Skip to Main Content

Infrastructure Software

Announcement

For appeals, questions and feedback about Oracle Forums, please email oracle-forums-moderators_us@oracle.com. Technical questions should be asked in the appropriate category. Thank you!

VirtualBox doesn't run anything

3338564Oct 31 2016 — edited Apr 12 2017

VirtualBox doesn't seem to work for me. I already uninstalled every firewall and antivirus programs but still everytime I try to run a machine, VirtualBox crashes with the following message:

Failed to open a session for the virtual machine XXX.

The virtual machine '*' has terminated unexpectedly during startup with exit code -1073741819 (0xc0000005). More details may be available in 'C:\Users\********\VirtualBox VMs\XXX\Logs\VBoxHardening.log'.

Result Code: E_FAIL (0x80004005)
Component: MachineWrap
Interface: IMachine {b2547866-a0a1-4391-8b86-6952d82efaa0}

The log-file:

2028.2244: Log file opened: 5.1.8r111374 g_hStartupLog=000000000000021c g_uNtVerCombined=0x63258000

2028.2244: \SystemRoot\System32\ntdll.dll:

2028.2244:     CreationTime:    2016-10-29T10:56:34.096114200Z

2028.2244:     LastWriteTime:   2016-10-29T10:56:34.195121200Z

2028.2244:     ChangeTime:      2016-10-29T13:40:11.316479900Z

2028.2244:     FileAttributes:  0x20

2028.2244:     Size:            0x1a8178

2028.2244:     NT Headers:      0xd8

2028.2244:     Timestamp:       0x57ae642e

2028.2244:     Machine:         0x8664 - amd64

2028.2244:     Timestamp:       0x57ae642e

2028.2244:     Image Version:   6.3

2028.2244:     SizeOfImage:     0x1ad000 (1757184)

2028.2244:     Resource Dir:    0x149000 LB 0x624a0

2028.2244:     ProductName:     Microsoft® Windows® Operating System

2028.2244:     ProductVersion:  6.3.9600.18438

2028.2244:     FileVersion:     6.3.9600.18438 (winblue_ltsb.160812-0914)

2028.2244:     FileDescription: NT Layer DLL

2028.2244: \SystemRoot\System32\kernel32.dll:

2028.2244:     CreationTime:    2015-09-06T16:31:15.623103500Z

2028.2244:     LastWriteTime:   2014-10-29T04:09:24.572407200Z

2028.2244:     ChangeTime:      2016-10-29T13:31:10.746839600Z

2028.2244:     FileAttributes:  0x20

2028.2244:     Size:            0x13fc30

2028.2244:     NT Headers:      0xf8

2028.2244:     Timestamp:       0x545054ca

2028.2244:     Machine:         0x8664 - amd64

2028.2244:     Timestamp:       0x545054ca

2028.2244:     Image Version:   6.3

2028.2244:     SizeOfImage:     0x13e000 (1302528)

2028.2244:     Resource Dir:    0x12e000 LB 0x518

2028.2244:     ProductName:     Microsoft® Windows® Operating System

2028.2244:     ProductVersion:  6.3.9600.17415

2028.2244:     FileVersion:     6.3.9600.17415 (winblue_r4.141028-1500)

2028.2244:     FileDescription: Windows NT BASE API Client DLL

2028.2244: \SystemRoot\System32\KernelBase.dll:

2028.2244:     CreationTime:    2016-10-29T10:05:47.514127100Z

2028.2244:     LastWriteTime:   2016-10-29T10:05:47.658136600Z

2028.2244:     ChangeTime:      2016-10-29T13:31:10.881760500Z

2028.2244:     FileAttributes:  0x20

2028.2244:     Size:            0x114cb0

2028.2244:     NT Headers:      0xf0

2028.2244:     Timestamp:       0x569e7eb1

2028.2244:     Machine:         0x8664 - amd64

2028.2244:     Timestamp:       0x569e7eb1

2028.2244:     Image Version:   6.3

2028.2244:     SizeOfImage:     0x115000 (1134592)

2028.2244:     Resource Dir:    0x110000 LB 0x3530

2028.2244:     ProductName:     Microsoft® Windows® Operating System

2028.2244:     ProductVersion:  6.3.9600.18202

2028.2244:     FileVersion:     6.3.9600.18202 (winblue_ltsb.160119-0600)

