Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 48e4.5aec: Log file opened: 6.1.34r150636 g_hStartupLog=0000000000000088 g_uNtVerCombined=0xa055f000
- 48e4.5aec: \SystemRoot\System32\ntdll.dll:
- 48e4.5aec: CreationTime: 2022-07-13T09:48:33.425384000Z
- 48e4.5aec: LastWriteTime: 2022-07-13T09:48:33.464782100Z
- 48e4.5aec: ChangeTime: 2022-07-15T09:20:37.898077300Z
- 48e4.5aec: FileAttributes: 0x20
- 48e4.5aec: Size: 0x207e08
- 48e4.5aec: NT Headers: 0xe0
- 48e4.5aec: Timestamp: 0x5398ab6f
- 48e4.5aec: Machine: 0x8664 - amd64
- 48e4.5aec: Timestamp: 0x5398ab6f
- 48e4.5aec: Image Version: 10.0
- 48e4.5aec: SizeOfImage: 0x209000 (2134016)
- 48e4.5aec: Resource Dir: 0x194000 LB 0x73528
- 48e4.5aec: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 48e4.5aec: [Raw version resource data: 0x1940f0 LB 0x380, codepage 0x0 (reserved 0x0)]
- 48e4.5aec: ProductName: Microsoft® Windows® Operating System
- 48e4.5aec: ProductVersion: 10.0.22000.778
- 48e4.5aec: FileVersion: 10.0.22000.778 (WinBuild.160101.0800)
- 48e4.5aec: FileDescription: NT Layer DLL
- 48e4.5aec: \SystemRoot\System32\kernel32.dll:
- 48e4.5aec: CreationTime: 2022-06-16T22:13:47.886924000Z
- 48e4.5aec: LastWriteTime: 2022-06-16T22:13:47.899916800Z
- 48e4.5aec: ChangeTime: 2022-07-13T09:49:56.810738300Z
- 48e4.5aec: FileAttributes: 0x20
- 48e4.5aec: Size: 0xc0058
- 48e4.5aec: NT Headers: 0xf8
- 48e4.5aec: Timestamp: 0xafec8296
- 48e4.5aec: Machine: 0x8664 - amd64
- 48e4.5aec: Timestamp: 0xafec8296
- 48e4.5aec: Image Version: 10.0
- 48e4.5aec: SizeOfImage: 0xbd000 (774144)
- 48e4.5aec: Resource Dir: 0xbb000 LB 0x520
- 48e4.5aec: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 48e4.5aec: [Raw version resource data: 0xbb0b0 LB 0x3a4, codepage 0x0 (reserved 0x0)]
- 48e4.5aec: ProductName: Microsoft® Windows® Operating System
- 48e4.5aec: ProductVersion: 10.0.22000.708
- 48e4.5aec: FileVersion: 10.0.22000.708 (WinBuild.160101.0800)
- 48e4.5aec: FileDescription: Windows NT BASE API Client DLL
- 48e4.5aec: \SystemRoot\System32\KernelBase.dll:
- 48e4.5aec: CreationTime: 2022-07-13T09:48:33.970578400Z
- 48e4.5aec: LastWriteTime: 2022-07-13T09:48:34.072201200Z
- 48e4.5aec: ChangeTime: 2022-07-15T09:21:13.777271800Z
- 48e4.5aec: FileAttributes: 0x20
- 48e4.5aec: Size: 0x380268
- 48e4.5aec: NT Headers: 0xf8
- 48e4.5aec: Timestamp: 0x960371d1
- 48e4.5aec: Machine: 0x8664 - amd64
- 48e4.5aec: Timestamp: 0x960371d1
- 48e4.5aec: Image Version: 10.0
- 48e4.5aec: SizeOfImage: 0x379000 (3641344)
- 48e4.5aec: Resource Dir: 0x34a000 LB 0x548
- 48e4.5aec: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 48e4.5aec: [Raw version resource data: 0x34a0b0 LB 0x3bc, codepage 0x0 (reserved 0x0)]
- 48e4.5aec: ProductName: Microsoft® Windows® Operating System
- 48e4.5aec: ProductVersion: 10.0.22000.795
- 48e4.5aec: FileVersion: 10.0.22000.795 (WinBuild.160101.0800)
- 48e4.5aec: FileDescription: Windows NT BASE API Client DLL
- 48e4.5aec: \SystemRoot\System32\apisetschema.dll:
- 48e4.5aec: CreationTime: 2021-06-05T12:04:59.928787900Z
- 48e4.5aec: LastWriteTime: 2021-06-05T12:04:59.928787900Z
- 48e4.5aec: ChangeTime: 2022-07-13T09:49:56.784497700Z
- 48e4.5aec: FileAttributes: 0x20
- 48e4.5aec: Size: 0x24150
- 48e4.5aec: NT Headers: 0xc8
- 48e4.5aec: Timestamp: 0x68d1dbaf
- 48e4.5aec: Machine: 0x8664 - amd64
- 48e4.5aec: Timestamp: 0x68d1dbaf
- 48e4.5aec: Image Version: 10.0
- 48e4.5aec: SizeOfImage: 0x23000 (143360)
- 48e4.5aec: Resource Dir: 0x22000 LB 0x408
- 48e4.5aec: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 48e4.5aec: [Raw version resource data: 0x22060 LB 0x3a8, codepage 0x0 (reserved 0x0)]
- 48e4.5aec: ProductName: Microsoft® Windows® Operating System
- 48e4.5aec: ProductVersion: 10.0.22000.1
- 48e4.5aec: FileVersion: 10.0.22000.1 (WinBuild.160101.0800)
- 48e4.5aec: FileDescription: ApiSet Schema DLL
- 48e4.5aec: NtOpenDirectoryObject failed on \Driver: 0xc0000022
- 48e4.5aec: supR3HardenedWinFindAdversaries: 0x20
- 48e4.5aec: \SystemRoot\System32\drivers\cfwids.sys:
- 48e4.5aec: CreationTime: 2021-03-02T21:06:14.000000000Z
- 48e4.5aec: LastWriteTime: 2021-09-28T21:02:42.000000000Z
- 48e4.5aec: ChangeTime: 2022-02-17T14:13:42.561653600Z
- 48e4.5aec: FileAttributes: 0x20
- 48e4.5aec: Size: 0x12400
- 48e4.5aec: NT Headers: 0xe0
- 48e4.5aec: Timestamp: 0x6144daa5
- 48e4.5aec: Machine: 0x8664 - amd64
- 48e4.5aec: Timestamp: 0x6144daa5
- 48e4.5aec: Image Version: 10.0
- 48e4.5aec: SizeOfImage: 0x13000 (77824)
- 48e4.5aec: Resource Dir: 0x11000 LB 0x550
- 48e4.5aec: [Version info resource found at 0x80! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 48e4.5aec: [Raw version resource data: 0x110a0 LB 0x318, codepage 0x0 (reserved 0x0)]
- 48e4.5aec: ProductName: SYSCORE
- 48e4.5aec: ProductVersion: 21.09.0.184
- 48e4.5aec: FileVersion: SYSCORE.21.09.0.184
- 48e4.5aec: PrivateBuild: SYSCORE.21.09.0.184
- 48e4.5aec: FileDescription: McAfee Personal Firewall IDS Plugin
- 48e4.5aec: \SystemRoot\System32\drivers\mfeavfk.sys:
- 48e4.5aec: CreationTime: 2021-03-02T21:06:12.000000000Z
- 48e4.5aec: LastWriteTime: 2021-09-28T21:02:42.000000000Z
- 48e4.5aec: ChangeTime: 2022-02-17T14:13:42.404177800Z
- 48e4.5aec: FileAttributes: 0x20
- 48e4.5aec: Size: 0x5f600
- 48e4.5aec: NT Headers: 0xf0
- 48e4.5aec: Timestamp: 0x6144da96
- 48e4.5aec: Machine: 0x8664 - amd64
- 48e4.5aec: Timestamp: 0x6144da96
- 48e4.5aec: Image Version: 10.0
- 48e4.5aec: SizeOfImage: 0x60000 (393216)
- 48e4.5aec: Resource Dir: 0x5e000 LB 0x758
- 48e4.5aec: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 48e4.5aec: [Raw version resource data: 0x5e110 LB 0x334, codepage 0x0 (reserved 0x0)]
- 48e4.5aec: ProductName: SYSCORE
- 48e4.5aec: ProductVersion: 21.09.0.184
- 48e4.5aec: FileVersion: SYSCORE.21.09.0.184
- 48e4.5aec: PrivateBuild: SYSCORE.21.09.0.184 F15,F16,F19
- 48e4.5aec: FileDescription: Anti-Virus File System Filter Driver
- 48e4.5aec: \SystemRoot\System32\drivers\mfefirek.sys:
- 48e4.5aec: CreationTime: 2021-03-02T21:06:12.000000000Z
- 48e4.5aec: LastWriteTime: 2021-09-28T21:02:42.000000000Z
- 48e4.5aec: ChangeTime: 2022-02-17T14:13:42.380174300Z
- 48e4.5aec: FileAttributes: 0x20
- 48e4.5aec: Size: 0x80800
- 48e4.5aec: NT Headers: 0xd8
- 48e4.5aec: Timestamp: 0x6144daa7
- 48e4.5aec: Machine: 0x8664 - amd64
- 48e4.5aec: Timestamp: 0x6144daa7
- 48e4.5aec: Image Version: 10.0
- 48e4.5aec: SizeOfImage: 0x82000 (532480)
- 48e4.5aec: Resource Dir: 0x80000 LB 0x388
- 48e4.5aec: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 48e4.5aec: [Raw version resource data: 0x80060 LB 0x328, codepage 0x0 (reserved 0x0)]
- 48e4.5aec: ProductName: SYSCORE
- 48e4.5aec: ProductVersion: 21.09.0.184
- 48e4.5aec: FileVersion: SYSCORE.21.09.0.184
- 48e4.5aec: PrivateBuild: SYSCORE.21.09.0.184 F17,F18
- 48e4.5aec: FileDescription: McAfee Core Firewall Engine Driver
- 48e4.5aec: \SystemRoot\System32\drivers\mfehidk.sys:
- 48e4.5aec: CreationTime: 2021-03-02T21:06:14.000000000Z
- 48e4.5aec: LastWriteTime: 2021-09-28T21:02:40.000000000Z
- 48e4.5aec: ChangeTime: 2022-02-17T14:13:42.033393300Z
- 48e4.5aec: FileAttributes: 0x20
- 48e4.5aec: Size: 0x109c00
- 48e4.5aec: NT Headers: 0x100
- 48e4.5aec: Timestamp: 0x6144db21
- 48e4.5aec: Machine: 0x8664 - amd64
- 48e4.5aec: Timestamp: 0x6144db21
- 48e4.5aec: Image Version: 10.0
- 48e4.5aec: SizeOfImage: 0x115000 (1134592)
- 48e4.5aec: Resource Dir: 0x112000 LB 0x780
- 48e4.5aec: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 48e4.5aec: [Raw version resource data: 0x112110 LB 0x320, codepage 0x0 (reserved 0x0)]
- 48e4.5aec: ProductName: SYSCORE
- 48e4.5aec: ProductVersion: 21.09.0.184
- 48e4.5aec: FileVersion: SYSCORE.21.09.0.184
- 48e4.5aec: PrivateBuild: SYSCORE.21.09.0.184 F14,F15,F16,F18,F20
- 48e4.5aec: FileDescription: McAfee Link Driver
- 48e4.5aec: \SystemRoot\System32\drivers\mfencbdc.sys:
- 48e4.5aec: CreationTime: 2021-09-16T08:52:14.000000000Z
- 48e4.5aec: LastWriteTime: 2021-09-16T08:52:14.000000000Z
- 48e4.5aec: ChangeTime: 2022-02-17T14:15:27.567390100Z
- 48e4.5aec: FileAttributes: 0x20
- 48e4.5aec: Size: 0x9be00
- 48e4.5aec: NT Headers: 0xe0
- 48e4.5aec: Timestamp: 0x61403be3
- 48e4.5aec: Machine: 0x8664 - amd64
- 48e4.5aec: Timestamp: 0x61403be3
- 48e4.5aec: Image Version: 10.0
- 48e4.5aec: SizeOfImage: 0xad000 (708608)
- 48e4.5aec: Resource Dir: 0xab000 LB 0x3d0
- 48e4.5aec: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 48e4.5aec: [Raw version resource data: 0xab060 LB 0x370, codepage 0x0 (reserved 0x0)]
- 48e4.5aec: ProductName: Anti-Malware Core
- 48e4.5aec: ProductVersion: 21.9.0
- 48e4.5aec: FileVersion: Anti-Malware Core.21.9.0.327
- 48e4.5aec: PrivateBuild: Anti-Malware Core.21.9.0.327
- 48e4.5aec: FileDescription: Event Driver
- 48e4.5aec: \SystemRoot\System32\drivers\mfewfpk.sys:
- 48e4.5aec: CreationTime: 2021-03-02T21:06:12.000000000Z
- 48e4.5aec: LastWriteTime: 2021-09-28T21:02:42.000000000Z
- 48e4.5aec: ChangeTime: 2022-02-17T14:13:40.787639300Z
- 48e4.5aec: FileAttributes: 0x20
- 48e4.5aec: Size: 0x3ea00
- 48e4.5aec: NT Headers: 0xe0
- 48e4.5aec: Timestamp: 0x6144da96
- 48e4.5aec: Machine: 0x8664 - amd64
- 48e4.5aec: Timestamp: 0x6144da96
- 48e4.5aec: Image Version: 10.0
- 48e4.5aec: SizeOfImage: 0x5a000 (368640)
- 48e4.5aec: Resource Dir: 0x58000 LB 0x380
- 48e4.5aec: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 48e4.5aec: [Raw version resource data: 0x58060 LB 0x320, codepage 0x0 (reserved 0x0)]
- 48e4.5aec: ProductName: SYSCORE
- 48e4.5aec: ProductVersion: 21.09.0.184
- 48e4.5aec: FileVersion: SYSCORE.21.09.0.184
- 48e4.5aec: PrivateBuild: SYSCORE.21.09.0.184 F17,F18
- 48e4.5aec: FileDescription: Anti-Virus Mini-Firewall Driver
- 48e4.5aec: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox'
- 48e4.5aec: Calling main()
- 48e4.5aec: SUPR3HardenedMain: pszProgName=VirtualBoxVM fFlags=0x2
- 48e4.5aec: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox'
- 48e4.5aec: SUPR3HardenedMain: Respawn #1
- 48e4.5aec: System32: \Device\HarddiskVolume3\Windows\System32
- 48e4.5aec: WinSxS: \Device\HarddiskVolume3\Windows\WinSxS
- 48e4.5aec: KnownDllPath: C:\Windows\System32
- 48e4.5aec: supR3HardenedWinInit: Performing a limited self purification...
- 48e4.5aec: supHardNtVpScanVirtualMemory: enmKind=SELF_PURIFICATION
- 48e4.5aec: *0000000000000000-0000000000c0ffff 0x0001/0x0000 0x0000000
- 48e4.5aec: *0000000000c10000-0000000000c10fff 0x0002/0x0002 0x0040000
- 48e4.5aec: 0000000000c11000-0000000000c1ffff 0x0001/0x0000 0x0000000
- 48e4.5aec: *0000000000c20000-0000000000c20fff 0x0002/0x0002 0x0040000
- 48e4.5aec: 0000000000c21000-0000000000c2ffff 0x0001/0x0000 0x0000000
- 48e4.5aec: *0000000000c30000-0000000000c4efff 0x0002/0x0002 0x0040000
- 48e4.5aec: 0000000000c4f000-0000000000c4ffff 0x0001/0x0000 0x0000000
- 48e4.5aec: *0000000000c50000-0000000000d00fff 0x0000/0x0004 0x0020000
- 48e4.5aec: 0000000000d01000-0000000000d03fff 0x0104/0x0004 0x0020000
- 48e4.5aec: 0000000000d04000-0000000000d4ffff 0x0004/0x0004 0x0020000
- 48e4.5aec: *0000000000d50000-0000000000d53fff 0x0002/0x0002 0x0040000
- 48e4.5aec: 0000000000d54000-0000000000d5ffff 0x0001/0x0000 0x0000000
- 48e4.5aec: *0000000000d60000-0000000000d61fff 0x0004/0x0004 0x0020000
- 48e4.5aec: 0000000000d62000-0000000000d6ffff 0x0001/0x0000 0x0000000
- 48e4.5aec: *0000000000d70000-0000000000d80fff 0x0002/0x0002 0x0040000
- 48e4.5aec: 0000000000d81000-0000000000d8ffff 0x0001/0x0000 0x0000000
- 48e4.5aec: *0000000000d90000-0000000000da0fff 0x0002/0x0002 0x0040000
- 48e4.5aec: 0000000000da1000-0000000000daffff 0x0001/0x0000 0x0000000
- 48e4.5aec: *0000000000db0000-0000000000db2fff 0x0002/0x0002 0x0040000
- 48e4.5aec: 0000000000db3000-0000000000dbffff 0x0001/0x0000 0x0000000
- 48e4.5aec: *0000000000dc0000-0000000000dc0fff 0x0004/0x0004 0x0020000
- 48e4.5aec: 0000000000dc1000-0000000000df1fff 0x0000/0x0004 0x0020000
- 48e4.5aec: 0000000000df2000-0000000000dfffff 0x0001/0x0000 0x0000000
- 48e4.5aec: *0000000000e00000-0000000000ef4fff 0x0000/0x0004 0x0020000
- 48e4.5aec: 0000000000ef5000-0000000000ef7fff 0x0004/0x0004 0x0020000
- 48e4.5aec: 0000000000ef8000-0000000000ffffff 0x0000/0x0004 0x0020000
- 48e4.5aec: *0000000001000000-0000000001000fff 0x0002/0x0002 0x0040000
- 48e4.5aec: 0000000001001000-000000000100ffff 0x0001/0x0000 0x0000000
- 48e4.5aec: *0000000001010000-000000000101ffff 0x0004/0x0004 0x0040000
- 48e4.5aec: *0000000001020000-0000000001022fff 0x0002/0x0002 0x0040000
- 48e4.5aec: 0000000001023000-000000000102ffff 0x0001/0x0000 0x0000000
- 48e4.5aec: *0000000001030000-0000000001040fff 0x0002/0x0002 0x0040000
- 48e4.5aec: 0000000001041000-000000000105ffff 0x0001/0x0000 0x0000000
- 48e4.5aec: *0000000001060000-0000000001069fff 0x0004/0x0004 0x0020000
- 48e4.5aec: 000000000106a000-000000000115ffff 0x0000/0x0004 0x0020000
- 48e4.5aec: *0000000001160000-000000000122dfff 0x0002/0x0002 0x0040000
- 48e4.5aec: 000000000122e000-000000000122ffff 0x0001/0x0000 0x0000000
- 48e4.5aec: *0000000001230000-0000000001240fff 0x0002/0x0002 0x0040000
- 48e4.5aec: 0000000001241000-000000000124ffff 0x0001/0x0000 0x0000000
- 48e4.5aec: *0000000001250000-0000000001251fff 0x0004/0x0004 0x0020000
- 48e4.5aec: 0000000001252000-0000000001281fff 0x0000/0x0004 0x0020000
- 48e4.5aec: 0000000001282000-000000000128ffff 0x0001/0x0000 0x0000000
- 48e4.5aec: *0000000001290000-00000000012b6fff 0x0004/0x0004 0x0020000
- 48e4.5aec: 00000000012b7000-000000000138ffff 0x0000/0x0004 0x0020000
- 48e4.5aec: 0000000001390000-00000000013bffff 0x0001/0x0000 0x0000000
- 48e4.5aec: *00000000013c0000-00000000013cefff 0x0004/0x0004 0x0020000
- 48e4.5aec: 00000000013cf000-00000000013cffff 0x0000/0x0004 0x0020000
- 48e4.5aec: *00000000013d0000-00000000015d9fff 0x0004/0x0004 0x0020000
- 48e4.5aec: 00000000015da000-00000000015dafff 0x0000/0x0004 0x0020000
- 48e4.5aec: 00000000015db000-000000007ffdffff 0x0001/0x0000 0x0000000
- 48e4.5aec: *000000007ffe0000-000000007ffe0fff 0x0002/0x0002 0x0020000
- 48e4.5aec: *000000007ffe1000-000000007ffe1fff 0x0002/0x0002 0x0020000
- 48e4.5aec: 000000007ffe2000-00007ff4d529ffff 0x0001/0x0000 0x0000000
- 48e4.5aec: *00007ff4d52a0000-00007ff4d52a4fff 0x0002/0x0002 0x0040000
- 48e4.5aec: 00007ff4d52a5000-00007ff4d539ffff 0x0000/0x0002 0x0040000
- 48e4.5aec: *00007ff4d53a0000-00007ff5d53bffff 0x0000/0x0004 0x0020000
- 48e4.5aec: *00007ff5d53c0000-00007ff5d73bffff 0x0000/0x0004 0x0020000
- 48e4.5aec: 00007ff5d73c0000-00007ff5d73c0fff 0x0004/0x0004 0x0020000
- 48e4.5aec: 00007ff5d73c1000-00007ff5d73cffff 0x0001/0x0000 0x0000000
- 48e4.5aec: *00007ff5d73d0000-00007ff5d73d0fff 0x0002/0x0002 0x0040000
- 48e4.5aec: 00007ff5d73d1000-00007ff75562ffff 0x0001/0x0000 0x0000000
- 48e4.5aec: *00007ff755630000-00007ff755630fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 48e4.5aec: 00007ff755631000-00007ff7556a7fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 48e4.5aec: 00007ff7556a8000-00007ff7556a8fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 48e4.5aec: 00007ff7556a9000-00007ff7556f1fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 48e4.5aec: 00007ff7556f2000-00007ff7556f4fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 48e4.5aec: 00007ff7556f5000-00007ff7556f7fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 48e4.5aec: 00007ff7556f8000-00007ff7556fafff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 48e4.5aec: 00007ff7556fb000-00007ff7556fbfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 48e4.5aec: 00007ff7556fc000-00007ff7556fdfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 48e4.5aec: 00007ff7556fe000-00007ff7556fefff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 48e4.5aec: 00007ff7556ff000-00007ff755747fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 48e4.5aec: 00007ff755748000-00007ffab699ffff 0x0001/0x0000 0x0000000
- 48e4.5aec: *00007ffab69a0000-00007ffab69a0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\KernelBase.dll
- 48e4.5aec: 00007ffab69a1000-00007ffab6b19fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\KernelBase.dll
- 48e4.5aec: 00007ffab6b1a000-00007ffab6ccbfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\KernelBase.dll
- 48e4.5aec: 00007ffab6ccc000-00007ffab6cd0fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\KernelBase.dll
- 48e4.5aec: 00007ffab6cd1000-00007ffab6d18fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\KernelBase.dll
- 48e4.5aec: 00007ffab6d19000-00007ffab787ffff 0x0001/0x0000 0x0000000
- 48e4.5aec: *00007ffab7880000-00007ffab7880fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\kernel32.dll
- 48e4.5aec: 00007ffab7881000-00007ffab78fdfff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\kernel32.dll
- 48e4.5aec: 00007ffab78fe000-00007ffab7931fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\kernel32.dll
- 48e4.5aec: 00007ffab7932000-00007ffab7932fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\kernel32.dll
- 48e4.5aec: 00007ffab7933000-00007ffab7933fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\kernel32.dll
- 48e4.5aec: 00007ffab7934000-00007ffab793cfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\kernel32.dll
- 48e4.5aec: 00007ffab793d000-00007ffab925ffff 0x0001/0x0000 0x0000000
- 48e4.5aec: *00007ffab9260000-00007ffab9260fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
- 48e4.5aec: 00007ffab9261000-00007ffab938bfff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
- 48e4.5aec: 00007ffab938c000-00007ffab93d3fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
- 48e4.5aec: 00007ffab93d4000-00007ffab93d4fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
- 48e4.5aec: 00007ffab93d5000-00007ffab93d6fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
- 48e4.5aec: 00007ffab93d7000-00007ffab93dffff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
- 48e4.5aec: 00007ffab93e0000-00007ffab9468fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
- 48e4.5aec: 00007ffab9469000-00007ffffffeffff 0x0001/0x0000 0x0000000
- 48e4.5aec: kernel32.dll: timestamp 0xafec8296 (rc=VINF_SUCCESS)
- 48e4.5aec: kernelbase.dll: timestamp 0x960371d1 (rc=VINF_SUCCESS)
- 48e4.5aec: VirtualBoxVM.exe: timestamp 0x623a5dfe (rc=VINF_SUCCESS)
- 48e4.5aec: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe: Signature #1/2: info status: 24202
- 48e4.5aec: '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
- 48e4.5aec: '\Device\HarddiskVolume3\Windows\System32\ntdll.dll' has no imports
- 48e4.5aec: supR3HardenedWinInit: SUPHARDNTVPKIND_SELF_PURIFICATION_LIMITED -> VINF_SUCCESS, cFixes=0
- 48e4.5aec: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe: Signature #1/2: info status: 24202
- 48e4.5aec: '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
- 48e4.5aec: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe)
- 48e4.5aec: supR3HardNtEnableThreadCreationEx:
- 48e4.5aec: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffab92daf50 pvNtTerminateThread=00007ffab9304960
- 48e4.5aec: supR3HardenedWinDoReSpawn(1): New child 5f00.18e0 [kernel32].
