Please help me.
Here's the log.
Code: Select all
4144.5360: Log file opened: 5.1.8r111374 g_hStartupLog=00000000000001a0 g_uNtVerCombined=0xa0383900
4144.5360: \SystemRoot\System32\ntdll.dll:
4144.5360: CreationTime: 2016-11-09T02:55:12.549482200Z
4144.5360: LastWriteTime: 2016-11-02T11:13:47.946508600Z
4144.5360: ChangeTime: 2016-11-09T05:49:25.730298000Z
4144.5360: FileAttributes: 0x20
4144.5360: Size: 0x1cbe88
4144.5360: NT Headers: 0xd8
4144.5360: Timestamp: 0x5819bc32
4144.5360: Machine: 0x8664 - amd64
4144.5360: Timestamp: 0x5819bc32
4144.5360: Image Version: 10.0
4144.5360: SizeOfImage: 0x1d1000 (1904640)
4144.5360: Resource Dir: 0x168000 LB 0x67998
4144.5360: ProductName: Microsoft® Windows® Operating System
4144.5360: ProductVersion: 10.0.14393.447
4144.5360: FileVersion: 10.0.14393.447 (rs1_release_inmarket.161102-0100)
4144.5360: FileDescription: NT Layer DLL
4144.5360: \SystemRoot\System32\kernel32.dll:
4144.5360: CreationTime: 2016-07-16T11:42:16.155721400Z
4144.5360: LastWriteTime: 2016-07-16T11:42:16.155721400Z
4144.5360: ChangeTime: 2016-09-25T23:54:22.159608600Z
4144.5360: FileAttributes: 0x20
4144.5360: Size: 0xaade8
4144.5360: NT Headers: 0xf0
4144.5360: Timestamp: 0x57899a29
4144.5360: Machine: 0x8664 - amd64
4144.5360: Timestamp: 0x57899a29
4144.5360: Image Version: 10.0
4144.5360: SizeOfImage: 0xab000 (700416)
4144.5360: Resource Dir: 0xa9000 LB 0x528
4144.5360: ProductName: Microsoft® Windows® Operating System
4144.5360: ProductVersion: 10.0.14393.0
4144.5360: FileVersion: 10.0.14393.0 (rs1_release.160715-1616)
4144.5360: FileDescription: Windows NT BASE API Client DLL
4144.5360: \SystemRoot\System32\KernelBase.dll:
4144.5360: CreationTime: 2016-10-13T00:24:37.488179500Z
4144.5360: LastWriteTime: 2016-10-05T10:31:27.772259900Z
4144.5360: ChangeTime: 2016-11-09T03:18:45.031298800Z
4144.5360: FileAttributes: 0x20
4144.5360: Size: 0x21c580
4144.5360: NT Headers: 0xf8
4144.5360: Timestamp: 0x57f4c4f0
4144.5360: Machine: 0x8664 - amd64
4144.5360: Timestamp: 0x57f4c4f0
4144.5360: Image Version: 10.0
4144.5360: SizeOfImage: 0x21d000 (2215936)
4144.5360: Resource Dir: 0x201000 LB 0x560
4144.5360: ProductName: Microsoft® Windows® Operating System
4144.5360: ProductVersion: 10.0.14393.321
4144.5360: FileVersion: 10.0.14393.321 (rs1_release_inmarket.161004-2338)
4144.5360: FileDescription: Windows NT BASE API Client DLL
4144.5360: \SystemRoot\System32\apisetschema.dll:
4144.5360: CreationTime: 2016-07-16T11:42:21.577586000Z
4144.5360: LastWriteTime: 2016-07-16T11:42:21.577586000Z
4144.5360: ChangeTime: 2016-09-25T23:54:20.487713100Z
4144.5360: FileAttributes: 0x20
4144.5360: Size: 0x18960
4144.5360: NT Headers: 0xc8
4144.5360: Timestamp: 0x57899bd2
4144.5360: Machine: 0x8664 - amd64
4144.5360: Timestamp: 0x57899bd2
4144.5360: Image Version: 10.0
4144.5360: SizeOfImage: 0x19000 (102400)
4144.5360: Resource Dir: 0x18000 LB 0x400
4144.5360: ProductName: Microsoft® Windows® Operating System
4144.5360: ProductVersion: 10.0.14393.0
4144.5360: FileVersion: 10.0.14393.0 (rs1_release.160715-1616)
4144.5360: FileDescription: ApiSet Schema DLL
4144.5360: supR3HardenedWinFindAdversaries: 0x0
4144.5360: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox'
4144.5360: Calling main()
4144.5360: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2
4144.5360: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox'
4144.5360: SUPR3HardenedMain: Respawn #1
4144.5360: System32: \Device\HarddiskVolume3\Windows\System32
4144.5360: WinSxS: \Device\HarddiskVolume3\Windows\WinSxS
4144.5360: KnownDllPath: C:\WINDOWS\System32
4144.5360: '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
4144.5360: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe)
4144.5360: supR3HardNtEnableThreadCreation:
4144.5360: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ff989c78d60 pvNtTerminateThread=00007ff989ca58b0
4144.5360: supR3HardenedWinDoReSpawn(1): New child 4890.1ce0 [kernel32].
4144.5360: supR3HardNtChildGatherData: PebBaseAddress=0000000000877000 cbPeb=0x388
4144.5360: supR3HardNtPuChFindNtdll: uNtDllParentAddr=00007ff989c00000 uNtDllChildAddr=00007ff989c00000
4144.5360: supR3HardenedWinSetupChildInit: uLdrInitThunk=00007ff989c78d60
4144.5360: supR3HardenedWinSetupChildInit: Start child.
4144.5360: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 1 ms.
4144.5360: supR3HardNtChildPurify: Startup delay kludge #1/0: 264 ms, 30 sleeps
4144.5360: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
4144.5360: *0000000000000000-ffffffffff97ffff 0x0001/0x0000 0x0000000
4144.5360: *0000000000680000-000000000065ffff 0x0004/0x0004 0x0020000
4144.5360: *00000000006a0000-0000000000689fff 0x0002/0x0002 0x0040000
4144.5360: 00000000006b6000-00000000006abfff 0x0001/0x0000 0x0000000
4144.5360: *00000000006c0000-00000000005c4fff 0x0000/0x0004 0x0020000
4144.5360: 00000000007bb000-00000000007b7fff 0x0104/0x0004 0x0020000
4144.5360: 00000000007be000-00000000007bbfff 0x0004/0x0004 0x0020000
4144.5360: *00000000007c0000-00000000007bbfff 0x0002/0x0002 0x0040000
4144.5360: 00000000007c4000-00000000007b7fff 0x0001/0x0000 0x0000000
4144.5360: *00000000007d0000-00000000007cdfff 0x0004/0x0004 0x0020000
4144.5360: 00000000007d2000-00000000007b3fff 0x0001/0x0000 0x0000000
4144.5360: *00000000007f0000-00000000007edfff 0x0040/0x0040 0x0020000 !!
4144.5360: supHardNtVpFreeOrReplacePrivateExecMemory: Freeing exec mem at 00000000007f0000 (LB 0x2000, 00000000007f0000 LB 0x2000)
4144.5360: supHardNtVpFreeOrReplacePrivateExecMemory: Free attempt #1 succeeded: 0x0 [00000000007f0000/00000000007f0000 LB 0/0x2000]
4144.5360: supHardNtVpFreeOrReplacePrivateExecMemory: QVM after free 0: [0000000000000000]/00000000007f0000 LB 0x10000 s=0x10000 ap=0x0 rp=0x00000000000001
4144.5360: 00000000007f2000-00000000007e3fff 0x0001/0x0000 0x0000000
4144.5360: *0000000000800000-0000000000788fff 0x0000/0x0004 0x0020000
4144.5360: 0000000000877000-0000000000873fff 0x0004/0x0004 0x0020000
4144.5360: 000000000087a000-00000000006f3fff 0x0000/0x0004 0x0020000
4144.5360: 0000000000a00000-ffffffff8141ffff 0x0001/0x0000 0x0000000
4144.5360: *000000007ffe0000-000000007ffdefff 0x0002/0x0002 0x0020000
4144.5360: 000000007ffe1000-000000007ffd1fff 0x0000/0x0002 0x0020000
4144.5360: 000000007fff0000-ffff800a0c9bffff 0x0001/0x0000 0x0000000
4144.5360: *00007ff6f3620000-00007ff6f35ecfff 0x0002/0x0002 0x0040000
4144.5360: 00007ff6f3653000-00007ff6f2f05fff 0x0001/0x0000 0x0000000
4144.5360: *00007ff6f3da0000-00007ff6f3da0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
4144.5360: 00007ff6f3da1000-00007ff6f3e0ffff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
4144.5360: 00007ff6f3e10000-00007ff6f3e10fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
4144.5360: 00007ff6f3e11000-00007ff6f3e55fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
4144.5360: 00007ff6f3e56000-00007ff6f3e56fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
4144.5360: 00007ff6f3e57000-00007ff6f3e57fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
4144.5360: 00007ff6f3e58000-00007ff6f3e5cfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
4144.5360: 00007ff6f3e5d000-00007ff6f3e5dfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
4144.5360: 00007ff6f3e5e000-00007ff6f3e5efff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
4144.5360: 00007ff6f3e5f000-00007ff6f3e62fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
4144.5360: 00007ff6f3e63000-00007ff6f3eaafff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
4144.5360: 00007ff6f3eab000-00007ff45e155fff 0x0001/0x0000 0x0000000
4144.5360: *00007ff989c00000-00007ff989c00fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
4144.5360: 00007ff989c01000-00007ff989d07fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
4144.5360: 00007ff989d08000-00007ff989d4bfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
4144.5360: 00007ff989d4c000-00007ff989d54fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
4144.5360: 00007ff989d55000-00007ff989d62fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
4144.5360: 00007ff989d63000-00007ff989d63fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
4144.5360: 00007ff989d64000-00007ff989d66fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
4144.5360: 00007ff989d67000-00007ff989dd0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
4144.5360: 00007ff989dd1000-00007ff313bc1fff 0x0001/0x0000 0x0000000
4144.5360: *00007ffffffe0000-00007ffffffcffff 0x0001/0x0002 0x0020000
4144.5360: VirtualBox.exe: timestamp 0x58062715 (rc=VINF_SUCCESS)
4144.5360: '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
4144.5360: '\Device\HarddiskVolume3\Windows\System32\ntdll.dll' has no imports
4144.5360: supR3HardNtChildPurify: cFixes=1 g_fSupAdversaries=0x80000000
4144.5360: supR3HardNtChildPurify: Startup delay kludge #1/1: 521 ms, 54 sleeps
4144.5360: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
4144.5360: *0000000000000000-ffffffffff97ffff 0x0001/0x0000 0x0000000
4144.5360: *0000000000680000-000000000065ffff 0x0004/0x0004 0x0020000
4144.5360: *00000000006a0000-0000000000689fff 0x0002/0x0002 0x0040000
4144.5360: 00000000006b6000-00000000006abfff 0x0001/0x0000 0x0000000
4144.5360: *00000000006c0000-00000000005c4fff 0x0000/0x0004 0x0020000
4144.5360: 00000000007bb000-00000000007b7fff 0x0104/0x0004 0x0020000
4144.5360: 00000000007be000-00000000007bbfff 0x0004/0x0004 0x0020000
4144.5360: *00000000007c0000-00000000007bbfff 0x0002/0x0002 0x0040000
4144.5360: 00000000007c4000-00000000007b7fff 0x0001/0x0000 0x0000000
4144.5360: *00000000007d0000-00000000007cdfff 0x0004/0x0004 0x0020000
4144.5360: 00000000007d2000-00000000007a3fff 0x0001/0x0000 0x0000000
4144.5360: *0000000000800000-0000000000788fff 0x0000/0x0004 0x0020000
4144.5360: 0000000000877000-0000000000873fff 0x0004/0x0004 0x0020000
4144.5360: 000000000087a000-00000000006f3fff 0x0000/0x0004 0x0020000
4144.5360: 0000000000a00000-ffffffff8141ffff 0x0001/0x0000 0x0000000
4144.5360: *000000007ffe0000-000000007ffdefff 0x0002/0x0002 0x0020000
4144.5360: 000000007ffe1000-000000007ffd1fff 0x0000/0x0002 0x0020000
4144.5360: 000000007fff0000-ffff800a0c9bffff 0x0001/0x0000 0x0000000
4144.5360: *00007ff6f3620000-00007ff6f35ecfff 0x0002/0x0002 0x0040000
4144.5360: 00007ff6f3653000-00007ff6f2f05fff 0x0001/0x0000 0x0000000
4144.5360: *00007ff6f3da0000-00007ff6f3da0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
4144.5360: 00007ff6f3da1000-00007ff6f3e0ffff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
4144.5360: 00007ff6f3e10000-00007ff6f3e10fff 0x0040/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
4144.5360: 00007ff6f3e11000-00007ff6f3e55fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
4144.5360: 00007ff6f3e56000-00007ff6f3e62fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
4144.5360: 00007ff6f3e63000-00007ff6f3eaafff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
4144.5360: 00007ff6f3eab000-00007ff45e155fff 0x0001/0x0000 0x0000000
4144.5360: *00007ff989c00000-00007ff989c00fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
4144.5360: 00007ff989c01000-00007ff989d07fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
4144.5360: 00007ff989d08000-00007ff989d4bfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
4144.5360: 00007ff989d4c000-00007ff989d4ffff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
4144.5360: 00007ff989d50000-00007ff989d54fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
4144.5360: 00007ff989d55000-00007ff989d62fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
4144.5360: 00007ff989d63000-00007ff989d63fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
4144.5360: 00007ff989d64000-00007ff989d66fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
4144.5360: 00007ff989d67000-00007ff989dd0fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume3\Windows\System32\ntdll.dll
4144.5360: 00007ff989dd1000-00007ff313bc1fff 0x0001/0x0000 0x0000000
4144.5360: *00007ffffffe0000-00007ffffffcffff 0x0001/0x0002 0x0020000
4144.5360: supR3HardNtChildPurify: Done after 1058 ms and 1 fixes (loop #1).
4890.1ce0: Log file opened: 5.1.8r111374 g_hStartupLog=0000000000000004 g_uNtVerCombined=0xa0383900
4890.1ce0: supR3HardenedVmProcessInit: uNtDllAddr=00007ff989c00000 g_uNtVerCombined=0xa0383900
4144.5360: supR3HardNtEnableThreadCreation:
4890.1ce0: ntdll.dll: timestamp 0x5819bc32 (rc=VINF_SUCCESS)
4890.1ce0: New simple heap: #1 0000000000b00000 LB 0x400000 (for 1904640 allocation)
4890.1ce0: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox'
4890.1ce0: System32: \Device\HarddiskVolume3\Windows\System32
4890.1ce0: WinSxS: \Device\HarddiskVolume3\Windows\WinSxS
4890.1ce0: KnownDllPath: C:\WINDOWS\System32
4890.1ce0: supR3HardenedVmProcessInit: Opening vboxdrv stub...
4890.1ce0: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
4890.1ce0: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
4890.1ce0: Registered Dll notification callback with NTDLL.
4890.1ce0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\kernel32.dll)
4890.1ce0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\kernel32.dll
4890.1ce0: supR3HardenedMonitor_LdrLoadDll: pName=C:\WINDOWS\System32\KERNEL32.DLL (Input=KERNEL32.DLL, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000004001:<flags> [calling]
4890.1ce0: supR3HardenedDllNotificationCallback: load 00007ff986f70000 LB 0x0021d000 C:\WINDOWS\System32\KERNELBASE.dll [fFlags=0x0]
4890.1ce0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\KernelBase.dll)
4890.1ce0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\KernelBase.dll
4890.1ce0: supR3HardenedDllNotificationCallback: load 00007ff9875c0000 LB 0x000ab000 C:\WINDOWS\System32\KERNEL32.DLL [fFlags=0x0]
4890.1ce0: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
4890.1ce0: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ff9875c0000 'C:\WINDOWS\System32\KERNEL32.DLL'
4890.1ce0: supR3HardenedDllNotificationCallback: load 00007ff6f3da0000 LB 0x0010b000 C:\Program Files\Oracle\VirtualBox\VirtualBox.exe [fFlags=0x0]
4890.1ce0: '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports
4890.1ce0: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe)
4890.1ce0: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBox.exe
4144.5360: supR3HardNtChildWaitFor[1]: Quitting: ExitCode=0xc0000005 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 174 ms, CloseEvents);