2028.2244:     FileDescription: Windows NT BASE API Client DLL

2028.2244: \SystemRoot\System32\apisetschema.dll:

2028.2244:     CreationTime:    2013-08-22T12:13:09.745625900Z

2028.2244:     LastWriteTime:   2013-08-22T12:35:12.091034400Z

2028.2244:     ChangeTime:      2015-09-06T13:04:57.236188800Z

2028.2244:     FileAttributes:  0x20

2028.2244:     Size:            0x11360

2028.2244:     NT Headers:      0xd0

2028.2244:     Timestamp:       0x52160049

2028.2244:     Machine:         0x8664 - amd64

2028.2244:     Timestamp:       0x52160049

2028.2244:     Image Version:   6.3

2028.2244:     SizeOfImage:     0x13000 (77824)

2028.2244:     Resource Dir:    0x11000 LB 0x3f8

2028.2244:     ProductName:     Microsoft® Windows® Operating System

2028.2244:     ProductVersion:  6.3.9600.16384

2028.2244:     FileVersion:     6.3.9600.16384 (winblue_rtm.130821-1623)

2028.2244:     FileDescription: ApiSet Schema DLL

2028.2244: NtOpenDirectoryObject failed on \Driver: 0xc0000022

2028.2244: supR3HardenedWinFindAdversaries: 0x880

2028.2244: \SystemRoot\System32\drivers\MBAMSwissArmy.sys:

2028.2244:     CreationTime:    2016-06-04T11:56:19.021248300Z

2028.2244:     LastWriteTime:   2016-10-28T14:11:53.502333600Z

2028.2244:     ChangeTime:      2016-10-28T14:11:53.502333600Z

2028.2244:     FileAttributes:  0x20

2028.2244:     Size:            0x2eed8

2028.2244:     NT Headers:      0xe0

2028.2244:     Timestamp:       0x55b855d9

2028.2244:     Machine:         0x8664 - amd64

2028.2244:     Timestamp:       0x55b855d9

2028.2244:     Image Version:   6.1

2028.2244:     SizeOfImage:     0x33000 (208896)

2028.2244:     Resource Dir:    0x31000 LB 0x3b8

2028.2244:     ProductName:     Malwarebytes Anti-Malware

2028.2244:     ProductVersion:  0.3.0.0

2028.2244:     FileVersion:     0.3.0.0

2028.2244:     FileDescription: Malwarebytes Anti-Malware

2028.2244: \SystemRoot\System32\drivers\mwac.sys:

2028.2244:     CreationTime:    2016-06-04T11:55:17.756921200Z

2028.2244:     LastWriteTime:   2016-06-04T11:55:17.933936900Z

2028.2244:     ChangeTime:      2016-06-04T11:55:17.933936900Z

2028.2244:     FileAttributes:  0x20

2028.2244:     Size:            0xff80

2028.2244:     NT Headers:      0xe0

2028.2244:     Timestamp:       0x53a0f444

2028.2244:     Machine:         0x8664 - amd64

2028.2244:     Timestamp:       0x53a0f444

2028.2244:     Image Version:   6.2

2028.2244:     SizeOfImage:     0x13000 (77824)

2028.2244:     Resource Dir:    0x11000 LB 0x3e0

2028.2244:     ProductName:     Malwarebytes Web Access Control

2028.2244:     ProductVersion:  1.0.6.0

2028.2244:     FileVersion:     1.0.6.0

2028.2244:     FileDescription: Malwarebytes Web Access Control

2028.2244: \SystemRoot\System32\drivers\mbamchameleon.sys:

2028.2244:     CreationTime:    2016-06-04T11:55:17.900929500Z

2028.2244:     LastWriteTime:   2016-06-04T11:55:17.962932700Z

2028.2244:     ChangeTime:      2016-06-04T11:55:17.962932700Z

2028.2244:     FileAttributes:  0x20

2028.2244:     Size:            0x22580

2028.2244:     NT Headers:      0xe0

2028.2244:     Timestamp:       0x56a95753

2028.2244:     Machine:         0x8664 - amd64

2028.2244:     Timestamp:       0x56a95753

2028.2244:     Image Version:   6.1

2028.2244:     SizeOfImage:     0x26000 (155648)

2028.2244:     Resource Dir:    0x24000 LB 0xba8

2028.2244:     ProductName:     Malwarebytes Chameleon

2028.2244:     ProductVersion:  1.1.22.0

2028.2244:     FileVersion:     1.1.22.0

2028.2244:     FileDescription: Malwarebytes Chameleon Protection Driver

2028.2244: \SystemRoot\System32\drivers\mbam.sys:

2028.2244:     CreationTime:    2016-06-04T11:55:17.708918300Z

2028.2244:     LastWriteTime:   2016-06-04T11:55:17.902929700Z

2028.2244:     ChangeTime:      2016-06-04T11:55:17.902929700Z

2028.2244:     FileAttributes:  0x20

2028.2244:     Size:            0x6980

2028.2244:     NT Headers:      0xd8

2028.2244:     Timestamp:       0x55ca3257

2028.2244:     Machine:         0x8664 - amd64

2028.2244:     Timestamp:       0x55ca3257

2028.2244:     Image Version:   6.1

2028.2244:     SizeOfImage:     0xa000 (40960)

2028.2244:     Resource Dir:    0x8000 LB 0x3a0

2028.2244:     ProductName:     Malwarebytes Anti-Malware

2028.2244:     ProductVersion:  0.1.16.0

2028.2244:     FileVersion:     0.1.16.0

2028.2244:     FileDescription: Malwarebytes Anti-Malware

2028.2244: \SystemRoot\System32\drivers\cmdguard.sys:

2028.2244:     CreationTime:    2016-08-31T10:50:30.000000000Z

2028.2244:     LastWriteTime:   2016-08-31T10:50:30.000000000Z

2028.2244:     ChangeTime:      2016-10-28T13:37:47.925754700Z

2028.2244:     FileAttributes:  0x20

2028.2244:     Size:            0xd0790

2028.2244:     NT Headers:      0xe0

2028.2244:     Timestamp:       0x57c6a61b

2028.2244:     Machine:         0x8664 - amd64

2028.2244:     Timestamp:       0x57c6a61b

2028.2244:     Image Version:   6.2

2028.2244:     SizeOfImage:     0xd8000 (884736)

2028.2244:     Resource Dir:    0xd5000 LB 0x3c8

2028.2244:     ProductName:     COMODO Internet Security Sandbox Driver

2028.2244:     ProductVersion:  8, 4, 0, 5164

2028.2244:     FileVersion:     8, 4, 0, 5164

2028.2244:     FileDescription: COMODO Internet Security Sandbox Driver

2028.2244: \SystemRoot\System32\drivers\cmderd.sys:

2028.2244:     CreationTime:    2016-08-31T10:50:24.000000000Z

2028.2244:     LastWriteTime:   2016-08-31T10:50:24.000000000Z

2028.2244:     ChangeTime:      2016-10-28T13:37:47.919753900Z

2028.2244:     FileAttributes:  0x20

2028.2244:     Size:            0x7de0

2028.2244:     NT Headers:      0xd0

2028.2244:     Timestamp:       0x57c6a605

2028.2244:     Machine:         0x8664 - amd64

2028.2244:     Timestamp:       0x57c6a605

2028.2244:     Image Version:   6.2

2028.2244:     SizeOfImage:     0xa000 (40960)

2028.2244:     Resource Dir:    0x8000 LB 0x3d0

2028.2244:     ProductName:     COMODO Internet Security Eradication Driver

2028.2244:     ProductVersion:  8, 4, 0, 5164

2028.2244:     FileVersion:     8, 4, 0, 5164

2028.2244:     FileDescription: COMODO Internet Security Eradication Driver

2028.2244: \SystemRoot\System32\drivers\inspect.sys:

2028.2244:     CreationTime:    2016-08-31T10:50:42.000000000Z

2028.2244:     LastWriteTime:   2016-08-31T10:50:42.000000000Z

2028.2244:     ChangeTime:      2016-10-28T13:38:01.182517900Z

2028.2244:     FileAttributes:  0x20

2028.2244:     Size:            0x21d40

2028.2244:     NT Headers:      0xd8

2028.2244:     Timestamp:       0x57c6a609

2028.2244:     Machine:         0x8664 - amd64

2028.2244:     Timestamp:       0x57c6a609

2028.2244:     Image Version:   6.2

2028.2244:     SizeOfImage:     0x22000 (139264)

2028.2244:     Resource Dir:    0x20000 LB 0x3c8

2028.2244:     ProductName:     COMODO Internet Security Firewall Driver

2028.2244:     ProductVersion:  8, 4, 0, 5164

2028.2244:     FileVersion:     8, 4, 0, 5164

2028.2244:     FileDescription: COMODO Internet Security Firewall Driver

2028.2244: \SystemRoot\System32\drivers\cmdhlp.sys:

2028.2244:     CreationTime:    2016-08-31T10:50:36.000000000Z

2028.2244:     LastWriteTime:   2016-08-31T10:50:36.000000000Z

2028.2244:     ChangeTime:      2016-10-28T13:37:48.929811900Z

2028.2244:     FileAttributes:  0x20

2028.2244:     Size:            0xb218

2028.2244:     NT Headers:      0xd8

2028.2244:     Timestamp:       0x57c6a60d

2028.2244:     Machine:         0x8664 - amd64

2028.2244:     Timestamp:       0x57c6a60d

2028.2244:     Image Version:   6.2

2028.2244:     SizeOfImage:     0xc000 (49152)

2028.2244:     Resource Dir:    0xa000 LB 0x3c0

2028.2244:     ProductName:     COMODO Internet Security Helper Driver

2028.2244:     ProductVersion:  8, 4, 0, 5164

2028.2244:     FileVersion:     8, 4, 0, 5164

2028.2244:     FileDescription: COMODO Internet Security Helper Driver

2028.2244: \SystemRoot\System32\guard64.dll:

2028.2244:     CreationTime:    2016-09-14T22:07:02.000000000Z

2028.2244:     LastWriteTime:   2016-09-14T22:07:02.000000000Z

2028.2244:     ChangeTime:      2016-10-28T13:37:44.027533800Z

2028.2244:     FileAttributes:  0x20

2028.2244:     Size:            0xc6b00

2028.2244:     NT Headers:      0x108

2028.2244:     Timestamp:       0x57d9cefe

2028.2244:     Machine:         0x8664 - amd64

2028.2244:     Timestamp:       0x57d9cefe

2028.2244:     Image Version:   0.0

2028.2244:     SizeOfImage:     0xca000 (827392)

2028.2244:     Resource Dir:    0xc7000 LB 0xd80

2028.2244:     ProductName:     COMODO Internet Security

2028.2244:     ProductVersion:  8, 4, 0, 5165

2028.2244:     FileVersion:     8, 4, 0, 5165

2028.2244:     FileDescription: COMODO Internet Security

2028.2244: \SystemRoot\System32\cmdvrt64.dll:

2028.2244:     CreationTime:    2016-09-14T22:05:08.000000000Z

2028.2244:     LastWriteTime:   2016-09-14T22:05:08.000000000Z

2028.2244:     ChangeTime:      2016-10-28T13:37:44.020528700Z

2028.2244:     FileAttributes:  0x20

2028.2244:     Size:            0x594b8

2028.2244:     NT Headers:      0x100

2028.2244:     Timestamp:       0x57d9cf01

2028.2244:     Machine:         0x8664 - amd64

2028.2244:     Timestamp:       0x57d9cf01

2028.2244:     Image Version:   0.0

2028.2244:     SizeOfImage:     0x5d000 (380928)

2028.2244:     Resource Dir:    0x5b000 LB 0x5ac

2028.2244:     ProductName:     COMODO Internet Security

2028.2244:     ProductVersion:  8, 4, 0, 5165

2028.2244:     FileVersion:     8, 4, 0, 5165

2028.2244:     FileDescription: COMODO Internet Security

2028.2244: \SystemRoot\System32\cmdkbd64.dll:

2028.2244:     CreationTime:    2016-09-14T22:04:14.000000000Z

2028.2244:     LastWriteTime:   2016-09-14T22:04:14.000000000Z

2028.2244:     ChangeTime:      2016-10-28T13:37:44.015528800Z

2028.2244:     FileAttributes:  0x20

2028.2244:     Size:            0xcab8

2028.2244:     NT Headers:      0xe8

2028.2244:     Timestamp:       0x57d9ceee

2028.2244:     Machine:         0x8664 - amd64

2028.2244:     Timestamp:       0x57d9ceee

2028.2244:     Image Version:   0.0

2028.2244:     SizeOfImage:     0xf000 (61440)

2028.2244:     Resource Dir:    0xd000 LB 0x5ac

2028.2244:     ProductName:     COMODO Internet Security

2028.2244:     ProductVersion:  8, 4, 0, 5165

2028.2244:     FileVersion:     8, 4, 0, 5165

2028.2244:     FileDescription: COMODO Internet Security

2028.2244: \SystemRoot\System32\cmdcsr.dll:

2028.2244:     CreationTime:    2016-09-14T22:07:20.000000000Z

2028.2244:     LastWriteTime:   2016-09-14T22:07:20.000000000Z

2028.2244:     ChangeTime:      2016-10-28T13:37:43.926523100Z

2028.2244:     FileAttributes:  0x20

2028.2244:     Size:            0xca58

2028.2244:     NT Headers:      0xd8

2028.2244:     Timestamp:       0x57d9ceeb

2028.2244:     Machine:         0x8664 - amd64

2028.2244:     Timestamp:       0x57d9ceeb

2028.2244:     Image Version:   0.0

2028.2244:     SizeOfImage:     0xc000 (49152)

2028.2244:     Resource Dir:    0xa000 LB 0x4a8

2028.2244:     ProductName:     COMODO Internet Security

2028.2244:     ProductVersion:  8, 4, 0, 5165

2028.2244:     FileVersion:     8, 4, 0, 5165

2028.2244:     FileDescription: COMODO Internet Security

2028.2244: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'

2028.2244: Calling main()

2028.2244: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2

2028.2244: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'

2028.2244: SUPR3HardenedMain: Respawn #1

2028.2244: System32:  \Device\HarddiskVolume2\Windows\System32

2028.2244: WinSxS:    \Device\HarddiskVolume2\Windows\WinSxS

2028.2244: KnownDllPath: C:\Windows\system32

2028.2244: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports

2028.2244: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe)

2028.2244: supR3HardNtEnableThreadCreation:

2028.2244: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ff851e88c80 pvNtTerminateThread=00007ff851f00be0

2028.2244: supR3HardenedWinDoReSpawn(1): New child 2360.1c88 [kernel32].

2028.2244: supR3HardNtChildGatherData: PebBaseAddress=00007ff71031a000 cbPeb=0x388

2028.2244: supR3HardNtPuChFindNtdll: uNtDllParentAddr=00007ff851e70000 uNtDllChildAddr=00007ff851e70000

2028.2244: supR3HardenedWinSetupChildInit: uLdrInitThunk=00007ff851e88c80

2028.2244: supR3HardenedWinSetupChildInit: Start child.

2028.2244: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.

2028.2244: supR3HardNtChildPurify: Startup delay kludge #1/0: 513 ms, 57 sleeps

2028.2244: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION

2028.2244:  *0000000000000000-ffffffffff8dffff 0x0001/0x0000 0x0000000

2028.2244:  *0000000000720000-00000000006fffff 0x0004/0x0004 0x0020000

2028.2244:  *0000000000740000-0000000000730fff 0x0002/0x0002 0x0040000

2028.2244:   000000000074f000-000000000074dfff 0x0001/0x0000 0x0000000

2028.2244:  *0000000000750000-0000000000654fff 0x0000/0x0004 0x0020000

2028.2244:   000000000084b000-0000000000847fff 0x0104/0x0004 0x0020000

2028.2244:   000000000084e000-000000000084bfff 0x0004/0x0004 0x0020000

2028.2244:  *0000000000850000-000000000084bfff 0x0002/0x0002 0x0040000

2028.2244:   0000000000854000-0000000000847fff 0x0001/0x0000 0x0000000

2028.2244:  *0000000000860000-000000000085dfff 0x0004/0x0004 0x0020000

2028.2244:   0000000000862000-0000000000853fff 0x0001/0x0000 0x0000000

2028.2244:  *0000000000870000-000000000086efff 0x0040/0x0040 0x0020000 !!

2028.2244: supHardNtVpFreeOrReplacePrivateExecMemory: Freeing exec mem at 0000000000870000 (LB 0x1000, 0000000000870000 LB 0x1000)

2028.2244: supHardNtVpFreeOrReplacePrivateExecMemory: Free attempt #1 succeeded: 0x0 [0000000000870000/0000000000870000 LB 0/0x1000]

2028.2244: supHardNtVpFreeOrReplacePrivateExecMemory: QVM after free 0: [0000000000000000]/0000000000870000 LB 0x7f770000 s=0x10000 ap=0x0 rp=0xcccccccc00000001

2028.2244:   0000000000871000-ffffffff81101fff 0x0001/0x0000 0x0000000

2028.2244:  *000000007ffe0000-000000007ffdefff 0x0002/0x0002 0x0020000

2028.2244:   000000007ffe1000-000000007ffd1fff 0x0000/0x0002 0x0020000

2028.2244:   000000007fff0000-ffff8009efceffff 0x0001/0x0000 0x0000000

2028.2244:  *00007ff7102f0000-00007ff7102ccfff 0x0002/0x0002 0x0040000

2028.2244:   00007ff710313000-00007ff71030bfff 0x0001/0x0000 0x0000000

2028.2244:  *00007ff71031a000-00007ff710318fff 0x0004/0x0004 0x0020000

2028.2244:   00007ff71031b000-00007ff710317fff 0x0001/0x0000 0x0000000

2028.2244:  *00007ff71031e000-00007ff71031bfff 0x0004/0x0004 0x0020000

2028.2244:   00007ff710320000-00007ff70fd4ffff 0x0001/0x0000 0x0000000

2028.2244:  *00007ff7108f0000-00007ff7108f0fff 0x0002/0x0080 0x1000000  \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe

2028.2244:   00007ff7108f1000-00007ff71095ffff 0x0020/0x0080 0x1000000  \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe

2028.2244:   00007ff710960000-00007ff710960fff 0x0080/0x0080 0x1000000  \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe

2028.2244:   00007ff710961000-00007ff7109a5fff 0x0002/0x0080 0x1000000  \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe

2028.2244:   00007ff7109a6000-00007ff7109a6fff 0x0004/0x0080 0x1000000  \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe

2028.2244:   00007ff7109a7000-00007ff7109a7fff 0x0008/0x0080 0x1000000  \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe

2028.2244:   00007ff7109a8000-00007ff7109acfff 0x0004/0x0080 0x1000000  \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe

2028.2244:   00007ff7109ad000-00007ff7109adfff 0x0008/0x0080 0x1000000  \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe

2028.2244:   00007ff7109ae000-00007ff7109aefff 0x0004/0x0080 0x1000000  \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe

2028.2244:   00007ff7109af000-00007ff7109b2fff 0x0008/0x0080 0x1000000  \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe

2028.2244:   00007ff7109b3000-00007ff7109fafff 0x0002/0x0080 0x1000000  \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe

2028.2244:   00007ff7109fb000-00007ff5cf585fff 0x0001/0x0000 0x0000000

2028.2244:  *00007ff851e70000-00007ff851e70fff 0x0002/0x0080 0x1000000  \Device\HarddiskVolume2\Windows\System32\ntdll.dll

2028.2244:   00007ff851e71000-00007ff851f9dfff 0x0020/0x0080 0x1000000  \Device\HarddiskVolume2\Windows\System32\ntdll.dll

2028.2244:   00007ff851f9e000-00007ff851fa3fff 0x0008/0x0080 0x1000000  \Device\HarddiskVolume2\Windows\System32\ntdll.dll

2028.2244:   00007ff851fa4000-00007ff851fb0fff 0x0002/0x0080 0x1000000  \Device\HarddiskVolume2\Windows\System32\ntdll.dll

2028.2244:   00007ff851fb1000-00007ff851fb1fff 0x0004/0x0080 0x1000000  \Device\HarddiskVolume2\Windows\System32\ntdll.dll

2028.2244:   00007ff851fb2000-00007ff851fb4fff 0x0008/0x0080 0x1000000  \Device\HarddiskVolume2\Windows\System32\ntdll.dll

2028.2244:   00007ff851fb5000-00007ff851fb5fff 0x0010/0x0080 0x1000000  \Device\HarddiskVolume2\Windows\System32\ntdll.dll

2028.2244:   00007ff851fb6000-00007ff85201cfff 0x0002/0x0080 0x1000000  \Device\HarddiskVolume2\Windows\System32\ntdll.dll

2028.2244:   00007ff85201d000-00007ff852009fff 0x0001/0x0000 0x0000000

2028.2244:  *00007ff852030000-00007ff85202efff 0x0040/0x0040 0x0020000 !!

2028.2244: supHardNtVpFreeOrReplacePrivateExecMemory: Freeing exec mem at 00007ff852030000 (LB 0x1000, 00007ff852030000 LB 0x1000)

2028.2244: supHardNtVpFreeOrReplacePrivateExecMemory: Free attempt #1 succeeded: 0x0 [00007ff852030000/00007ff852030000 LB 0/0x1000]

2028.2244: supHardNtVpFreeOrReplacePrivateExecMemory: QVM after free 0: [0000000000000000]/00007ff852030000 LB 0x7adfb0000 s=0x10000 ap=0x0 rp=0xcccccccc00000001

2028.2244:   00007ff852031000-00007ff0a4081fff 0x0001/0x0000 0x0000000

2028.2244:  *00007ffffffe0000-00007ffffffcffff 0x0001/0x0002 0x0020000

2028.2244: VirtualBox.exe: timestamp 0x58062715 (rc=VINF_SUCCESS)

2028.2244: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports

2028.2244: '\Device\HarddiskVolume2\Windows\System32\ntdll.dll' has no imports

2028.2244: ntdll.dll: Differences in section #1 (.text) between file and memory:

2028.2244:   00007ff851f02070 / 0x0092070: 4c != e9

2028.2244:   00007ff851f02072 / 0x0092072: d1 != df

2028.2244:   00007ff851f02073 / 0x0092073: b8 != 12

2028.2244:   00007ff851f02074 / 0x0092074: 9b != 00

2028.2244:   Restored 0x2000 bytes of original file content at 00007ff851f00c8e

2028.2244: supR3HardNtChildPurify: cFixes=3 g_fSupAdversaries=0x880

2028.2244: supR3HardNtChildPurify: Startup delay kludge #1/1: 513 ms, 57 sleeps

2028.2244: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION

2028.2244:  *0000000000000000-ffffffffff8dffff 0x0001/0x0000 0x0000000

2028.2244:  *0000000000720000-00000000006fffff 0x0004/0x0004 0x0020000

2028.2244:  *0000000000740000-0000000000730fff 0x0002/0x0002 0x0040000

2028.2244:   000000000074f000-000000000074dfff 0x0001/0x0000 0x0000000

2028.2244:  *0000000000750000-0000000000654fff 0x0000/0x0004 0x0020000

2028.2244:   000000000084b000-0000000000847fff 0x0104/0x0004 0x0020000

2028.2244:   000000000084e000-000000000084bfff 0x0004/0x0004 0x0020000

2028.2244:  *0000000000850000-000000000084bfff 0x0002/0x0002 0x0040000

2028.2244:   0000000000854000-0000000000847fff 0x0001/0x0000 0x0000000

2028.2244:  *0000000000860000-000000000085dfff 0x0004/0x0004 0x0020000

2028.2244:   0000000000862000-ffffffff810e3fff 0x0001/0x0000 0x0000000

2028.2244:  *000000007ffe0000-000000007ffdefff 0x0002/0x0002 0x0020000

2028.2244:   000000007ffe1000-000000007ffd1fff 0x0000/0x0002 0x0020000

2028.2244:   000000007fff0000-ffff8009efceffff 0x0001/0x0000 0x0000000

2028.2244:  *00007ff7102f0000-00007ff7102ccfff 0x0002/0x0002 0x0040000

2028.2244:   00007ff710313000-00007ff71030bfff 0x0001/0x0000 0x0000000

2028.2244:  *00007ff71031a000-00007ff710318fff 0x0004/0x0004 0x0020000

2028.2244:   00007ff71031b000-00007ff710317fff 0x0001/0x0000 0x0000000

2028.2244:  *00007ff71031e000-00007ff71031bfff 0x0004/0x0004 0x0020000

2028.2244:   00007ff710320000-00007ff70fd4ffff 0x0001/0x0000 0x0000000

2028.2244:  *00007ff7108f0000-00007ff7108f0fff 0x0002/0x0080 0x1000000  \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe

2028.2244:   00007ff7108f1000-00007ff71095ffff 0x0020/0x0080 0x1000000  \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe

2028.2244:   00007ff710960000-00007ff710960fff 0x0040/0x0080 0x1000000  \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe

2028.2244:   00007ff710961000-00007ff7109a5fff 0x0002/0x0080 0x1000000  \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe

2028.2244:   00007ff7109a6000-00007ff7109b2fff 0x0004/0x0080 0x1000000  \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe

2028.2244:   00007ff7109b3000-00007ff7109fafff 0x0002/0x0080 0x1000000  \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe

2028.2244:   00007ff7109fb000-00007ff5cf585fff 0x0001/0x0000 0x0000000

2028.2244:  *00007ff851e70000-00007ff851e70fff 0x0002/0x0080 0x1000000  \Device\HarddiskVolume2\Windows\System32\ntdll.dll

2028.2244:   00007ff851e71000-00007ff851f9dfff 0x0020/0x0080 0x1000000  \Device\HarddiskVolume2\Windows\System32\ntdll.dll

2028.2244:   00007ff851f9e000-00007ff851fa3fff 0x0004/0x0080 0x1000000  \Device\HarddiskVolume2\Windows\System32\ntdll.dll

2028.2244:   00007ff851fa4000-00007ff851fb0fff 0x0002/0x0080 0x1000000  \Device\HarddiskVolume2\Windows\System32\ntdll.dll

2028.2244:   00007ff851fb1000-00007ff851fb4fff 0x0004/0x0080 0x1000000  \Device\HarddiskVolume2\Windows\System32\ntdll.dll

2028.2244:   00007ff851fb5000-00007ff851fb5fff 0x0010/0x0080 0x1000000  \Device\HarddiskVolume2\Windows\System32\ntdll.dll

2028.2244:   00007ff851fb6000-00007ff85201cfff 0x0002/0x0080 0x1000000  \Device\HarddiskVolume2\Windows\System32\ntdll.dll

2028.2244:   00007ff85201d000-00007ff0a4059fff 0x0001/0x0000 0x0000000

2028.2244:  *00007ffffffe0000-00007ffffffcffff 0x0001/0x0002 0x0020000

2028.2244: supR3HardNtChildPurify: Done after 1184 ms and 3 fixes (loop #1).

2028.2244: supR3HardNtEnableThreadCreation:

2360.1c88: Log file opened: 5.1.8r111374 g_hStartupLog=0000000000000004 g_uNtVerCombined=0x63258000

2360.1c88: supR3HardenedVmProcessInit: uNtDllAddr=00007ff851e70000 g_uNtVerCombined=0x63258000

2360.1c88: ntdll.dll: timestamp 0x57ae642e (rc=VINF_SUCCESS)

2360.1c88: New simple heap: #1 0000000000970000 LB 0x400000 (for 1757184 allocation)

2360.1c88: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'

2360.1c88: System32:  \Device\HarddiskVolume2\Windows\System32

2360.1c88: WinSxS:    \Device\HarddiskVolume2\Windows\WinSxS

2360.1c88: KnownDllPath: C:\Windows\system32

2360.1c88: supR3HardenedVmProcessInit: Opening vboxdrv stub...

2360.1c88: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...

2360.1c88: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...

2360.1c88: Registered Dll notification callback with NTDLL.

2360.1c88: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\kernel32.dll)

2360.1c88: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\kernel32.dll

2360.1c88: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\KERNEL32.DLL (Input=KERNEL32.DLL, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000801:<flags> [calling]

2360.1c88: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]

2360.1c88: supR3HardenedDllNotificationCallback: load   00007ff84f110000 LB 0x00115000 C:\Windows\system32\KERNELBASE.dll [fFlags=0x0]

2360.1c88: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Windows\System32\KernelBase.dll)

2360.1c88: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\KernelBase.dll

2360.1c88: supR3HardenedDllNotificationCallback: load   00007ff84f5c0000 LB 0x0013e000 C:\Windows\system32\KERNEL32.DLL [fFlags=0x0]

2360.1c88: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]

2360.1c88: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff84f5c0000 'C:\Windows\system32\KERNEL32.DLL'

2360.1c88: supR3HardenedDllNotificationCallback: load   00007ff7108f0000 LB 0x0010b000 C:\Program Files\Oracle\VirtualBox\VirtualBox.exe [fFlags=0x0]

2360.1c88: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports

2360.1c88: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe)

2360.1c88: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe

2028.2244: supR3HardNtChildWaitFor[1]: Quitting: ExitCode=0xc0000005 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 117 ms, CloseEvents);

How do I fix this?

Regards

Christian

Comments
Post Details
Added on Oct 31 2016
6 comments
17,279 views