918: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
- 3f24.4918: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140_1.dll'...
- 3f24.4918: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140_1.dll' -> '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rcNtRedir=0xc0150008]
- 3f24.4918: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140.dll'...
- 3f24.4918: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140.dll' -> '\Device\HarddiskVolume5\Windows\System32\vcruntime140.dll' [rcNtRedir=0xc0150008]
- 3f24.4918: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.4918: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxVMM.dll
- 3f24.4918: supR3HardenedDllNotificationCallback: load 00007ffb231c0000 LB 0x0058f000 C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL [fFlags=0x0]
- 3f24.4918: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxVMM.dll
- 3f24.4918: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb231c0000 'C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL'
- 3f24.31ac: \Device\HarddiskVolume5\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9425e4c3b1ac1c47\nvldumdx.dll: Signature #2/3: VERR_CR_X509_CPV_NOT_VALID_AT_TIME for 0x674f5e4f; retrying against current time: 0x67f2b435.
- 3f24.31ac: \Device\HarddiskVolume5\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9425e4c3b1ac1c47\nvldumdx.dll: Signature #2/3: VERR_CR_X509_CPV_NOT_VALID_AT_TIME (-23033) w/ timestamp=0x67f2b435/now.
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #32 'version.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #33 'user32.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9425e4c3b1ac1c47\nvldumdx.dll) WinVerifyTrust
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9425e4c3b1ac1c47\nvldumdx.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume5\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'version.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'version.dll' -> '\Device\HarddiskVolume5\Windows\System32\version.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\version.dll
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9425e4c3b1ac1c47\nvldumdx.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
- 3f24.31ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9425e4c3b1ac1c47\nvldumdx.dll
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbcb010000 LB 0x000c4000 C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9425e4c3b1ac1c47\nvldumdx.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9425e4c3b1ac1c47\nvldumdx.dll
- 3f24.31ac: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd5e50000 'api-ms-win-core-synch-l1-2-0'
- 3f24.31ac: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-fibers-l1-1-1) -> 0x0, fPresent=1
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd5e50000 'api-ms-win-core-fibers-l1-1-1'
- 3f24.31ac: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd5e50000 'api-ms-win-core-synch-l1-2-0'
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\kernel32.dll
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\kernel32.dll (Input=kernel32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7870000 'C:\Windows\System32\kernel32.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcb010000 'C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9425e4c3b1ac1c47\nvldumdx.dll'
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\msasn1.dll
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\msasn1.dll (Input=msasn1.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd5af0000 'C:\Windows\System32\msasn1.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd09b0000 'C:\Windows\System32\cryptnet.dll'
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\cryptbase.dll
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\cryptbase.dll (Input=cryptbase.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd56e0000 'C:\Windows\System32\cryptbase.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #35 'oleaut32.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\wldp.dll) WinVerifyTrust
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\wldp.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume5\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\oleaut32.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\wldp.dll (Input=wldp.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 3f24.31ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\wldp.dll
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbd5630000 LB 0x0004a000 C:\Windows\System32\wldp.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\wldp.dll
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd5630000 'C:\Windows\System32\wldp.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\drvstore.dll) WinVerifyTrust
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\drvstore.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\msvcrt.dll
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\drvstore.dll (Input=drvstore.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 3f24.31ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\drvstore.dll
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbd04b0000 LB 0x00162000 C:\Windows\System32\drvstore.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\drvstore.dll
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd04b0000 'C:\Windows\System32\drvstore.dll'
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\devobj.dll
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\devobj.dll (Input=devobj.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd5b10000 'C:\Windows\System32\devobj.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\wintrust.dll
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\wintrust.dll (Input=wintrust.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd65c0000 'C:\Windows\System32\wintrust.dll'
- 3f24.31ac: \Device\HarddiskVolume5\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9425e4c3b1ac1c47\nvgpucomp64.dll: Signature #2/3: VERR_CR_X509_CPV_NOT_VALID_AT_TIME for 0x674f5f1d; retrying against current time: 0x67f2b436.
- 3f24.31ac: \Device\HarddiskVolume5\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9425e4c3b1ac1c47\nvgpucomp64.dll: Signature #2/3: VERR_CR_X509_CPV_NOT_VALID_AT_TIME (-23033) w/ timestamp=0x67f2b436/now.
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'ole32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'shell32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9425e4c3b1ac1c47\nvgpucomp64.dll) WinVerifyTrust
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9425e4c3b1ac1c47\nvgpucomp64.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume5\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume5\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\shell32.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume5\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9425e4c3b1ac1c47\nvgpucomp64.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.31ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9425e4c3b1ac1c47\nvgpucomp64.dll
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbc2bf0000 LB 0x02d10000 C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9425e4c3b1ac1c47\nvgpucomp64.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9425e4c3b1ac1c47\nvgpucomp64.dll
- 3f24.31ac: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd5e50000 'api-ms-win-core-synch-l1-2-0'
- 3f24.31ac: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-fibers-l1-1-1) -> 0x0, fPresent=1
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd5e50000 'api-ms-win-core-fibers-l1-1-1'
- 3f24.31ac: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd5e50000 'api-ms-win-core-synch-l1-2-0'
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\kernel32.dll
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\kernel32.dll (Input=kernel32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7870000 'C:\Windows\System32\kernel32.dll'
- 3f24.31ac: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-string-l1-1-0) -> 0x0, fPresent=1
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-string-l1-1-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd5e50000 'api-ms-win-core-string-l1-1-0'
- 3f24.31ac: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-l1-2-1) -> 0x0, fPresent=1
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-l1-2-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd5e50000 'api-ms-win-core-localization-l1-2-1'
- 3f24.31ac: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-datetime-l1-1-1) -> 0x0, fPresent=1
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-datetime-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd5e50000 'api-ms-win-core-datetime-l1-1-1'
- 3f24.31ac: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-obsolete-l1-2-0) -> 0x0, fPresent=1
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-obsolete-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd5e50000 'api-ms-win-core-localization-obsolete-l1-2-0'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbc2bf0000 'C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9425e4c3b1ac1c47\nvgpucomp64.dll'
- 3f24.31ac: \Device\HarddiskVolume5\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9425e4c3b1ac1c47\nvd3dumx.dll: Signature #2/3: VERR_CR_X509_CPV_NOT_VALID_AT_TIME for 0x674f5d85; retrying against current time: 0x67f2b436.
- 3f24.31ac: \Device\HarddiskVolume5\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9425e4c3b1ac1c47\nvd3dumx.dll: Signature #2/3: VERR_CR_X509_CPV_NOT_VALID_AT_TIME (-23033) w/ timestamp=0x67f2b436/now.
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'version.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'gdi32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'winmm.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9425e4c3b1ac1c47\nvd3dumx.dll) WinVerifyTrust
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9425e4c3b1ac1c47\nvd3dumx.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume5\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\winmm.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume5\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume5\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume5\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'version.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'version.dll' -> '\Device\HarddiskVolume5\Windows\System32\version.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\version.dll
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9425e4c3b1ac1c47\nvd3dumx.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.31ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9425e4c3b1ac1c47\nvd3dumx.dll
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffb6fd70000 LB 0x01d8c000 C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9425e4c3b1ac1c47\nvd3dumx.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9425e4c3b1ac1c47\nvd3dumx.dll
- 3f24.31ac: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd5e50000 'api-ms-win-core-synch-l1-2-0'
- 3f24.31ac: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-fibers-l1-1-1) -> 0x0, fPresent=1
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd5e50000 'api-ms-win-core-fibers-l1-1-1'
- 3f24.31ac: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd5e50000 'api-ms-win-core-synch-l1-2-0'
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\kernel32.dll
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\kernel32.dll (Input=kernel32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7870000 'C:\Windows\System32\kernel32.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb6fd70000 'C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9425e4c3b1ac1c47\nvd3dumx.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'msvcp_win.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\directxdatabasehelper.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\directxdatabasehelper.dll
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbcf3a0000 LB 0x00049000 C:\Windows\SYSTEM32\directxdatabasehelper.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\directxdatabasehelper.dll [avoiding WinVerifyTrust]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\directxdatabasehelper.dll'
- 3f24.31ac: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(ext-ms-win-core-resourcepolicy-l1-1-0.dll) -> 0x0, fPresent=1
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=ext-ms-win-core-resourcepolicy-l1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'rpcrt4.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\ResourcePolicyClient.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\ResourcePolicyClient.dll
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbd3950000 LB 0x00015000 C:\Windows\SYSTEM32\resourcepolicyclient.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\ResourcePolicyClient.dll [avoiding WinVerifyTrust]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd3950000 'ext-ms-win-core-resourcepolicy-l1-1-0.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume5\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\ResourcePolicyClient.dll'
- 3f24.31ac: supR3HardenedDllNotificationCallback: Unload 00007ffbd3950000 LB 0x00015000 C:\Windows\SYSTEM32\resourcepolicyclient.dll [flags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9425e4c3b1ac1c47\nvldumdx.dll
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9425e4c3b1ac1c47\nvldumdx.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcb010000 'C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9425e4c3b1ac1c47\nvldumdx.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6e00000 'C:\Windows\System32\gdi32.dll'
- 3f24.31ac: supR3HardenedDllNotificationCallback: Unload 00007ffb6fd70000 LB 0x01d8c000 C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9425e4c3b1ac1c47\nvd3dumx.dll [flags=0x0]
- 3f24.31ac: supR3HardenedDllNotificationCallback: Unload 00007ffbc2bf0000 LB 0x02d10000 C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9425e4c3b1ac1c47\nvgpucomp64.dll [flags=0x0]
- 3f24.31ac: supR3HardenedDllNotificationCallback: Unload 00007ffbd04b0000 LB 0x00162000 C:\Windows\System32\drvstore.dll [flags=0x0]
- 3f24.31ac: supR3HardenedDllNotificationCallback: Unload 00007ffbd5630000 LB 0x0004a000 C:\Windows\System32\wldp.dll [flags=0x0]
- 3f24.31ac: supR3HardenedDllNotificationCallback: Unload 00007ffbcb010000 LB 0x000c4000 C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9425e4c3b1ac1c47\nvldumdx.dll [flags=0x0]
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000c98 pwszName=\Device\HarddiskVolume5\Windows\System32\DataExchange.dll
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000002440e2782e0
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000002440e2782e0
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=77058853787D8A28928248724CB83756300506B8
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package051020~31bf3856ad364e35~amd64~~10.0.22621.4830.cat'; file='\Device\HarddiskVolume5\Windows\System32\DataExchange.dll'
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #27 'msvcp_win.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\DataExchange.dll) WinVerifyTrust
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\DataExchange.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\dataexchange.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
- 3f24.31ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\DataExchange.dll
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffba0740000 LB 0x0005e000 C:\Windows\system32\dataexchange.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\DataExchange.dll
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffba0740000 'C:\Windows\system32\dataexchange.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #43 'combase.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #45 'msvcp_win.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\twinapi.appcore.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\twinapi.appcore.dll
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbcb1a0000 LB 0x002a5000 C:\Windows\system32\twinapi.appcore.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\twinapi.appcore.dll [avoiding WinVerifyTrust]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\msvcp_win.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume5\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\combase.dll
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\twinapi.appcore.dll'
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\SHCore.dll
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\Shcore.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7fd0000 'C:\Windows\system32\Shcore.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'oleaut32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'rpcrt4.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\TextInputFramework.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\TextInputFramework.dll
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbc0650000 LB 0x00143000 C:\Windows\SYSTEM32\textinputframework.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\TextInputFramework.dll [avoiding WinVerifyTrust]
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'msvcp_win.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\CoreMessaging.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\CoreMessaging.dll
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbd23f0000 LB 0x00135000 C:\Windows\SYSTEM32\CoreMessaging.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\CoreMessaging.dll [avoiding WinVerifyTrust]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume5\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume5\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\oleaut32.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\CoreMessaging.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\TextInputFramework.dll'
- 3f24.31ac: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-security-sddl-l1-1-0.dll) -> 0x0, fPresent=1
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-security-sddl-l1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6b90000 'api-ms-win-security-sddl-l1-1-0.dll'
- 3f24.31ac: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(ext-ms-win-rtcore-ntuser-window-ext-l1-1-0.dll) -> 0x0, fPresent=1
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=ext-ms-win-rtcore-ntuser-window-ext-l1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd71d0000 'ext-ms-win-rtcore-ntuser-window-ext-l1-1-0.dll'
- 3f24.31ac: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(ext-ms-win-rtcore-ntuser-integration-l1-1-0.dll) -> 0x0, fPresent=1
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=ext-ms-win-rtcore-ntuser-integration-l1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd71d0000 'ext-ms-win-rtcore-ntuser-integration-l1-1-0.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #33 'coremessaging.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\CoreUIComponents.dll)
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\CoreUIComponents.dll
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbce810000 LB 0x0036c000 C:\Windows\SYSTEM32\CoreUIComponents.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\CoreUIComponents.dll [avoiding WinVerifyTrust]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'coremessaging.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'coremessaging.dll' -> '\Device\HarddiskVolume5\Windows\System32\coremessaging.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\CoreMessaging.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume5\Windows\System32\CoreUIComponents.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd8bb0000 'C:\Windows\System32\RPCRT4.dll'
- 3f24.31ac: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-security-systemfunctions-l1-1-0) -> 0x0, fPresent=1
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-security-systemfunctions-l1-1-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7a40000 'api-ms-win-security-systemfunctions-l1-1-0'
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\msctf.dll
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\MSCTF.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7390000 'C:\Windows\System32\MSCTF.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd76c0000 'C:\Windows\System32\ole32.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd75e0000 'C:\Windows\System32\OLEAUT32.dll'
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000d14 pwszName=\Device\HarddiskVolume5\Windows\System32\wbem\wbemprox.dll
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000002440e2782e0
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000002440e2782e0
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=9AD36488966AA7858FEFB09EE4C1DB68C5F52047
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package04~31bf3856ad364e35~amd64~~10.0.22621.4890.cat'; file='\Device\HarddiskVolume5\Windows\System32\wbem\wbemprox.dll'
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'wbemcomn.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\wbem\wbemprox.dll) WinVerifyTrust
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\wbem\wbemprox.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wbemcomn.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'wbemcomn.dll' -> '\Device\HarddiskVolume5\Windows\System32\wbemcomn.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000d24 pwszName=\Device\HarddiskVolume5\Windows\System32\wbemcomn.dll
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000002440e2782e0
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000002440e2782e0
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=48E4CF81FAA1F76B63306E69DB1B016762CEEDB5
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package04~31bf3856ad364e35~amd64~~10.0.22621.4890.cat'; file='\Device\HarddiskVolume5\Windows\System32\wbemcomn.dll'
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\wbemcomn.dll) WinVerifyTrust
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\wbemcomn.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wbem\wbemprox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
- 3f24.31ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\wbem\wbemprox.dll
- 3f24.31ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\wbemcomn.dll
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbcf850000 LB 0x00080000 C:\Windows\SYSTEM32\wbemcomn.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\wbemcomn.dll
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbcf8d0000 LB 0x00010000 C:\Windows\system32\wbem\wbemprox.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\wbem\wbemprox.dll
- 3f24.31ac: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(API-MS-Win-Core-LocalRegistry-L1-1-0.dll) -> 0x0, fPresent=1
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Core-LocalRegistry-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd5e50000 'API-MS-Win-Core-LocalRegistry-L1-1-0.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcf8d0000 'C:\Windows\system32\wbem\wbemprox.dll'
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000d70 pwszName=\Device\HarddiskVolume5\Windows\System32\wbem\wbemsvc.dll
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000002440e2782e0
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000002440e2782e0
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=90D9CA995849F184A9BB705EF47370C35858B12B
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package04~31bf3856ad364e35~amd64~~10.0.22621.4890.cat'; file='\Device\HarddiskVolume5\Windows\System32\wbem\wbemsvc.dll'
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'rpcrt4.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\wbem\wbemsvc.dll) WinVerifyTrust
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\wbem\wbemsvc.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume5\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wbem\wbemsvc.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
- 3f24.31ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\wbem\wbemsvc.dll
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbcaff0000 LB 0x00014000 C:\Windows\system32\wbem\wbemsvc.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\wbem\wbemsvc.dll
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcaff0000 'C:\Windows\system32\wbem\wbemsvc.dll'
- 3f24.31ac: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-l1-2-0.dll) -> 0x0, fPresent=1
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-l1-2-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd5e50000 'api-ms-win-core-localization-l1-2-0.dll'
- 3f24.31ac: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-obsolete-l1-1-0.dll) -> 0x0, fPresent=1
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-obsolete-l1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd5e50000 'api-ms-win-core-localization-obsolete-l1-1-0.dll'
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000be0 pwszName=\Device\HarddiskVolume5\Windows\System32\wbem\fastprox.dll
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000002440e2782e0
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000002440e2782e0
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=B04A0E1E5BC0341B6D82872D9E65FE40A6B3AA40
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package04~31bf3856ad364e35~amd64~~10.0.22621.4890.cat'; file='\Device\HarddiskVolume5\Windows\System32\wbem\fastprox.dll'
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #20 'wbemcomn.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\wbem\fastprox.dll) WinVerifyTrust
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\wbem\fastprox.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wbemcomn.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'wbemcomn.dll' -> '\Device\HarddiskVolume5\Windows\System32\wbemcomn.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\wbemcomn.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wbem\fastprox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
- 3f24.31ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\wbem\fastprox.dll
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbc6eb0000 LB 0x000f8000 C:\Windows\system32\wbem\fastprox.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\wbem\fastprox.dll
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbc6eb0000 'C:\Windows\system32\wbem\fastprox.dll'
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000be4 pwszName=\Device\HarddiskVolume5\Windows\System32\amsi.dll
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000002440e2782e0
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000002440e2782e0
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=E2ACDC6C91AD00483DCF60BAE07E77D4A30A9EA6
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package05~31bf3856ad364e35~amd64~~10.0.22621.5039.cat'; file='\Device\HarddiskVolume5\Windows\System32\amsi.dll'
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'rpcrt4.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\amsi.dll) WinVerifyTrust
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\amsi.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume5\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\amsi.dll (Input=amsi.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 3f24.31ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\amsi.dll
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbc11e0000 LB 0x0001d000 C:\Windows\System32\amsi.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\amsi.dll
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbc11e0000 'C:\Windows\System32\amsi.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'advapi32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'oleaut32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'ole32.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\ProgramData\Microsoft\Windows Defender\Platform\4.18.25020.1009-0\MpOAV.dll) WinVerifyTrust
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\ProgramData\Microsoft\Windows Defender\Platform\4.18.25020.1009-0\MpOAV.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume5\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume5\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume5\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25020.1009-0\MpOav.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.31ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\ProgramData\Microsoft\Windows Defender\Platform\4.18.25020.1009-0\MpOAV.dll
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffbc0fb0000 LB 0x00080000 C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25020.1009-0\MpOav.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\ProgramData\Microsoft\Windows Defender\Platform\4.18.25020.1009-0\MpOAV.dll
- 3f24.31ac: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd5e50000 'api-ms-win-core-synch-l1-2-0'
- 3f24.31ac: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-fibers-l1-1-1) -> 0x0, fPresent=1
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd5e50000 'api-ms-win-core-fibers-l1-1-1'
- 3f24.31ac: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd5e50000 'api-ms-win-core-synch-l1-2-0'
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\kernel32.dll
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\kernel32.dll (Input=kernel32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7870000 'C:\Windows\System32\kernel32.dll'
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\version.dll
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\version.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd0a20000 'C:\Windows\system32\version.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbc0fb0000 'C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.25020.1009-0\MpOav.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd7a40000 'C:\Windows\System32\ADVAPI32.dll'
- 3f24.4950: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd76c0000 'C:\Windows\system32\ole32.dll'
- 3f24.4950: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.4950: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000012c8 pwszName=\Device\HarddiskVolume5\Windows\System32\ExplorerFrame.dll
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000002440e2782e0
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000002440e2782e0
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=DBD48D0DF8066ECE124022573DA184ABD5FF6353
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package05113~31bf3856ad364e35~amd64~~10.0.22621.5037.cat'; file='\Device\HarddiskVolume5\Windows\System32\ExplorerFrame.dll'
- 3f24.31ac: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'shcore.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'shell32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'shlwapi.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #28 'rpcrt4.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #45 'advapi32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #46 'imm32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #48 'user32.dll'.
- 3f24.31ac: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #49 'gdi32.dll'.
- 3f24.31ac: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\ExplorerFrame.dll) WinVerifyTrust
- 3f24.31ac: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\ExplorerFrame.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume5\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume5\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume5\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\imm32.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume5\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume5\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume5\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\shlwapi.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume5\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\shell32.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shcore.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'shcore.dll' -> '\Device\HarddiskVolume5\Windows\System32\shcore.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\SHCore.dll
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
- 3f24.31ac: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\explorerframe.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
- 3f24.31ac: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\ExplorerFrame.dll
- 3f24.31ac: supR3HardenedDllNotificationCallback: load 00007ffba0370000 LB 0x002c1000 C:\Windows\system32\explorerframe.dll [fFlags=0x0]
- 3f24.31ac: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\ExplorerFrame.dll
- 3f24.31ac: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffba0370000 'C:\Windows\system32\explorerframe.dll'
- 3f24.22e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.22e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.22e0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'vcruntime140.dll'.
- 3f24.22e0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vcruntime140_1.dll'.
- 3f24.22e0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msvcp140.dll'.
- 3f24.22e0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vboxrt.dll'.
- 3f24.22e0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'user32.dll'.
- 3f24.22e0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'shell32.dll'.
- 3f24.22e0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'ole32.dll'.
- 3f24.22e0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll) WinVerifyTrust
- 3f24.22e0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll
- 3f24.22e0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
- 3f24.22e0: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume5\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
- 3f24.22e0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
- 3f24.22e0: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume5\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
- 3f24.22e0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\shell32.dll
- 3f24.22e0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 3f24.22e0: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume5\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 3f24.22e0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
- 3f24.22e0: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
- 3f24.22e0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp140.dll'...
- 3f24.22e0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp140.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcp140.dll' [rcNtRedir=0xc0150008]
- 3f24.22e0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140_1.dll'...
- 3f24.22e0: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140_1.dll' -> '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rcNtRedir=0xc0150008]
- 3f24.22e0: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll
- 3f24.22e0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140.dll'...
- 3f24.22e0: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140.dll' -> '\Device\HarddiskVolume5\Windows\System32\vcruntime140.dll' [rcNtRedir=0xc0150008]
- 3f24.22e0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.22e0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll
- 3f24.22e0: supR3HardenedDllNotificationCallback: load 00007ffbc9d50000 LB 0x00021000 C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL [fFlags=0x0]
- 3f24.22e0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll
- 3f24.22e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbc9d50000 'C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL'
- 3f24.1290: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.1290: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.1290: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'vcruntime140.dll'.
- 3f24.1290: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vcruntime140_1.dll'.
- 3f24.1290: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msvcp140.dll'.
- 3f24.1290: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vboxrt.dll'.
- 3f24.1290: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll) WinVerifyTrust
- 3f24.1290: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll
- 3f24.1290: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
- 3f24.1290: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
- 3f24.1290: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp140.dll'...
- 3f24.1290: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp140.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcp140.dll' [rcNtRedir=0xc0150008]
- 3f24.1290: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\msvcp140.dll
- 3f24.1290: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140_1.dll'...
- 3f24.1290: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140_1.dll' -> '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rcNtRedir=0xc0150008]
- 3f24.1290: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140.dll'...
- 3f24.1290: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140.dll' -> '\Device\HarddiskVolume5\Windows\System32\vcruntime140.dll' [rcNtRedir=0xc0150008]
- 3f24.1290: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.1290: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll
- 3f24.1290: supR3HardenedDllNotificationCallback: load 00007ffbc9e00000 LB 0x0000d000 C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL [fFlags=0x0]
- 3f24.1290: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll
- 3f24.1290: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbc9e00000 'C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL'
- 3f24.4950: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd8150000 'C:\Windows\system32\Shell32.dll'
- 3f24.4950: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000d30 pwszName=\Device\HarddiskVolume5\Windows\System32\WinHvPlatform.dll
- 3f24.4950: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 000002440e2782e0
- 3f24.4950: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=000002440e2782e0
- 3f24.4950: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=E00664AAD131505CFEA4FB69BEF260571D07D0D8
- 3f24.4950: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.4950: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.4950: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package02~31bf3856ad364e35~amd64~~10.0.22621.5039.cat'; file='\Device\HarddiskVolume5\Windows\System32\WinHvPlatform.dll'
- 3f24.4950: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 3f24.4950: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'vid.dll'.
- 3f24.4950: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #29 'devobj.dll'.
- 3f24.4950: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\WinHvPlatform.dll) WinVerifyTrust
- 3f24.4950: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\WinHvPlatform.dll
- 3f24.4950: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'devobj.dll'...
- 3f24.4950: supR3HardenedWinVerifyCacheProcessImportTodos: 'devobj.dll' -> '\Device\HarddiskVolume5\Windows\System32\devobj.dll' [rcNtRedir=0xc0150008]
- 3f24.4950: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\devobj.dll
- 3f24.4950: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vid.dll'...
- 3f24.4950: supR3HardenedWinVerifyCacheProcessImportTodos: 'vid.dll' -> '\Device\HarddiskVolume5\Windows\System32\vid.dll' [rcNtRedir=0xc0150008]
- 3f24.4950: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.4950: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.4950: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\vid.dll) WinVerifyTrust
- 3f24.4950: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\vid.dll
- 3f24.4950: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\WinHvPlatform.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.4950: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\WinHvPlatform.dll
- 3f24.4950: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\vid.dll
- 3f24.4950: supR3HardenedDllNotificationCallback: load 00007ffbb9b60000 LB 0x0003e000 C:\Windows\SYSTEM32\vid.dll [fFlags=0x0]
- 3f24.4950: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\vid.dll
- 3f24.4950: supR3HardenedDllNotificationCallback: load 00007ffbc9ce0000 LB 0x00047000 C:\Windows\system32\WinHvPlatform.dll [fFlags=0x0]
- 3f24.4950: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\WinHvPlatform.dll
- 3f24.4950: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbc9ce0000 'C:\Windows\system32\WinHvPlatform.dll'
- 3f24.4950: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\vid.dll
- 3f24.4950: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\vid.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.4950: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbb9b60000 'C:\Windows\system32\vid.dll'
- 3f24.4950: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.4950: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.4950: '\Device\HarddiskVolume5\Windows\System32\ntdll.dll' has no imports
- 3f24.4950: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\ntdll.dll) WinVerifyTrust
- 3f24.4950: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\ntdll.dll
- 3f24.4950: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\NTDLL.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.4950: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd8d10000 'C:\Windows\system32\NTDLL.DLL'
- 3f24.4950: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.4950: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.4950: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.4950: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\crypt32.dll
- 3f24.4950: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.4950: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.4950: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'vcruntime140.dll'.
- 3f24.4950: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vcruntime140_1.dll'.
- 3f24.4950: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
- 3f24.4950: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vboxddu.dll'.
- 3f24.4950: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'vboxdd2.dll'.
- 3f24.4950: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
- 3f24.4950: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'setupapi.dll'.
- 3f24.4950: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'ws2_32.dll'.
- 3f24.4950: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'ole32.dll'.
- 3f24.4950: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'iphlpapi.dll'.
- 3f24.4950: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxDD.dll) WinVerifyTrust
- 3f24.4950: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxDD.dll
- 3f24.4950: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'iphlpapi.dll'...
- 3f24.4950: supR3HardenedWinVerifyCacheProcessImportTodos: 'iphlpapi.dll' -> '\Device\HarddiskVolume5\Windows\System32\iphlpapi.dll' [rcNtRedir=0xc0150008]
- 3f24.4950: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.4950: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.4950: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\IPHLPAPI.DLL) WinVerifyTrust
- 3f24.4950: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\IPHLPAPI.DLL
- 3f24.4950: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
- 3f24.4950: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume5\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
- 3f24.4950: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
- 3f24.4950: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume5\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
- 3f24.4950: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\ws2_32.dll
- 3f24.4950: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
- 3f24.4950: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume5\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
- 3f24.4950: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\setupapi.dll
- 3f24.4950: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 3f24.4950: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume5\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 3f24.4950: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxdd2.dll'...
- 3f24.4950: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxdd2.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\vboxdd2.dll' [rcNtRedir=0xc0150008]
- 3f24.4950: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.4950: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.4950: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'vboxrt.dll'.
- 3f24.4950: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vcruntime140.dll'.
- 3f24.4950: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxDD2.dll) WinVerifyTrust
- 3f24.4950: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxDD2.dll
- 3f24.4950: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxddu.dll'...
- 3f24.4950: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxddu.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\vboxddu.dll' [rcNtRedir=0xc0150008]
- 3f24.4950: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140.dll'...
- 3f24.4950: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140.dll' -> '\Device\HarddiskVolume5\Windows\System32\vcruntime140.dll' [rcNtRedir=0xc0150008]
- 3f24.4950: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
- 3f24.4950: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
- 3f24.4950: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.4950: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.4950: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'vcruntime140.dll'.
- 3f24.4950: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
- 3f24.4950: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
- 3f24.4950: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'setupapi.dll'.
- 3f24.4950: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'advapi32.dll'.
- 3f24.4950: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxDDU.dll) WinVerifyTrust
- 3f24.4950: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxDDU.dll
- 3f24.4950: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
- 3f24.4950: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
- 3f24.4950: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140_1.dll'...
- 3f24.4950: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140_1.dll' -> '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rcNtRedir=0xc0150008]
- 3f24.4950: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140.dll'...
- 3f24.4950: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140.dll' -> '\Device\HarddiskVolume5\Windows\System32\vcruntime140.dll' [rcNtRedir=0xc0150008]
- 3f24.4950: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
- 3f24.4950: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume5\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
- 3f24.4950: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
- 3f24.4950: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume5\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
- 3f24.4950: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\setupapi.dll
- 3f24.4950: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 3f24.4950: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume5\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 3f24.4950: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
- 3f24.4950: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
- 3f24.4950: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140.dll'...
- 3f24.4950: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140.dll' -> '\Device\HarddiskVolume5\Windows\System32\vcruntime140.dll' [rcNtRedir=0xc0150008]
- 3f24.4950: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxDD.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.4950: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxDD.dll
- 3f24.4950: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxDDU.dll
- 3f24.4950: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxDD2.dll
- 3f24.4950: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\IPHLPAPI.DLL
- 3f24.4950: supR3HardenedDllNotificationCallback: load 00007ffbb60e0000 LB 0x00071000 C:\Program Files\Oracle\VirtualBox\VBoxDDU.dll [fFlags=0x0]
- 3f24.4950: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxDDU.dll
- 3f24.4950: supR3HardenedDllNotificationCallback: load 00007ffb21c60000 LB 0x0085d000 C:\Program Files\Oracle\VirtualBox\VBoxDD2.dll [fFlags=0x0]
- 3f24.4950: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxDD2.dll
- 3f24.4950: supR3HardenedDllNotificationCallback: load 00007ffbd48d0000 LB 0x0002d000 C:\Windows\SYSTEM32\IPHLPAPI.DLL [fFlags=0x0]
- 3f24.4950: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\IPHLPAPI.DLL
- 3f24.4950: supR3HardenedDllNotificationCallback: load 00007ffaea1a0000 LB 0x00a2d000 C:\Program Files\Oracle\VirtualBox\VBoxDD.DLL [fFlags=0x0]
- 3f24.4950: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxDD.dll
- 3f24.4950: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaea1a0000 'C:\Program Files\Oracle\VirtualBox\VBoxDD.DLL'
- 3f24.4950: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\rsaenh.dll
- 3f24.4950: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.4950: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.4950: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.4950: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxC.dll
- 3f24.4950: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxC.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.4950: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb721e0000 'C:\Program Files\Oracle\VirtualBox\VBoxC.DLL'
- 3f24.4950: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.4950: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.4950: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxDD2.dll
- 3f24.4950: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxDD2.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.4950: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffb21c60000 'C:\Program Files\Oracle\VirtualBox\VBoxDD2.DLL'
- 3f24.1f7c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.1f7c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.1f7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'vcruntime140.dll'.
- 3f24.1f7c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
- 3f24.1f7c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll) WinVerifyTrust
- 3f24.1f7c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll
- 3f24.1f7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
- 3f24.1f7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
- 3f24.1f7c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140.dll'...
- 3f24.1f7c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140.dll' -> '\Device\HarddiskVolume5\Windows\System32\vcruntime140.dll' [rcNtRedir=0xc0150008]
- 3f24.1f7c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.1f7c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll
- 3f24.1f7c: supR3HardenedDllNotificationCallback: load 00007ffbc9bd0000 LB 0x00014000 C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL [fFlags=0x0]
- 3f24.1f7c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll
- 3f24.1f7c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbc9bd0000 'C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL'
- 3f24.1408: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.1408: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.1408: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'vcruntime140.dll'.
- 3f24.1408: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vcruntime140_1.dll'.
- 3f24.1408: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msvcp140.dll'.
- 3f24.1408: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vboxrt.dll'.
- 3f24.1408: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll) WinVerifyTrust
- 3f24.1408: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll
- 3f24.1408: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
- 3f24.1408: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
- 3f24.1408: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp140.dll'...
- 3f24.1408: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp140.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcp140.dll' [rcNtRedir=0xc0150008]
- 3f24.1408: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140_1.dll'...
- 3f24.1408: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140_1.dll' -> '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rcNtRedir=0xc0150008]
- 3f24.1408: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140.dll'...
- 3f24.1408: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140.dll' -> '\Device\HarddiskVolume5\Windows\System32\vcruntime140.dll' [rcNtRedir=0xc0150008]
- 3f24.1408: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.1408: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll
- 3f24.1408: supR3HardenedDllNotificationCallback: load 00007ffbc9d40000 LB 0x0000c000 C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL [fFlags=0x0]
- 3f24.1408: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll
- 3f24.1408: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbc9d40000 'C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL'
- 3f24.56f0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.56f0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.56f0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'vcruntime140.dll'.
- 3f24.56f0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vcruntime140_1.dll'.
- 3f24.56f0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'msvcp140.dll'.
- 3f24.56f0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vboxrt.dll'.
- 3f24.56f0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll) WinVerifyTrust
- 3f24.56f0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll
- 3f24.56f0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
- 3f24.56f0: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
- 3f24.56f0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp140.dll'...
- 3f24.56f0: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp140.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcp140.dll' [rcNtRedir=0xc0150008]
- 3f24.56f0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140_1.dll'...
- 3f24.56f0: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140_1.dll' -> '\Device\HarddiskVolume5\Windows\System32\vcruntime140_1.dll' [rcNtRedir=0xc0150008]
- 3f24.56f0: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vcruntime140.dll'...
- 3f24.56f0: supR3HardenedWinVerifyCacheProcessImportTodos: 'vcruntime140.dll' -> '\Device\HarddiskVolume5\Windows\System32\vcruntime140.dll' [rcNtRedir=0xc0150008]
- 3f24.56f0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.56f0: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll
- 3f24.56f0: supR3HardenedDllNotificationCallback: load 00007ffbc9cd0000 LB 0x0000d000 C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL [fFlags=0x0]
- 3f24.56f0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll
- 3f24.56f0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbc9cd0000 'C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL'
- 3f24.4950: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.4950: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.4950: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'ws2_32.dll'.
- 3f24.4950: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #22 'rpcrt4.dll'.
- 3f24.4950: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\mswsock.dll) WinVerifyTrust
- 3f24.4950: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\mswsock.dll
- 3f24.4950: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 3f24.4950: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume5\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 3f24.4950: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
- 3f24.4950: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume5\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
- 3f24.4950: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\ws2_32.dll
- 3f24.4950: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\mswsock.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.4950: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\mswsock.dll
- 3f24.4950: supR3HardenedDllNotificationCallback: load 00007ffbd53b0000 LB 0x0006a000 C:\Windows\system32\mswsock.dll [fFlags=0x0]
- 3f24.4950: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\mswsock.dll
- 3f24.4950: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd53b0000 'C:\Windows\system32\mswsock.dll'
- 3f24.4950: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd4e30000 'C:\Windows\system32\rsaenh.dll'
- 3f24.4950: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbd6450000 'C:\Windows\System32\crypt32.dll'
- 3f24.4950: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
- 3f24.4950: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume5\Windows\System32\MMDevAPI.dll) WinVerifyTrust
- 3f24.4950: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\MMDevAPI.dll
- 3f24.4950: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
- 3f24.4950: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume5\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
- 3f24.4950: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\MMDevApi.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
- 3f24.4950: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\MMDevAPI.dll
- 3f24.4950: supR3HardenedDllNotificationCallback: load 00007ffbcfa70000 LB 0x0009e000 C:\Windows\System32\MMDevApi.dll [fFlags=0x0]
- 3f24.4950: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\MMDevAPI.dll
- 3f24.4950: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcfa70000 'C:\Windows\System32\MMDevApi.dll'
- 3f24.4950: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume5\Windows\System32\MMDevAPI.dll
- 3f24.4950: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\MMDEVAPI.DLL (Input=MMDEVAPI.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 3f24.4950: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffbcfa70000 'C:\Windows\System32\MMDEVAPI.DLL'
- 3f24.56f0: supR3HardenedDllNotificationCallback: Unload 00007ffbc9cd0000 LB 0x0000d000 C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL [flags=0x0]
- 3f24.1408: supR3HardenedDllNotificationCallback: Unload 00007ffbc9d40000 LB 0x0000c000 C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL [flags=0x0]
- 3f24.1f7c: supR3HardenedDllNotificationCallback: Unload 00007ffbc9bd0000 LB 0x00014000 C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL [flags=0x0]
- 3f24.1290: supR3HardenedDllNotificationCallback: Unload 00007ffbc9e00000 LB 0x0000d000 C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL [flags=0x0]
- 3f24.22e0: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 3f24.22e0: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume5\Windows\System32\edputil.dll)
- 3f24.22e0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume5\Windows\System32\edputil.dll
- 3f24.22e0: supR3HardenedDllNotificationCallback: load 00007ffbabd70000 LB 0x00028000 C:\Windows\SYSTEM32\edputil.dll [fFlags=0x0]
- 3f24.22e0: supR3HardenedScreenImage/LdrLoadDll: cache hit (22900) on \Device\HarddiskVolume5\Windows\System32\edputil.dll [avoiding WinVerifyTrust]
- 3f24.22e0: supR3HardenedDllNotificationCallback: Unload 00007ffbc9d50000 LB 0x00021000 C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL [flags=0x0]
- 3f24.4950: supR3HardenedDllNotificationCallback: Unload 00007ffaea1a0000 LB 0x00a2d000 C:\Program Files\Oracle\VirtualBox\VBoxDD.DLL [flags=0x0]
- 3f24.4950: supR3HardenedDllNotificationCallback: Unload 00007ffbb60e0000 LB 0x00071000 C:\Program Files\Oracle\VirtualBox\VBoxDDU.dll [flags=0x0]
- 3f24.4950: supR3HardenedDllNotificationCallback: Unload 00007ffb21c60000 LB 0x0085d000 C:\Program Files\Oracle\VirtualBox\VBoxDD2.dll [flags=0x0]
- 3f24.4950: supR3HardenedDllNotificationCallback: Unload 00007ffbd48d0000 LB 0x0002d000 C:\Windows\SYSTEM32\IPHLPAPI.DLL [flags=0x0]
- 3f24.31ac: supR3HardenedDllNotificationCallback: Unload 00007ffb231c0000 LB 0x0058f000 C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL [flags=0x0]
- 3f24.31ac: supR3HardenedDllNotificationCallback: Unload 00007ffba0370000 LB 0x002c1000 C:\Windows\system32\explorerframe.dll [flags=0x0]
- 3f24.31ac: supR3HardenedDllNotificationCallback: Unload 00007ffb9d270000 LB 0x0006a000 C:\Windows\System32\thumbcache.dll [flags=0x0]
- 3f24.31ac: supR3HardenedDllNotificationCallback: Unload 00007ffb88be0000 LB 0x000e9000 C:\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll [flags=0x0]
- 3f24.31ac: supR3HardenedDllNotificationCallback: Unload 00007ffbcaff0000 LB 0x00014000 C:\Windows\system32\wbem\wbemsvc.dll [flags=0x0]
- 3f24.31ac: supR3HardenedDllNotificationCallback: Unload 00007ffbcf8d0000 LB 0x00010000 C:\Windows\system32\wbem\wbemprox.dll [flags=0x0]
- 3f24.31ac: supR3HardenedDllNotificationCallback: Unload 00007ffba0740000 LB 0x0005e000 C:\Windows\system32\dataexchange.dll [flags=0x0]
- 3f24.31ac: supR3HardenedDllNotificationCallback: Unload 00007ffbcb1a0000 LB 0x002a5000 C:\Windows\system32\twinapi.appcore.dll [flags=0x0]
- 3f24.31ac: supR3HardenedDllNotificationCallback: Unload 00007ffb721e0000 LB 0x003f6000 C:\Program Files\Oracle\VirtualBox\VBoxC.dll [flags=0x0]
- 3f24.31ac: supR3HardenedDllNotificationCallback: Unload 00007ffbc6eb0000 LB 0x000f8000 C:\Windows\system32\wbem\fastprox.dll [flags=0x0]
- 3f24.31ac: supR3HardenedDllNotificationCallback: Unload 00007ffbcf850000 LB 0x00080000 C:\Windows\SYSTEM32\wbemcomn.dll [flags=0x0]
- 3f24.31ac: Terminating the normal way: rcExit=0
- 46ec.54b0: supR3HardNtChildWaitFor[2]: Quitting: ExitCode=0x0 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 8396 ms, the end);
- 2534.14dc: supR3HardNtChildWaitFor[1]: Quitting: ExitCode=0x0 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 9361 ms, the end);
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement