Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 37c.1fe4: Log file opened: 5.1.12r112440 g_hStartupLog=0000000000000074 g_uNtVerCombined=0x611db110
- 37c.1fe4: \SystemRoot\System32\ntdll.dll:
- 37c.1fe4: CreationTime: 2010-11-21T03:23:51.351694200Z
- 37c.1fe4: LastWriteTime: 2010-11-21T03:23:51.367294200Z
- 37c.1fe4: ChangeTime: 2016-12-14T23:11:41.388944700Z
- 37c.1fe4: FileAttributes: 0x20
- 37c.1fe4: Size: 0x1a6d60
- 37c.1fe4: NT Headers: 0xe0
- 37c.1fe4: Timestamp: 0x4ce7c8f9
- 37c.1fe4: Machine: 0x8664 - amd64
- 37c.1fe4: Timestamp: 0x4ce7c8f9
- 37c.1fe4: Image Version: 6.1
- 37c.1fe4: SizeOfImage: 0x1a9000 (1740800)
- 37c.1fe4: Resource Dir: 0x151000 LB 0x560d8
- 37c.1fe4: ProductName: Microsoft® Windows® Operating System
- 37c.1fe4: ProductVersion: 6.1.7601.17514
- 37c.1fe4: FileVersion: 6.1.7601.17514 (win7sp1_rtm.101119-1850)
- 37c.1fe4: FileDescription: NT Layer DLL
- 37c.1fe4: \SystemRoot\System32\kernel32.dll:
- 37c.1fe4: CreationTime: 2010-11-21T03:24:07.965723400Z
- 37c.1fe4: LastWriteTime: 2010-11-21T03:24:07.981323400Z
- 37c.1fe4: ChangeTime: 2016-12-14T23:11:08.145286300Z
- 37c.1fe4: FileAttributes: 0x20
- 37c.1fe4: Size: 0x11b800
- 37c.1fe4: NT Headers: 0xe8
- 37c.1fe4: Timestamp: 0x4ce7c78b
- 37c.1fe4: Machine: 0x8664 - amd64
- 37c.1fe4: Timestamp: 0x4ce7c78b
- 37c.1fe4: Image Version: 6.1
- 37c.1fe4: SizeOfImage: 0x11f000 (1175552)
- 37c.1fe4: Resource Dir: 0x116000 LB 0x528
- 37c.1fe4: ProductName: Microsoft® Windows® Operating System
- 37c.1fe4: ProductVersion: 6.1.7601.17514
- 37c.1fe4: FileVersion: 6.1.7601.17514 (win7sp1_rtm.101119-1850)
- 37c.1fe4: FileDescription: Windows NT BASE API Client DLL
- 37c.1fe4: \SystemRoot\System32\KernelBase.dll:
- 37c.1fe4: CreationTime: 2010-11-21T03:24:26.217755400Z
- 37c.1fe4: LastWriteTime: 2010-11-21T03:24:26.248955500Z
- 37c.1fe4: ChangeTime: 2016-12-14T23:11:08.176486400Z
- 37c.1fe4: FileAttributes: 0x20
- 37c.1fe4: Size: 0x66800
- 37c.1fe4: NT Headers: 0xf0
- 37c.1fe4: Timestamp: 0x4ce7c78c
- 37c.1fe4: Machine: 0x8664 - amd64
- 37c.1fe4: Timestamp: 0x4ce7c78c
- 37c.1fe4: Image Version: 6.1
- 37c.1fe4: SizeOfImage: 0x6b000 (438272)
- 37c.1fe4: Resource Dir: 0x69000 LB 0x530
- 37c.1fe4: ProductName: Microsoft® Windows® Operating System
- 37c.1fe4: ProductVersion: 6.1.7601.17514
- 37c.1fe4: FileVersion: 6.1.7601.17514 (win7sp1_rtm.101119-1850)
- 37c.1fe4: FileDescription: Windows NT BASE API Client DLL
- 37c.1fe4: \SystemRoot\System32\apisetschema.dll:
- 37c.1fe4: CreationTime: 2009-07-13T23:18:54.866423200Z
- 37c.1fe4: LastWriteTime: 2009-07-14T01:24:53.779000000Z
- 37c.1fe4: ChangeTime: 2016-12-14T23:10:45.572046700Z
- 37c.1fe4: FileAttributes: 0x20
- 37c.1fe4: Size: 0x1a00
- 37c.1fe4: NT Headers: 0xc0
- 37c.1fe4: Timestamp: 0x4a5bdeab
- 37c.1fe4: Machine: 0x8664 - amd64
- 37c.1fe4: Timestamp: 0x4a5bdeab
- 37c.1fe4: Image Version: 6.1
- 37c.1fe4: SizeOfImage: 0x50000 (327680)
- 37c.1fe4: Resource Dir: 0x30000 LB 0x3f0
- 37c.1fe4: ProductName: Microsoft® Windows® Operating System
- 37c.1fe4: ProductVersion: 6.1.7600.16385
- 37c.1fe4: FileVersion: 6.1.7600.16385 (win7_rtm.090713-1255)
- 37c.1fe4: FileDescription: ApiSet Schema DLL
- 37c.1fe4: supR3HardenedWinFindAdversaries: 0x0
- 37c.1fe4: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
- 37c.1fe4: Calling main()
- 37c.1fe4: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
- 37c.1fe4: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
- 37c.1fe4: SUPR3HardenedMain: Respawn #1
- 37c.1fe4: System32: \Device\HarddiskVolume2\Windows\System32
- 37c.1fe4: WinSxS: \Device\HarddiskVolume2\Windows\winsxs
- 37c.1fe4: KnownDllPath: C:\Windows\system32
- 37c.1fe4: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
- 37c.1fe4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe)
- 37c.1fe4: supR3HardNtEnableThreadCreation:
- 37c.1fe4: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00000000776dc320 pvNtTerminateThread=0000000077701840
- 37c.1fe4: supR3HardenedWinDoReSpawn(1): New child b20.a6c [kernel32].
- 37c.1fe4: supR3HardNtChildGatherData: PebBaseAddress=000007fffffd8000 cbPeb=0x380
- 37c.1fe4: supR3HardNtPuChFindNtdll: uNtDllParentAddr=00000000776b0000 uNtDllChildAddr=00000000776b0000
- 37c.1fe4: supR3HardenedWinSetupChildInit: uLdrInitThunk=00000000776dc320
- 37c.1fe4: supR3HardenedWinSetupChildInit: Start child.
- 37c.1fe4: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
- 37c.1fe4: supR3HardNtChildPurify: Startup delay kludge #1/0: 257 ms, 32 sleeps
- 37c.1fe4: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
- 37c.1fe4: *0000000000000000-fffffffffffeffff 0x0001/0x0000 0x0000000
- 37c.1fe4: *0000000000010000-fffffffffffeffff 0x0004/0x0004 0x0020000
- 37c.1fe4: *0000000000030000-000000000002bfff 0x0002/0x0002 0x0040000
- 37c.1fe4: 0000000000034000-0000000000027fff 0x0001/0x0000 0x0000000
- 37c.1fe4: *0000000000040000-000000000003efff 0x0004/0x0004 0x0020000
- 37c.1fe4: 0000000000041000-0000000000031fff 0x0001/0x0000 0x0000000
- 37c.1fe4: *0000000000050000-000000000004efff 0x0004/0x0004 0x0020000
- 37c.1fe4: 0000000000051000-0000000000041fff 0x0001/0x0000 0x0000000
- 37c.1fe4: *0000000000060000-000000000005efff 0x0040/0x0040 0x0020000 !!
- 37c.1fe4: supHardNtVpFreeOrReplacePrivateExecMemory: Freeing exec mem at 0000000000060000 (LB 0x1000, 0000000000060000 LB 0x1000)
- 37c.1fe4: supHardNtVpFreeOrReplacePrivateExecMemory: Free attempt #1 succeeded: 0x0 [0000000000060000/0000000000060000 LB 0/0x1000]
- 37c.1fe4: supHardNtVpFreeOrReplacePrivateExecMemory: QVM after free 0: [0000000000000000]/0000000000060000 LB 0x80000 s=0x10000 ap=0x0 rp=0xcccccccc00000001
- 37c.1fe4: 0000000000061000-fffffffffffe1fff 0x0001/0x0000 0x0000000
- 37c.1fe4: *00000000000e0000-fffffffffffe3fff 0x0000/0x0004 0x0020000
- 37c.1fe4: 00000000001dc000-00000000001d9fff 0x0104/0x0004 0x0020000
- 37c.1fe4: 00000000001de000-00000000001dbfff 0x0004/0x0004 0x0020000
- 37c.1fe4: 00000000001e0000-ffffffff88d0ffff 0x0001/0x0000 0x0000000
- 37c.1fe4: *00000000776b0000-00000000776b0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
- 37c.1fe4: 00000000776b1000-00000000777b2fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
- 37c.1fe4: 00000000777b3000-00000000777e1fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
- 37c.1fe4: 00000000777e2000-00000000777edfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
- 37c.1fe4: 00000000777ee000-0000000077858fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
- 37c.1fe4: 0000000077859000-00000000700d1fff 0x0001/0x0000 0x0000000
- 37c.1fe4: *000000007efe0000-000000007dfdffff 0x0000/0x0002 0x0020000
- 37c.1fe4: *000000007ffe0000-000000007ffdefff 0x0002/0x0002 0x0020000
- 37c.1fe4: 000000007ffe1000-000000007ffd1fff 0x0000/0x0002 0x0020000
- 37c.1fe4: 000000007fff0000-ffffffffc0ddffff 0x0001/0x0000 0x0000000
- 37c.1fe4: *000000013f200000-000000013f200fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 37c.1fe4: 000000013f201000-000000013f26ffff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 37c.1fe4: 000000013f270000-000000013f270fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 37c.1fe4: 000000013f271000-000000013f2b5fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 37c.1fe4: 000000013f2b6000-000000013f2b6fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 37c.1fe4: 000000013f2b7000-000000013f2b7fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 37c.1fe4: 000000013f2b8000-000000013f2bcfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 37c.1fe4: 000000013f2bd000-000000013f2bdfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 37c.1fe4: 000000013f2be000-000000013f2befff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 37c.1fe4: 000000013f2bf000-000000013f2c2fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 37c.1fe4: 000000013f2c3000-000000013f30afff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 37c.1fe4: 000000013f30b000-fffff8037ec45fff 0x0001/0x0000 0x0000000
- 37c.1fe4: *000007feff9d0000-000007feff9d0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\apisetschema.dll
- 37c.1fe4: 000007feff9d1000-000007fdff3f1fff 0x0001/0x0000 0x0000000
- 37c.1fe4: *000007fffffb0000-000007fffff8cfff 0x0002/0x0002 0x0040000
- 37c.1fe4: 000007fffffd3000-000007fffffcdfff 0x0001/0x0000 0x0000000
- 37c.1fe4: *000007fffffd8000-000007fffffd6fff 0x0004/0x0004 0x0020000
- 37c.1fe4: 000007fffffd9000-000007fffffd3fff 0x0001/0x0000 0x0000000
- 37c.1fe4: *000007fffffde000-000007fffffdbfff 0x0004/0x0004 0x0020000
- 37c.1fe4: *000007fffffe0000-000007fffffcffff 0x0001/0x0002 0x0020000
- 37c.1fe4: apisetschema.dll: timestamp 0x4a5bdeab (rc=VINF_SUCCESS)
- 37c.1fe4: VirtualBox.exe: timestamp 0x58594e7b (rc=VINF_SUCCESS)
- 37c.1fe4: '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
- 37c.1fe4: '\Device\HarddiskVolume2\Windows\System32\apisetschema.dll' has no imports
- 37c.1fe4: '\Device\HarddiskVolume2\Windows\System32\ntdll.dll' has no imports
- 37c.1fe4: supR3HardNtChildPurify: cFixes=1 g_fSupAdversaries=0x80000000 cPatchCount=0
- 37c.1fe4: supR3HardNtChildPurify: Startup delay kludge #1/1: 516 ms, 63 sleeps
- 37c.1fe4: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
- 37c.1fe4: *0000000000000000-fffffffffffeffff 0x0001/0x0000 0x0000000
- 37c.1fe4: *0000000000010000-fffffffffffeffff 0x0004/0x0004 0x0020000
- 37c.1fe4: *0000000000030000-000000000002bfff 0x0002/0x0002 0x0040000
- 37c.1fe4: 0000000000034000-0000000000027fff 0x0001/0x0000 0x0000000
- 37c.1fe4: *0000000000040000-000000000003efff 0x0004/0x0004 0x0020000
- 37c.1fe4: 0000000000041000-0000000000031fff 0x0001/0x0000 0x0000000
- 37c.1fe4: *0000000000050000-000000000004efff 0x0004/0x0004 0x0020000
- 37c.1fe4: 0000000000051000-fffffffffffc1fff 0x0001/0x0000 0x0000000
- 37c.1fe4: *00000000000e0000-fffffffffffe3fff 0x0000/0x0004 0x0020000
- 37c.1fe4: 00000000001dc000-00000000001d9fff 0x0104/0x0004 0x0020000
- 37c.1fe4: 00000000001de000-00000000001dbfff 0x0004/0x0004 0x0020000
- 37c.1fe4: 00000000001e0000-ffffffff88d0ffff 0x0001/0x0000 0x0000000
- 37c.1fe4: *00000000776b0000-00000000776b0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
- 37c.1fe4: 00000000776b1000-00000000777b2fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
- 37c.1fe4: 00000000777b3000-00000000777e1fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
- 37c.1fe4: 00000000777e2000-00000000777ebfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
- 37c.1fe4: 00000000777ec000-00000000777edfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
- 37c.1fe4: 00000000777ee000-0000000077858fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\ntdll.dll
- 37c.1fe4: 0000000077859000-00000000700d1fff 0x0001/0x0000 0x0000000
- 37c.1fe4: *000000007efe0000-000000007dfdffff 0x0000/0x0002 0x0020000
- 37c.1fe4: *000000007ffe0000-000000007ffdefff 0x0002/0x0002 0x0020000
- 37c.1fe4: 000000007ffe1000-000000007ffd1fff 0x0000/0x0002 0x0020000
- 37c.1fe4: 000000007fff0000-ffffffffc0ddffff 0x0001/0x0000 0x0000000
- 37c.1fe4: *000000013f200000-000000013f200fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 37c.1fe4: 000000013f201000-000000013f26ffff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 37c.1fe4: 000000013f270000-000000013f270fff 0x0040/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 37c.1fe4: 000000013f271000-000000013f2b5fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 37c.1fe4: 000000013f2b6000-000000013f2c2fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 37c.1fe4: 000000013f2c3000-000000013f30afff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Program Files\Oracle\VirtualBox\VirtualBox.exe
- 37c.1fe4: 000000013f30b000-fffff8037ec45fff 0x0001/0x0000 0x0000000
- 37c.1fe4: *000007feff9d0000-000007feff9d0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume2\Windows\System32\apisetschema.dll
- 37c.1fe4: 000007feff9d1000-000007fdff3f1fff 0x0001/0x0000 0x0000000
- 37c.1fe4: *000007fffffb0000-000007fffff8cfff 0x0002/0x0002 0x0040000
- 37c.1fe4: 000007fffffd3000-000007fffffcdfff 0x0001/0x0000 0x0000000
- 37c.1fe4: *000007fffffd8000-000007fffffd6fff 0x0004/0x0004 0x0020000
- 37c.1fe4: 000007fffffd9000-000007fffffd3fff 0x0001/0x0000 0x0000000
- 37c.1fe4: *000007fffffde000-000007fffffdbfff 0x0004/0x0004 0x0020000
- 37c.1fe4: *000007fffffe0000-000007fffffcffff 0x0001/0x0002 0x0020000
- 37c.1fe4: supR3HardNtChildPurify: Done after 1968 ms and 1 fixes (loop #1).
- 37c.1fe4: supR3HardNtEnableThreadCreation:
- b20.a6c: Log file opened: 5.1.12r112440 g_hStartupLog=0000000000000004 g_uNtVerCombined=0x611db100
- b20.a6c: supR3HardenedVmProcessInit: uNtDllAddr=00000000776b0000 g_uNtVerCombined=0x611db100
- b20.a6c: ntdll.dll: timestamp 0x4ce7c8f9 (rc=VINF_SUCCESS)
- b20.a6c: New simple heap: #1 00000000002e0000 LB 0x400000 (for 1740800 allocation)
- b20.a6c: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume2\Program Files\Oracle\VirtualBox'
- b20.a6c: System32: \Device\HarddiskVolume2\Windows\System32
- b20.a6c: WinSxS: \Device\HarddiskVolume2\Windows\winsxs
- b20.a6c: KnownDllPath: C:\Windows\system32
- b20.a6c: supR3HardenedVmProcessInit: Opening vboxdrv stub...
- b20.a6c: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
- b20.a6c: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
- b20.a6c: Registered Dll notification callback with NTDLL.
- b20.a6c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\kernel32.dll)
- b20.a6c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\kernel32.dll
- b20.a6c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\kernel32.dll (Input=kernel32.dll, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000000000:<flags> [calling]
- b20.a6c: supR3HardenedScreenImage/NtCreateSection: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
- b20.a6c: supR3HardenedDllNotificationCallback: load 0000000077490000 LB 0x0011f000 C:\Windows\system32\kernel32.dll [fFlags=0x0]
- b20.a6c: supR3HardenedScreenImage/LdrLoadDll: cache hit (Unknown Status 22900 (0x5974)) on \Device\HarddiskVolume2\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
- b20.a6c: supR3HardenedDllNotificationCallback: load 000007fefd820000 LB 0x0006b000 C:\Windows\system32\KERNELBASE.dll [fFlags=0x0]
- b20.a6c: supHardenedWinVerifyImageByHandle: -> 22900 (\Device\HarddiskVolume2\Windows\System32\KernelBase.dll)
- b20.a6c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume2\Windows\System32\KernelBase.dll
- b20.a6c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=0000000077490000 'C:\Windows\system32\kernel32.dll'
- 37c.1fe4: supR3HardNtChildWaitFor[1]: Quitting: ExitCode=0xc0000005 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 760 ms, CloseEvents);
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement