Hardening Error after Upgrade to 6.0 TrendMicro VirusScan

Discussions related to using VirtualBox on Windows hosts.

Hardening Error after Upgrade to 6.0 TrendMicro VirusScan

Postby BaboM » 20. Dec 2018, 15:46

After upgrading to Version 6.0, i cannot start VMs anymore.
In the Hardening Log i can see TrendMicro Dlls. Its not an option to uninstall the Virusscan.

In Version 5.2 everything works fine.

Error Code: E_FAIL (0x80004005)
Komponente: MachineWrap
Interface: IMachine {5047460a-265d-4538-b23e-ddba5fb84976}
Attachments
VBoxHardening.log
(22.52 KiB) Downloaded 200 times
BaboM
 
Posts: 1
Joined: 20. Dec 2018, 15:40

Re: Hardening Error after Upgrade to 6.0 TrendMicro VirusScan

Postby mpack » 20. Dec 2018, 15:49

FAQ: Diagnosing VirtualBox Hardening Issues.

If it is truly not an option to provide an execution environment which is compatible with VirtualBox, then uninstall VirtualBox.
mpack
Site Moderator
 
Posts: 29689
Joined: 4. Sep 2008, 17:09
Primary OS: MS Windows 10
VBox Version: PUEL
Guest OSses: Mostly XP

Re: Hardening Error after Upgrade to 6.0 TrendMicro VirusScan

Postby vdir » 20. Dec 2018, 18:35

Same issue. Got it working by opening the TM Agent, clicking Settings (gear icon on bottom) -> Protection -> Trusted Programs List and adding VirtualBoxVM.exe to the list.
vdir
 
Posts: 2
Joined: 31. Oct 2017, 02:31

Hardening error with 6.0.0; 5.2.22 works OK

Postby Greg Bailey » 20. Dec 2018, 19:25

Just upgraded from VirtualBox 5.2.22 to the new 6.0.0 version, and am unable to launch any VMs with a graphical display.

Starting a headless VM (via "vagrant") appeared to work OK.

I've performed full uninstall / reboot / reinstall after the initial failure, and the same error persists.

I don't have an easy way to disable Trend since my Windows 10 workstation is "managed" by my organization, although I've reached out for help there as well.

I'm attaching a ZIP file containing VBoxHardening.log files from both the 5.2.22 and 6.0.0 versions.
Attachments
VBoxHardening.zip
(27.43 KiB) Downloaded 80 times
Greg Bailey
 
Posts: 11
Joined: 2. Nov 2007, 18:47
Location: Phoenix, AZ, US

Re: Hardening error with 6.0.0; 5.2.22 works OK

Postby BuddOvit » 21. Dec 2018, 10:13

You are not alone :)

I've got exactly the same issue. Hardening log is pretty much identical to yours. Also running Trend Micro managed by the organisation.
BuddOvit
 
Posts: 2
Joined: 19. Dec 2018, 19:42

Re: Hardening Error after Upgrade to 6.0 TrendMicro VirusScan

Postby socratis » 23. Dec 2018, 02:09

@Greg Bailey, @BuddOvit
I merged your topic with an existing one talking about the same thing. Read the thread (and the solution) from the beginning please...

It helps if you search before creating a new topic, make my life easier and yours less complicated... ;)
If you obfuscate any information requested, I will obfuscate my response. These are virtual UUIDs, not real ones.
Do NOT reply with the "QUOTE" button, please use the "POST REPLY", at the bottom of the form.
socratis
Site Moderator
 
Posts: 25220
Joined: 22. Oct 2010, 11:03
Location: Greece
Primary OS: Mac OS X other
VBox Version: PUEL
Guest OSses: Win(*>98), Linux*, OSX>10.5

Re: Hardening Error after Upgrade to 6.0 TrendMicro VirusScan

Postby poshcodebear » 26. Dec 2018, 19:44

I'm running into the same problem, also have Trend Micro, and also have no option to uninstall due to company policy (and a different department manages the AV, so I can't add exceptions for it). Thanks to Greg Bailey's comment about headless launch, I tried to launch one of my servers in headless mode (using the downward drop-down arrow next to the "Start" button), which worked, AND I was able to attach to it by hitting the "Start" (now changed to "Show") button.

Considering this was working fine in 5.22 and previous, and the only change was upgrading to 6.0, either VirtualBox turned up the hardening past a point Trend Micro isn't yet compatible with (have additional hardening features been activated in the new release?), or we all had an exclusion list that included VirtualBox in Trend Micro and it doesn't recognize the new executables.

Or it's a bug and the new version just doesn't like Trend (I'd get rid of it and stick with Windows Defender if my company would let me; I'm sure most of us would).

Anyway, that means we have a functioning workaround (at least, it works for me) until this gets fixed (either by Trend Micro, Oracle, or our individual IT departments, depending on what the root cause is).

Workaround steps:
(repeated as bullet list to make it easier for people to find when scanning through the replies)
  1. Click the downward arrow next to the Start arrow
  2. Select Headless start
  3. Click on the Show button to bring up the console window

I hope this helps!
poshcodebear
 
Posts: 2
Joined: 23. Oct 2018, 01:21

Re: Hardening Error after Upgrade to 6.0 TrendMicro VirusScan

Postby socratis » 26. Dec 2018, 22:41

@poshcodebear
Do you mind posting a VBox.log and a VBoxhardening.log from a Normal start when it fails? ZIPPED...
If you obfuscate any information requested, I will obfuscate my response. These are virtual UUIDs, not real ones.
Do NOT reply with the "QUOTE" button, please use the "POST REPLY", at the bottom of the form.
socratis
Site Moderator
 
Posts: 25220
Joined: 22. Oct 2010, 11:03
Location: Greece
Primary OS: Mac OS X other
VBox Version: PUEL
Guest OSses: Win(*>98), Linux*, OSX>10.5

Re: Hardening Error after Upgrade to 6.0 TrendMicro VirusScan

Postby buker » 25. Jan 2019, 16:16

I experience the same problem. I use VirtualBox 6.0.2 r128162 (Qt5.6.2) and Trend Micro OfficeScan 12.0.5261.
I'm attaching VboxHardening.log
Attachments
VBoxHardening.log
(45.14 KiB) Downloaded 48 times
buker
 
Posts: 1
Joined: 25. Jan 2019, 15:55

Issues with VBox 6.0.4

Postby GregB169 » 11. Feb 2019, 14:49

Hello

I have upgraded several times from the 5.2 branch to the 6.x branch and cannot get VMs to either build or start if they were built under 5.2. I have my local IT team add exemptions to see if my AV, Trend Micro, was the issue.

Attached is my vBox Hardening log to see if there is something else that I am missing.

Thanks

Greg
Attachments
Dev2-2019-02-06-15-40-00.zip
(3.43 KiB) Downloaded 28 times
GregB169
 
Posts: 2
Joined: 11. Feb 2019, 14:46

Re: Issues with VBox 6.0.4

Postby socratis » 12. Feb 2019, 02:45

4f80.4758: supR3HardenedWinFindAdversaries: 0x8
4f80.4758: \SystemRoot\System32\drivers\tmcomm.sys:
...
4f80.4758: FileDescription: TrendMicro Common Module

Please read really carefully the following FAQ: Diagnosing VirtualBox Hardening Issues for some generic guidelines/ideas.

I'm merging your topic with the other posts that deal with TrendMicro and I'm going to make it a sticky until this is resolved.
If you obfuscate any information requested, I will obfuscate my response. These are virtual UUIDs, not real ones.
Do NOT reply with the "QUOTE" button, please use the "POST REPLY", at the bottom of the form.
socratis
Site Moderator
 
Posts: 25220
Joined: 22. Oct 2010, 11:03
Location: Greece
Primary OS: Mac OS X other
VBox Version: PUEL
Guest OSses: Win(*>98), Linux*, OSX>10.5

Re: Hardening Error after Upgrade to 6.0 TrendMicro VirusScan

Postby TomSmi » 19. Feb 2019, 11:31

Hi, I had simiar issues with VirtualBox and TrendMicro OfficeScan.
Adding those exceptions to TM OS allowed me to run VMs in VirtualBox Again:

C:\Windows\System32\ntdll.dll
C:\Windows\System32\kernel32.dll
C:\Windows\System32\KernelBase.dll
C:\Windows\System32\apisetschema.dll
C:\Windows\System32\apisetschema.dlC:\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe

--
Best regards,
Tom
TomSmi
 
Posts: 2
Joined: 19. Feb 2019, 11:19

Re: Hardening Error after Upgrade to 6.0 TrendMicro VirusScan

Postby socratis » 19. Feb 2019, 11:53

@Tom,
I don't think that the system DLLs are necessary. Just the "C:\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe" is required.
If you obfuscate any information requested, I will obfuscate my response. These are virtual UUIDs, not real ones.
Do NOT reply with the "QUOTE" button, please use the "POST REPLY", at the bottom of the form.
socratis
Site Moderator
 
Posts: 25220
Joined: 22. Oct 2010, 11:03
Location: Greece
Primary OS: Mac OS X other
VBox Version: PUEL
Guest OSses: Win(*>98), Linux*, OSX>10.5

Re: Hardening Error after Upgrade to 6.0 TrendMicro VirusScan

Postby TomSmi » 19. Feb 2019, 15:12

@socratis, you're right!
Thanks for help.
TomSmi
 
Posts: 2
Joined: 19. Feb 2019, 11:19

Re: Hardening Error after Upgrade to 6.0 TrendMicro VirusScan

Postby GregB169 » 27. Feb 2019, 16:47

The path update was the issue for me. Not sure why Trend is not allowing this but adding this to the exclusion list worked. "C:\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe"
GregB169
 
Posts: 2
Joined: 11. Feb 2019, 14:46

Next

Return to VirtualBox on Windows Hosts

Who is online

Users browsing this forum: Mannekino, Mitchellmitchellmitchell, socratis and 62 guests