- 48e4.5aec: supR3HardNtChildGatherData: PebBaseAddress=00000000009ad000 cbPeb=0x388
- 48e4.5aec: supR3HardNtPuChFindNtdll: uNtDllParentAddr=00007ffab9260000 uNtDllChildAddr=00007ffab9260000
- 48e4.5aec: supR3HardenedWinSetupChildInit: uLdrInitThunk=00007ffab92daf50
- 48e4.5aec: supR3HardenedWinSetupChildInit: Initial context:
- rax=0000000000000000 rbx=0000000000000000 rcx=00007ff755637900 rdx=00000000009ad000
- rsi=0000000000000000 rdi=0000000000000000 r8 =0000000000000000 r9 =0000000000000000
- r10=0000000000000000 r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
- r14=0000000000000000 r15=0000000000000000 P1=0000000000000000 P2=0000000000000000
- rip=00007ffab9264830 rsp=00000000007ffd18 rbp=0000000000000000 ctxflags=0010001b
- cs=0033 ss=002b ds=0000 es=0000 fs=0000 gs=0000 eflags=00000200 mxcrx=00001f80
- P3=0000000000000000 P4=0000000000000000 P5=0000000000000000 P6=0000000000000000
- dr0=0000000000000000 dr1=0000000000000000 dr2=0000000000000000 dr3=0000000000000000
- dr6=0000000000000000 dr7=0000000000000000 vcr=0000000000000000 dcr=0000000000000000
- lbt=0000000000000000 lbf=0000000000000000 lxt=0000000000000000 lxf=0000000000000000
- 48e4.5aec: supR3HardenedWinSetupChildInit: Start child.
- 48e4.5aec: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
- 48e4.5aec: supR3HardNtChildPurify: Startup delay kludge #1/0: 523 ms, 33 sleeps
- 48e4.5aec: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
- 48e4.5aec: *0000000000000000-00000000006bffff 0x0001/0x0000 0x0000000
- 48e4.5aec: *00000000006c0000-00000000006dffff 0x0004/0x0004 0x0020000
- 48e4.5aec: *00000000006e0000-00000000006fefff 0x0002/0x0002 0x0040000
- 48e4.5aec: 00000000006ff000-00000000006fffff 0x0001/0x0000 0x0000000
- 48e4.5aec: *0000000000700000-00000000007fafff 0x0000/0x0004 0x0020000
- 48e4.5aec: 00000000007fb000-00000000007fdfff 0x0104/0x0004 0x0020000
- 48e4.5aec: 00000000007fe000-00000000007fffff 0x0004/0x0004 0x0020000
- 48e4.5aec: *0000000000800000-00000000009acfff 0x0000/0x0004 0x0020000
- 48e4.5aec: 00000000009ad000-00000000009affff 0x0004/0x0004 0x0020000
- 48e4.5aec: 00000000009b0000-00000000009fffff 0x0000/0x0004 0x0020000
- 48e4.5aec: *0000000000a00000-0000000000a03fff 0x0002/0x0002 0x0040000
- 48e4.5aec: 0000000000a04000-0000000000a0ffff 0x0001/0x0000 0x0000000
- 48e4.5aec: *0000000000a10000-0000000000a11fff 0x0004/0x0004 0x0020000
- 48e4.5aec: 0000000000a12000-000000007ffdffff 0x0001/0x0000 0x0000000
- 48e4.5aec: *000000007ffe0000-000000007ffe0fff 0x0002/0x0002 0x0020000
- 48e4.5aec: *000000007ffe1000-000000007ffe1fff 0x0002/0x0002 0x0020000
- 48e4.5aec: 000000007ffe2000-00007ff55ce0ffff 0x0001/0x0000 0x0000000
- 48e4.5aec: *00007ff55ce10000-00007ff55ce10fff 0x0002/0x0002 0x0040000
- 48e4.5aec: 00007ff55ce11000-00007ff75562ffff 0x0001/0x0000 0x0000000
- 48e4.5aec: *00007ff755630000-00007ff755630fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 48e4.5aec: 00007ff755631000-00007ff7556a7fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 48e4.5aec: 00007ff7556a8000-00007ff7556a8fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 48e4.5aec: 00007ff7556a9000-00007ff7556f1fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 48e4.5aec: 00007ff7556f2000-00007ff7556f2fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 48e4.5aec: 00007ff7556f3000-00007ff7556f3fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 48e4.5aec: 00007ff7556f4000-00007ff7556f8fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 48e4.5aec: 00007ff7556f9000-00007ff7556f9fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 48e4.5aec: 00007ff7556fa000-00007ff7556fafff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 48e4.5aec: 00007ff7556fb000-00007ff7556fefff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 48e4.5aec: 00007ff7556ff000-00007ff755747fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 48e4.5aec: 00007ff755748000-00007ffab925ffff 0x0001/0x0000 0x0000000
- 48e4.5aec: *00007ffab9260000-00007ffab9260fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
- 48e4.5aec: 00007ffab9261000-00007ffab938bfff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
- 48e4.5aec: 00007ffab938c000-00007ffab93d3fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
- 48e4.5aec: 00007ffab93d4000-00007ffab93dffff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
- 48e4.5aec: 00007ffab93e0000-00007ffab93eefff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
- 48e4.5aec: 00007ffab93ef000-00007ffab93effff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
- 48e4.5aec: 00007ffab93f0000-00007ffab93f2fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
- 48e4.5aec: 00007ffab93f3000-00007ffab9468fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
- 48e4.5aec: 00007ffab9469000-00007ffffffeffff 0x0001/0x0000 0x0000000
- 48e4.5aec: supR3HardNtChildPurify: Done after 527 ms and 0 fixes (loop #0).
- 5f00.18e0: Log file opened: 6.1.34r150636 g_hStartupLog=0000000000000004 g_uNtVerCombined=0xa055f000
- 5f00.18e0: supR3HardenedVmProcessInit: uNtDllAddr=00007ffab9260000 g_uNtVerCombined=0xa055f000 (stack ~00000000007ff798)
- 5f00.18e0: ntdll.dll: timestamp 0x5398ab6f (rc=VINF_SUCCESS)
- 5f00.18e0: New simple heap: #1 0000000000b20000 LB 0x800000 (for 2134016 allocation)
- 48e4.5aec: supR3HardNtEnableThreadCreationEx:
- 5f00.18e0: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox'
- 5f00.18e0: System32: \Device\HarddiskVolume3\Windows\System32
- 5f00.18e0: WinSxS: \Device\HarddiskVolume3\Windows\WinSxS
- 5f00.18e0: KnownDllPath: C:\Windows\System32
- 5f00.18e0: supR3HardenedVmProcessInit: Opening vboxdrv stub...
- 5f00.18e0: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
- 5f00.18e0: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
- 5f00.18e0: Registered Dll notification callback with NTDLL.
- 5f00.18e0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\kernel32.dll)
- 5f00.18e0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\kernel32.dll
- 5f00.18e0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\KERNEL32.DLL (Input=KERNEL32.DLL, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000004001:<flags> [calling]
- 5f00.18e0: supR3HardenedDllNotificationCallback: load 00007ffab69a0000 LB 0x00379000 C:\Windows\System32\KERNELBASE.dll [fFlags=0x0]
- 5f00.18e0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\KernelBase.dll)
- 5f00.18e0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\KernelBase.dll
- 5f00.18e0: supR3HardenedDllNotificationCallback: load 00007ffab7880000 LB 0x000bd000 C:\Windows\System32\KERNEL32.DLL [fFlags=0x0]
- 5f00.18e0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
- 5f00.18e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab7880000 'C:\Windows\System32\KERNEL32.DLL'
- 5f00.18e0: supR3HardenedDllNotificationCallback: load 00007ff755630000 LB 0x00118000 C:\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe [fFlags=0x0]
- 5f00.18e0: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe: Signature #1/2: info status: 24202
- 5f00.18e0: '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
- 5f00.18e0: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe)
- 5f00.18e0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 5f00.18e0: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffab92daf50 pvNtTerminateThread=00007ffab9304960
- 48e4.5aec: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 78 ms.
- 5f00.18e0: \SystemRoot\System32\ntdll.dll:
- 5f00.18e0: CreationTime: 2022-07-13T09:48:33.425384000Z
- 5f00.18e0: LastWriteTime: 2022-07-13T09:48:33.464782100Z
- 5f00.18e0: ChangeTime: 2022-07-15T09:20:37.898077300Z
- 5f00.18e0: FileAttributes: 0x20
- 5f00.18e0: Size: 0x207e08
- 5f00.18e0: NT Headers: 0xe0
- 5f00.18e0: Timestamp: 0x5398ab6f
- 5f00.18e0: Machine: 0x8664 - amd64
- 5f00.18e0: Timestamp: 0x5398ab6f
- 5f00.18e0: Image Version: 10.0
- 5f00.18e0: SizeOfImage: 0x209000 (2134016)
- 5f00.18e0: Resource Dir: 0x194000 LB 0x73528
- 5f00.18e0: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 5f00.18e0: [Raw version resource data: 0x1940f0 LB 0x380, codepage 0x0 (reserved 0x0)]
- 5f00.18e0: ProductName: Microsoft® Windows® Operating System
- 5f00.18e0: ProductVersion: 10.0.22000.778
- 5f00.18e0: FileVersion: 10.0.22000.778 (WinBuild.160101.0800)
- 5f00.18e0: FileDescription: NT Layer DLL
- 5f00.18e0: \SystemRoot\System32\kernel32.dll:
- 5f00.18e0: CreationTime: 2022-06-16T22:13:47.886924000Z
- 5f00.18e0: LastWriteTime: 2022-06-16T22:13:47.899916800Z
- 5f00.18e0: ChangeTime: 2022-07-13T09:49:56.810738300Z
- 5f00.18e0: FileAttributes: 0x20
- 5f00.18e0: Size: 0xc0058
- 5f00.18e0: NT Headers: 0xf8
- 5f00.18e0: Timestamp: 0xafec8296
- 5f00.18e0: Machine: 0x8664 - amd64
- 5f00.18e0: Timestamp: 0xafec8296
- 5f00.18e0: Image Version: 10.0
- 5f00.18e0: SizeOfImage: 0xbd000 (774144)
- 5f00.18e0: Resource Dir: 0xbb000 LB 0x520
- 5f00.18e0: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 5f00.18e0: [Raw version resource data: 0xbb0b0 LB 0x3a4, codepage 0x0 (reserved 0x0)]
- 5f00.18e0: ProductName: Microsoft® Windows® Operating System
- 5f00.18e0: ProductVersion: 10.0.22000.708
- 5f00.18e0: FileVersion: 10.0.22000.708 (WinBuild.160101.0800)
- 5f00.18e0: FileDescription: Windows NT BASE API Client DLL
- 5f00.18e0: \SystemRoot\System32\KernelBase.dll:
- 5f00.18e0: CreationTime: 2022-07-13T09:48:33.970578400Z
- 5f00.18e0: LastWriteTime: 2022-07-13T09:48:34.072201200Z
- 5f00.18e0: ChangeTime: 2022-07-15T09:21:13.777271800Z
- 5f00.18e0: FileAttributes: 0x20
- 5f00.18e0: Size: 0x380268
- 5f00.18e0: NT Headers: 0xf8
- 5f00.18e0: Timestamp: 0x960371d1
- 5f00.18e0: Machine: 0x8664 - amd64
- 5f00.18e0: Timestamp: 0x960371d1
- 5f00.18e0: Image Version: 10.0
- 5f00.18e0: SizeOfImage: 0x379000 (3641344)
- 5f00.18e0: Resource Dir: 0x34a000 LB 0x548
- 5f00.18e0: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 5f00.18e0: [Raw version resource data: 0x34a0b0 LB 0x3bc, codepage 0x0 (reserved 0x0)]
- 5f00.18e0: ProductName: Microsoft® Windows® Operating System
- 5f00.18e0: ProductVersion: 10.0.22000.795
- 5f00.18e0: FileVersion: 10.0.22000.795 (WinBuild.160101.0800)
- 5f00.18e0: FileDescription: Windows NT BASE API Client DLL
- 5f00.18e0: \SystemRoot\System32\apisetschema.dll:
- 5f00.18e0: CreationTime: 2021-06-05T12:04:59.928787900Z
- 5f00.18e0: LastWriteTime: 2021-06-05T12:04:59.928787900Z
- 5f00.18e0: ChangeTime: 2022-07-13T09:49:56.784497700Z
- 5f00.18e0: FileAttributes: 0x20
- 5f00.18e0: Size: 0x24150
- 5f00.18e0: NT Headers: 0xc8
- 5f00.18e0: Timestamp: 0x68d1dbaf
- 5f00.18e0: Machine: 0x8664 - amd64
- 5f00.18e0: Timestamp: 0x68d1dbaf
- 5f00.18e0: Image Version: 10.0
- 5f00.18e0: SizeOfImage: 0x23000 (143360)
- 5f00.18e0: Resource Dir: 0x22000 LB 0x408
- 5f00.18e0: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 5f00.18e0: [Raw version resource data: 0x22060 LB 0x3a8, codepage 0x0 (reserved 0x0)]
- 5f00.18e0: ProductName: Microsoft® Windows® Operating System
- 5f00.18e0: ProductVersion: 10.0.22000.1
- 5f00.18e0: FileVersion: 10.0.22000.1 (WinBuild.160101.0800)
- 5f00.18e0: FileDescription: ApiSet Schema DLL
- 5f00.18e0: NtOpenDirectoryObject failed on \Driver: 0xc0000022
- 5f00.18e0: supR3HardenedWinFindAdversaries: 0x20
- 5f00.18e0: \SystemRoot\System32\drivers\cfwids.sys:
- 5f00.18e0: CreationTime: 2021-03-02T21:06:14.000000000Z
- 5f00.18e0: LastWriteTime: 2021-09-28T21:02:42.000000000Z
- 5f00.18e0: ChangeTime: 2022-02-17T14:13:42.561653600Z
- 5f00.18e0: FileAttributes: 0x20
- 5f00.18e0: Size: 0x12400
- 5f00.18e0: NT Headers: 0xe0
- 5f00.18e0: Timestamp: 0x6144daa5
- 5f00.18e0: Machine: 0x8664 - amd64
- 5f00.18e0: Timestamp: 0x6144daa5
- 5f00.18e0: Image Version: 10.0
- 5f00.18e0: SizeOfImage: 0x13000 (77824)
- 5f00.18e0: Resource Dir: 0x11000 LB 0x550
- 5f00.18e0: [Version info resource found at 0x80! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 5f00.18e0: [Raw version resource data: 0x110a0 LB 0x318, codepage 0x0 (reserved 0x0)]
- 5f00.18e0: ProductName: SYSCORE
- 5f00.18e0: ProductVersion: 21.09.0.184
- 5f00.18e0: FileVersion: SYSCORE.21.09.0.184
- 5f00.18e0: PrivateBuild: SYSCORE.21.09.0.184
- 5f00.18e0: FileDescription: McAfee Personal Firewall IDS Plugin
- 5f00.18e0: \SystemRoot\System32\drivers\mfeavfk.sys:
- 5f00.18e0: CreationTime: 2021-03-02T21:06:12.000000000Z
- 5f00.18e0: LastWriteTime: 2021-09-28T21:02:42.000000000Z
- 5f00.18e0: ChangeTime: 2022-02-17T14:13:42.404177800Z
- 5f00.18e0: FileAttributes: 0x20
- 5f00.18e0: Size: 0x5f600
- 5f00.18e0: NT Headers: 0xf0
- 5f00.18e0: Timestamp: 0x6144da96
- 5f00.18e0: Machine: 0x8664 - amd64
- 5f00.18e0: Timestamp: 0x6144da96
- 5f00.18e0: Image Version: 10.0
- 5f00.18e0: SizeOfImage: 0x60000 (393216)
- 5f00.18e0: Resource Dir: 0x5e000 LB 0x758
- 5f00.18e0: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 5f00.18e0: [Raw version resource data: 0x5e110 LB 0x334, codepage 0x0 (reserved 0x0)]
- 5f00.18e0: ProductName: SYSCORE
- 5f00.18e0: ProductVersion: 21.09.0.184
- 5f00.18e0: FileVersion: SYSCORE.21.09.0.184
- 5f00.18e0: PrivateBuild: SYSCORE.21.09.0.184 F15,F16,F19
- 5f00.18e0: FileDescription: Anti-Virus File System Filter Driver
- 5f00.18e0: \SystemRoot\System32\drivers\mfefirek.sys:
- 5f00.18e0: CreationTime: 2021-03-02T21:06:12.000000000Z
- 5f00.18e0: LastWriteTime: 2021-09-28T21:02:42.000000000Z
- 5f00.18e0: ChangeTime: 2022-02-17T14:13:42.380174300Z
- 5f00.18e0: FileAttributes: 0x20
- 5f00.18e0: Size: 0x80800
- 5f00.18e0: NT Headers: 0xd8
- 5f00.18e0: Timestamp: 0x6144daa7
- 5f00.18e0: Machine: 0x8664 - amd64
- 5f00.18e0: Timestamp: 0x6144daa7
- 5f00.18e0: Image Version: 10.0
- 5f00.18e0: SizeOfImage: 0x82000 (532480)
- 5f00.18e0: Resource Dir: 0x80000 LB 0x388
- 5f00.18e0: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 5f00.18e0: [Raw version resource data: 0x80060 LB 0x328, codepage 0x0 (reserved 0x0)]
- 5f00.18e0: ProductName: SYSCORE
- 5f00.18e0: ProductVersion: 21.09.0.184
- 5f00.18e0: FileVersion: SYSCORE.21.09.0.184
- 5f00.18e0: PrivateBuild: SYSCORE.21.09.0.184 F17,F18
- 5f00.18e0: FileDescription: McAfee Core Firewall Engine Driver
- 5f00.18e0: \SystemRoot\System32\drivers\mfehidk.sys:
- 5f00.18e0: CreationTime: 2021-03-02T21:06:14.000000000Z
- 5f00.18e0: LastWriteTime: 2021-09-28T21:02:40.000000000Z
- 5f00.18e0: ChangeTime: 2022-02-17T14:13:42.033393300Z
- 5f00.18e0: FileAttributes: 0x20
- 5f00.18e0: Size: 0x109c00
- 5f00.18e0: NT Headers: 0x100
- 5f00.18e0: Timestamp: 0x6144db21
- 5f00.18e0: Machine: 0x8664 - amd64
- 5f00.18e0: Timestamp: 0x6144db21
- 5f00.18e0: Image Version: 10.0
- 5f00.18e0: SizeOfImage: 0x115000 (1134592)
- 5f00.18e0: Resource Dir: 0x112000 LB 0x780
- 5f00.18e0: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 5f00.18e0: [Raw version resource data: 0x112110 LB 0x320, codepage 0x0 (reserved 0x0)]
- 5f00.18e0: ProductName: SYSCORE
- 5f00.18e0: ProductVersion: 21.09.0.184
- 5f00.18e0: FileVersion: SYSCORE.21.09.0.184
- 5f00.18e0: PrivateBuild: SYSCORE.21.09.0.184 F14,F15,F16,F18,F20
- 5f00.18e0: FileDescription: McAfee Link Driver
- 5f00.18e0: \SystemRoot\System32\drivers\mfencbdc.sys:
- 5f00.18e0: CreationTime: 2021-09-16T08:52:14.000000000Z
- 5f00.18e0: LastWriteTime: 2021-09-16T08:52:14.000000000Z
- 5f00.18e0: ChangeTime: 2022-02-17T14:15:27.567390100Z
- 5f00.18e0: FileAttributes: 0x20
- 5f00.18e0: Size: 0x9be00
- 5f00.18e0: NT Headers: 0xe0
- 5f00.18e0: Timestamp: 0x61403be3
- 5f00.18e0: Machine: 0x8664 - amd64
- 5f00.18e0: Timestamp: 0x61403be3
- 5f00.18e0: Image Version: 10.0
- 5f00.18e0: SizeOfImage: 0xad000 (708608)
- 5f00.18e0: Resource Dir: 0xab000 LB 0x3d0
- 5f00.18e0: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 5f00.18e0: [Raw version resource data: 0xab060 LB 0x370, codepage 0x0 (reserved 0x0)]
- 5f00.18e0: ProductName: Anti-Malware Core
- 5f00.18e0: ProductVersion: 21.9.0
- 5f00.18e0: FileVersion: Anti-Malware Core.21.9.0.327
- 5f00.18e0: PrivateBuild: Anti-Malware Core.21.9.0.327
- 5f00.18e0: FileDescription: Event Driver
- 5f00.18e0: \SystemRoot\System32\drivers\mfewfpk.sys:
- 5f00.18e0: CreationTime: 2021-03-02T21:06:12.000000000Z
- 5f00.18e0: LastWriteTime: 2021-09-28T21:02:42.000000000Z
- 5f00.18e0: ChangeTime: 2022-02-17T14:13:40.787639300Z
- 5f00.18e0: FileAttributes: 0x20
- 5f00.18e0: Size: 0x3ea00
- 5f00.18e0: NT Headers: 0xe0
- 5f00.18e0: Timestamp: 0x6144da96
- 5f00.18e0: Machine: 0x8664 - amd64
- 5f00.18e0: Timestamp: 0x6144da96
- 5f00.18e0: Image Version: 10.0
- 5f00.18e0: SizeOfImage: 0x5a000 (368640)
- 5f00.18e0: Resource Dir: 0x58000 LB 0x380
- 5f00.18e0: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 5f00.18e0: [Raw version resource data: 0x58060 LB 0x320, codepage 0x0 (reserved 0x0)]
- 5f00.18e0: ProductName: SYSCORE
- 5f00.18e0: ProductVersion: 21.09.0.184
- 5f00.18e0: FileVersion: SYSCORE.21.09.0.184
- 5f00.18e0: PrivateBuild: SYSCORE.21.09.0.184 F17,F18
- 5f00.18e0: FileDescription: Anti-Virus Mini-Firewall Driver
- 5f00.18e0: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox'
- 5f00.18e0: Calling main()
- 5f00.18e0: SUPR3HardenedMain: pszProgName=VirtualBoxVM fFlags=0x2
- 5f00.18e0: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox'
- 5f00.18e0: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe: Signature #1/2: info status: 24202
- 5f00.18e0: '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
- 5f00.18e0: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe)
- 5f00.18e0: SUPR3HardenedMain: Respawn #2
- 5f00.18e0: supR3HardNtEnableThreadCreationEx:
- 5f00.18e0: supR3HardenedDllNotificationCallback: load 00007ffab9040000 LB 0x0009e000 C:\Windows\System32\sechost.dll [fFlags=0x0]
- 5f00.18e0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\sechost.dll)
- 5f00.18e0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\sechost.dll
- 5f00.18e0: '\Device\HarddiskVolume3\Windows\System32\ntdll.dll' has no imports
- 5f00.18e0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\ntdll.dll)
- 5f00.18e0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\ntdll.dll
- 5f00.18e0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\ntdll.dll (Input=ntdll.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 5f00.18e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab9260000 'C:\Windows\System32\ntdll.dll'
- 5f00.18e0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\KernelBase.dll [lacks WinVerifyTrust]
- 5f00.18e0: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\KernelBase.dll (Input=KernelBase, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 5f00.18e0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab69a0000 'C:\Windows\System32\KernelBase.dll'
- 5f00.18e0: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffab92daf50 pvNtTerminateThread=00007ffab9304960
- 5f00.18e0: supR3HardenedWinDoReSpawn(2): New child 37b8.37bc [kernel32].
- 5f00.18e0: supR3HardenedWinReSpawn: NtSetInformationThread/ThreadHideFromDebugger failed: 0xc0000022 (harmless)
- 5f00.18e0: supR3HardNtChildGatherData: PebBaseAddress=00000000005b5000 cbPeb=0x388
- 5f00.18e0: supR3HardNtPuChFindNtdll: uNtDllParentAddr=00007ffab9260000 uNtDllChildAddr=00007ffab9260000
- 5f00.18e0: supR3HardenedWinSetupChildInit: uLdrInitThunk=00007ffab92daf50
- 5f00.18e0: supR3HardenedWinSetupChildInit: Initial context:
- rax=0000000000000000 rbx=0000000000000000 rcx=00007ff755637900 rdx=00000000005b5000
- rsi=0000000000000000 rdi=0000000000000000 r8 =0000000000000000 r9 =0000000000000000
- r10=0000000000000000 r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
- r14=0000000000000000 r15=0000000000000000 P1=0000000000000000 P2=0000000000000000
- rip=00007ffab9264830 rsp=00000000003ffe98 rbp=0000000000000000 ctxflags=0010001b
- cs=0033 ss=002b ds=0000 es=0000 fs=0000 gs=0000 eflags=00000200 mxcrx=00001f80
- P3=0000000000000000 P4=0000000000000000 P5=0000000000000000 P6=0000000000000000
- dr0=0000000000000000 dr1=0000000000000000 dr2=0000000000000000 dr3=0000000000000000
- dr6=0000000000000000 dr7=0000000000000000 vcr=0000000000000000 dcr=0000000000000000
- lbt=0000000000000000 lbf=0000000000000000 lxt=0000000000000000 lxf=0000000000000000
- 5f00.18e0: kernel32.dll: timestamp 0xafec8296 (rc=VINF_SUCCESS)
- 5f00.18e0: supR3HardenedWinSetupChildInit: Start child.
- 5f00.18e0: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
- 5f00.18e0: supR3HardNtChildPurify: Startup delay kludge #1/0: 513 ms, 33 sleeps
- 5f00.18e0: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
- 5f00.18e0: *0000000000000000-00000000002bffff 0x0001/0x0000 0x0000000
- 5f00.18e0: *00000000002c0000-00000000002dffff 0x0004/0x0004 0x0020000
- 5f00.18e0: *00000000002e0000-00000000002fefff 0x0002/0x0002 0x0040000
- 5f00.18e0: 00000000002ff000-00000000002fffff 0x0001/0x0000 0x0000000
- 5f00.18e0: *0000000000300000-00000000003fafff 0x0000/0x0004 0x0020000
- 5f00.18e0: 00000000003fb000-00000000003fdfff 0x0104/0x0004 0x0020000
- 5f00.18e0: 00000000003fe000-00000000003fffff 0x0004/0x0004 0x0020000
- 5f00.18e0: *0000000000400000-00000000005b4fff 0x0000/0x0004 0x0020000
- 5f00.18e0: 00000000005b5000-00000000005b7fff 0x0004/0x0004 0x0020000
- 5f00.18e0: 00000000005b8000-00000000005fffff 0x0000/0x0004 0x0020000
- 5f00.18e0: *0000000000600000-0000000000603fff 0x0002/0x0002 0x0040000
- 5f00.18e0: 0000000000604000-000000000060ffff 0x0001/0x0000 0x0000000
- 5f00.18e0: *0000000000610000-0000000000611fff 0x0004/0x0004 0x0020000
- 5f00.18e0: 0000000000612000-000000007ffdffff 0x0001/0x0000 0x0000000
- 5f00.18e0: *000000007ffe0000-000000007ffe0fff 0x0002/0x0002 0x0020000
- 5f00.18e0: *000000007ffe1000-000000007ffe1fff 0x0002/0x0002 0x0020000
- 5f00.18e0: 000000007ffe2000-00007ff59a0effff 0x0001/0x0000 0x0000000
- 5f00.18e0: *00007ff59a0f0000-00007ff59a0f0fff 0x0002/0x0002 0x0040000
- 5f00.18e0: 00007ff59a0f1000-00007ff75562ffff 0x0001/0x0000 0x0000000
- 5f00.18e0: *00007ff755630000-00007ff755630fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 5f00.18e0: 00007ff755631000-00007ff7556a7fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 5f00.18e0: 00007ff7556a8000-00007ff7556a8fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 5f00.18e0: 00007ff7556a9000-00007ff7556f1fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 5f00.18e0: 00007ff7556f2000-00007ff7556f2fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 5f00.18e0: 00007ff7556f3000-00007ff7556f3fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 5f00.18e0: 00007ff7556f4000-00007ff7556f8fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 5f00.18e0: 00007ff7556f9000-00007ff7556f9fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 5f00.18e0: 00007ff7556fa000-00007ff7556fafff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 5f00.18e0: 00007ff7556fb000-00007ff7556fefff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 5f00.18e0: 00007ff7556ff000-00007ff755747fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 5f00.18e0: 00007ff755748000-00007ffab925ffff 0x0001/0x0000 0x0000000
- 5f00.18e0: *00007ffab9260000-00007ffab9260fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
- 5f00.18e0: 00007ffab9261000-00007ffab938bfff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
- 5f00.18e0: 00007ffab938c000-00007ffab93d3fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
- 5f00.18e0: 00007ffab93d4000-00007ffab93dffff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
- 5f00.18e0: 00007ffab93e0000-00007ffab93eefff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
- 5f00.18e0: 00007ffab93ef000-00007ffab93effff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
- 5f00.18e0: 00007ffab93f0000-00007ffab93f2fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
- 5f00.18e0: 00007ffab93f3000-00007ffab9468fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
- 5f00.18e0: 00007ffab9469000-00007ffffffeffff 0x0001/0x0000 0x0000000
- 5f00.18e0: VirtualBoxVM.exe: timestamp 0x623a5dfe (rc=VINF_SUCCESS)
- 5f00.18e0: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe: Signature #1/2: info status: 24202
- 5f00.18e0: '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
- 5f00.18e0: '\Device\HarddiskVolume3\Windows\System32\ntdll.dll' has no imports
- 5f00.18e0: supR3HardNtChildPurify: Done after 545 ms and 0 fixes (loop #0).
- 5f00.18e0: supR3HardenedEarlyCompact: Removed heap 1 (0x00000000b20000 LB 0x800000)
- 37b8.37bc: Log file opened: 6.1.34r150636 g_hStartupLog=0000000000000004 g_uNtVerCombined=0xa055f000
- 5f00.18e0: supR3HardNtEnableThreadCreationEx:
- 37b8.37bc: supR3HardenedVmProcessInit: uNtDllAddr=00007ffab9260000 g_uNtVerCombined=0xa055f000 (stack ~00000000003ff918)
- 37b8.37bc: ntdll.dll: timestamp 0x5398ab6f (rc=VINF_SUCCESS)
- 37b8.37bc: New simple heap: #1 0000000000720000 LB 0x800000 (for 2134016 allocation)
- 37b8.37bc: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox'
- 37b8.37bc: System32: \Device\HarddiskVolume3\Windows\System32
- 37b8.37bc: WinSxS: \Device\HarddiskVolume3\Windows\WinSxS
- 37b8.37bc: KnownDllPath: C:\Windows\System32
- 37b8.37bc: supR3HardenedVmProcessInit: Opening vboxdrv...
- 37b8.37bc: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
- 37b8.37bc: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
- 37b8.37bc: Registered Dll notification callback with NTDLL.
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\kernel32.dll)
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\kernel32.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\KERNEL32.DLL (Input=KERNEL32.DLL, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000004001:<flags> [calling]
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffab69a0000 LB 0x00379000 C:\Windows\System32\KERNELBASE.dll [fFlags=0x0]
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\KernelBase.dll)
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\KernelBase.dll
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffab7880000 LB 0x000bd000 C:\Windows\System32\KERNEL32.DLL [fFlags=0x0]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab7880000 'C:\Windows\System32\KERNEL32.DLL'
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ff755630000 LB 0x00118000 C:\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe [fFlags=0x0]
- 37b8.37bc: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe: Signature #1/2: info status: 24202
- 37b8.37bc: '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe)
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
- 37b8.37bc: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffab92daf50 pvNtTerminateThread=00007ffab9304960
- 5f00.18e0: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 91 ms.
- 37b8.37bc: \SystemRoot\System32\ntdll.dll:
- 37b8.37bc: CreationTime: 2022-07-13T09:48:33.425384000Z
- 37b8.37bc: LastWriteTime: 2022-07-13T09:48:33.464782100Z
- 37b8.37bc: ChangeTime: 2022-07-15T09:20:37.898077300Z
- 37b8.37bc: FileAttributes: 0x20
- 37b8.37bc: Size: 0x207e08
- 37b8.37bc: NT Headers: 0xe0
- 37b8.37bc: Timestamp: 0x5398ab6f
- 37b8.37bc: Machine: 0x8664 - amd64
- 37b8.37bc: Timestamp: 0x5398ab6f
- 37b8.37bc: Image Version: 10.0
- 37b8.37bc: SizeOfImage: 0x209000 (2134016)
- 37b8.37bc: Resource Dir: 0x194000 LB 0x73528
- 37b8.37bc: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 37b8.37bc: [Raw version resource data: 0x1940f0 LB 0x380, codepage 0x0 (reserved 0x0)]
- 37b8.37bc: ProductName: Microsoft® Windows® Operating System
- 37b8.37bc: ProductVersion: 10.0.22000.778
- 37b8.37bc: FileVersion: 10.0.22000.778 (WinBuild.160101.0800)
- 37b8.37bc: FileDescription: NT Layer DLL
- 37b8.37bc: \SystemRoot\System32\kernel32.dll:
- 37b8.37bc: CreationTime: 2022-06-16T22:13:47.886924000Z
- 37b8.37bc: LastWriteTime: 2022-06-16T22:13:47.899916800Z
- 37b8.37bc: ChangeTime: 2022-07-13T09:49:56.810738300Z
- 37b8.37bc: FileAttributes: 0x20
- 37b8.37bc: Size: 0xc0058
- 37b8.37bc: NT Headers: 0xf8
- 37b8.37bc: Timestamp: 0xafec8296
- 37b8.37bc: Machine: 0x8664 - amd64
- 37b8.37bc: Timestamp: 0xafec8296
- 37b8.37bc: Image Version: 10.0
- 37b8.37bc: SizeOfImage: 0xbd000 (774144)
- 37b8.37bc: Resource Dir: 0xbb000 LB 0x520
- 37b8.37bc: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 37b8.37bc: [Raw version resource data: 0xbb0b0 LB 0x3a4, codepage 0x0 (reserved 0x0)]
- 37b8.37bc: ProductName: Microsoft® Windows® Operating System
- 37b8.37bc: ProductVersion: 10.0.22000.708
- 37b8.37bc: FileVersion: 10.0.22000.708 (WinBuild.160101.0800)
- 37b8.37bc: FileDescription: Windows NT BASE API Client DLL
- 37b8.37bc: \SystemRoot\System32\KernelBase.dll:
- 37b8.37bc: CreationTime: 2022-07-13T09:48:33.970578400Z
- 37b8.37bc: LastWriteTime: 2022-07-13T09:48:34.072201200Z
- 37b8.37bc: ChangeTime: 2022-07-15T09:21:13.777271800Z
- 37b8.37bc: FileAttributes: 0x20
- 37b8.37bc: Size: 0x380268
- 37b8.37bc: NT Headers: 0xf8
- 37b8.37bc: Timestamp: 0x960371d1
- 37b8.37bc: Machine: 0x8664 - amd64
- 37b8.37bc: Timestamp: 0x960371d1
- 37b8.37bc: Image Version: 10.0
- 37b8.37bc: SizeOfImage: 0x379000 (3641344)
- 37b8.37bc: Resource Dir: 0x34a000 LB 0x548
- 37b8.37bc: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 37b8.37bc: [Raw version resource data: 0x34a0b0 LB 0x3bc, codepage 0x0 (reserved 0x0)]
- 37b8.37bc: ProductName: Microsoft® Windows® Operating System
- 37b8.37bc: ProductVersion: 10.0.22000.795
- 37b8.37bc: FileVersion: 10.0.22000.795 (WinBuild.160101.0800)
- 37b8.37bc: FileDescription: Windows NT BASE API Client DLL
- 37b8.37bc: \SystemRoot\System32\apisetschema.dll:
- 37b8.37bc: CreationTime: 2021-06-05T12:04:59.928787900Z
- 37b8.37bc: LastWriteTime: 2021-06-05T12:04:59.928787900Z
- 37b8.37bc: ChangeTime: 2022-07-13T09:49:56.784497700Z
- 37b8.37bc: FileAttributes: 0x20
- 37b8.37bc: Size: 0x24150
- 37b8.37bc: NT Headers: 0xc8
- 37b8.37bc: Timestamp: 0x68d1dbaf
- 37b8.37bc: Machine: 0x8664 - amd64
- 37b8.37bc: Timestamp: 0x68d1dbaf
- 37b8.37bc: Image Version: 10.0
- 37b8.37bc: SizeOfImage: 0x23000 (143360)
- 37b8.37bc: Resource Dir: 0x22000 LB 0x408
- 37b8.37bc: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 37b8.37bc: [Raw version resource data: 0x22060 LB 0x3a8, codepage 0x0 (reserved 0x0)]
- 37b8.37bc: ProductName: Microsoft® Windows® Operating System
- 37b8.37bc: ProductVersion: 10.0.22000.1
- 37b8.37bc: FileVersion: 10.0.22000.1 (WinBuild.160101.0800)
- 37b8.37bc: FileDescription: ApiSet Schema DLL
- 37b8.37bc: NtOpenDirectoryObject failed on \Driver: 0xc0000022
- 37b8.37bc: supR3HardenedWinFindAdversaries: 0x20
- 37b8.37bc: \SystemRoot\System32\drivers\cfwids.sys:
- 37b8.37bc: CreationTime: 2021-03-02T21:06:14.000000000Z
- 37b8.37bc: LastWriteTime: 2021-09-28T21:02:42.000000000Z
- 37b8.37bc: ChangeTime: 2022-02-17T14:13:42.561653600Z
- 37b8.37bc: FileAttributes: 0x20
- 37b8.37bc: Size: 0x12400
- 37b8.37bc: NT Headers: 0xe0
- 37b8.37bc: Timestamp: 0x6144daa5
- 37b8.37bc: Machine: 0x8664 - amd64
- 37b8.37bc: Timestamp: 0x6144daa5
- 37b8.37bc: Image Version: 10.0
- 37b8.37bc: SizeOfImage: 0x13000 (77824)
- 37b8.37bc: Resource Dir: 0x11000 LB 0x550
- 37b8.37bc: [Version info resource found at 0x80! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 37b8.37bc: [Raw version resource data: 0x110a0 LB 0x318, codepage 0x0 (reserved 0x0)]
- 37b8.37bc: ProductName: SYSCORE
- 37b8.37bc: ProductVersion: 21.09.0.184
- 37b8.37bc: FileVersion: SYSCORE.21.09.0.184
- 37b8.37bc: PrivateBuild: SYSCORE.21.09.0.184
- 37b8.37bc: FileDescription: McAfee Personal Firewall IDS Plugin
- 37b8.37bc: \SystemRoot\System32\drivers\mfeavfk.sys:
- 37b8.37bc: CreationTime: 2021-03-02T21:06:12.000000000Z
- 37b8.37bc: LastWriteTime: 2021-09-28T21:02:42.000000000Z
- 37b8.37bc: ChangeTime: 2022-02-17T14:13:42.404177800Z
- 37b8.37bc: FileAttributes: 0x20
- 37b8.37bc: Size: 0x5f600
- 37b8.37bc: NT Headers: 0xf0
- 37b8.37bc: Timestamp: 0x6144da96
- 37b8.37bc: Machine: 0x8664 - amd64
- 37b8.37bc: Timestamp: 0x6144da96
- 37b8.37bc: Image Version: 10.0
- 37b8.37bc: SizeOfImage: 0x60000 (393216)
- 37b8.37bc: Resource Dir: 0x5e000 LB 0x758
- 37b8.37bc: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 37b8.37bc: [Raw version resource data: 0x5e110 LB 0x334, codepage 0x0 (reserved 0x0)]
- 37b8.37bc: ProductName: SYSCORE
- 37b8.37bc: ProductVersion: 21.09.0.184
- 37b8.37bc: FileVersion: SYSCORE.21.09.0.184
- 37b8.37bc: PrivateBuild: SYSCORE.21.09.0.184 F15,F16,F19
- 37b8.37bc: FileDescription: Anti-Virus File System Filter Driver
- 37b8.37bc: \SystemRoot\System32\drivers\mfefirek.sys:
- 37b8.37bc: CreationTime: 2021-03-02T21:06:12.000000000Z
- 37b8.37bc: LastWriteTime: 2021-09-28T21:02:42.000000000Z
- 37b8.37bc: ChangeTime: 2022-02-17T14:13:42.380174300Z
- 37b8.37bc: FileAttributes: 0x20
- 37b8.37bc: Size: 0x80800
- 37b8.37bc: NT Headers: 0xd8
- 37b8.37bc: Timestamp: 0x6144daa7
- 37b8.37bc: Machine: 0x8664 - amd64
- 37b8.37bc: Timestamp: 0x6144daa7
- 37b8.37bc: Image Version: 10.0
- 37b8.37bc: SizeOfImage: 0x82000 (532480)
- 37b8.37bc: Resource Dir: 0x80000 LB 0x388
- 37b8.37bc: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 37b8.37bc: [Raw version resource data: 0x80060 LB 0x328, codepage 0x0 (reserved 0x0)]
- 37b8.37bc: ProductName: SYSCORE
- 37b8.37bc: ProductVersion: 21.09.0.184
- 37b8.37bc: FileVersion: SYSCORE.21.09.0.184
- 37b8.37bc: PrivateBuild: SYSCORE.21.09.0.184 F17,F18
- 37b8.37bc: FileDescription: McAfee Core Firewall Engine Driver
- 37b8.37bc: \SystemRoot\System32\drivers\mfehidk.sys:
- 37b8.37bc: CreationTime: 2021-03-02T21:06:14.000000000Z
- 37b8.37bc: LastWriteTime: 2021-09-28T21:02:40.000000000Z
- 37b8.37bc: ChangeTime: 2022-02-17T14:13:42.033393300Z
- 37b8.37bc: FileAttributes: 0x20
- 37b8.37bc: Size: 0x109c00
- 37b8.37bc: NT Headers: 0x100
- 37b8.37bc: Timestamp: 0x6144db21
- 37b8.37bc: Machine: 0x8664 - amd64
- 37b8.37bc: Timestamp: 0x6144db21
- 37b8.37bc: Image Version: 10.0
- 37b8.37bc: SizeOfImage: 0x115000 (1134592)
- 37b8.37bc: Resource Dir: 0x112000 LB 0x780
- 37b8.37bc: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 37b8.37bc: [Raw version resource data: 0x112110 LB 0x320, codepage 0x0 (reserved 0x0)]
- 37b8.37bc: ProductName: SYSCORE
- 37b8.37bc: ProductVersion: 21.09.0.184
- 37b8.37bc: FileVersion: SYSCORE.21.09.0.184
- 37b8.37bc: PrivateBuild: SYSCORE.21.09.0.184 F14,F15,F16,F18,F20
- 37b8.37bc: FileDescription: McAfee Link Driver
- 37b8.37bc: \SystemRoot\System32\drivers\mfencbdc.sys:
- 37b8.37bc: CreationTime: 2021-09-16T08:52:14.000000000Z
- 37b8.37bc: LastWriteTime: 2021-09-16T08:52:14.000000000Z
- 37b8.37bc: ChangeTime: 2022-02-17T14:15:27.567390100Z
- 37b8.37bc: FileAttributes: 0x20
- 37b8.37bc: Size: 0x9be00
- 37b8.37bc: NT Headers: 0xe0
- 37b8.37bc: Timestamp: 0x61403be3
- 37b8.37bc: Machine: 0x8664 - amd64
- 37b8.37bc: Timestamp: 0x61403be3
- 37b8.37bc: Image Version: 10.0
- 37b8.37bc: SizeOfImage: 0xad000 (708608)
- 37b8.37bc: Resource Dir: 0xab000 LB 0x3d0
- 37b8.37bc: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 37b8.37bc: [Raw version resource data: 0xab060 LB 0x370, codepage 0x0 (reserved 0x0)]
- 37b8.37bc: ProductName: Anti-Malware Core
- 37b8.37bc: ProductVersion: 21.9.0
- 37b8.37bc: FileVersion: Anti-Malware Core.21.9.0.327
- 37b8.37bc: PrivateBuild: Anti-Malware Core.21.9.0.327
- 37b8.37bc: FileDescription: Event Driver
- 37b8.37bc: \SystemRoot\System32\drivers\mfewfpk.sys:
- 37b8.37bc: CreationTime: 2021-03-02T21:06:12.000000000Z
- 37b8.37bc: LastWriteTime: 2021-09-28T21:02:42.000000000Z
- 37b8.37bc: ChangeTime: 2022-02-17T14:13:40.787639300Z
- 37b8.37bc: FileAttributes: 0x20
- 37b8.37bc: Size: 0x3ea00
- 37b8.37bc: NT Headers: 0xe0
- 37b8.37bc: Timestamp: 0x6144da96
- 37b8.37bc: Machine: 0x8664 - amd64
- 37b8.37bc: Timestamp: 0x6144da96
- 37b8.37bc: Image Version: 10.0
- 37b8.37bc: SizeOfImage: 0x5a000 (368640)
- 37b8.37bc: Resource Dir: 0x58000 LB 0x380
- 37b8.37bc: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
- 37b8.37bc: [Raw version resource data: 0x58060 LB 0x320, codepage 0x0 (reserved 0x0)]
- 37b8.37bc: ProductName: SYSCORE
- 37b8.37bc: ProductVersion: 21.09.0.184
- 37b8.37bc: FileVersion: SYSCORE.21.09.0.184
- 37b8.37bc: PrivateBuild: SYSCORE.21.09.0.184 F17,F18
- 37b8.37bc: FileDescription: Anti-Virus Mini-Firewall Driver
- 37b8.37bc: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox'
- 37b8.37bc: Calling main()
- 37b8.37bc: SUPR3HardenedMain: pszProgName=VirtualBoxVM fFlags=0x2
- 37b8.37bc: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox'
- 37b8.37bc: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe: Signature #1/2: info status: 24202
- 37b8.37bc: '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe)
- 37b8.37bc: SUPR3HardenedMain: Final process, opening VBoxDrv...
- 37b8.37bc: supR3HardenedEarlyCompact: Removed heap 1 (0x00000000720000 LB 0x800000)
- 37b8.37bc: supR3HardNtEnableThreadCreationEx:
- 37b8.37bc: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSupLib.dll: Signature #1/2: info status: 24202
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSupLib.dll)
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSupLib.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 37b8.37bc: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffaad010000 LB 0x00005000 C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL [fFlags=0x0]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaad010000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaad010000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaad010000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #29 'rpcrt4.dll'.
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\wintrust.dll)
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\wintrust.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll)
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\msvcrt.dll)
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\msvcrt.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffab83f0000 LB 0x000a3000 C:\Windows\System32\msvcrt.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffab7760000 LB 0x00120000 C:\Windows\System32\RPCRT4.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffab68b0000 LB 0x00067000 C:\Windows\System32\Wintrust.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffab6dc0000 LB 0x00111000 C:\Windows\System32\ucrtbase.dll [fFlags=0x0]
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\ucrtbase.dll)
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\ucrtbase.dll
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffab6740000 LB 0x00162000 C:\Windows\System32\CRYPT32.dll [fFlags=0x0]
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\crypt32.dll)
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\crypt32.dll
- 37b8.37bc: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab69a0000 'api-ms-win-core-synch-l1-2-0'
- 37b8.37bc: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-fibers-l1-1-1) -> 0x0, fPresent=1
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab69a0000 'api-ms-win-core-fibers-l1-1-1'
- 37b8.37bc: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab69a0000 'api-ms-win-core-synch-l1-2-0'
- 37b8.37bc: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-l1-2-1) -> 0x0, fPresent=1
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-l1-2-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab69a0000 'api-ms-win-core-localization-l1-2-1'
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\msasn1.dll)
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\msasn1.dll
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffab6030000 LB 0x00012000 C:\Windows\SYSTEM32\MSASN1.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msasn1.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab68b0000 'C:\Windows\system32\Wintrust.dll'
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\bcrypt.dll)
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\bcrypt.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\bcrypt.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 37b8.37bc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffab6120000 LB 0x00027000 C:\Windows\system32\bcrypt.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\bcrypt.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6120000 'C:\Windows\system32\bcrypt.dll'
- 37b8.37bc: bcrypt.dll loaded at 00007ffab6120000, BCryptOpenAlgorithmProvider at 00007ffab6125a30, preloading providers:
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\bcryptprimitives.dll)
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\bcryptprimitives.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\bcryptprimitives.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffab6920000 LB 0x0007f000 C:\Windows\System32\bcryptprimitives.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\bcryptprimitives.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6920000 'C:\Windows\system32\bcryptprimitives.dll'
- 37b8.37bc: BCryptOpenAlgorithmProvider(,'MD2',0,0) -> 0x0 (hAlgo=00000000011507f0)
- 37b8.37bc: BCryptOpenAlgorithmProvider(,'MD4',0,0) -> 0x0 (hAlgo=0000000001151dc0)
- 37b8.37bc: BCryptOpenAlgorithmProvider(,'MD5',0,0) -> 0x0 (hAlgo=0000000001152110)
- 37b8.37bc: BCryptOpenAlgorithmProvider(,'SHA1',0,0) -> 0x0 (hAlgo=0000000001152460)
- 37b8.37bc: BCryptOpenAlgorithmProvider(,'SHA256',0,0) -> 0x0 (hAlgo=00000000011527b0)
- 37b8.37bc: BCryptOpenAlgorithmProvider(,'SHA512',0,0) -> 0x0 (hAlgo=0000000001152b00)
- 37b8.37bc: BCryptOpenAlgorithmProvider(,'RSA',0,0) -> 0x0 (hAlgo=0000000001152e50)
- 37b8.37bc: BCryptOpenAlgorithmProvider(,'DSA',0,0) -> 0x0 (hAlgo=00000000011531a0)
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\cryptsp.dll)
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\cryptsp.dll
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffab5fe0000 LB 0x00018000 C:\Windows\SYSTEM32\CRYPTSP.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\cryptsp.dll [lacks WinVerifyTrust]
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\rsaenh.dll)
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\rsaenh.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffab5850000 LB 0x00035000 C:\Windows\system32\rsaenh.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\cryptbase.dll)
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\cryptbase.dll
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffab5f00000 LB 0x0000c000 C:\Windows\SYSTEM32\CRYPTBASE.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\cryptbase.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab7880000 'C:\Windows\System32\kernel32.dll'
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wintrust.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\WINTRUST.DLL (Input=WINTRUST.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab68b0000 'C:\Windows\System32\WINTRUST.DLL'
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\CRYPT32.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\CRYPT32.dll'
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffab7730000 LB 0x0001f000 C:\Windows\System32\imagehlp.dll [fFlags=0x0]
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\imagehlp.dll)
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\imagehlp.dll
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffab9040000 LB 0x0009e000 C:\Windows\System32\sechost.dll [fFlags=0x0]
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\sechost.dll)
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\sechost.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'rpcrt4.dll'.
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\gpapi.dll)
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\gpapi.dll
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffab5d80000 LB 0x00024000 C:\Windows\SYSTEM32\gpapi.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gpapi.dll [lacks WinVerifyTrust]
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\profapi.dll)
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\profapi.dll
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffab6670000 LB 0x00021000 C:\Windows\SYSTEM32\profapi.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\profapi.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'crypt32.dll'.
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\cryptnet.dll)
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\cryptnet.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'crypt32.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'crypt32.dll' -> '\Device\HarddiskVolume3\Windows\System32\crypt32.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\cryptnet.dll (Input=cryptnet.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffaa3720000 LB 0x00031000 C:\Windows\System32\cryptnet.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa3720000 'C:\Windows\System32\cryptnet.dll'
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa3720000 'C:\Windows\System32\cryptnet.dll'
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa3720000 'C:\Windows\System32\cryptnet.dll'
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa3720000 'C:\Windows\System32\cryptnet.dll'
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa3720000 'C:\Windows\System32\cryptnet.dll'
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\cryptnet.dll (rcNtResolve=0xc0150008) *pfFlags=0x2 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa3720000 'C:\Windows\System32\cryptnet.dll'
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa3720000 'C:\Windows\System32\cryptnet.dll'
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa3720000 'C:\Windows\System32\cryptnet.dll'
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa3720000 'C:\Windows\System32\cryptnet.dll'
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa3720000 'C:\Windows\System32\cryptnet.dll'
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa3720000 'C:\Windows\System32\cryptnet.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa3720000 'C:\Windows\System32\cryptnet.dll'
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\cryptnet.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa3720000 'C:\Windows\System32\cryptnet.dll'
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffab90e0000 LB 0x000ae000 C:\Windows\System32\advapi32.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'sechost.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #27 'rpcrt4.dll'.
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\advapi32.dll)
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\advapi32.dll
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'sechost.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'sechost.dll' -> '\Device\HarddiskVolume3\Windows\System32\sechost.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\sechost.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000000 pwszName=\SystemRoot\System32\ntdll.dll
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile: New context 0000000001236bc0
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000001236bc0
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=9645A818EDD1CE222F74503C54ECACF6B01D5633
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\rpcrt4.dll (Input=rpcrt4.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab7760000 'C:\Windows\System32\rpcrt4.dll'
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0415~31bf3856ad364e35~amd64~~10.0.22000.795.cat'; file='\SystemRoot\System32\ntdll.dll'
- 37b8.37bc: g_pfnWinVerifyTrust=00007ffab68c04a0
- 37b8.37bc: supR3HardenedScreenImage/preload: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll [redoing WinVerifyTrust]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardenedScreenImage/preload: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardenedScreenImage/preload: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wintrust.dll [redoing WinVerifyTrust]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardenedScreenImage/preload: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\wintrust.dll'
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\advapi32.dll'
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\cryptnet.dll'
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\profapi.dll'
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\gpapi.dll'
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\sechost.dll'
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\imagehlp.dll'
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\cryptbase.dll'
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\rsaenh.dll'
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\cryptsp.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\bcryptprimitives.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\bcrypt.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\msasn1.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\ucrtbase.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 24202) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSupLib.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 24202) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\KernelBase.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\kernel32.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\system32\crypt32.dll'
- 37b8.37bc: supR3HardenedWinIsDesiredRootCA: Adding 0x5ad46780fa5df300 DC=com, DC=microsoft, CN=Microsoft Root Certificate Authority
- 37b8.37bc: supR3HardenedWinIsDesiredRootCA: Adding 0xea5386456178582b C=ZA, ST=Western Cape, L=Durbanville, O=Thawte, OU=Thawte Certification, CN=Thawte Timestamping CA
- 37b8.37bc: supR3HardenedWinIsDesiredRootCA: Adding 0x560ad29254e89100 C=GB, ST=Greater Manchester, L=Salford, O=COMODO CA Limited, CN=COMODO RSA Certification Authority
- 37b8.37bc: supR3HardenedWinIsDesiredRootCA: Adding 0x3be670c1bd02a900 OU=Copyright (c) 1997 Microsoft Corp., OU=Microsoft Corporation, CN=Microsoft Root Authority
- 37b8.37bc: supR3HardenedWinIsDesiredRootCA: Adding 0xe991ee72b03db500 C=US, O=Symantec Corporation, CN=Symantec Enterprise Mobile Root for Microsoft
- 37b8.37bc: supR3HardenedWinIsDesiredRootCA: Adding 0x4d3835aa4180b200 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2011
- 37b8.37bc: supR3HardenedWinIsDesiredRootCA: Adding 0x646e3fe3ba08df00 C=US, O=MSFT, CN=Microsoft Authenticode(tm) Root Authority
- 37b8.37bc: supR3HardenedWinIsDesiredRootCA: Adding 0xece4e4289e08b900 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010
- 37b8.37bc: supR3HardenedWinIsDesiredRootCA: Adding 0xf3bb4d7e894b420 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft ECC TS Root Certificate Authority 2018
- 37b8.37bc: supR3HardenedWinIsDesiredRootCA: Adding 0x43a9cc371ff5385a O=Microsoft Trust Network, OU=Microsoft Corporation, OU=Microsoft Time Stamping Service Root, OU=Copyright (c) 1997 Microsoft Corp.
- 37b8.37bc: supR3HardenedWinIsDesiredRootCA: Adding 0x2e2d2c7c68f0202e O=VeriSign Trust Network, OU=VeriSign, Inc., OU=VeriSign Time Stamping Service Root, OU=NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc.
- 37b8.37bc: supR3HardenedWinIsDesiredRootCA: Adding 0xcec3d46562b9be8e C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft ECC Product Root Certificate Authority 2018
- 37b8.37bc: supR3HardenedWinIsDesiredRootCA: Adding 0xca58a05dd401ae00 C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Time Stamp Root Certificate Authority 2014
- 37b8.37bc: supR3HardenedWinIsDesiredRootCA: Adding 0x2ca429a5c4c6a700 C=IT, L=Milan, O=Actalis S.p.A./03358520967, CN=Actalis Authentication Root CA
- 37b8.37bc: supR3HardenedWinIsDesiredRootCA: Adding 0x61a3a33f81aace00 C=US, ST=UT, L=Salt Lake City, O=The USERTRUST Network, OU=http://www.usertrust.com, CN=UTN-USERFirst-Object
- 37b8.37bc: supR3HardenedWinIsDesiredRootCA: Adding 0x3d993fde1950a700 C=US, O=IdenTrust, CN=IdenTrust Commercial Root CA 1
- 37b8.37bc: supR3HardenedWinIsDesiredRootCA: Adding 0x6b7bdc34cd37bb00 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root G2
- 37b8.37bc: supR3HardenedWinIsDesiredRootCA: Adding 0x57ba5395b561bf00 C=BM, O=QuoVadis Limited, OU=Root Certification Authority, CN=QuoVadis Root Certification Authority
- 37b8.37bc: supR3HardenedWinIsDesiredRootCA: Adding 0xbbde687390e6bf00 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Trusted Root G4
- 37b8.37bc: supR3HardenedWinIsDesiredRootCA: Adding 0x83085097e9afdf00 O=Digital Signature Trust Co., CN=DST Root CA X3
- 37b8.37bc: supR3HardenedWinIsDesiredRootCA: Adding 0xe248b7eeee4af00 C=CH, O=SwissSign AG, CN=SwissSign Gold CA - G2
- 37b8.37bc: supR3HardenedWinIsDesiredRootCA: Adding 0x780679907625cc00 OU=GlobalSign Root CA - R3, O=GlobalSign, CN=GlobalSign
- 37b8.37bc: supR3HardenedWinIsDesiredRootCA: Adding 0x3d98ab22bb04a300 C=IE, O=Baltimore, OU=CyberTrust, CN=Baltimore CyberTrust Root
- 37b8.37bc: supR3HardenedWinIsDesiredRootCA: Adding 0xeae16ef49d40be00 C=GB, ST=Greater Manchester, L=Salford, O=Comodo CA Limited, CN=AAA Certificate Services
- 37b8.37bc: supR3HardenedWinIsDesiredRootCA: Adding 0x3714f47324e8ad00 C=US, O=Internet Security Research Group, CN=ISRG Root X1
- 37b8.37bc: supR3HardenedWinIsDesiredRootCA: Adding 0x8ff6fc03c1edbd00 C=US, ST=Arizona, L=Scottsdale, O=Starfield Technologies, Inc., CN=Starfield Root Certificate Authority - G2
- 37b8.37bc: supR3HardenedWinIsDesiredRootCA: Adding 0xc6fa4243b695b600 C=US, O=Entrust, Inc., OU=www.entrust.net/CPS is incorporated by reference, OU=(c) 2006 Entrust, Inc., CN=Entrust Root Certification Authority
- 37b8.37bc: supR3HardenedWinIsDesiredRootCA: Adding 0xa3ce8d99e60eda00 C=BE, O=GlobalSign nv-sa, OU=Root CA, CN=GlobalSign Root CA
- 37b8.37bc: supR3HardenedWinIsDesiredRootCA: Adding 0xa671e9fec832b700 C=US, O=Starfield Technologies, Inc., OU=Starfield Class 2 Certification Authority
- 37b8.37bc: supR3HardenedWinIsDesiredRootCA: Adding 0xa8de7211e13be200 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root CA
- 37b8.37bc: supR3HardenedWinIsDesiredRootCA: Adding 0x3178d37f87f1c400 C=CH, O=SwissSign AG, CN=SwissSign Silver CA - G2
- 37b8.37bc: supR3HardenedWinIsDesiredRootCA: Adding 0xd45980fbf0a0ac00 C=US, O=thawte, Inc., OU=Certification Services Division, OU=(c) 2006 thawte, Inc. - For authorized use only, CN=thawte Primary Root CA
- 37b8.37bc: supR3HardenedWinIsDesiredRootCA: Adding 0xc9edb72b684ba00 C=US, O=Entrust, Inc., OU=See www.entrust.net/legal-terms, OU=(c) 2009 Entrust, Inc. - for authorized use only, CN=Entrust Root Certification Authority - G2
- 37b8.37bc: supR3HardenedWinIsDesiredRootCA: Adding 0xf5cd95e581a4ab00 C=US, O=SecureTrust Corporation, CN=SecureTrust CA
- 37b8.37bc: supR3HardenedWinIsDesiredRootCA: Adding 0xf966ca73e8079500 OU=GlobalSign Root CA - R6, O=GlobalSign, CN=GlobalSign
- 37b8.37bc: supR3HardenedWinIsDesiredRootCA: Adding 0xbebef0d2217f0bfb C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Global Root G3
- 37b8.37bc: supR3HardenedWinIsDesiredRootCA: Adding 0x14018a1bf29e595c C=US, O=VeriSign, Inc., OU=Class 3 Public Primary Certification Authority
- 37b8.37bc: supR3HardenedWinIsDesiredRootCA: Adding 0x7c4fd32ec1b1ce00 C=PL, O=Unizeto Sp. z o.o., CN=Certum CA
- 37b8.37bc: supR3HardenedWinIsDesiredRootCA: Adding 0xd4fbe673e5ccc600 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert High Assurance EV Root CA
- 37b8.37bc: supR3HardenedWinIsDesiredRootCA: Adding 0xb352b1523915d000 C=JP, O=SECOM Trust Systems CO.,LTD., OU=Security Communication RootCA2
- 37b8.37bc: supR3HardenedWinIsDesiredRootCA: Adding 0x73e85f1bda5faa00 C=DE, O=T-Systems Enterprise Services GmbH, OU=T-Systems Trust Center, CN=T-TeleSec GlobalRoot Class 2
- 37b8.37bc: supR3HardenedWinIsDesiredRootCA: Adding 0xb28612a94b4dad00 O=Entrust.net, OU=www.entrust.net/CPS_2048 incorp. by ref. (limits liab.), OU=(c) 1999 Entrust.net Limited, CN=Entrust.net Certification Authority (2048)
- 37b8.37bc: supR3HardenedWinIsDesiredRootCA: Adding 0xe87add30c52db600 C=BE, O=GlobalSign nv-sa, CN=GlobalSign Code Signing Root R45
- 37b8.37bc: supR3HardenedWinIsDesiredRootCA: Adding 0x357a29080824af00 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2006 VeriSign, Inc. - For authorized use only, CN=VeriSign Class 3 Public Primary Certification Authority - G5
- 37b8.37bc: supR3HardenedWinIsDesiredRootCA: Adding 0x59faf1086271bf00 C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com, Inc., CN=Go Daddy Root Certificate Authority - G2
- 37b8.37bc: supR3HardenedWinIsDesiredRootCA: Adding 0x466cbc09db88c100 C=IL, O=StartCom Ltd., OU=Secure Digital Certificate Signing, CN=StartCom Certification Authority
- 37b8.37bc: supR3HardenedWinIsDesiredRootCA: Adding 0xb16dd37ffeb3b300 C=JP, O=SECOM Trust.net, OU=Security Communication RootCA1
- 37b8.37bc: supR3HardenedWinIsDesiredRootCA: Adding 0x3401b15e3761c700 C=US, O=VeriSign, Inc., OU=VeriSign Trust Network, OU=(c) 2008 VeriSign, Inc. - For authorized use only, CN=VeriSign Universal Root Certification Authority
- 37b8.37bc: supR3HardenedWinIsDesiredRootCA: Adding 0xc30e361765128000 C=US, ST=New Jersey, L=Jersey City, O=The USERTRUST Network, CN=USERTrust RSA Certification Authority
- 37b8.37bc: supR3HardenedWinIsDesiredRootCA: Adding 0x7b3081c535b843ae C=US, O=Google Trust Services LLC, CN=GTS Root R4
- 37b8.37bc: supR3HardenedWinIsDesiredRootCA: Adding 0x491857ead79dde00 C=US, O=The Go Daddy Group, Inc., OU=Go Daddy Class 2 Certification Authority
- 37b8.37bc: supR3HardenedWinIsDesiredRootCA: Adding 0xdc1801b225aea100 C=BM, O=QuoVadis Limited, CN=QuoVadis Root CA 2 G3
- 37b8.37bc: supR3HardenedWinIsDesiredRootCA: Adding 0xc2ba72a37dfbe300 C=PL, O=Unizeto Technologies S.A., OU=Certum Certification Authority, CN=Certum Trusted Network CA
- 37b8.37bc: supR3HardenedWinIsDesiredRootCA: Adding 0x8043e4ce150ead00 C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Assured ID Root CA
- 37b8.37bc: supR3HardenedWinIsDesiredRootCA: Adding 0xf2e6331af7b700 C=SE, O=AddTrust AB, OU=AddTrust External TTP Network, CN=AddTrust External CA Root
- 37b8.37bc: supR3HardenedWinIsDesiredRootCA: Adding 0xfc891b3fa9f8c200 C=GR, L=Athens, O=Hellenic Academic and Research Institutions Cert. Authority, CN=Hellenic Academic and Research Institutions RootCA 2015
- 37b8.37bc: supR3HardenedWinRetrieveTrustedRootCAs: cAdded=56
- 37b8.37bc: SUPR3HardenedMain: Load Runtime...
- 37b8.37bc: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxRT.dll: Signature #1/2: info status: 24202
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rpcrt4.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ws2_32.dll'.
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxRT.dll) WinVerifyTrust
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxRT.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'rpcrt4.dll'.
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\ws2_32.dll) WinVerifyTrust
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\ws2_32.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll: Signature #1/2: info status: 24202
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll) WinVerifyTrust
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll: Signature #1/2: info status: 24202
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll: Signature #1/2: info status: 24202
- 37b8.37bc: Detected WinVerifyTrust recursion: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll)
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll) WinVerifyTrust
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000a01:<flags> [calling]
- 37b8.37bc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxRT.dll
- 37b8.37bc: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll [avoiding WinVerifyTrust]
- 37b8.37bc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 000000006cda0000 LB 0x000d2000 C:\Program Files\Oracle\VirtualBox\MSVCR100.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll [avoiding WinVerifyTrust]
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 000000006c790000 LB 0x00098000 C:\Program Files\Oracle\VirtualBox\MSVCP100.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffab91b0000 LB 0x0006f000 C:\Windows\System32\WS2_32.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ws2_32.dll
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffa6ad30000 LB 0x005ec000 C:\Program Files\Oracle\VirtualBox\VBoxRT.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxRT.dll
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxRT.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa6ad30000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxRT.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa6ad30000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxRT.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa6ad30000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxRT.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa6ad30000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxRT.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa6ad30000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxRT.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa6ad30000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa6ad30000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa6ad30000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa6ad30000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa6ad30000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa6ad30000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa6ad30000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa6ad30000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxRT.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa6ad30000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa6ad30000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa6ad30000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa6ad30000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa6ad30000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa6ad30000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa6ad30000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa6ad30000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa6ad30000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa6ad30000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa6ad30000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa6ad30000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa6ad30000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa6ad30000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa6ad30000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa6ad30000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxRT.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxRT.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa6ad30000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa6ad30000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa6ad30000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rescheduled]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa6ad30000 'C:\Program Files\Oracle\VirtualBox\VBoxRT.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 24202) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll'
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wintrust.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab68b0000 'C:\Windows\system32\Wintrust.dll'
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\system32\crypt32.dll'
- 37b8.37bc: SUPR3HardenedMain: Load TrustedMain...
- 37b8.37bc: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll: Signature #1/2: info status: 24202
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'opengl32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'uicommon.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcp100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'qt5corevbox.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'qt5guivbox.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'qt5widgetsvbox.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'qt5openglvbox.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'user32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #11 'ole32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #12 'oleaut32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #13 'winmm.dll'.
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll) WinVerifyTrust
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume3\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\winmm.dll) WinVerifyTrust
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\winmm.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume3\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'combase.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'rpcrt4.dll'.
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\oleaut32.dll) WinVerifyTrust
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\oleaut32.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume3\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\combase.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'rpcrt4.dll'.
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\combase.dll)
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\combase.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll'.
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll)
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\msvcp_win.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #45 'gdi32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #46 'user32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #47 'combase.dll'.
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\ole32.dll) WinVerifyTrust
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\ole32.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume3\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\combase.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\user32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'win32u.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #38 'gdi32.dll'.
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\user32.dll)
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\user32.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'win32u.dll'.
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\gdi32.dll)
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\gdi32.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcp_win.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\win32u.dll'.
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\win32u.dll)
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\win32u.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\win32u.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'win32u.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #38 'gdi32.dll'.
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\user32.dll) WinVerifyTrust
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5openglvbox.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5openglvbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5openglvbox.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll: Signature #1/2: info status: 24202
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\win32u.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'qt5widgetsvbox.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'qt5guivbox.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5corevbox.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'msvcr100.dll'.
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll) WinVerifyTrust
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll: Signature #1/2: info status: 24202
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll: Signature #1/2: info status: 24202
- 37b8.37bc: Detected WinVerifyTrust recursion: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'shell32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ole32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ws2_32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'mpr.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'msvcp100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'msvcr100.dll'.
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll)
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll: Signature #1/2: info status: 24202
- 37b8.37bc: Detected WinVerifyTrust recursion: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'ole32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'opengl32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'gdi32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qt5corevbox.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcp100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msvcr100.dll'.
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll)
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll: Signature #1/2: info status: 24202
- 37b8.37bc: Detected WinVerifyTrust recursion: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5guivbox.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qt5corevbox.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'shell32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcp100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msvcr100.dll'.
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 24202 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll)
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume3\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\shell32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #71 'user32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #73 'gdi32.dll'.
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\shell32.dll)
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\shell32.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\user32.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\user32.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume3\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume3\Windows\System32\opengl32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'advapi32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'gdi32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'glu32.dll'.
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\opengl32.dll)
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\opengl32.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ole32.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'mpr.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'mpr.dll' -> '\Device\HarddiskVolume3\Windows\System32\mpr.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: Detected WinVerifyTrust recursion: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\mpr.dll'.
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\mpr.dll)
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\mpr.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ws2_32.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\advapi32.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ole32.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume3\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\shell32.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\user32.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'glu32.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'glu32.dll' -> '\Device\HarddiskVolume3\Windows\System32\glu32.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: Detected WinVerifyTrust recursion: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume3\Windows\System32\glu32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'opengl32.dll'.
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\glu32.dll)
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\glu32.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\user32.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\advapi32.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\user32.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcp_win.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume3\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\opengl32.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\user32.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'user32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5guivbox.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qt5corevbox.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'shell32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'msvcp100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'msvcr100.dll'.
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll) WinVerifyTrust
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll [redoing WinVerifyTrust]
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume3\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\shell32.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\user32.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedScreenImage/Imports: 0 (was 24202) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [redoing WinVerifyTrust]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedScreenImage/Imports: 0 (was 24202) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'uicommon.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'uicommon.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\uicommon.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\UICommon.dll: Signature #1/2: info status: 24202
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'vboxrt.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcr100.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'qt5corevbox.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'qt5guivbox.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'qt5widgetsvbox.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'advapi32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'ole32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'oleaut32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'rpcrt4.dll'.
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\UICommon.dll) WinVerifyTrust
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\UICommon.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'opengl32.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'opengl32.dll' -> '\Device\HarddiskVolume3\Windows\System32\opengl32.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\opengl32.dll [redoing WinVerifyTrust]
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000001e8 pwszName=\Device\HarddiskVolume3\Windows\System32\opengl32.dll
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000001236bc0
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000001236bc0
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2D524BD25A743CA0A9032840CDC536A92793110A
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume3\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\oleaut32.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ole32.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\advapi32.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\user32.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5widgetsvbox.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5widgetsvbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5widgetsvbox.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll [lacks WinVerifyTrust]
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-OpenGL-Package~31bf3856ad364e35~amd64~~10.0.22000.708.cat'; file='\Device\HarddiskVolume3\Windows\System32\opengl32.dll'
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 37b8.37bc: supR3HardenedScreenImage/Imports: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\opengl32.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000a01:<flags> [calling]
- 37b8.37bc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll
- 37b8.37bc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\opengl32.dll
- 37b8.37bc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\UICommon.dll
- 37b8.37bc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
- 37b8.37bc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
- 37b8.37bc: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll [avoiding WinVerifyTrust]
- 37b8.37bc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll
- 37b8.37bc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winmm.dll
- 37b8.37bc: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\glu32.dll [avoiding WinVerifyTrust]
- 37b8.37bc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\mpr.dll [avoiding WinVerifyTrust]
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'win32u.dll'.
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\DXCore.dll)
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\DXCore.dll
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffab6ee0000 LB 0x00026000 C:\Windows\System32\win32u.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\win32u.dll [avoiding WinVerifyTrust]
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffab6d20000 LB 0x0009d000 C:\Windows\System32\msvcp_win.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcp_win.dll [avoiding WinVerifyTrust]
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffab6f10000 LB 0x00112000 C:\Windows\System32\gdi32full.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #35 'gdi32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #37 'user32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #38 'win32u.dll'.
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\gdi32full.dll)
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\gdi32full.dll
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffab7ed0000 LB 0x00029000 C:\Windows\System32\GDI32.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [avoiding WinVerifyTrust]
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffab71a0000 LB 0x001ac000 C:\Windows\System32\USER32.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\user32.dll [avoiding WinVerifyTrust]
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffab7350000 LB 0x00379000 C:\Windows\System32\combase.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\combase.dll [avoiding WinVerifyTrust]
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffaafe60000 LB 0x00038000 C:\Windows\SYSTEM32\dxcore.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\DXCore.dll [avoiding WinVerifyTrust]
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffa7a3a0000 LB 0x0002d000 C:\Windows\SYSTEM32\GLU32.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume3\Windows\System32\glu32.dll [avoiding WinVerifyTrust]
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffa79bf0000 LB 0x00101000 C:\Windows\SYSTEM32\OPENGL32.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\opengl32.dll
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffab85e0000 LB 0x007b8000 C:\Windows\System32\SHELL32.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\shell32.dll [avoiding WinVerifyTrust]
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffab8da0000 LB 0x0019a000 C:\Windows\System32\ole32.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ole32.dll
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffa8c1b0000 LB 0x0001d000 C:\Windows\SYSTEM32\MPR.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\mpr.dll [avoiding WinVerifyTrust]
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 000000006c830000 LB 0x00565000 C:\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffa6a730000 LB 0x005f7000 C:\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 000000006c220000 LB 0x00561000 C:\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 24202 (0x5e8a)) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll [avoiding WinVerifyTrust]
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffab8500000 LB 0x000d6000 C:\Windows\System32\OLEAUT32.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\oleaut32.dll
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffa604f0000 LB 0x02320000 C:\Program Files\Oracle\VirtualBox\UICommon.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\UICommon.dll
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 000000006c1c0000 LB 0x00054000 C:\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5OpenGLVBox.dll
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffaafab0000 LB 0x00033000 C:\Windows\SYSTEM32\WINMM.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winmm.dll
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffa69f70000 LB 0x001c9000 C:\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\DXCore.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\DXCore.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume3\Windows\System32\glu32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\glu32.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\mpr.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\mpr.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\shell32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\shell32.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\win32u.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\user32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\combase.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\combase.dll' [rescheduled]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\kernel32.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\win32u.dll [redoing WinVerifyTrust]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\win32u.dll'.
- 37b8.37bc: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume3\Windows\System32\win32u.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\user32.dll [redoing WinVerifyTrust]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\user32.dll'.
- 37b8.37bc: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume3\Windows\System32\user32.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\gdi32.dll [redoing WinVerifyTrust]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32.dll'.
- 37b8.37bc: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume3\Windows\System32\gdi32.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcp_win.dll [redoing WinVerifyTrust]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll'.
- 37b8.37bc: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume3\Windows\System32\msvcp_win.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\win32u.dll [redoing WinVerifyTrust]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\win32u.dll'.
- 37b8.37bc: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume3\Windows\System32\win32u.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcp_win.dll [redoing WinVerifyTrust]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll'.
- 37b8.37bc: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume3\Windows\System32\msvcp_win.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\kernel32.dll (Input=kernel32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab7880000 'C:\Windows\System32\kernel32.dll'
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\DXCore.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\DXCore.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume3\Windows\System32\glu32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\glu32.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\mpr.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\mpr.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\shell32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\shell32.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\win32u.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\user32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\combase.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\combase.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\DXCore.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\DXCore.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume3\Windows\System32\glu32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\glu32.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\mpr.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\mpr.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\shell32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\shell32.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\win32u.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\user32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\combase.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\combase.dll' [rescheduled]
- 37b8.37bc: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-string-l1-1-0) -> 0x0, fPresent=1
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-string-l1-1-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab69a0000 'api-ms-win-core-string-l1-1-0'
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\DXCore.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\DXCore.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume3\Windows\System32\glu32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\glu32.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\mpr.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\mpr.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\shell32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\shell32.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\win32u.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\user32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\combase.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\combase.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\DXCore.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\DXCore.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume3\Windows\System32\glu32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\glu32.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\mpr.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\mpr.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\shell32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\shell32.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\win32u.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\user32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\combase.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\combase.dll' [rescheduled]
- 37b8.37bc: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-datetime-l1-1-1) -> 0x0, fPresent=1
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-datetime-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab69a0000 'api-ms-win-core-datetime-l1-1-1'
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\DXCore.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\DXCore.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume3\Windows\System32\glu32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\glu32.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\mpr.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\mpr.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\shell32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\shell32.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\win32u.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\user32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\combase.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\combase.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\DXCore.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\DXCore.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume3\Windows\System32\glu32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\glu32.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\mpr.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\mpr.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\shell32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\shell32.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\win32u.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\user32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\combase.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\combase.dll' [rescheduled]
- 37b8.37bc: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-obsolete-l1-2-0) -> 0x0, fPresent=1
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-obsolete-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab69a0000 'api-ms-win-core-localization-obsolete-l1-2-0'
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\DXCore.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\DXCore.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume3\Windows\System32\glu32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\glu32.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\mpr.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\mpr.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\shell32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\shell32.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\win32u.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\user32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\combase.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\combase.dll' [rescheduled]
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #26 'win32u.dll'.
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\imm32.dll)
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\imm32.dll
- 37b8.37bc: supR3HardenedMonitor_NtCreateSection: NtMapViewOfSection failed on 0000000000000570 (hFile=0000000000000540) with 0xc0000022 -> STATUS_TRUST_FAILURE
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\imm32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\imm32.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\DXCore.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\DXCore.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume3\Windows\System32\glu32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\glu32.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\mpr.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\mpr.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\shell32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\shell32.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\win32u.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\user32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\combase.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\combase.dll' [rescheduled]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\imm32.dll [redoing WinVerifyTrust]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\imm32.dll'.
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume3\Windows\System32\imm32.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'win32u.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'win32u.dll' -> '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\win32u.dll [redoing WinVerifyTrust]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\win32u.dll'.
- 37b8.37bc: supR3HardenedScreenImage/Imports: WinVerifyTrust not available, rescheduling \Device\HarddiskVolume3\Windows\System32\win32u.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\IMM32.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffab8020000 LB 0x00031000 C:\Windows\System32\IMM32.DLL [fFlags=0x0]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\imm32.dll [avoiding WinVerifyTrust]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab8020000 'C:\Windows\system32\IMM32.DLL'
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\imm32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\imm32.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\DXCore.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\DXCore.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume3\Windows\System32\glu32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\glu32.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\mpr.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\mpr.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\shell32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\shell32.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\win32u.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\user32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\combase.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\combase.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\imm32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\imm32.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\DXCore.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\DXCore.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume3\Windows\System32\glu32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\glu32.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\mpr.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\mpr.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\shell32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\shell32.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\win32u.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\user32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\combase.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\combase.dll' [rescheduled]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\advapi32.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\ADVAPI32.DLL (Input=ADVAPI32.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab90e0000 'C:\Windows\System32\ADVAPI32.DLL'
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\imm32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\imm32.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\DXCore.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\DXCore.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 22900 (0x5974) '\Device\HarddiskVolume3\Windows\System32\glu32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 22900 (was 22900) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\glu32.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\mpr.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\mpr.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\shell32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\shell32.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=Unknown Status 24202 (0x5e8a) '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 24202 (was 24202) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\win32u.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\win32u.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\gdi32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\user32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rescheduled]
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\combase.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\combase.dll' [rescheduled]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa69f70000 'C:\Program Files\Oracle\VirtualBox\VirtualBoxVM.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\imm32.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\gdi32full.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\DXCore.dll'
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000004f4 pwszName=\Device\HarddiskVolume3\Windows\System32\glu32.dll
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000001236bc0
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000001236bc0
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=AA7DC3A3EEA8D84E88346437F6D9D5DF9B3C090B
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-OpenGL-Package~31bf3856ad364e35~amd64~~10.0.22000.708.cat'; file='\Device\HarddiskVolume3\Windows\System32\glu32.dll'
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\glu32.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\mpr.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\shell32.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 24202) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5WidgetsVBox.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\win32u.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\gdi32.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\user32.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\combase.dll'
- 37b8.37bc: SUPR3HardenedMain: Calling TrustedMain (00007ffa69f716c0)...
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #31 'combase.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #32 'msvcp_win.dll'.
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\windows.storage.dll)
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\windows.storage.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'combase.dll'.
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\WinTypes.dll)
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\WinTypes.dll
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffab46d0000 LB 0x00166000 C:\Windows\SYSTEM32\wintypes.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\WinTypes.dll [avoiding WinVerifyTrust]
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffab4840000 LB 0x00867000 C:\Windows\SYSTEM32\windows.storage.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\windows.storage.dll [avoiding WinVerifyTrust]
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffab8300000 LB 0x000ea000 C:\Windows\System32\SHCORE.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\SHCore.dll)
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\SHCore.dll
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffab76d0000 LB 0x0005d000 C:\Windows\System32\shlwapi.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcrt.dll'.
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\shlwapi.dll)
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\shlwapi.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcp_win.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume3\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\combase.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcp_win.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume3\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\combase.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\shlwapi.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\SHCore.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\WinTypes.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\windows.storage.dll'
- 37b8.37bc: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\platforms\qwindows.dll: Signature #1/2: info status: 24202
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'gdi32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'ole32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'user32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'imm32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'winmm.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'oleaut32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'shell32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'advapi32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'qt5guivbox.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'qt5corevbox.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'msvcr100.dll'.
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\platforms\qwindows.dll) WinVerifyTrust
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\platforms\qwindows.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5corevbox.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5corevbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5corevbox.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5CoreVBox.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'qt5guivbox.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'qt5guivbox.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\qt5guivbox.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\Qt5GuiVBox.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\advapi32.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume3\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\shell32.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume3\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\oleaut32.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winmm.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'winmm.dll' -> '\Device\HarddiskVolume3\Windows\System32\winmm.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winmm.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'imm32.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'imm32.dll' -> '\Device\HarddiskVolume3\Windows\System32\imm32.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\imm32.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ole32.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\platforms\qwindows.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\platforms\qwindows.dll
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffa6a600000 LB 0x0012e000 C:\Program Files\Oracle\VirtualBox\platforms\qwindows.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\platforms\qwindows.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa6a600000 'C:\Program Files\Oracle\VirtualBox\platforms\qwindows.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'rpcrt4.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #38 'bcryptprimitives.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #51 'combase.dll'.
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume3\Windows\System32\rpcss.dll)
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\rpcss.dll
- 37b8.37bc: supR3HardenedMonitor_NtCreateSection: NtMapViewOfSection failed on 0000000000000664 (hFile=000000000000065c) with 0xc0000022 -> STATUS_TRUST_FAILURE
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'msvcrt.dll'.
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\kernel.appcore.dll)
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\kernel.appcore.dll
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffab58f0000 LB 0x00018000 C:\Windows\SYSTEM32\kernel.appcore.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\kernel.appcore.dll [avoiding WinVerifyTrust]
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume3\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\combase.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'bcryptprimitives.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'bcryptprimitives.dll' -> '\Device\HarddiskVolume3\Windows\System32\bcryptprimitives.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\bcryptprimitives.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\kernel.appcore.dll'
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=000000000000061c pwszName=\Device\HarddiskVolume3\Windows\System32\rpcss.dll
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000001236bc0
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000001236bc0
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=6F8588C53CF005F56300DEE3FD5DAA315FCB234C
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0415~31bf3856ad364e35~amd64~~10.0.22000.795.cat'; file='\Device\HarddiskVolume3\Windows\System32\rpcss.dll'
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 22900) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\rpcss.dll'
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000006c0 pwszName=\Device\HarddiskVolume3\Windows\System32\uxtheme.dll
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000001236bc0
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000001236bc0
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=61274C2BDE408C67C424C4C13D53130AFD0B246D
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rsaenh.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\rsaenh.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0410~31bf3856ad364e35~amd64~~10.0.22000.675.cat'; file='\Device\HarddiskVolume3\Windows\System32\uxtheme.dll'
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #40 'gdi32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #41 'user32.dll'.
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\uxtheme.dll) WinVerifyTrust
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\uxtheme.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'gdi32.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'gdi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\gdi32.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
- 37b8.37bc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\uxtheme.dll
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffaaf8e0000 LB 0x000ac000 C:\Windows\system32\uxtheme.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\uxtheme.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaaf8e0000 'C:\Windows\system32\uxtheme.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab71a0000 'C:\Windows\system32\user32.dll'
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\shell32.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab85e0000 'C:\Windows\system32\shell32.dll'
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\SHCore.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\SHCore.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab8300000 'C:\Windows\system32\SHCore.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: error opening 'C:\Windows\system32\wintab32.dll': 0 (NtPath=\??\C:\Windows\system32\wintab32.dll; Input=C:\Windows\system32\wintab32.dll; rcNtGetDll=0x0
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc0000034 'C:\Windows\system32\wintab32.dll'
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winmm.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\winmm.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaafab0000 'C:\Windows\system32\winmm.dll'
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winmm.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\winmm.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaafab0000 'C:\Windows\system32\winmm.dll'
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\shell32.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab85e0000 'C:\Windows\system32\shell32.dll'
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\uxtheme.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\uxtheme.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaaf8e0000 'C:\Windows\system32\uxtheme.dll'
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\advapi32.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\advapi32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab90e0000 'C:\Windows\system32\advapi32.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #15 'rpcrt4.dll'.
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\userenv.dll) WinVerifyTrust
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\userenv.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\userenv.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\userenv.dll
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffab5db0000 LB 0x00029000 C:\Windows\system32\userenv.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\userenv.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5db0000 'C:\Windows\system32\userenv.dll'
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\kernel32.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\kernel32.dll (Input=kernel32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab7880000 'C:\Windows\System32\kernel32.dll'
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffab70f0000 LB 0x000af000 C:\Windows\System32\clbcatq.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #30 'rpcrt4.dll'.
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\clbcatq.dll)
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\clbcatq.dll
- 37b8.37bc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rpcss.dll
- 37b8.37bc: supR3HardenedMonitor_NtCreateSection: NtMapViewOfSection failed on 00000000000004d0 (hFile=0000000000000410) with 0xc0000022 -> STATUS_TRUST_FAILURE
- 37b8.5c88: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 37b8.5c88: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 37b8.5c88: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 37b8.5c88: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 37b8.5c88: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.5c88: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.5c88: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\clbcatq.dll'
- 37b8.5c88: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxC.dll: Signature #1/2: info status: 24202
- 37b8.5c88: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.5c88: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
- 37b8.5c88: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
- 37b8.5c88: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
- 37b8.5c88: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'advapi32.dll'.
- 37b8.5c88: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ole32.dll'.
- 37b8.5c88: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'oleaut32.dll'.
- 37b8.5c88: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxC.dll) WinVerifyTrust
- 37b8.5c88: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxC.dll
- 37b8.5c88: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
- 37b8.5c88: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume3\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
- 37b8.5c88: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\oleaut32.dll
- 37b8.5c88: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
- 37b8.5c88: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
- 37b8.5c88: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ole32.dll
- 37b8.5c88: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
- 37b8.5c88: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
- 37b8.5c88: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\advapi32.dll
- 37b8.5c88: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
- 37b8.5c88: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
- 37b8.5c88: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
- 37b8.5c88: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
- 37b8.5c88: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll
- 37b8.5c88: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
- 37b8.5c88: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
- 37b8.5c88: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxC.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
- 37b8.5c88: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxC.dll
- 37b8.5c88: supR3HardenedDllNotificationCallback: load 00007ffa6a140000 LB 0x003c2000 C:\Program Files\Oracle\VirtualBox\VBoxC.dll [fFlags=0x0]
- 37b8.5c88: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxC.dll
- 37b8.5c88: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa6a140000 'C:\Program Files\Oracle\VirtualBox\VBoxC.dll'
- 37b8.5c88: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll: Signature #1/2: info status: 24202
- 37b8.5c88: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.5c88: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
- 37b8.5c88: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
- 37b8.5c88: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'advapi32.dll'.
- 37b8.5c88: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'shlwapi.dll'.
- 37b8.5c88: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'ole32.dll'.
- 37b8.5c88: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'oleaut32.dll'.
- 37b8.5c88: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'rpcrt4.dll'.
- 37b8.5c88: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll) WinVerifyTrust
- 37b8.5c88: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll
- 37b8.5c88: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 37b8.5c88: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 37b8.5c88: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
- 37b8.5c88: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume3\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
- 37b8.5c88: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\oleaut32.dll
- 37b8.5c88: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
- 37b8.5c88: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
- 37b8.5c88: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ole32.dll
- 37b8.5c88: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
- 37b8.5c88: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
- 37b8.5c88: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\shlwapi.dll
- 37b8.5c88: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
- 37b8.5c88: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
- 37b8.5c88: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\advapi32.dll
- 37b8.5c88: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
- 37b8.5c88: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
- 37b8.5c88: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
- 37b8.5c88: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
- 37b8.5c88: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
- 37b8.5c88: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll
- 37b8.5c88: supR3HardenedDllNotificationCallback: load 00007ffa6a510000 LB 0x000ef000 C:\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll [fFlags=0x0]
- 37b8.5c88: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll
- 37b8.5c88: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa6a510000 'C:\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll'
- 37b8.5c88: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\oleaut32.dll
- 37b8.5c88: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\oleaut32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
- 37b8.5c88: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab8500000 'C:\Windows\System32\oleaut32.dll'
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000007c0 pwszName=\Device\HarddiskVolume3\Windows\System32\DWrite.dll
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000001236bc0
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000001236bc0
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=8AE5D5BE47C4C094784D740DD813A46A9A210B4C
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-OneCore-Graphics-DirectX-Package~31bf3856ad364e35~amd64~~10.0.22000.653.cat'; file='\Device\HarddiskVolume3\Windows\System32\DWrite.dll'
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'rpcrt4.dll'.
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\DWrite.dll) WinVerifyTrust
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\DWrite.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\dwrite.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\DWrite.dll
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffa96340000 LB 0x0025f000 C:\Windows\system32\dwrite.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\DWrite.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa96340000 'C:\Windows\system32\dwrite.dll'
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\shell32.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab85e0000 'C:\Windows\system32\shell32.dll'
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffab7db0000 LB 0x0011e000 C:\Windows\System32\MSCTF.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\msctf.dll)
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\msctf.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\msctf.dll'
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=00000000000009bc pwszName=\Device\HarddiskVolume3\Windows\System32\DataExchange.dll
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000001236bc0
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000001236bc0
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=101A03863CE4DE896B456ABD0FCE21AF048BCA12
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-OneCore-AppRuntime-merged-Package~31bf3856ad364e35~amd64~~10.0.22000.795.cat'; file='\Device\HarddiskVolume3\Windows\System32\DataExchange.dll'
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #27 'msvcp_win.dll'.
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\DataExchange.dll) WinVerifyTrust
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\DataExchange.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcp_win.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\dataexchange.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
- 37b8.37bc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\DataExchange.dll
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffa75d20000 LB 0x0005d000 C:\Windows\system32\dataexchange.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\DataExchange.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa75d20000 'C:\Windows\system32\dataexchange.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #40 'combase.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #42 'msvcp_win.dll'.
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\twinapi.appcore.dll)
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\twinapi.appcore.dll
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffaa90a0000 LB 0x00266000 C:\Windows\system32\twinapi.appcore.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\twinapi.appcore.dll [avoiding WinVerifyTrust]
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'combase.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'combase.dll' -> '\Device\HarddiskVolume3\Windows\System32\combase.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\combase.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\twinapi.appcore.dll'
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\SHCore.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\Shcore.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab8300000 'C:\Windows\system32\Shcore.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'oleaut32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'rpcrt4.dll'.
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\TextInputFramework.dll)
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\TextInputFramework.dll
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffaa4b90000 LB 0x0012d000 C:\Windows\SYSTEM32\textinputframework.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\TextInputFramework.dll [avoiding WinVerifyTrust]
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'msvcp_win.dll'.
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\CoreMessaging.dll)
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\CoreMessaging.dll
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffaaf4f0000 LB 0x00132000 C:\Windows\SYSTEM32\CoreMessaging.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\CoreMessaging.dll [avoiding WinVerifyTrust]
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume3\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\oleaut32.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\CoreMessaging.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\TextInputFramework.dll'
- 37b8.37bc: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-security-sddl-l1-1-0.dll) -> 0x0, fPresent=1
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-security-sddl-l1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab9040000 'api-ms-win-security-sddl-l1-1-0.dll'
- 37b8.37bc: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(ext-ms-win-rtcore-ntuser-window-ext-l1-1-0.dll) -> 0x0, fPresent=1
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=ext-ms-win-rtcore-ntuser-window-ext-l1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab71a0000 'ext-ms-win-rtcore-ntuser-window-ext-l1-1-0.dll'
- 37b8.37bc: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(ext-ms-win-rtcore-ntuser-integration-l1-1-0.dll) -> 0x0, fPresent=1
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=ext-ms-win-rtcore-ntuser-integration-l1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab71a0000 'ext-ms-win-rtcore-ntuser-integration-l1-1-0.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #33 'coremessaging.dll'.
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\CoreUIComponents.dll)
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\CoreUIComponents.dll
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffaaacc0000 LB 0x0036d000 C:\Windows\SYSTEM32\CoreUIComponents.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\CoreUIComponents.dll [avoiding WinVerifyTrust]
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'coremessaging.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'coremessaging.dll' -> '\Device\HarddiskVolume3\Windows\System32\coremessaging.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\CoreMessaging.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\CoreUIComponents.dll'
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\RPCRT4.dll (Input=RPCRT4.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab7760000 'C:\Windows\System32\RPCRT4.dll'
- 37b8.37bc: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-security-systemfunctions-l1-1-0) -> 0x0, fPresent=1
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-security-systemfunctions-l1-1-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab90e0000 'api-ms-win-security-systemfunctions-l1-1-0'
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msctf.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\MSCTF.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab7db0000 'C:\Windows\System32\MSCTF.dll'
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\shell32.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab85e0000 'C:\Windows\system32\shell32.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab85e0000 'C:\Windows\system32\shell32.dll'
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ole32.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\ole32.dll (Input=ole32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab8da0000 'C:\Windows\System32\ole32.dll'
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\oleaut32.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\OLEAUT32.dll (Input=OLEAUT32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab8500000 'C:\Windows\System32\OLEAUT32.dll'
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000ac0 pwszName=\Device\HarddiskVolume3\Windows\System32\wbem\wbemprox.dll
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000001236bc0
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000001236bc0
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=72A7777E2E42F8ED9F54E831EF23DA9E1E18ED1C
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0410~31bf3856ad364e35~amd64~~10.0.22000.675.cat'; file='\Device\HarddiskVolume3\Windows\System32\wbem\wbemprox.dll'
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #16 'wbemcomn.dll'.
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\wbem\wbemprox.dll) WinVerifyTrust
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\wbem\wbemprox.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wbemcomn.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'wbemcomn.dll' -> '\Device\HarddiskVolume3\Windows\System32\wbemcomn.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000ac4 pwszName=\Device\HarddiskVolume3\Windows\System32\wbemcomn.dll
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000001236bc0
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000001236bc0
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=45A464176830F0AA8063DB542765DA4B4DCE6F9E
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0410~31bf3856ad364e35~amd64~~10.0.22000.675.cat'; file='\Device\HarddiskVolume3\Windows\System32\wbemcomn.dll'
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\wbemcomn.dll) WinVerifyTrust
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\wbemcomn.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wbem\wbemprox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
- 37b8.37bc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wbem\wbemprox.dll
- 37b8.37bc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wbemcomn.dll
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffa9ac60000 LB 0x00082000 C:\Windows\SYSTEM32\wbemcomn.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wbemcomn.dll
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffaa4db0000 LB 0x00010000 C:\Windows\system32\wbem\wbemprox.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wbem\wbemprox.dll
- 37b8.37bc: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(API-MS-Win-Core-LocalRegistry-L1-1-0.dll) -> 0x0, fPresent=1
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=API-MS-Win-Core-LocalRegistry-L1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab69a0000 'API-MS-Win-Core-LocalRegistry-L1-1-0.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa4db0000 'C:\Windows\system32\wbem\wbemprox.dll'
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000ad4 pwszName=\Device\HarddiskVolume3\Windows\System32\wbem\wbemsvc.dll
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000001236bc0
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000001236bc0
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=3B9E6574CB33BE95DDDFC06987443AD17F741154
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\crypt32.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\crypt32.dll (Input=crypt32.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0410~31bf3856ad364e35~amd64~~10.0.22000.675.cat'; file='\Device\HarddiskVolume3\Windows\System32\wbem\wbemsvc.dll'
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'rpcrt4.dll'.
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\wbem\wbemsvc.dll) WinVerifyTrust
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\wbem\wbemsvc.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wbem\wbemsvc.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
- 37b8.37bc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wbem\wbemsvc.dll
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffa9a250000 LB 0x00014000 C:\Windows\system32\wbem\wbemsvc.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wbem\wbemsvc.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa9a250000 'C:\Windows\system32\wbem\wbemsvc.dll'
- 37b8.37bc: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-l1-2-0.dll) -> 0x0, fPresent=1
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-l1-2-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab69a0000 'api-ms-win-core-localization-l1-2-0.dll'
- 37b8.37bc: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-obsolete-l1-1-0.dll) -> 0x0, fPresent=1
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-obsolete-l1-1-0.dll (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab69a0000 'api-ms-win-core-localization-obsolete-l1-1-0.dll'
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000ad0 pwszName=\Device\HarddiskVolume3\Windows\System32\wbem\fastprox.dll
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000001236bc0
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000001236bc0
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=C006C9BBF3712859F7F5F20A758C570A45C51802
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0410~31bf3856ad364e35~amd64~~10.0.22000.675.cat'; file='\Device\HarddiskVolume3\Windows\System32\wbem\fastprox.dll'
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #20 'wbemcomn.dll'.
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\wbem\fastprox.dll) WinVerifyTrust
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\wbem\fastprox.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wbemcomn.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'wbemcomn.dll' -> '\Device\HarddiskVolume3\Windows\System32\wbemcomn.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wbemcomn.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\wbem\fastprox.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
- 37b8.37bc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wbem\fastprox.dll
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffa94a40000 LB 0x000fa000 C:\Windows\system32\wbem\fastprox.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wbem\fastprox.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa94a40000 'C:\Windows\system32\wbem\fastprox.dll'
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000b18 pwszName=\Device\HarddiskVolume3\Windows\System32\amsi.dll
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000001236bc0
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000001236bc0
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=2B275E46A4D44743A2E7B3BD101381367F8671AE
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package04~31bf3856ad364e35~amd64~~10.0.22000.795.cat'; file='\Device\HarddiskVolume3\Windows\System32\amsi.dll'
- 37b8.37bc: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #14 'rpcrt4.dll'.
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\amsi.dll) WinVerifyTrust
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\amsi.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\amsi.dll (Input=amsi.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 37b8.37bc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\amsi.dll
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffa969d0000 LB 0x00025000 C:\Windows\System32\amsi.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\amsi.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa969d0000 'C:\Windows\System32\amsi.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'advapi32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'ole32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'oleaut32.dll'.
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.2205.7-0\MpOAV.dll) WinVerifyTrust
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.2205.7-0\MpOAV.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume3\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2205.7-0\MpOav.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.2205.7-0\MpOAV.dll
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffa93be0000 LB 0x0007b000 C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2205.7-0\MpOav.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\ProgramData\Microsoft\Windows Defender\Platform\4.18.2205.7-0\MpOAV.dll
- 37b8.37bc: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab69a0000 'api-ms-win-core-synch-l1-2-0'
- 37b8.37bc: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-l1-2-1) -> 0x0, fPresent=1
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-l1-2-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab69a0000 'api-ms-win-core-localization-l1-2-1'
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\kernel32.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\kernel32.dll (Input=kernel32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab7880000 'C:\Windows\System32\kernel32.dll'
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\version.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\version.dll)
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\version.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\version.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
- 37b8.37bc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\version.dll [avoiding WinVerifyTrust]
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffaacf80000 LB 0x0000a000 C:\Windows\system32\version.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\version.dll [avoiding WinVerifyTrust]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaacf80000 'C:\Windows\system32\version.dll'
- 37b8.37bc: Detected loader lock ownership: rc=VINF_SUCCESS '\Device\HarddiskVolume3\Windows\System32\version.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=0 for '\Device\HarddiskVolume3\Windows\System32\version.dll' [rescheduled]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa93be0000 'C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2205.7-0\MpOav.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\version.dll'
- 37b8.37bc: \Device\HarddiskVolume3\Program Files\McAfee\MfeAV\AMSIExt.dll: Owner is administrators group.
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'psapi.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'oleaut32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'ole32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'user32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'advapi32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'shlwapi.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'shell32.dll'.
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\McAfee\MfeAV\AMSIExt.dll) WinVerifyTrust
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\McAfee\MfeAV\AMSIExt.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shell32.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'shell32.dll' -> '\Device\HarddiskVolume3\Windows\System32\shell32.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'shlwapi.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'shlwapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\shlwapi.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\shlwapi.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume3\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'psapi.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'psapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\psapi.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\psapi.dll) WinVerifyTrust
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\psapi.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\McAfee\MfeAV\AMSIExt.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\McAfee\MfeAV\AMSIExt.dll
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffab7750000 LB 0x00008000 C:\Windows\System32\PSAPI.DLL [fFlags=0x0]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\psapi.dll
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffa93af0000 LB 0x000ea000 C:\Program Files\McAfee\MfeAV\AMSIExt.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\McAfee\MfeAV\AMSIExt.dll
- 37b8.37bc: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab69a0000 'api-ms-win-core-synch-l1-2-0'
- 37b8.37bc: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-fibers-l1-1-1) -> 0x0, fPresent=1
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab69a0000 'api-ms-win-core-fibers-l1-1-1'
- 37b8.37bc: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab69a0000 'api-ms-win-core-synch-l1-2-0'
- 37b8.37bc: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-fibers-l1-1-1) -> 0x0, fPresent=1
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab69a0000 'api-ms-win-core-fibers-l1-1-1'
- 37b8.37bc: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-l1-2-1) -> 0x0, fPresent=1
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-l1-2-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab69a0000 'api-ms-win-core-localization-l1-2-1'
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\kernel32.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\kernel32.dll (Input=kernel32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab7880000 'C:\Windows\System32\kernel32.dll'
- 37b8.37bc: Error (rc=0):
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: rejecting UNC name '\\?\C:\Windows\System32\version.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0xc00000fb
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\version.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\version.dll (Input=version.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaacf80000 'C:\Windows\System32\version.dll'
- 37b8.37bc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\McAfee\MfeAV\AMSIExt.dll
- 37b8.37bc: supR3HardenedMonitor_NtCreateSection: NtMapViewOfSection failed on 0000000000000bc0 (hFile=0000000000000bbc) with 0xc0000022 -> STATUS_TRUST_FAILURE
- 37b8.37bc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\McAfee\MfeAV\AMSIExt.dll
- 37b8.37bc: supR3HardenedMonitor_NtCreateSection: NtMapViewOfSection failed on 0000000000000bc0 (hFile=0000000000000bbc) with 0xc0000022 -> STATUS_TRUST_FAILURE
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa93af0000 'C:\Program Files\McAfee\MfeAV\AMSIExt.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: \Device\HarddiskVolume3\Program Files\Common Files\McAfee\SystemCore\mfehida.dll: Owner is administrators group.
- 37b8.37bc: \Device\HarddiskVolume3\Program Files\Common Files\McAfee\SystemCore\mfehida.dll: Signature #3/3: VERR_CR_X509_CPV_NO_TRUSTED_PATHS (-23021) w/ timestamp=0x6144da9f/link.
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'psapi.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'advapi32.dll'.
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'wintrust.dll'.
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Common Files\McAfee\SystemCore\mfehida.dll) WinVerifyTrust
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Common Files\McAfee\SystemCore\mfehida.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'wintrust.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'wintrust.dll' -> '\Device\HarddiskVolume3\Windows\System32\wintrust.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\wintrust.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'psapi.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'psapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\psapi.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\psapi.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Common Files\McAfee\SystemCore\mfehida.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
- 37b8.37bc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Common Files\McAfee\SystemCore\mfehida.dll
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffa9e6f0000 LB 0x0008a000 C:\Program Files\Common Files\McAfee\SystemCore\mfehida.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Common Files\McAfee\SystemCore\mfehida.dll
- 37b8.37bc: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab69a0000 'api-ms-win-core-synch-l1-2-0'
- 37b8.37bc: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-fibers-l1-1-1) -> 0x0, fPresent=1
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab69a0000 'api-ms-win-core-fibers-l1-1-1'
- 37b8.37bc: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab69a0000 'api-ms-win-core-synch-l1-2-0'
- 37b8.37bc: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-fibers-l1-1-1) -> 0x0, fPresent=1
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab69a0000 'api-ms-win-core-fibers-l1-1-1'
- 37b8.37bc: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-l1-2-1) -> 0x0, fPresent=1
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-l1-2-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab69a0000 'api-ms-win-core-localization-l1-2-1'
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\kernel32.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\kernel32.dll (Input=kernel32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab7880000 'C:\Windows\System32\kernel32.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa9e6f0000 'C:\Program Files\Common Files\McAfee\SystemCore\mfehida.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Common Files\McAfee\SystemCore\mfehida.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Common Files\McAfee\SystemCore\mfehida.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa9e6f0000 'C:\Program Files\Common Files\McAfee\SystemCore\mfehida.dll'
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Common Files\McAfee\SystemCore\mfehida.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Common Files\McAfee\SystemCore\mfehida.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa9e6f0000 'C:\Program Files\Common Files\McAfee\SystemCore\mfehida.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab90e0000 'C:\Windows\System32\advapi32.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: \Device\HarddiskVolume3\Program Files\Common Files\McAfee\SystemCore\mfemmsa.dll: Owner is administrators group.
- 37b8.37bc: \Device\HarddiskVolume3\Program Files\Common Files\McAfee\SystemCore\mfemmsa.dll: Signature #3/3: VERR_CR_X509_CPV_NO_TRUSTED_PATHS (-23021) w/ timestamp=0x6144db1a/link.
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.37bc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'advapi32.dll'.
- 37b8.37bc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Common Files\McAfee\SystemCore\mfemmsa.dll) WinVerifyTrust
- 37b8.37bc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Common Files\McAfee\SystemCore\mfemmsa.dll
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
- 37b8.37bc: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Common Files\McAfee\SystemCore\mfemmsa.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
- 37b8.37bc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Common Files\McAfee\SystemCore\mfemmsa.dll
- 37b8.37bc: supR3HardenedDllNotificationCallback: load 00007ffa9a000000 LB 0x000be000 C:\Program Files\Common Files\McAfee\SystemCore\mfemmsa.dll [fFlags=0x0]
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Common Files\McAfee\SystemCore\mfemmsa.dll
- 37b8.37bc: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab69a0000 'api-ms-win-core-synch-l1-2-0'
- 37b8.37bc: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-fibers-l1-1-1) -> 0x0, fPresent=1
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab69a0000 'api-ms-win-core-fibers-l1-1-1'
- 37b8.37bc: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-synch-l1-2-0) -> 0x0, fPresent=1
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-synch-l1-2-0 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab69a0000 'api-ms-win-core-synch-l1-2-0'
- 37b8.37bc: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-fibers-l1-1-1) -> 0x0, fPresent=1
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-fibers-l1-1-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab69a0000 'api-ms-win-core-fibers-l1-1-1'
- 37b8.37bc: supR3HardenedIsApiSetDll: ApiSetQueryApiSetPresence(api-ms-win-core-localization-l1-2-1) -> 0x0, fPresent=1
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=api-ms-win-core-localization-l1-2-1 (rcNtResolve=0x0) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab69a0000 'api-ms-win-core-localization-l1-2-1'
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\kernel32.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\kernel32.dll (Input=kernel32, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab7880000 'C:\Windows\System32\kernel32.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa9a000000 'C:\Program Files\Common Files\McAfee\SystemCore\mfemmsa.dll'
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Common Files\McAfee\SystemCore\mfemmsa.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Common Files\McAfee\SystemCore\mfemmsa.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa9a000000 'C:\Program Files\Common Files\McAfee\SystemCore\mfemmsa.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab90e0000 'C:\Windows\System32\advapi32.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab90e0000 'C:\Windows\System32\ADVAPI32.dll'
- 37b8.480c: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxVMM.dll: Signature #1/2: info status: 24202
- 37b8.480c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.480c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
- 37b8.480c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
- 37b8.480c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxVMM.dll) WinVerifyTrust
- 37b8.480c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxVMM.dll
- 37b8.480c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
- 37b8.480c: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
- 37b8.480c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
- 37b8.480c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
- 37b8.480c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.480c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxVMM.dll
- 37b8.480c: supR3HardenedDllNotificationCallback: load 00007ffa69ab0000 LB 0x0037e000 C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL [fFlags=0x0]
- 37b8.480c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxVMM.dll
- 37b8.480c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa69ab0000 'C:\Program Files\Oracle\VirtualBox\VBoxVMM.DLL'
- 37b8.2314: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab8da0000 'C:\Windows\system32\ole32.dll'
- 37b8.46e4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab8da0000 'C:\Windows\system32\ole32.dll'
- 37b8.60c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab8da0000 'C:\Windows\system32\ole32.dll'
- 37b8.3e14: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab8da0000 'C:\Windows\system32\ole32.dll'
- 37b8.46e4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.46e4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000ca8 pwszName=\Device\HarddiskVolume3\Windows\System32\NetSetupShim.dll
- 37b8.46e4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000001236bc0
- 37b8.46e4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000001236bc0
- 37b8.46e4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=6F8C888F69F54D27A8AFD63EDE4EB670F37A9036
- 37b8.46e4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.46e4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.46e4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package04111~31bf3856ad364e35~amd64~~10.0.22000.708.cat'; file='\Device\HarddiskVolume3\Windows\System32\NetSetupShim.dll'
- 37b8.46e4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 37b8.46e4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
- 37b8.46e4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #31 'rpcrt4.dll'.
- 37b8.46e4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #32 'oleaut32.dll'.
- 37b8.46e4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #34 'ws2_32.dll'.
- 37b8.46e4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #35 'netsetupapi.dll'.
- 37b8.46e4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #36 'setupapi.dll'.
- 37b8.46e4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #37 'devrtl.dll'.
- 37b8.46e4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\NetSetupShim.dll) WinVerifyTrust
- 37b8.46e4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\NetSetupShim.dll
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'devrtl.dll'...
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: 'devrtl.dll' -> '\Device\HarddiskVolume3\Windows\System32\devrtl.dll' [rcNtRedir=0xc0150008]
- 37b8.46e4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000cc4 pwszName=\Device\HarddiskVolume3\Windows\System32\devrtl.dll
- 37b8.46e4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000001236bc0
- 37b8.46e4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000001236bc0
- 37b8.46e4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=33E077F8355DAA7AD265B0AA861AC4D610180021
- 37b8.46e4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.46e4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.46e4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package0415~31bf3856ad364e35~amd64~~10.0.22000.795.cat'; file='\Device\HarddiskVolume3\Windows\System32\devrtl.dll'
- 37b8.46e4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 37b8.46e4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\devrtl.dll) WinVerifyTrust
- 37b8.46e4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\devrtl.dll
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
- 37b8.46e4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.46e4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.46e4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 37b8.46e4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\setupapi.dll) WinVerifyTrust
- 37b8.46e4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\setupapi.dll
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'netsetupapi.dll'...
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: 'netsetupapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\netsetupapi.dll' [rcNtRedir=0xc0150008]
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 37b8.46e4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.46e4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.46e4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 37b8.46e4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #17 'rpcrt4.dll'.
- 37b8.46e4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\NetSetupApi.dll) WinVerifyTrust
- 37b8.46e4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\NetSetupApi.dll
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
- 37b8.46e4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ws2_32.dll
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'oleaut32.dll'...
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: 'oleaut32.dll' -> '\Device\HarddiskVolume3\Windows\System32\oleaut32.dll' [rcNtRedir=0xc0150008]
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 37b8.46e4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\NetSetupShim.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
- 37b8.46e4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\NetSetupShim.dll
- 37b8.46e4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\cfgmgr32.dll)
- 37b8.46e4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\cfgmgr32.dll
- 37b8.46e4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\NetSetupApi.dll
- 37b8.46e4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\devrtl.dll
- 37b8.46e4: supR3HardenedDllNotificationCallback: load 00007ffab6440000 LB 0x0004c000 C:\Windows\SYSTEM32\cfgmgr32.dll [fFlags=0x0]
- 37b8.46e4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\cfgmgr32.dll [avoiding WinVerifyTrust]
- 37b8.46e4: supR3HardenedDllNotificationCallback: load 00007ffaa6910000 LB 0x00028000 C:\Windows\System32\NetSetupApi.dll [fFlags=0x0]
- 37b8.46e4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\NetSetupApi.dll
- 37b8.46e4: supR3HardenedDllNotificationCallback: load 00007ffab7940000 LB 0x0046c000 C:\Windows\System32\SETUPAPI.dll [fFlags=0x0]
- 37b8.46e4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\setupapi.dll
- 37b8.46e4: supR3HardenedDllNotificationCallback: load 00007ffa96be0000 LB 0x00014000 C:\Windows\System32\DEVRTL.dll [fFlags=0x0]
- 37b8.46e4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\devrtl.dll
- 37b8.46e4: supR3HardenedDllNotificationCallback: load 00007ffa94430000 LB 0x0007b000 C:\Windows\System32\NetSetupShim.dll [fFlags=0x0]
- 37b8.46e4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\NetSetupShim.dll
- 37b8.46e4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa94430000 'C:\Windows\System32\NetSetupShim.dll'
- 37b8.46e4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.46e4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessWvtTodos: 0 (was 0) fWinVerifyTrust=1 for '\Device\HarddiskVolume3\Windows\System32\cfgmgr32.dll'
- 37b8.46e4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.46e4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.46e4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
- 37b8.46e4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #23 'rpcrt4.dll'.
- 37b8.46e4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #24 'nsi.dll'.
- 37b8.46e4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #25 'winnsi.dll'.
- 37b8.46e4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\NetSetupEngine.dll) WinVerifyTrust
- 37b8.46e4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\NetSetupEngine.dll
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'winnsi.dll'...
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: 'winnsi.dll' -> '\Device\HarddiskVolume3\Windows\System32\winnsi.dll' [rcNtRedir=0xc0150008]
- 37b8.46e4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.46e4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.46e4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\winnsi.dll) WinVerifyTrust
- 37b8.46e4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\winnsi.dll
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'nsi.dll'...
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: 'nsi.dll' -> '\Device\HarddiskVolume3\Windows\System32\nsi.dll' [rcNtRedir=0xc0150008]
- 37b8.46e4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.46e4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.46e4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\nsi.dll) WinVerifyTrust
- 37b8.46e4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\nsi.dll
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
- 37b8.46e4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\NetSetupEngine.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.46e4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\NetSetupEngine.dll
- 37b8.46e4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winnsi.dll
- 37b8.46e4: supR3HardenedDllNotificationCallback: load 00007ffab8130000 LB 0x00009000 C:\Windows\System32\NSI.dll [fFlags=0x0]
- 37b8.46e4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\nsi.dll
- 37b8.46e4: supR3HardenedDllNotificationCallback: load 00007ffaade20000 LB 0x0000c000 C:\Windows\SYSTEM32\WINNSI.DLL [fFlags=0x0]
- 37b8.46e4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\winnsi.dll
- 37b8.46e4: supR3HardenedDllNotificationCallback: load 00007ffa69e90000 LB 0x000d3000 C:\Windows\System32\NetSetupEngine.dll [fFlags=0x0]
- 37b8.46e4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\NetSetupEngine.dll
- 37b8.46e4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa69e90000 'C:\Windows\System32\NetSetupEngine.dll'
- 37b8.5eec: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll: Signature #1/2: info status: 24202
- 37b8.5eec: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.5eec: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
- 37b8.5eec: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
- 37b8.5eec: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxvmm.dll'.
- 37b8.5eec: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vboxrt.dll'.
- 37b8.5eec: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'user32.dll'.
- 37b8.5eec: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll) WinVerifyTrust
- 37b8.5eec: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll
- 37b8.5eec: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 37b8.5eec: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 37b8.5eec: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
- 37b8.5eec: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
- 37b8.5eec: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
- 37b8.5eec: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
- 37b8.5eec: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxVMM.dll
- 37b8.5eec: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
- 37b8.5eec: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
- 37b8.5eec: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
- 37b8.5eec: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
- 37b8.5eec: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.5eec: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll
- 37b8.5eec: supR3HardenedDllNotificationCallback: load 00007ffaac1f0000 LB 0x00010000 C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL [fFlags=0x0]
- 37b8.5eec: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.dll
- 37b8.5eec: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaac1f0000 'C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL'
- 37b8.3078: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll: Signature #1/2: info status: 24202
- 37b8.3078: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.3078: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
- 37b8.3078: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
- 37b8.3078: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
- 37b8.3078: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll) WinVerifyTrust
- 37b8.3078: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll
- 37b8.3078: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
- 37b8.3078: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
- 37b8.3078: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
- 37b8.3078: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
- 37b8.3078: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
- 37b8.3078: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
- 37b8.3078: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.3078: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll
- 37b8.3078: supR3HardenedDllNotificationCallback: load 00007ffaa8120000 LB 0x0000d000 C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL [fFlags=0x0]
- 37b8.3078: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.dll
- 37b8.3078: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa8120000 'C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL'
- 37b8.46e4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab85e0000 'C:\Windows\system32\Shell32.dll'
- 37b8.46e4: supR3HardNtViCallWinVerifyTrustCatFile: hFile=0000000000000db0 pwszName=\Device\HarddiskVolume3\Windows\System32\WinHvPlatform.dll
- 37b8.46e4: supR3HardNtViCallWinVerifyTrustCatFile: Cached context 0000000001236bc0
- 37b8.46e4: supR3HardNtViCallWinVerifyTrustCatFile: hCatAdmin=0000000001236bc0
- 37b8.46e4: supR3HardNtViCallWinVerifyTrustCatFile: cbHash=20 wszDigest=8B3A29BB93DC85DF241632350324C9785EA8BDD9
- 37b8.46e4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.46e4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.46e4: supR3HardNtViCallWinVerifyTrustCatFile: WinVerifyTrust => 0x0; cat='C:\Windows\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\HyperV-Hypervisor-API-Package~31bf3856ad364e35~amd64~~10.0.22000.71.cat'; file='\Device\HarddiskVolume3\Windows\System32\WinHvPlatform.dll'
- 37b8.46e4: supR3HardNtViCallWinVerifyTrustCatFile -> 0 (org 22900)
- 37b8.46e4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'vid.dll'.
- 37b8.46e4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #29 'devobj.dll'.
- 37b8.46e4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\WinHvPlatform.dll) WinVerifyTrust
- 37b8.46e4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\WinHvPlatform.dll
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'devobj.dll'...
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: 'devobj.dll' -> '\Device\HarddiskVolume3\Windows\System32\devobj.dll' [rcNtRedir=0xc0150008]
- 37b8.46e4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.46e4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.46e4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #19 'cfgmgr32.dll'.
- 37b8.46e4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\devobj.dll) WinVerifyTrust
- 37b8.46e4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\devobj.dll
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vid.dll'...
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vid.dll' -> '\Device\HarddiskVolume3\Windows\System32\vid.dll' [rcNtRedir=0xc0150008]
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'cfgmgr32.dll'...
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: 'cfgmgr32.dll' -> '\Device\HarddiskVolume3\Windows\System32\cfgmgr32.dll' [rcNtRedir=0xc0150008]
- 37b8.46e4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\cfgmgr32.dll
- 37b8.46e4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.46e4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.46e4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\vid.dll) WinVerifyTrust
- 37b8.46e4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\vid.dll
- 37b8.46e4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\WinHvPlatform.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.46e4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\WinHvPlatform.dll
- 37b8.46e4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\vid.dll
- 37b8.46e4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\devobj.dll
- 37b8.46e4: supR3HardenedDllNotificationCallback: load 00007ffa70970000 LB 0x0002d000 C:\Windows\SYSTEM32\vid.dll [fFlags=0x0]
- 37b8.46e4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\vid.dll
- 37b8.46e4: supR3HardenedDllNotificationCallback: load 00007ffab6410000 LB 0x0002c000 C:\Windows\SYSTEM32\DEVOBJ.dll [fFlags=0x0]
- 37b8.46e4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\devobj.dll
- 37b8.46e4: supR3HardenedDllNotificationCallback: load 00007ffa69a60000 LB 0x00046000 C:\Windows\system32\WinHvPlatform.dll [fFlags=0x0]
- 37b8.46e4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\WinHvPlatform.dll
- 37b8.46e4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa69a60000 'C:\Windows\system32\WinHvPlatform.dll'
- 37b8.46e4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\vid.dll
- 37b8.46e4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\vid.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.46e4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa70970000 'C:\Windows\system32\vid.dll'
- 37b8.46e4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.46e4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.46e4: '\Device\HarddiskVolume3\Windows\System32\ntdll.dll' has no imports
- 37b8.46e4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\ntdll.dll) WinVerifyTrust
- 37b8.46e4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\ntdll.dll
- 37b8.46e4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\NTDLL.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.46e4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab9260000 'C:\Windows\system32\NTDLL.DLL'
- 37b8.46e4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.46e4: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxDD.dll: Signature #1/2: info status: 24202
- 37b8.46e4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.46e4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
- 37b8.46e4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
- 37b8.46e4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
- 37b8.46e4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vboxddu.dll'.
- 37b8.46e4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'vboxdd2.dll'.
- 37b8.46e4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #6 'user32.dll'.
- 37b8.46e4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #7 'setupapi.dll'.
- 37b8.46e4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #8 'ws2_32.dll'.
- 37b8.46e4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #9 'ole32.dll'.
- 37b8.46e4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #10 'iphlpapi.dll'.
- 37b8.46e4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxDD.dll) WinVerifyTrust
- 37b8.46e4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxDD.dll
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'iphlpapi.dll'...
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: 'iphlpapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\iphlpapi.dll' [rcNtRedir=0xc0150008]
- 37b8.46e4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.46e4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.46e4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\IPHLPAPI.DLL) WinVerifyTrust
- 37b8.46e4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\IPHLPAPI.DLL
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ole32.dll'...
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ole32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ole32.dll' [rcNtRedir=0xc0150008]
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'ws2_32.dll'...
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: 'ws2_32.dll' -> '\Device\HarddiskVolume3\Windows\System32\ws2_32.dll' [rcNtRedir=0xc0150008]
- 37b8.46e4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ws2_32.dll
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
- 37b8.46e4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\setupapi.dll
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 37b8.46e4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\user32.dll
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxdd2.dll'...
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxdd2.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxdd2.dll' [rcNtRedir=0xc0150008]
- 37b8.46e4: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxDD2.dll: Signature #1/2: info status: 24202
- 37b8.46e4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.46e4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
- 37b8.46e4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
- 37b8.46e4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxDD2.dll) WinVerifyTrust
- 37b8.46e4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxDD2.dll
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxddu.dll'...
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxddu.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxddu.dll' [rcNtRedir=0xc0150008]
- 37b8.46e4: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxDDU.dll: Signature #1/2: info status: 24202
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
- 37b8.46e4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll
- 37b8.46e4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.46e4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
- 37b8.46e4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxrt.dll'.
- 37b8.46e4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'user32.dll'.
- 37b8.46e4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #4 'setupapi.dll'.
- 37b8.46e4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #5 'advapi32.dll'.
- 37b8.46e4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxDDU.dll) WinVerifyTrust
- 37b8.46e4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxDDU.dll
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
- 37b8.46e4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxVMM.dll
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'advapi32.dll'...
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: 'advapi32.dll' -> '\Device\HarddiskVolume3\Windows\System32\advapi32.dll' [rcNtRedir=0xc0150008]
- 37b8.46e4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\advapi32.dll
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'setupapi.dll'...
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: 'setupapi.dll' -> '\Device\HarddiskVolume3\Windows\System32\setupapi.dll' [rcNtRedir=0xc0150008]
- 37b8.46e4: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\setupapi.dll
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'user32.dll'...
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: 'user32.dll' -> '\Device\HarddiskVolume3\Windows\System32\user32.dll' [rcNtRedir=0xc0150008]
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
- 37b8.46e4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxDD.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.46e4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxDD.dll
- 37b8.46e4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxDDU.dll
- 37b8.46e4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxDD2.dll
- 37b8.46e4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\IPHLPAPI.DLL
- 37b8.46e4: supR3HardenedDllNotificationCallback: load 00007ffa73090000 LB 0x00066000 C:\Program Files\Oracle\VirtualBox\VBoxDDU.dll [fFlags=0x0]
- 37b8.46e4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxDDU.dll
- 37b8.46e4: supR3HardenedDllNotificationCallback: load 00007ffa68e90000 LB 0x0085c000 C:\Program Files\Oracle\VirtualBox\VBoxDD2.dll [fFlags=0x0]
- 37b8.46e4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxDD2.dll
- 37b8.46e4: supR3HardenedDllNotificationCallback: load 00007ffab5420000 LB 0x0002d000 C:\Windows\SYSTEM32\IPHLPAPI.DLL [fFlags=0x0]
- 37b8.46e4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\IPHLPAPI.DLL
- 37b8.46e4: supR3HardenedDllNotificationCallback: load 00007ffa65040000 LB 0x00a04000 C:\Program Files\Oracle\VirtualBox\VBoxDD.DLL [fFlags=0x0]
- 37b8.46e4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxDD.dll
- 37b8.46e4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa65040000 'C:\Program Files\Oracle\VirtualBox\VBoxDD.DLL'
- 37b8.46e4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.46e4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxC.dll
- 37b8.46e4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxC.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.46e4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa6a140000 'C:\Program Files\Oracle\VirtualBox\VBoxC.DLL'
- 37b8.46e4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.46e4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxDD2.dll
- 37b8.46e4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxDD2.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.46e4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffa68e90000 'C:\Program Files\Oracle\VirtualBox\VBoxDD2.DLL'
- 37b8.820: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll: Signature #1/2: info status: 24202
- 37b8.820: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.820: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
- 37b8.820: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'vboxvmm.dll'.
- 37b8.820: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
- 37b8.820: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll) WinVerifyTrust
- 37b8.820: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll
- 37b8.820: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
- 37b8.820: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
- 37b8.820: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
- 37b8.820: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
- 37b8.820: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxVMM.dll
- 37b8.820: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
- 37b8.820: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
- 37b8.820: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.820: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll
- 37b8.820: supR3HardenedDllNotificationCallback: load 00007ffaa7f30000 LB 0x00014000 C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL [fFlags=0x0]
- 37b8.820: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSharedFolders.dll
- 37b8.820: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa7f30000 'C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL'
- 37b8.25cc: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll: Signature #1/2: info status: 24202
- 37b8.25cc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.25cc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
- 37b8.25cc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
- 37b8.25cc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxvmm.dll'.
- 37b8.25cc: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #3 'vboxrt.dll'.
- 37b8.25cc: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll) WinVerifyTrust
- 37b8.25cc: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll
- 37b8.25cc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
- 37b8.25cc: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
- 37b8.25cc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxvmm.dll'...
- 37b8.25cc: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxvmm.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxvmm.dll' [rcNtRedir=0xc0150008]
- 37b8.25cc: supR3HardenedScreenImage/Imports: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxVMM.dll
- 37b8.25cc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
- 37b8.25cc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
- 37b8.25cc: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
- 37b8.25cc: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
- 37b8.25cc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.25cc: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll
- 37b8.25cc: supR3HardenedDllNotificationCallback: load 00007ffaa6a00000 LB 0x0000c000 C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL [fFlags=0x0]
- 37b8.25cc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.dll
- 37b8.25cc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa6a00000 'C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL'
- 37b8.3188: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll: Signature #1/2: info status: 24202
- 37b8.3188: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.3188: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcr100.dll'.
- 37b8.3188: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #1 'msvcp100.dll'.
- 37b8.3188: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #2 'vboxrt.dll'.
- 37b8.3188: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll) WinVerifyTrust
- 37b8.3188: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll
- 37b8.3188: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'vboxrt.dll'...
- 37b8.3188: supR3HardenedWinVerifyCacheProcessImportTodos: 'vboxrt.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\vboxrt.dll' [rcNtRedir=0xc0150008]
- 37b8.3188: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp100.dll'...
- 37b8.3188: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcp100.dll' [rcNtRedir=0xc0150008]
- 37b8.3188: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcr100.dll'...
- 37b8.3188: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcr100.dll' -> '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\msvcr100.dll' [rcNtRedir=0xc0150008]
- 37b8.3188: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.3188: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll
- 37b8.3188: supR3HardenedDllNotificationCallback: load 00007ffaa4cd0000 LB 0x0000d000 C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL [fFlags=0x0]
- 37b8.3188: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.dll
- 37b8.3188: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa4cd0000 'C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL'
- 37b8.46e4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.46e4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab5850000 'C:\Windows\system32\rsaenh.dll'
- 37b8.46e4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab6740000 'C:\Windows\System32\crypt32.dll'
- 37b8.46e4: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcp_win.dll'.
- 37b8.46e4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\MMDevAPI.dll) WinVerifyTrust
- 37b8.46e4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\MMDevAPI.dll
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcp_win.dll'...
- 37b8.46e4: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcp_win.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcp_win.dll' [rcNtRedir=0xc0150008]
- 37b8.46e4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\MMDevApi.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000002009:<flags> [calling]
- 37b8.46e4: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\MMDevAPI.dll
- 37b8.46e4: supR3HardenedDllNotificationCallback: load 00007ffaa96b0000 LB 0x0009c000 C:\Windows\System32\MMDevApi.dll [fFlags=0x0]
- 37b8.46e4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\MMDevAPI.dll
- 37b8.46e4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa96b0000 'C:\Windows\System32\MMDevApi.dll'
- 37b8.46e4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\MMDevAPI.dll
- 37b8.46e4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\MMDEVAPI.DLL (Input=MMDEVAPI.DLL, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.46e4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffaa96b0000 'C:\Windows\System32\MMDEVAPI.DLL'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab85e0000 'C:\Windows\system32\shell32.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab85e0000 'C:\Windows\system32\shell32.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab85e0000 'C:\Windows\system32\shell32.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab85e0000 'C:\Windows\system32\shell32.dll'
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\shell32.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\shell32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab85e0000 'C:\Windows\system32\shell32.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab85e0000 'C:\Windows\system32\shell32.dll'
- 37b8.37bc: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\ole32.dll
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\ole32.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000009:<flags> [calling]
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab8da0000 'C:\Windows\system32\ole32.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab85e0000 'C:\Windows\system32\shell32.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab85e0000 'C:\Windows\system32\shell32.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab85e0000 'C:\Windows\system32\shell32.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab85e0000 'C:\Windows\system32\shell32.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab85e0000 'C:\Windows\system32\shell32.dll'
- 37b8.37bc: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffab85e0000 'C:\Windows\system32\shell32.dll'
- 37b8.3188: supR3HardenedDllNotificationCallback: Unload 00007ffaa4cd0000 LB 0x0000d000 C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL [flags=0x0]
- 37b8.25cc: supR3HardenedDllNotificationCallback: Unload 00007ffaa6a00000 LB 0x0000c000 C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL [flags=0x0]
- 37b8.820: supR3HardenedDllNotificationCallback: Unload 00007ffaa7f30000 LB 0x00014000 C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL [flags=0x0]
- 37b8.3078: supR3HardenedDllNotificationCallback: Unload 00007ffaa8120000 LB 0x0000d000 C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL [flags=0x0]
- 37b8.5eec: supR3HardenedDllNotificationCallback: Unload 00007ffaac1f0000 LB 0x00010000 C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL [flags=0x0]
- 37b8.46e4: supR3HardenedDllNotificationCallback: Unload 00007ffa65040000 LB 0x00a04000 C:\Program Files\Oracle\VirtualBox\VBoxDD.DLL [flags=0x0]
- 37b8.46e4: supR3HardenedDllNotificationCallback: Unload 00007ffa73090000 LB 0x00066000 C:\Program Files\Oracle\VirtualBox\VBoxDDU.dll [flags=0x0]
- 37b8.46e4: supR3HardenedDllNotificationCallback: Unload 00007ffa68e90000 LB 0x0085c000 C:\Program Files\Oracle\VirtualBox\VBoxDD2.dll [flags=0x0]
- 37b8.46e4: supR3HardenedDllNotificationCallback: Unload 00007ffab5420000 LB 0x0002d000 C:\Windows\SYSTEM32\IPHLPAPI.DLL [flags=0x0]
- 37b8.37bc: supR3HardenedDllNotificationCallback: Unload 00007ffa6a510000 LB 0x000ef000 C:\Program Files\Oracle\VirtualBox\VBoxProxyStub.dll [flags=0x0]
- 37b8.37bc: supR3HardenedDllNotificationCallback: Unload 00007ffa9a250000 LB 0x00014000 C:\Windows\system32\wbem\wbemsvc.dll [flags=0x0]
- 37b8.37bc: supR3HardenedDllNotificationCallback: Unload 00007ffaa4db0000 LB 0x00010000 C:\Windows\system32\wbem\wbemprox.dll [flags=0x0]
- 37b8.37bc: supR3HardenedDllNotificationCallback: Unload 00007ffa75d20000 LB 0x0005d000 C:\Windows\system32\dataexchange.dll [flags=0x0]
- 37b8.37bc: supR3HardenedDllNotificationCallback: Unload 00007ffaa90a0000 LB 0x00266000 C:\Windows\system32\twinapi.appcore.dll [flags=0x0]
- 37b8.37bc: supR3HardenedDllNotificationCallback: Unload 00007ffa6a140000 LB 0x003c2000 C:\Program Files\Oracle\VirtualBox\VBoxC.dll [flags=0x0]
- 37b8.37bc: supR3HardenedDllNotificationCallback: Unload 00007ffa94430000 LB 0x0007b000 C:\Windows\System32\NetSetupShim.dll [flags=0x0]
- 37b8.37bc: supR3HardenedDllNotificationCallback: Unload 00007ffaa6910000 LB 0x00028000 C:\Windows\System32\NetSetupApi.dll [flags=0x0]
- 37b8.37bc: supR3HardenedDllNotificationCallback: Unload 00007ffab7940000 LB 0x0046c000 C:\Windows\System32\SETUPAPI.dll [flags=0x0]
- 37b8.37bc: supR3HardenedDllNotificationCallback: Unload 00007ffa96be0000 LB 0x00014000 C:\Windows\System32\DEVRTL.dll [flags=0x0]
- 37b8.37bc: supR3HardenedDllNotificationCallback: Unload 00007ffa94a40000 LB 0x000fa000 C:\Windows\system32\wbem\fastprox.dll [flags=0x0]
- 37b8.37bc: supR3HardenedDllNotificationCallback: Unload 00007ffa9ac60000 LB 0x00082000 C:\Windows\SYSTEM32\wbemcomn.dll [flags=0x0]
- 37b8.37bc: Terminating the normal way: rcExit=0
- 5f00.18e0: supR3HardNtChildWaitFor[2]: Quitting: ExitCode=0x0 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 33615 ms, the end);
- 48e4.5aec: supR3HardNtChildWaitFor[1]: Quitting: ExitCode=0x0 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 34298 ms, the end);
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement