Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 1830.2334: Log file opened: 4.3.20r96996 g_hStartupLog=0000000000000028 g_uNtVerCombined=0x63258000
- 1830.2334: \SystemRoot\System32\ntdll.dll:
- 1830.2334: CreationTime: 2014-03-18T10:14:36.739928900Z
- 1830.2334: LastWriteTime: 2014-03-18T10:14:36.943083200Z
- 1830.2334: ChangeTime: 2015-03-22T20:02:26.484770300Z
- 1830.2334: FileAttributes: 0x20
- 1830.2334: Size: 0x1a5d10
- 1830.2334: NT Headers: 0xe8
- 1830.2334: Timestamp: 0x530895af
- 1830.2334: Machine: 0x8664 - amd64
- 1830.2334: Timestamp: 0x530895af
- 1830.2334: Image Version: 6.3
- 1830.2334: SizeOfImage: 0x1aa000 (1744896)
- 1830.2334: Resource Dir: 0x145000 LB 0x62450
- 1830.2334: ProductName: Microsoft® Windows® Operating System
- 1830.2334: ProductVersion: 6.3.9600.17031
- 1830.2334: FileVersion: 6.3.9600.17031 (winblue_gdr.140221-1952)
- 1830.2334: FileDescription: NT Layer DLL
- 1830.2334: \SystemRoot\System32\kernel32.dll:
- 1830.2334: CreationTime: 2014-03-18T10:14:49.197174700Z
- 1830.2334: LastWriteTime: 2014-03-18T10:14:49.212801700Z
- 1830.2334: ChangeTime: 2015-03-23T13:50:01.033577300Z
- 1830.2334: FileAttributes: 0x20
- 1830.2334: Size: 0x13b1c0
- 1830.2334: NT Headers: 0xe8
- 1830.2334: Timestamp: 0x53089385
- 1830.2334: Machine: 0x8664 - amd64
- 1830.2334: Timestamp: 0x53089385
- 1830.2334: Image Version: 6.3
- 1830.2334: SizeOfImage: 0x13a000 (1286144)
- 1830.2334: Resource Dir: 0x12a000 LB 0x520
- 1830.2334: ProductName: Microsoft® Windows® Operating System
- 1830.2334: ProductVersion: 6.3.9600.17031
- 1830.2334: FileVersion: 6.3.9600.17031 (winblue_gdr.140221-1952)
- 1830.2334: FileDescription: Windows NT BASE API Client DLL
- 1830.2334: \SystemRoot\System32\KernelBase.dll:
- 1830.2334: CreationTime: 2014-03-18T10:14:36.614929200Z
- 1830.2334: LastWriteTime: 2014-03-18T10:14:36.646181500Z
- 1830.2334: ChangeTime: 2015-03-23T13:50:01.346102100Z
- 1830.2334: FileAttributes: 0x20
- 1830.2334: Size: 0x1109f8
- 1830.2334: NT Headers: 0xf0
- 1830.2334: Timestamp: 0x53089862
- 1830.2334: Machine: 0x8664 - amd64
- 1830.2334: Timestamp: 0x53089862
- 1830.2334: Image Version: 6.3
- 1830.2334: SizeOfImage: 0x110000 (1114112)
- 1830.2334: Resource Dir: 0x10b000 LB 0x3530
- 1830.2334: ProductName: Microsoft® Windows® Operating System
- 1830.2334: ProductVersion: 6.3.9600.17031
- 1830.2334: FileVersion: 6.3.9600.17031 (winblue_gdr.140221-1952)
- 1830.2334: FileDescription: Windows NT BASE API Client DLL
- 1830.2334: \SystemRoot\System32\apisetschema.dll:
- 1830.2334: CreationTime: 2013-08-22T12:13:09.745625900Z
- 1830.2334: LastWriteTime: 2013-08-22T12:35:12.091034400Z
- 1830.2334: ChangeTime: 2015-03-22T20:01:58.062827800Z
- 1830.2334: FileAttributes: 0x20
- 1830.2334: Size: 0x11360
- 1830.2334: NT Headers: 0xd0
- 1830.2334: Timestamp: 0x52160049
- 1830.2334: Machine: 0x8664 - amd64
- 1830.2334: Timestamp: 0x52160049
- 1830.2334: Image Version: 6.3
- 1830.2334: SizeOfImage: 0x13000 (77824)
- 1830.2334: Resource Dir: 0x11000 LB 0x3f8
- 1830.2334: ProductName: Microsoft® Windows® Operating System
- 1830.2334: ProductVersion: 6.3.9600.16384
- 1830.2334: FileVersion: 6.3.9600.16384 (winblue_rtm.130821-1623)
- 1830.2334: FileDescription: ApiSet Schema DLL
- 1830.2334: NtOpenDirectoryObject failed on \Driver: 0xc0000022
- 1830.2334: supR3HardenedWinFindAdversaries: 0x0
- 1830.2334: Calling main()
- 1830.2334: SUPR3HardenedMain: pszProgName=VBoxHeadless fFlags=0x0
- 1830.2334: SUPR3HardenedMain: Respawn #1
- 1830.2334: System32: \Device\HarddiskVolume4\Windows\System32
- 1830.2334: WinSxS: \Device\HarddiskVolume4\Windows\WinSxS
- 1830.2334: KnownDllPath: C:\Windows\system32
- 1830.2334: '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxHeadless.exe' has no imports
- 1830.2334: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxHeadless.exe)
- 1830.2334: supR3HardNtEnableThreadCreation:
- 1830.2334: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007fffdcec6a4c pvNtTerminateThread=00007fffdcf0b0b0
- 1830.2334: supR3HardenedWinDoReSpawn(1): New child 235c.227c [kernel32].
- 1830.2334: supR3HardNtChildGatherData: PebBaseAddress=00007ff6edd29000 cbPeb=0x388
- 1830.2334: supR3HardNtPuChFindNtdll: uNtDllParentAddr=00007fffdce70000 uNtDllChildAddr=00007fffdce70000
- 1830.2334: supR3HardenedWinSetupChildInit: uLdrInitThunk=00007fffdcec6a4c
- 1830.2334: supR3HardenedWinSetupChildInit: Start child.
- 1830.2334: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
- 1830.2334: supR3HardNtChildPurify: Startup delay kludge #1/0: 262 ms, 24 sleeps
- 1830.2334: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
- 1830.2334: *0000000000000000-ffffffffff38ffff 0x0001/0x0000 0x0000000
- 1830.2334: *0000000000c70000-0000000000c4ffff 0x0004/0x0004 0x0020000
- 1830.2334: *0000000000c90000-0000000000c80fff 0x0002/0x0002 0x0040000
- 1830.2334: 0000000000c9f000-0000000000c9dfff 0x0001/0x0000 0x0000000
- 1830.2334: *0000000000ca0000-0000000000ba3fff 0x0000/0x0004 0x0020000
- 1830.2334: 0000000000d9c000-0000000000d98fff 0x0104/0x0004 0x0020000
- 1830.2334: 0000000000d9f000-0000000000d9dfff 0x0004/0x0004 0x0020000
- 1830.2334: *0000000000da0000-0000000000d9bfff 0x0002/0x0002 0x0040000
- 1830.2334: 0000000000da4000-0000000000d97fff 0x0001/0x0000 0x0000000
- 1830.2334: *0000000000db0000-0000000000dadfff 0x0004/0x0004 0x0020000
- 1830.2334: 0000000000db2000-ffffffff81b83fff 0x0001/0x0000 0x0000000
- 1830.2334: *000000007ffe0000-000000007ffdefff 0x0002/0x0002 0x0020000
- 1830.2334: 000000007ffe1000-000000007ffd1fff 0x0000/0x0002 0x0020000
- 1830.2334: 000000007fff0000-ffff800a122dffff 0x0001/0x0000 0x0000000
- 1830.2334: *00007ff6edd00000-00007ff6edcdcfff 0x0002/0x0002 0x0040000
- 1830.2334: 00007ff6edd23000-00007ff6edd1cfff 0x0001/0x0000 0x0000000
- 1830.2334: *00007ff6edd29000-00007ff6edd27fff 0x0004/0x0004 0x0020000
- 1830.2334: 00007ff6edd2a000-00007ff6edd25fff 0x0001/0x0000 0x0000000
- 1830.2334: *00007ff6edd2e000-00007ff6edd2bfff 0x0004/0x0004 0x0020000
- 1830.2334: 00007ff6edd30000-00007ff6ed38ffff 0x0001/0x0000 0x0000000
- 1830.2334: *00007ff6ee6d0000-00007ff6ee6cefff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxHeadless.exe
- 1830.2334: 00007ff6ee6d1000-00007ff6ee64cfff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxHeadless.exe
- 1830.2334: 00007ff6ee755000-00007ff6ee753fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxHeadless.exe
- 1830.2334: 00007ff6ee756000-00007ff6ee718fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxHeadless.exe
- 1830.2334: 00007ff6ee793000-00007ff6ee791fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxHeadless.exe
- 1830.2334: 00007ff6ee794000-00007ff6ee792fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxHeadless.exe
- 1830.2334: 00007ff6ee795000-00007ff6ee792fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxHeadless.exe
- 1830.2334: 00007ff6ee797000-00007ff6ee795fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxHeadless.exe
- 1830.2334: 00007ff6ee798000-00007ff6ee796fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxHeadless.exe
- 1830.2334: 00007ff6ee799000-00007ff6ee794fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxHeadless.exe
- 1830.2334: 00007ff6ee79d000-00007ff6ee763fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxHeadless.exe
- 1830.2334: 00007ff6ee7d6000-00007fee0013bfff 0x0001/0x0000 0x0000000
- 1830.2334: *00007fffdce70000-00007fffdce6efff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
- 1830.2334: 00007fffdce71000-00007fffdcd47fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
- 1830.2334: 00007fffdcf9a000-00007fffdcf90fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
- 1830.2334: 00007fffdcfa3000-00007fffdcf95fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
- 1830.2334: 00007fffdcfb0000-00007fffdcfaefff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
- 1830.2334: 00007fffdcfb1000-00007fffdcfaffff 0x0010/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
- 1830.2334: 00007fffdcfb2000-00007fffdcf49fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll
- 1830.2334: 00007fffdd01a000-00007fffba053fff 0x0001/0x0000 0x0000000
- 1830.2334: *00007ffffffe0000-00007ffffffcffff 0x0001/0x0002 0x0020000
- 1830.2334: VBoxHeadless.exe: timestamp 0x546f44b2 (rc=VINF_SUCCESS)
- 1830.2334: '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VBoxHeadless.exe' has no imports
- 1830.2334: '\Device\HarddiskVolume4\Windows\System32\ntdll.dll' has no imports
- 1830.2334: supR3HardNtChildPurify: Done after 308 ms and 0 fixes (loop #0).
- 235c.227c: Log file opened: 4.3.20r96996 g_hStartupLog=0000000000000008 g_uNtVerCombined=0x63258000
- 235c.227c: supR3HardenedVmProcessInit: uNtDllAddr=00007fffdce70000
- 235c.227c: ntdll.dll: timestamp 0x530895af (rc=VINF_SUCCESS)
- 235c.227c: New simple heap: #1 0000000000ec0000 LB 0x400000 (for 1744896 allocation)
- 1830.2334: supR3HardNtEnableThreadCreation:
- 235c.227c: System32: \Device\HarddiskVolume4\Windows\System32
- 235c.227c: WinSxS: \Device\HarddiskVolume4\Windows\WinSxS
- 235c.227c: KnownDllPath: C:\Windows\system32
- 235c.227c: supR3HardenedVmProcessInit: Opening vboxdrv stub...
- 235c.227c: Error opening VBoxDrvStub: STATUS_OBJECT_NAME_NOT_FOUND
- 235c.227c: supR3HardenedWinReadErrorInfoDevice: NtCreateFile -> 0xc0000034
- 235c.227c: Error -101 in supR3HardenedWinReSpawn! (enmWhat=3)
- 235c.227c: NtCreateFile(\Device\VBoxDrvStub) failed: 0xc0000034 STATUS_OBJECT_NAME_NOT_FOUND (0 retries)
- Driver is probably stuck stopping/starting. Try 'sc.exe query vboxdrv' to get more information about its state. Rebooting may actually help.
- 1830.2334: supR3HardenedWinCheckChild: enmRequest=2 rc=-101 enmWhat=3 supR3HardenedWinReSpawn: NtCreateFile(\Device\VBoxDrvStub) failed: 0xc0000034 STATUS_OBJECT_NAME_NOT_FOUND (0 retries)
- Driver is probably stuck stopping/starting. Try 'sc.exe query vboxdrv' to get more information about its state. Rebooting may actually help.
- 1830.2334: Error -101 in supR3HardenedWinReSpawn! (enmWhat=3)
- 1830.2334: NtCreateFile(\Device\VBoxDrvStub) failed: 0xc0000034 STATUS_OBJECT_NAME_NOT_FOUND (0 retries)
- Driver is probably stuck stopping/starting. Try 'sc.exe query vboxdrv' to get more information about its state. Rebooting may actually help.
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement