VirtualBox

Ticket #17662: VBoxHardening.log

File VBoxHardening.log, 18.6 KB (added by AshokMazumder, 6 years ago)
Line 
19d4.9d8: Log file opened: 5.2.8r121009 g_hStartupLog=0000000000000068 g_uNtVerCombined=0xa03ad700
29d4.9d8: \SystemRoot\System32\ntdll.dll:
39d4.9d8: CreationTime: 2017-03-18T20:57:39.201977500Z
49d4.9d8: LastWriteTime: 2017-03-18T20:57:39.201977500Z
59d4.9d8: ChangeTime: 2018-04-04T04:47:42.181105700Z
69d4.9d8: FileAttributes: 0x20
79d4.9d8: Size: 0x1d7450
89d4.9d8: NT Headers: 0xe0
99d4.9d8: Timestamp: 0xb79b6ddb
109d4.9d8: Machine: 0x8664 - amd64
119d4.9d8: Timestamp: 0xb79b6ddb
129d4.9d8: Image Version: 10.0
139d4.9d8: SizeOfImage: 0x1db000 (1945600)
149d4.9d8: Resource Dir: 0x170000 LB 0x69398
159d4.9d8: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
169d4.9d8: [Raw version resource data: 0x1700f0 LB 0x380, codepage 0x0 (reserved 0x0)]
179d4.9d8: ProductName: Microsoft® Windows® Operating System
189d4.9d8: ProductVersion: 10.0.15063.0
199d4.9d8: FileVersion: 10.0.15063.0 (WinBuild.160101.0800)
209d4.9d8: FileDescription: NT Layer DLL
219d4.9d8: \SystemRoot\System32\kernel32.dll:
229d4.9d8: CreationTime: 2017-03-18T20:57:15.887502700Z
239d4.9d8: LastWriteTime: 2017-03-18T20:57:15.887502700Z
249d4.9d8: ChangeTime: 2018-04-04T04:47:39.931076300Z
259d4.9d8: FileAttributes: 0x20
269d4.9d8: Size: 0xad068
279d4.9d8: NT Headers: 0xf8
289d4.9d8: Timestamp: 0x17a3637d
299d4.9d8: Machine: 0x8664 - amd64
309d4.9d8: Timestamp: 0x17a3637d
319d4.9d8: Image Version: 10.0
329d4.9d8: SizeOfImage: 0xae000 (712704)
339d4.9d8: Resource Dir: 0xac000 LB 0x520
349d4.9d8: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
359d4.9d8: [Raw version resource data: 0xac0b0 LB 0x3a4, codepage 0x0 (reserved 0x0)]
369d4.9d8: ProductName: Microsoft® Windows® Operating System
379d4.9d8: ProductVersion: 10.0.15063.0
389d4.9d8: FileVersion: 10.0.15063.0 (WinBuild.160101.0800)
399d4.9d8: FileDescription: Windows NT BASE API Client DLL
409d4.9d8: \SystemRoot\System32\KernelBase.dll:
419d4.9d8: CreationTime: 2017-03-18T20:57:35.951701900Z
429d4.9d8: LastWriteTime: 2017-03-18T20:57:35.951701900Z
439d4.9d8: ChangeTime: 2018-04-04T04:47:39.993574700Z
449d4.9d8: FileAttributes: 0x20
459d4.9d8: Size: 0x249bf0
469d4.9d8: NT Headers: 0x100
479d4.9d8: Timestamp: 0x461a0ff5
489d4.9d8: Machine: 0x8664 - amd64
499d4.9d8: Timestamp: 0x461a0ff5
509d4.9d8: Image Version: 10.0
519d4.9d8: SizeOfImage: 0x249000 (2396160)
529d4.9d8: Resource Dir: 0x22a000 LB 0x548
539d4.9d8: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
549d4.9d8: [Raw version resource data: 0x22a0b0 LB 0x3bc, codepage 0x0 (reserved 0x0)]
559d4.9d8: ProductName: Microsoft® Windows® Operating System
569d4.9d8: ProductVersion: 10.0.15063.0
579d4.9d8: FileVersion: 10.0.15063.0 (WinBuild.160101.0800)
589d4.9d8: FileDescription: Windows NT BASE API Client DLL
599d4.9d8: \SystemRoot\System32\apisetschema.dll:
609d4.9d8: CreationTime: 2017-03-18T20:57:35.373527900Z
619d4.9d8: LastWriteTime: 2017-03-18T20:57:35.373527900Z
629d4.9d8: ChangeTime: 2018-04-04T04:47:21.446473600Z
639d4.9d8: FileAttributes: 0x20
649d4.9d8: Size: 0x1ada0
659d4.9d8: NT Headers: 0xc0
669d4.9d8: Timestamp: 0x76544b2
679d4.9d8: Machine: 0x8664 - amd64
689d4.9d8: Timestamp: 0x76544b2
699d4.9d8: Image Version: 10.0
709d4.9d8: SizeOfImage: 0x1b000 (110592)
719d4.9d8: Resource Dir: 0x1a000 LB 0x408
729d4.9d8: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
739d4.9d8: [Raw version resource data: 0x1a060 LB 0x3a8, codepage 0x0 (reserved 0x0)]
749d4.9d8: ProductName: Microsoft® Windows® Operating System
759d4.9d8: ProductVersion: 10.0.15063.0
769d4.9d8: FileVersion: 10.0.15063.0 (WinBuild.160101.0800)
779d4.9d8: FileDescription: ApiSet Schema DLL
789d4.9d8: NtOpenDirectoryObject failed on \Driver: 0xc0000022
799d4.9d8: supR3HardenedWinFindAdversaries: 0x3
809d4.9d8: \SystemRoot\System32\drivers\SysPlant.sys:
819d4.9d8: CreationTime: 2017-11-29T08:50:43.541005400Z
829d4.9d8: LastWriteTime: 2018-03-15T12:16:02.622294500Z
839d4.9d8: ChangeTime: 2018-04-03T15:55:01.504909500Z
849d4.9d8: FileAttributes: 0x20
859d4.9d8: Size: 0x30548
869d4.9d8: NT Headers: 0xf0
879d4.9d8: Timestamp: 0x5a1adc8a
889d4.9d8: Machine: 0x8664 - amd64
899d4.9d8: Timestamp: 0x5a1adc8a
909d4.9d8: Image Version: 5.0
919d4.9d8: SizeOfImage: 0x31000 (200704)
929d4.9d8: Resource Dir: 0x2f000 LB 0x49c
939d4.9d8: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
949d4.9d8: [Raw version resource data: 0x2f0b8 LB 0x3e4, codepage 0x4e4 (reserved 0x0)]
959d4.9d8: ProductName: Symantec CMC Firewall
969d4.9d8: ProductVersion: 14.0.3856.1100
979d4.9d8: FileVersion: 14.0.3856.1100
989d4.9d8: FileDescription: Symantec CMC Firewall SysPlant
999d4.9d8: \SystemRoot\System32\sysfer.dll:
1009d4.9d8: CreationTime: 2017-11-29T08:50:43.395898800Z
1019d4.9d8: LastWriteTime: 2018-03-15T12:16:02.606653000Z
1029d4.9d8: ChangeTime: 2018-04-03T16:21:27.407406100Z
1039d4.9d8: FileAttributes: 0x20
1049d4.9d8: Size: 0x7cee8
1059d4.9d8: NT Headers: 0xf8
1069d4.9d8: Timestamp: 0x5a1adc96
1079d4.9d8: Machine: 0x8664 - amd64
1089d4.9d8: Timestamp: 0x5a1adc96
1099d4.9d8: Image Version: 0.0
1109d4.9d8: SizeOfImage: 0x95000 (610304)
1119d4.9d8: Resource Dir: 0x91000 LB 0x490
1129d4.9d8: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
1139d4.9d8: [Raw version resource data: 0x910b8 LB 0x3d8, codepage 0x4e4 (reserved 0x0)]
1149d4.9d8: ProductName: Symantec CMC Firewall
1159d4.9d8: ProductVersion: 14.0.3856.1100
1169d4.9d8: FileVersion: 14.0.3856.1100
1179d4.9d8: FileDescription: Symantec CMC Firewall sysfer
1189d4.9d8: \SystemRoot\System32\drivers\symevent64x86.sys:
1199d4.9d8: CreationTime: 2017-11-29T08:53:05.303638500Z
1209d4.9d8: LastWriteTime: 2017-11-29T08:53:04.933809100Z
1219d4.9d8: ChangeTime: 2018-04-03T15:55:01.504909500Z
1229d4.9d8: FileAttributes: 0x20
1239d4.9d8: Size: 0x190d0
1249d4.9d8: NT Headers: 0xe0
1259d4.9d8: Timestamp: 0x584f629e
1269d4.9d8: Machine: 0x8664 - amd64
1279d4.9d8: Timestamp: 0x584f629e
1289d4.9d8: Image Version: 6.2
1299d4.9d8: SizeOfImage: 0x23000 (143360)
1309d4.9d8: Resource Dir: 0x21000 LB 0x3c8
1319d4.9d8: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
1329d4.9d8: [Raw version resource data: 0x210b8 LB 0x310, codepage 0x4e4 (reserved 0x0)]
1339d4.9d8: ProductName: SYMEVENT
1349d4.9d8: ProductVersion: 14.0.4.16
1359d4.9d8: FileVersion: 14.0.4.16
1369d4.9d8: FileDescription: Symantec Event Library
1379d4.9d8: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox'
1389d4.9d8: Calling main()
1399d4.9d8: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
1409d4.9d8: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox'
1419d4.9d8: SUPR3HardenedMain: Respawn #1
1429d4.9d8: System32: \Device\HarddiskVolume1\Windows\System32
1439d4.9d8: WinSxS: \Device\HarddiskVolume1\Windows\WinSxS
1449d4.9d8: KnownDllPath: C:\WINDOWS\System32
1459d4.9d8: '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
1469d4.9d8: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe)
1479d4.9d8: supR3HardNtEnableThreadCreation:
1489d4.9d8: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ff9068d9ad0 pvNtTerminateThread=00007ff906905e00
1499d4.9d8: supR3HardenedWinDoReSpawn(1): New child 293c.2ac4 [kernel32].
1509d4.9d8: supR3HardNtChildGatherData: PebBaseAddress=000000000086c000 cbPeb=0x388
1519d4.9d8: supR3HardNtPuChFindNtdll: uNtDllParentAddr=00007ff906860000 uNtDllChildAddr=00007ff906860000
1529d4.9d8: supR3HardenedWinSetupChildInit: uLdrInitThunk=00007ff9068d9ad0
1539d4.9d8: supR3HardenedWinSetupChildInit: Start child.
1549d4.9d8: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
1559d4.9d8: supR3HardNtChildPurify: Startup delay kludge #1/0: 515 ms, 33 sleeps
1569d4.9d8: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
1579d4.9d8: *0000000000000000-000000000076ffff 0x0001/0x0000 0x0000000
1589d4.9d8: *0000000000770000-000000000078ffff 0x0004/0x0004 0x0020000
1599d4.9d8: *0000000000790000-00000000007a7fff 0x0002/0x0002 0x0040000
1609d4.9d8: 00000000007a8000-00000000007affff 0x0001/0x0000 0x0000000
1619d4.9d8: *00000000007b0000-00000000007b3fff 0x0002/0x0002 0x0040000
1629d4.9d8: 00000000007b4000-00000000007bffff 0x0001/0x0000 0x0000000
1639d4.9d8: *00000000007c0000-00000000007c0fff 0x0004/0x0004 0x0020000
1649d4.9d8: 00000000007c1000-00000000007fffff 0x0001/0x0000 0x0000000
1659d4.9d8: *0000000000800000-000000000086bfff 0x0000/0x0004 0x0020000
1669d4.9d8: 000000000086c000-000000000086efff 0x0004/0x0004 0x0020000
1679d4.9d8: 000000000086f000-00000000009fffff 0x0000/0x0004 0x0020000
1689d4.9d8: *0000000000a00000-0000000000afafff 0x0000/0x0004 0x0020000
1699d4.9d8: 0000000000afb000-0000000000afdfff 0x0104/0x0004 0x0020000
1709d4.9d8: 0000000000afe000-0000000000afffff 0x0004/0x0004 0x0020000
1719d4.9d8: 0000000000b00000-000000007ffdffff 0x0001/0x0000 0x0000000
1729d4.9d8: *000000007ffe0000-000000007ffe0fff 0x0002/0x0002 0x0020000
1739d4.9d8: *000000007ffe1000-000000007ffeffff 0x0000/0x0002 0x0020000
1749d4.9d8: 000000007fff0000-00007ff7bbf3ffff 0x0001/0x0000 0x0000000
1759d4.9d8: *00007ff7bbf40000-00007ff7bbf62fff 0x0002/0x0002 0x0040000
1769d4.9d8: 00007ff7bbf63000-00007ff7bc9effff 0x0001/0x0000 0x0000000
1779d4.9d8: *00007ff7bc9f0000-00007ff7bc9f0fff 0x0040/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
1789d4.9d8: 00007ff7bc9f1000-00007ff7bca61fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
1799d4.9d8: 00007ff7bca62000-00007ff7bca62fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
1809d4.9d8: 00007ff7bca63000-00007ff7bcaa8fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
1819d4.9d8: 00007ff7bcaa9000-00007ff7bcaa9fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
1829d4.9d8: 00007ff7bcaaa000-00007ff7bcaaafff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
1839d4.9d8: 00007ff7bcaab000-00007ff7bcaaffff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
1849d4.9d8: 00007ff7bcab0000-00007ff7bcab0fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
1859d4.9d8: 00007ff7bcab1000-00007ff7bcab1fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
1869d4.9d8: 00007ff7bcab2000-00007ff7bcab5fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
1879d4.9d8: 00007ff7bcab6000-00007ff7bcafdfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
1889d4.9d8: 00007ff7bcafe000-00007ff7bcafffff 0x0001/0x0000 0x0000000
1899d4.9d8: *00007ff7bcb00000-00007ff7bcb00fff 0x0004/0x0004 0x0020000
1909d4.9d8: 00007ff7bcb01000-00007ff90685ffff 0x0001/0x0000 0x0000000
1919d4.9d8: *00007ff906860000-00007ff906860fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
1929d4.9d8: 00007ff906861000-00007ff90696ffff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
1939d4.9d8: 00007ff906970000-00007ff9069b4fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
1949d4.9d8: 00007ff9069b5000-00007ff9069bcfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
1959d4.9d8: 00007ff9069bd000-00007ff9069cafff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
1969d4.9d8: 00007ff9069cb000-00007ff9069cbfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
1979d4.9d8: 00007ff9069cc000-00007ff9069cefff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
1989d4.9d8: 00007ff9069cf000-00007ff906a3afff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
1999d4.9d8: 00007ff906a3b000-00007ffffffdffff 0x0001/0x0000 0x0000000
2009d4.9d8: *00007ffffffe0000-00007ffffffeffff 0x0001/0x0002 0x0020000
2019d4.9d8: VirtualBox.exe: timestamp 0x5a942b95 (rc=VINF_SUCCESS)
2029d4.9d8: '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
2039d4.9d8: VirtualBox.exe: Differences in section #0 (headers) between file and memory:
2049d4.9d8: 00007ff7bc9f0162 / 0x0000162: 00 != 11
2059d4.9d8: 00007ff7bc9f0164 / 0x0000164: 00 != 14
2069d4.9d8: Restored 0x400 bytes of original file content at 00007ff7bc9f0000
2079d4.9d8: '\Device\HarddiskVolume1\Windows\System32\ntdll.dll' has no imports
2089d4.9d8: supR3HardNtChildPurify: cFixes=1 g_fSupAdversaries=0x3
2099d4.9d8: supR3HardNtChildPurify: Startup delay kludge #1/1: 515 ms, 32 sleeps
2109d4.9d8: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
2119d4.9d8: *0000000000000000-000000000076ffff 0x0001/0x0000 0x0000000
2129d4.9d8: *0000000000770000-000000000078ffff 0x0004/0x0004 0x0020000
2139d4.9d8: *0000000000790000-00000000007a7fff 0x0002/0x0002 0x0040000
2149d4.9d8: 00000000007a8000-00000000007affff 0x0001/0x0000 0x0000000
2159d4.9d8: *00000000007b0000-00000000007b3fff 0x0002/0x0002 0x0040000
2169d4.9d8: 00000000007b4000-00000000007bffff 0x0001/0x0000 0x0000000
2179d4.9d8: *00000000007c0000-00000000007c0fff 0x0004/0x0004 0x0020000
2189d4.9d8: 00000000007c1000-00000000007fffff 0x0001/0x0000 0x0000000
2199d4.9d8: *0000000000800000-000000000086bfff 0x0000/0x0004 0x0020000
2209d4.9d8: 000000000086c000-000000000086efff 0x0004/0x0004 0x0020000
2219d4.9d8: 000000000086f000-00000000009fffff 0x0000/0x0004 0x0020000
2229d4.9d8: *0000000000a00000-0000000000afafff 0x0000/0x0004 0x0020000
2239d4.9d8: 0000000000afb000-0000000000afdfff 0x0104/0x0004 0x0020000
2249d4.9d8: 0000000000afe000-0000000000afffff 0x0004/0x0004 0x0020000
2259d4.9d8: 0000000000b00000-000000007ffdffff 0x0001/0x0000 0x0000000
2269d4.9d8: *000000007ffe0000-000000007ffe0fff 0x0002/0x0002 0x0020000
2279d4.9d8: *000000007ffe1000-000000007ffeffff 0x0000/0x0002 0x0020000
2289d4.9d8: 000000007fff0000-00007ff7bbf3ffff 0x0001/0x0000 0x0000000
2299d4.9d8: *00007ff7bbf40000-00007ff7bbf62fff 0x0002/0x0002 0x0040000
2309d4.9d8: 00007ff7bbf63000-00007ff7bc9effff 0x0001/0x0000 0x0000000
2319d4.9d8: *00007ff7bc9f0000-00007ff7bc9f0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
2329d4.9d8: 00007ff7bc9f1000-00007ff7bca61fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
2339d4.9d8: 00007ff7bca62000-00007ff7bca62fff 0x0040/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
2349d4.9d8: 00007ff7bca63000-00007ff7bcaa8fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
2359d4.9d8: 00007ff7bcaa9000-00007ff7bcab5fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
2369d4.9d8: 00007ff7bcab6000-00007ff7bcafdfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Program Files\Oracle\VirtualBox\VirtualBox.exe
2379d4.9d8: 00007ff7bcafe000-00007ff7bcafffff 0x0001/0x0000 0x0000000
2389d4.9d8: *00007ff7bcb00000-00007ff7bcb00fff 0x0004/0x0004 0x0020000
2399d4.9d8: 00007ff7bcb01000-00007ff90685ffff 0x0001/0x0000 0x0000000
2409d4.9d8: *00007ff906860000-00007ff906860fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
2419d4.9d8: 00007ff906861000-00007ff90696ffff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
2429d4.9d8: 00007ff906970000-00007ff9069b4fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
2439d4.9d8: 00007ff9069b5000-00007ff9069b8fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
2449d4.9d8: 00007ff9069b9000-00007ff9069bcfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
2459d4.9d8: 00007ff9069bd000-00007ff9069cafff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
2469d4.9d8: 00007ff9069cb000-00007ff9069cbfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
2479d4.9d8: 00007ff9069cc000-00007ff9069cefff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
2489d4.9d8: 00007ff9069cf000-00007ff906a3afff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume1\Windows\System32\ntdll.dll
2499d4.9d8: 00007ff906a3b000-00007ffffffdffff 0x0001/0x0000 0x0000000
2509d4.9d8: *00007ffffffe0000-00007ffffffeffff 0x0001/0x0002 0x0020000
2519d4.9d8: supR3HardNtChildPurify: Done after 1093 ms and 1 fixes (loop #1).
2529d4.9d8: supR3HardNtEnableThreadCreation:
253293c.2ac4: Log file opened: 5.2.8r121009 g_hStartupLog=0000000000000004 g_uNtVerCombined=0xa03ad700
254293c.2ac4: supR3HardenedVmProcessInit: uNtDllAddr=00007ff906860000 g_uNtVerCombined=0xa03ad700
255293c.2ac4: ntdll.dll: timestamp 0xb79b6ddb (rc=VINF_SUCCESS)
256293c.2ac4: New simple heap: #1 0000000000c00000 LB 0x400000 (for 1945600 allocation)
257293c.2ac4: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume1\Program Files\Oracle\VirtualBox'
258293c.2ac4: System32: \Device\HarddiskVolume1\Windows\System32
259293c.2ac4: WinSxS: \Device\HarddiskVolume1\Windows\WinSxS
260293c.2ac4: KnownDllPath: C:\WINDOWS\System32
261293c.2ac4: supR3HardenedVmProcessInit: Opening vboxdrv stub...
262293c.2ac4: Error opening VBoxDrvStub: STATUS_OBJECT_NAME_NOT_FOUND
263293c.2ac4: supR3HardenedWinReadErrorInfoDevice: NtCreateFile -> 0xc0000034
264293c.2ac4: Error -101 in supR3HardenedWinReSpawn! (enmWhat=3)
265293c.2ac4: NtCreateFile(\Device\VBoxDrvStub) failed: 0xc0000034 STATUS_OBJECT_NAME_NOT_FOUND (0 retries)
266
267Driver is probably stuck stopping/starting. Try 'sc.exe query vboxdrv' to get more information about its state. Rebooting may actually help.
2689d4.9d8: supR3HardenedWinCheckChild: enmRequest=2 rc=-101 enmWhat=3 supR3HardenedWinReSpawn: NtCreateFile(\Device\VBoxDrvStub) failed: 0xc0000034 STATUS_OBJECT_NAME_NOT_FOUND (0 retries)
269
270Driver is probably stuck stopping/starting. Try 'sc.exe query vboxdrv' to get more information about its state. Rebooting may actually help.
2719d4.9d8: Error -101 in supR3HardenedWinReSpawn! (enmWhat=3)
2729d4.9d8: NtCreateFile(\Device\VBoxDrvStub) failed: 0xc0000034 STATUS_OBJECT_NAME_NOT_FOUND (0 retries)
273
274Driver is probably stuck stopping/starting. Try 'sc.exe query vboxdrv' to get more information about its state. Rebooting may actually help.

© 2024 Oracle Support Privacy / Do Not Sell My Info Terms of Use Trademark Policy Automated Access Etiquette