Code: Select all
27d8.c30: Log file opened: 5.2.8r121009 g_hStartupLog=0000000000000068 g_uNtVerCombined=0xa03fab00
27d8.c30: \SystemRoot\System32\ntdll.dll:
27d8.c30: CreationTime: 2018-02-14T09:15:16.065071600Z
27d8.c30: LastWriteTime: 2018-02-10T06:15:34.902092600Z
27d8.c30: ChangeTime: 2018-03-14T07:18:45.526098000Z
27d8.c30: FileAttributes: 0x20
27d8.c30: Size: 0x1dd100
27d8.c30: NT Headers: 0xe0
27d8.c30: Timestamp: 0xeffc9126
27d8.c30: Machine: 0x8664 - amd64
27d8.c30: Timestamp: 0xeffc9126
27d8.c30: Image Version: 10.0
27d8.c30: SizeOfImage: 0x1e0000 (1966080)
27d8.c30: Resource Dir: 0x174000 LB 0x6a1d8
27d8.c30: [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
27d8.c30: [Raw version resource data: 0x1740f0 LB 0x380, codepage 0x0 (reserved 0x0)]
27d8.c30: ProductName: Microsoft® Windows® Operating System
27d8.c30: ProductVersion: 10.0.16299.248
27d8.c30: FileVersion: 10.0.16299.248 (WinBuild.160101.0800)
27d8.c30: FileDescription: NT Layer DLL
27d8.c30: \SystemRoot\System32\kernel32.dll:
27d8.c30: CreationTime: 2017-09-29T13:42:04.954227600Z
27d8.c30: LastWriteTime: 2017-09-29T13:42:04.954227600Z
27d8.c30: ChangeTime: 2017-12-26T10:27:53.853930500Z
27d8.c30: FileAttributes: 0x20
27d8.c30: Size: 0xab868
27d8.c30: NT Headers: 0xe8
27d8.c30: Timestamp: 0xc2cf900
27d8.c30: Machine: 0x8664 - amd64
27d8.c30: Timestamp: 0xc2cf900
27d8.c30: Image Version: 10.0
27d8.c30: SizeOfImage: 0xae000 (712704)
27d8.c30: Resource Dir: 0xac000 LB 0x520
27d8.c30: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
27d8.c30: [Raw version resource data: 0xac0b0 LB 0x3a4, codepage 0x0 (reserved 0x0)]
27d8.c30: ProductName: Microsoft® Windows® Operating System
27d8.c30: ProductVersion: 10.0.16299.15
27d8.c30: FileVersion: 10.0.16299.15 (WinBuild.160101.0800)
27d8.c30: FileDescription: Windows NT BASE API Client DLL
27d8.c30: \SystemRoot\System32\KernelBase.dll:
27d8.c30: CreationTime: 2018-03-14T07:16:34.539362200Z
27d8.c30: LastWriteTime: 2018-03-01T07:40:10.084338900Z
27d8.c30: ChangeTime: 2018-03-14T14:41:04.181008800Z
27d8.c30: FileAttributes: 0x20
27d8.c30: Size: 0x265ff8
27d8.c30: NT Headers: 0xf0
27d8.c30: Timestamp: 0x90a96867
27d8.c30: Machine: 0x8664 - amd64
27d8.c30: Timestamp: 0x90a96867
27d8.c30: Image Version: 10.0
27d8.c30: SizeOfImage: 0x266000 (2514944)
27d8.c30: Resource Dir: 0x245000 LB 0x548
27d8.c30: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
27d8.c30: [Raw version resource data: 0x2450b0 LB 0x3bc, codepage 0x0 (reserved 0x0)]
27d8.c30: ProductName: Microsoft® Windows® Operating System
27d8.c30: ProductVersion: 10.0.16299.309
27d8.c30: FileVersion: 10.0.16299.309 (WinBuild.160101.0800)
27d8.c30: FileDescription: Windows NT BASE API Client DLL
27d8.c30: \SystemRoot\System32\apisetschema.dll:
27d8.c30: CreationTime: 2017-09-29T13:42:07.095026600Z
27d8.c30: LastWriteTime: 2017-09-29T13:42:07.095026600Z
27d8.c30: ChangeTime: 2018-03-14T07:18:45.791871300Z
27d8.c30: FileAttributes: 0x20
27d8.c30: Size: 0x1b398
27d8.c30: NT Headers: 0xc8
27d8.c30: Timestamp: 0xf30abf31
27d8.c30: Machine: 0x8664 - amd64
27d8.c30: Timestamp: 0xf30abf31
27d8.c30: Image Version: 10.0
27d8.c30: SizeOfImage: 0x1c000 (114688)
27d8.c30: Resource Dir: 0x1b000 LB 0x408
27d8.c30: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
27d8.c30: [Raw version resource data: 0x1b060 LB 0x3a8, codepage 0x0 (reserved 0x0)]
27d8.c30: ProductName: Microsoft® Windows® Operating System
27d8.c30: ProductVersion: 10.0.16299.15
27d8.c30: FileVersion: 10.0.16299.15 (WinBuild.160101.0800)
27d8.c30: FileDescription: ApiSet Schema DLL
27d8.c30: NtOpenDirectoryObject failed on \Driver: 0xc0000022
27d8.c30: supR3HardenedWinFindAdversaries: 0x18
27d8.c30: \SystemRoot\System32\drivers\tmcomm.sys:
27d8.c30: CreationTime: 2017-04-06T23:40:56.000000000Z
27d8.c30: LastWriteTime: 2017-10-15T20:53:42.000000000Z
27d8.c30: ChangeTime: 2018-01-16T08:52:19.306542200Z
27d8.c30: FileAttributes: 0x20
27d8.c30: Size: 0x6ac98
27d8.c30: NT Headers: 0x100
27d8.c30: Timestamp: 0x59dfcffd
27d8.c30: Machine: 0x8664 - amd64
27d8.c30: Timestamp: 0x59dfcffd
27d8.c30: Image Version: 10.0
27d8.c30: SizeOfImage: 0x6c000 (442368)
27d8.c30: Resource Dir: 0x6a000 LB 0x568
27d8.c30: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
27d8.c30: [Raw version resource data: 0x6a060 LB 0x504, codepage 0x0 (reserved 0x0)]
27d8.c30: ProductName: Trend Micro Eyes
27d8.c30: ProductVersion: 7.0
27d8.c30: FileVersion: 7.0.0.1147
27d8.c30: SpecialBuild: 1147
27d8.c30: PrivateBuild: Build 1147 - 10/13/2017
27d8.c30: FileDescription: TrendMicro Common Module
27d8.c30: \SystemRoot\System32\drivers\tmactmon.sys:
27d8.c30: CreationTime: 2017-04-05T21:42:40.000000000Z
27d8.c30: LastWriteTime: 2018-01-10T15:21:42.000000000Z
27d8.c30: ChangeTime: 2018-01-16T08:52:19.306542200Z
27d8.c30: FileAttributes: 0x20
27d8.c30: Size: 0x20a58
27d8.c30: NT Headers: 0xe0
27d8.c30: Timestamp: 0x5a55adf0
27d8.c30: Machine: 0x8664 - amd64
27d8.c30: Timestamp: 0x5a55adf0
27d8.c30: Image Version: 6.0
27d8.c30: SizeOfImage: 0x24000 (147456)
27d8.c30: Resource Dir: 0x22000 LB 0x590
27d8.c30: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
27d8.c30: [Raw version resource data: 0x22060 LB 0x52c, codepage 0x0 (reserved 0x0)]
27d8.c30: ProductName: Trend Micro AEGIS
27d8.c30: ProductVersion: 2.976
27d8.c30: FileVersion: 2.976.0.2126
27d8.c30: SpecialBuild: 2126
27d8.c30: PrivateBuild: Build 2126 - 1/10/2018
27d8.c30: FileDescription: TrendMicro Activity Monitor Module
27d8.c30: \SystemRoot\System32\drivers\tmevtmgr.sys:
27d8.c30: CreationTime: 2017-04-05T21:42:42.000000000Z
27d8.c30: LastWriteTime: 2018-01-10T15:21:56.000000000Z
27d8.c30: ChangeTime: 2018-01-16T08:52:19.322170200Z
27d8.c30: FileAttributes: 0x20
27d8.c30: Size: 0x17678
27d8.c30: NT Headers: 0xe8
27d8.c30: Timestamp: 0x5a55ade9
27d8.c30: Machine: 0x8664 - amd64
27d8.c30: Timestamp: 0x5a55ade9
27d8.c30: Image Version: 6.0
27d8.c30: SizeOfImage: 0x18000 (98304)
27d8.c30: Resource Dir: 0x16000 LB 0x590
27d8.c30: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
27d8.c30: [Raw version resource data: 0x16060 LB 0x52c, codepage 0x0 (reserved 0x0)]
27d8.c30: ProductName: Trend Micro AEGIS
27d8.c30: ProductVersion: 2.976
27d8.c30: FileVersion: 2.976.0.2126
27d8.c30: SpecialBuild: 2126
27d8.c30: PrivateBuild: Build 2126 - 1/10/2018
27d8.c30: FileDescription: TrendMicro Event Management Module
27d8.c30: \SystemRoot\System32\drivers\tmebc64.sys:
27d8.c30: CreationTime: 2016-04-21T09:08:08.000000000Z
27d8.c30: LastWriteTime: 2016-04-21T09:08:08.000000000Z
27d8.c30: ChangeTime: 2018-01-16T08:58:58.930700000Z
27d8.c30: FileAttributes: 0x20
27d8.c30: Size: 0x11b38
27d8.c30: NT Headers: 0xf8
27d8.c30: Timestamp: 0x564ac673
27d8.c30: Machine: 0x8664 - amd64
27d8.c30: Timestamp: 0x564ac673
27d8.c30: Image Version: 6.0
27d8.c30: SizeOfImage: 0x12000 (73728)
27d8.c30: Resource Dir: 0x10000 LB 0x6f8
27d8.c30: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
27d8.c30: [Raw version resource data: 0x10060 LB 0x694, codepage 0x0 (reserved 0x0)]
27d8.c30: ProductName: Trend Micro Early Boot Clean
27d8.c30: ProductVersion: 1.5
27d8.c30: FileVersion: 1.5.0.1023
27d8.c30: SpecialBuild: 1023
27d8.c30: PrivateBuild: Build 1023 - 11/17/2015
27d8.c30: FileDescription: Trend Micro early boot driver
27d8.c30: \SystemRoot\System32\drivers\tmeevw.sys:
27d8.c30: CreationTime: 2016-07-15T04:48:26.000000000Z
27d8.c30: LastWriteTime: 2017-04-25T12:39:52.000000000Z
27d8.c30: ChangeTime: 2017-12-26T10:36:10.890112200Z
27d8.c30: FileAttributes: 0x20
27d8.c30: Size: 0x22ed8
27d8.c30: NT Headers: 0xf8
27d8.c30: Timestamp: 0x58f08d99
27d8.c30: Machine: 0x8664 - amd64
27d8.c30: Timestamp: 0x58f08d99
27d8.c30: Image Version: 10.0
27d8.c30: SizeOfImage: 0x23000 (143360)
27d8.c30: Resource Dir: 0x1d000 LB 0x4df0
27d8.c30: [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
27d8.c30: [Raw version resource data: 0x218fc LB 0x4f4, codepage 0x4e4 (reserved 0x0)]
27d8.c30: ProductName: Trend Micro EagleEye
27d8.c30: ProductVersion: 3.0
27d8.c30: FileVersion: 3.0.0.1005
27d8.c30: SpecialBuild: 1005
27d8.c30: PrivateBuild: Build 1005 - 4/14/2017
27d8.c30: FileDescription: Trend Micro EagleEye Driver (VW) (amd64-fre)
27d8.c30: \SystemRoot\System32\drivers\sakfile.sys:
27d8.c30: CreationTime: 2018-01-16T08:43:14.564816500Z
27d8.c30: LastWriteTime: 2018-01-16T08:43:14.564816500Z
27d8.c30: ChangeTime: 2018-01-16T08:43:14.564816500Z
27d8.c30: FileAttributes: 0x20
27d8.c30: Size: 0x1ee98
27d8.c30: NT Headers: 0xe0
27d8.c30: Timestamp: 0x59def819
27d8.c30: Machine: 0x8664 - amd64
27d8.c30: Timestamp: 0x59def819
27d8.c30: Image Version: 0.0
27d8.c30: SizeOfImage: 0x1e000 (122880)
27d8.c30: Resource Dir: 0x1c000 LB 0x558
27d8.c30: [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
27d8.c30: [Raw version resource data: 0x1c060 LB 0x4f4, codepage 0x0 (reserved 0x0)]
27d8.c30: ProductName: OfficeScan - Data Protection (DLPE-SDK)
27d8.c30: ProductVersion: 6.2
27d8.c30: FileVersion: 6.2.0.1148
27d8.c30: SpecialBuild: 1148
27d8.c30: PrivateBuild: Build 1148 - 10/12/2017
27d8.c30: FileDescription: Trend Micro Data Loss Prevention Driver
27d8.c30: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume3\Oracle\VirtualBox'
27d8.c30: Calling main()
27d8.c30: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
27d8.c30: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume3\Oracle\VirtualBox'
27d8.c30: SUPR3HardenedMain: Respawn #1
27d8.c30: System32: \Device\HarddiskVolume3\Windows\System32
27d8.c30: WinSxS: \Device\HarddiskVolume3\Windows\WinSxS
27d8.c30: KnownDllPath: C:\WINDOWS\System32
27d8.c30: '\Device\HarddiskVolume3\Oracle\VirtualBox\VirtualBox.exe' has no imports
27d8.c30: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Oracle\VirtualBox\VirtualBox.exe)
27d8.c30: supR3HardNtEnableThreadCreation:
27d8.c30: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffb593791e0 pvNtTerminateThread=00007ffb593a08d0
27d8.c30: supR3HardenedWinDoReSpawn(1): New child 3190.2330 [kernel32].
27d8.c30: supR3HardNtChildGatherData: PebBaseAddress=0000000001074000 cbPeb=0x388
27d8.c30: supR3HardNtPuChFindNtdll: uNtDllParentAddr=00007ffb59300000 uNtDllChildAddr=00007ffb59300000
27d8.c30: supR3HardenedWinSetupChildInit: uLdrInitThunk=00007ffb593791e0
27d8.c30: supR3HardenedWinSetupChildInit: Start child.
27d8.c30: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
27d8.c30: supR3HardNtChildPurify: Startup delay kludge #1/0: 516 ms, 41 sleeps
27d8.c30: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
27d8.c30: *0000000000000000-0000000000faffff 0x0001/0x0000 0x0000000
27d8.c30: *0000000000fb0000-0000000000fcffff 0x0004/0x0004 0x0020000
27d8.c30: *0000000000fd0000-0000000000fe8fff 0x0002/0x0002 0x0040000
27d8.c30: 0000000000fe9000-0000000000feffff 0x0001/0x0000 0x0000000
27d8.c30: *0000000000ff0000-0000000000ff3fff 0x0002/0x0002 0x0040000
27d8.c30: 0000000000ff4000-0000000000ffffff 0x0001/0x0000 0x0000000
27d8.c30: *0000000001000000-0000000001073fff 0x0000/0x0004 0x0020000
27d8.c30: 0000000001074000-0000000001076fff 0x0004/0x0004 0x0020000
27d8.c30: 0000000001077000-00000000011fffff 0x0000/0x0004 0x0020000
27d8.c30: *0000000001200000-00000000012fafff 0x0000/0x0004 0x0020000
27d8.c30: 00000000012fb000-00000000012fdfff 0x0104/0x0004 0x0020000
27d8.c30: 00000000012fe000-00000000012fffff 0x0004/0x0004 0x0020000
27d8.c30: *0000000001300000-0000000001300fff 0x0004/0x0004 0x0020000
27d8.c30: 0000000001301000-000000007ffdffff 0x0001/0x0000 0x0000000
27d8.c30: *000000007ffe0000-000000007ffe0fff 0x0002/0x0002 0x0020000
27d8.c30: *000000007ffe1000-000000007ffeffff 0x0000/0x0002 0x0020000
27d8.c30: 000000007fff0000-00007ff682aeffff 0x0001/0x0000 0x0000000
27d8.c30: *00007ff682af0000-00007ff682b12fff 0x0002/0x0002 0x0040000
27d8.c30: 00007ff682b13000-00007ff6838dffff 0x0001/0x0000 0x0000000
27d8.c30: *00007ff6838e0000-00007ff6838e0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Oracle\VirtualBox\VirtualBox.exe
27d8.c30: 00007ff6838e1000-00007ff683951fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume3\Oracle\VirtualBox\VirtualBox.exe
27d8.c30: 00007ff683952000-00007ff683952fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume3\Oracle\VirtualBox\VirtualBox.exe
27d8.c30: 00007ff683953000-00007ff683998fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Oracle\VirtualBox\VirtualBox.exe
27d8.c30: 00007ff683999000-00007ff683999fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Oracle\VirtualBox\VirtualBox.exe
27d8.c30: 00007ff68399a000-00007ff68399afff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Oracle\VirtualBox\VirtualBox.exe
27d8.c30: 00007ff68399b000-00007ff68399ffff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Oracle\VirtualBox\VirtualBox.exe
27d8.c30: 00007ff6839a0000-00007ff6839a0fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Oracle\VirtualBox\VirtualBox.exe
27d8.c30: 00007ff6839a1000-00007ff6839a1fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Oracle\VirtualBox\VirtualBox.exe
27d8.c30: 00007ff6839a2000-00007ff6839a5fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Oracle\VirtualBox\VirtualBox.exe
27d8.c30: 00007ff6839a6000-00007ff6839edfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Oracle\VirtualBox\VirtualBox.exe
27d8.c30: 00007ff6839ee000-00007ffb592fffff 0x0001/0x0000 0x0000000
27d8.c30: *00007ffb59300000-00007ffb59300fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
27d8.c30: 00007ffb59301000-00007ffb59412fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
27d8.c30: 00007ffb59413000-00007ffb59458fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
27d8.c30: 00007ffb59459000-00007ffb59460fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
27d8.c30: 00007ffb59461000-00007ffb5946efff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
27d8.c30: 00007ffb5946f000-00007ffb5946ffff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
27d8.c30: 00007ffb59470000-00007ffb59472fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
27d8.c30: 00007ffb59473000-00007ffb594dffff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
27d8.c30: 00007ffb594e0000-00007ffffffdffff 0x0001/0x0000 0x0000000
27d8.c30: *00007ffffffe0000-00007ffffffeffff 0x0001/0x0002 0x0020000
27d8.c30: VirtualBox.exe: timestamp 0x5a942b95 (rc=VINF_SUCCESS)
27d8.c30: '\Device\HarddiskVolume3\Oracle\VirtualBox\VirtualBox.exe' has no imports
27d8.c30: '\Device\HarddiskVolume3\Windows\System32\ntdll.dll' has no imports
27d8.c30: supR3HardNtChildPurify: Done after 546 ms and 0 fixes (loop #0).
27d8.c30: supR3HardNtEnableThreadCreation:
3190.2330: Log file opened: 5.2.8r121009 g_hStartupLog=0000000000000004 g_uNtVerCombined=0xa03fab00
3190.2330: supR3HardenedVmProcessInit: uNtDllAddr=00007ffb59300000 g_uNtVerCombined=0xa03fab00
3190.2330: ntdll.dll: timestamp 0xeffc9126 (rc=VINF_SUCCESS)
3190.2330: New simple heap: #1 0000000001410000 LB 0x400000 (for 1966080 allocation)
3190.2330: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume3\Oracle\VirtualBox'
3190.2330: System32: \Device\HarddiskVolume3\Windows\System32
3190.2330: WinSxS: \Device\HarddiskVolume3\Windows\WinSxS
3190.2330: KnownDllPath: C:\WINDOWS\System32
3190.2330: supR3HardenedVmProcessInit: Opening vboxdrv stub...
3190.2330: Error opening VBoxDrvStub: STATUS_OBJECT_NAME_NOT_FOUND
3190.2330: supR3HardenedWinReadErrorInfoDevice: NtCreateFile -> 0xc0000034
3190.2330: Error -101 in supR3HardenedWinReSpawn! (enmWhat=3)
3190.2330: NtCreateFile(\Device\VBoxDrvStub) failed: 0xc0000034 STATUS_OBJECT_NAME_NOT_FOUND (0 retries)
Driver is probably stuck stopping/starting. Try 'sc.exe query vboxdrv' to get more information about its state. Rebooting may actually help.
27d8.c30: supR3HardenedWinCheckChild: enmRequest=2 rc=-101 enmWhat=3 supR3HardenedWinReSpawn: NtCreateFile(\Device\VBoxDrvStub) failed: 0xc0000034 STATUS_OBJECT_NAME_NOT_FOUND (0 retries)
Driver is probably stuck stopping/starting. Try 'sc.exe query vboxdrv' to get more information about its state. Rebooting may actually help.
27d8.c30: Error -101 in supR3HardenedWinReSpawn! (enmWhat=3)
27d8.c30: NtCreateFile(\Device\VBoxDrvStub) failed: 0xc0000034 STATUS_OBJECT_NAME_NOT_FOUND (0 retries)
Driver is probably stuck stopping/starting. Try 'sc.exe query vboxdrv' to get more information about its state. Rebooting may actually help.