Page 1 of 1

Hardening problems - possibly connected with SentinelOne

Posted: 27. Mar 2022, 20:01
by Magnar
Hi,
I'm experiencing hardening issues on a couple of Windows hosts (Debian guest).
The guest VM runs fine in normal mode, but crashes when I try to run in headless or detachable mode.
The problem appeared almost simultaneously on both a Windows 7 host and a Windows 10 host, and the common denominator that I spotted was that both had a fairly recent install of the SentinelOne security package. So I suspect that's the culprit.

Error message:
Failed to open a session for the virtual machine sf-mas3.

The virtual machine 'sf-mas3' has terminated unexpectedly during startup with exit code -1073741819 (0xc0000005). More details may be available in 'C:\Users\F1100584\VirtualBox VMs\sf-mas3\Logs\VBoxHardening.log'.

Result Code: E_FAIL (0x80004005)
Component: MachineWrap
Interface: IMachine {85632c68-b5bb-4316-a900-5eb28d3413df}
According to the hardening troubleshooting guide, the very last line of the hardening log should be an error code or 0, but it doesn't appear to be either.
VBoxHardening.log file attached.

The SentinelOne software hasn't blocked Virtualbox, according to the guys in charge.

I'm at a loss here, has anyone encountered the same problem?

Re: Hardening problems - possibly connected with SentinelOne

Posted: 27. Mar 2022, 21:59
by mjhammer
@Magnar, No you are not alone. My VBox isntallation on a windows 11 host acts the exact same way. I had to downgrade to .30 to overcome a CPU lockup issue, and it did the same behaviour as .32 on my host. Not a real problem for me. But you are not alone. MJH

Re: Hardening problems - possibly connected with SentinelOne

Posted: 27. Mar 2022, 21:59
by fth0
Do you have 2019 SHA-2 Code Signing Support requirement for Windows and WSUS installed on your Windows 7 host? If not, please install it and see if it makes a difference.