36b4.454: Log file opened: 5.1.12r112440 g_hStartupLog=0000000000000078 g_uNtVerCombined=0xa0383900 36b4.454: \SystemRoot\System32\ntdll.dll: 36b4.454: CreationTime: 2016-12-09T16:29:15.743030700Z 36b4.454: LastWriteTime: 2016-11-11T10:13:03.409595100Z 36b4.454: ChangeTime: 2016-12-15T09:59:07.047708300Z 36b4.454: FileAttributes: 0x20 36b4.454: Size: 0x1cc888 36b4.454: NT Headers: 0xd8 36b4.454: Timestamp: 0x5825887f 36b4.454: Machine: 0x8664 - amd64 36b4.454: Timestamp: 0x5825887f 36b4.454: Image Version: 10.0 36b4.454: SizeOfImage: 0x1d1000 (1904640) 36b4.454: Resource Dir: 0x168000 LB 0x67988 36b4.454: ProductName: Microsoft® Windows® Operating System 36b4.454: ProductVersion: 10.0.14393.479 36b4.454: FileVersion: 10.0.14393.479 (rs1_release.161110-2025) 36b4.454: FileDescription: NT Layer DLL 36b4.454: \SystemRoot\System32\kernel32.dll: 36b4.454: CreationTime: 2016-07-16T11:42:16.155721400Z 36b4.454: LastWriteTime: 2016-07-16T11:42:16.155721400Z 36b4.454: ChangeTime: 2016-10-01T19:09:35.919501900Z 36b4.454: FileAttributes: 0x20 36b4.454: Size: 0xaade8 36b4.454: NT Headers: 0xf0 36b4.454: Timestamp: 0x57899a29 36b4.454: Machine: 0x8664 - amd64 36b4.454: Timestamp: 0x57899a29 36b4.454: Image Version: 10.0 36b4.454: SizeOfImage: 0xab000 (700416) 36b4.454: Resource Dir: 0xa9000 LB 0x528 36b4.454: ProductName: Microsoft® Windows® Operating System 36b4.454: ProductVersion: 10.0.14393.0 36b4.454: FileVersion: 10.0.14393.0 (rs1_release.160715-1616) 36b4.454: FileDescription: Windows NT BASE API Client DLL 36b4.454: \SystemRoot\System32\KernelBase.dll: 36b4.454: CreationTime: 2016-12-09T16:28:22.786852700Z 36b4.454: LastWriteTime: 2016-11-11T10:13:54.529597600Z 36b4.454: ChangeTime: 2016-12-15T09:59:07.031089300Z 36b4.454: FileAttributes: 0x20 36b4.454: Size: 0x21c780 36b4.454: NT Headers: 0xf8 36b4.454: Timestamp: 0x582588e6 36b4.454: Machine: 0x8664 - amd64 36b4.454: Timestamp: 0x582588e6 36b4.454: Image Version: 10.0 36b4.454: SizeOfImage: 0x21d000 (2215936) 36b4.454: Resource Dir: 0x201000 LB 0x550 36b4.454: ProductName: Microsoft® Windows® Operating System 36b4.454: ProductVersion: 10.0.14393.479 36b4.454: FileVersion: 10.0.14393.479 (rs1_release.161110-2025) 36b4.454: FileDescription: Windows NT BASE API Client DLL 36b4.454: \SystemRoot\System32\apisetschema.dll: 36b4.454: CreationTime: 2016-07-16T11:42:21.577586000Z 36b4.454: LastWriteTime: 2016-07-16T11:42:21.577586000Z 36b4.454: ChangeTime: 2016-09-29T09:59:51.463720800Z 36b4.454: FileAttributes: 0x20 36b4.454: Size: 0x18960 36b4.454: NT Headers: 0xc8 36b4.454: Timestamp: 0x57899bd2 36b4.454: Machine: 0x8664 - amd64 36b4.454: Timestamp: 0x57899bd2 36b4.454: Image Version: 10.0 36b4.454: SizeOfImage: 0x19000 (102400) 36b4.454: Resource Dir: 0x18000 LB 0x400 36b4.454: ProductName: Microsoft® Windows® Operating System 36b4.454: ProductVersion: 10.0.14393.0 36b4.454: FileVersion: 10.0.14393.0 (rs1_release.160715-1616) 36b4.454: FileDescription: ApiSet Schema DLL 36b4.454: Found driver avgfwfd (0x100) 36b4.454: supR3HardenedWinFindAdversaries: 0x100 36b4.454: \SystemRoot\System32\drivers\avgrkx64.sys: 36b4.454: CreationTime: 2015-08-10T14:25:40.000000000Z 36b4.454: LastWriteTime: 2016-06-01T12:16:40.000000000Z 36b4.454: ChangeTime: 2016-09-29T09:25:03.148456200Z 36b4.454: FileAttributes: 0x20 36b4.454: Size: 0xcf00 36b4.454: NT Headers: 0xd8 36b4.454: Timestamp: 0x574ec40f 36b4.454: Machine: 0x8664 - amd64 36b4.454: Timestamp: 0x574ec40f 36b4.454: Image Version: 6.2 36b4.454: SizeOfImage: 0xb000 (45056) 36b4.454: Resource Dir: 0x9000 LB 0x510 36b4.454: ProductName: AVG Internet Security 36b4.454: ProductVersion: 16.90.0.7673 36b4.454: FileVersion: 16.90.0.7673 36b4.454: SpecialBuild: AvCompile_2016_0601_131222(7673), SVNRev cc10eaccfa4cdc44f6f43b26dbe769983b6f0839 (av/devel), av, gbn 16.90.2.18750 36b4.454: PrivateBuild: x64 Release_Unicode_DRIVER 36b4.454: FileDescription: AVG Anti-Rootkit Driver 36b4.454: \SystemRoot\System32\drivers\avgmfx64.sys: 36b4.454: CreationTime: 2016-09-26T17:19:22.000000000Z 36b4.454: LastWriteTime: 2016-09-26T17:19:22.000000000Z 36b4.454: ChangeTime: 2016-11-23T16:41:48.118372900Z 36b4.454: FileAttributes: 0x20 36b4.454: Size: 0x3e100 36b4.454: NT Headers: 0xe8 36b4.454: Timestamp: 0x57e94a81 36b4.454: Machine: 0x8664 - amd64 36b4.454: Timestamp: 0x57e94a81 36b4.454: Image Version: 6.2 36b4.454: SizeOfImage: 0x3c000 (245760) 36b4.454: Resource Dir: 0x3a000 LB 0x560 36b4.454: ProductName: AVG Internet Security 36b4.454: ProductVersion: 16.121.0.7858 36b4.454: FileVersion: 16.121.0.7858 36b4.454: SpecialBuild: AvCompile_2016_0926_180907(7858), SVNRev 89be4c719ae91eb486fd7c7ebc47674d4095f27f (release/SmallUpdate2016-12_release), av, gbn 16.121.0.7858 36b4.454: PrivateBuild: x64 Release_Unicode_DRIVER 36b4.454: FileDescription: AVG Resident Shield Minifilter Driver 36b4.454: \SystemRoot\System32\drivers\avgidsdrivera.sys: 36b4.454: CreationTime: 2016-10-17T17:19:16.000000000Z 36b4.454: LastWriteTime: 2016-10-17T17:19:16.000000000Z 36b4.454: ChangeTime: 2016-11-23T16:41:48.840496100Z 36b4.454: FileAttributes: 0x20 36b4.454: Size: 0x4c500 36b4.454: NT Headers: 0xd8 36b4.454: Timestamp: 0x5804f9fb 36b4.454: Machine: 0x8664 - amd64 36b4.454: Timestamp: 0x5804f9fb 36b4.454: Image Version: 6.2 36b4.454: SizeOfImage: 0x50000 (327680) 36b4.454: Resource Dir: 0x4e000 LB 0x580 36b4.454: ProductName: AVG Internet Security 36b4.454: ProductVersion: 16.131.0.7915 36b4.454: FileVersion: 16.131.0.7915 36b4.454: SpecialBuild: AvCompile_2016_1017_180230(7915), SVNRev df02baa198725a1b47077360d46f634c9bf38a3b (release/SmallUpdate2016-13_release), av, gbn 16.131.0.7915 36b4.454: PrivateBuild: x64 Release_Unicode_DRIVER 36b4.454: FileDescription: AVG IDS Application Activity Monitor Driver. 36b4.454: \SystemRoot\System32\drivers\avgidsha.sys: 36b4.454: CreationTime: 2015-08-20T12:58:04.000000000Z 36b4.454: LastWriteTime: 2016-10-05T15:01:16.000000000Z 36b4.454: ChangeTime: 2016-11-23T16:41:48.718947400Z 36b4.454: FileAttributes: 0x20 36b4.454: Size: 0x41300 36b4.454: NT Headers: 0xd8 36b4.454: Timestamp: 0x57f5079c 36b4.454: Machine: 0x8664 - amd64 36b4.454: Timestamp: 0x57f5079c 36b4.454: Image Version: 6.2 36b4.454: SizeOfImage: 0x3f000 (258048) 36b4.454: Resource Dir: 0x3d000 LB 0x540 36b4.454: ProductName: AVG Internet Security 36b4.454: ProductVersion: 16.130.0.7889 36b4.454: FileVersion: 16.130.0.7889 36b4.454: SpecialBuild: AvCompile_2016_1005_154353(7889), SVNRev 91e4972c99c0d1eff222c378862577f230331aac (av/devel), av, gbn 16.130.0.7889 36b4.454: PrivateBuild: x64 Release_Unicode_DRIVER 36b4.454: FileDescription: AVG Application Activity Monitor Helper Driver 36b4.454: \SystemRoot\System32\drivers\avgloga.sys: 36b4.454: CreationTime: 2016-02-16T15:05:56.000000000Z 36b4.454: LastWriteTime: 2016-02-16T15:05:56.000000000Z 36b4.454: ChangeTime: 2016-09-29T09:25:02.664058800Z 36b4.454: FileAttributes: 0x20 36b4.454: Size: 0x58120 36b4.454: NT Headers: 0xe0 36b4.454: Timestamp: 0x56c32c53 36b4.454: Machine: 0x8664 - amd64 36b4.454: Timestamp: 0x56c32c53 36b4.454: Image Version: 6.2 36b4.454: SizeOfImage: 0x55000 (348160) 36b4.454: Resource Dir: 0x53000 LB 0x500 36b4.454: ProductName: AVG Internet Security 36b4.454: ProductVersion: 16.60.0.7513 36b4.454: FileVersion: 16.60.0.7513 36b4.454: SpecialBuild: AvCompile_2016_0216_145142(7513), SVNRev f797a3270884e4c0f85189d098fc7633e15c31ee (av/devel), av, gbn 16.60.1.59398 36b4.454: PrivateBuild: x64 Release_Unicode_DRIVER 36b4.454: FileDescription: AVG Logging Driver 36b4.454: \SystemRoot\System32\drivers\avgldx64.sys: 36b4.454: CreationTime: 2016-10-19T14:13:48.000000000Z 36b4.454: LastWriteTime: 2016-10-19T14:13:48.000000000Z 36b4.454: ChangeTime: 2016-11-23T16:41:46.500731900Z 36b4.454: FileAttributes: 0x20 36b4.454: Size: 0x41500 36b4.454: NT Headers: 0xe0 36b4.454: Timestamp: 0x5807717a 36b4.454: Machine: 0x8664 - amd64 36b4.454: Timestamp: 0x5807717a 36b4.454: Image Version: 6.2 36b4.454: SizeOfImage: 0x40000 (262144) 36b4.454: Resource Dir: 0x3e000 LB 0x540 36b4.454: ProductName: AVG Internet Security 36b4.454: ProductVersion: 16.131.0.7916 36b4.454: FileVersion: 16.131.0.7916 36b4.454: SpecialBuild: AvCompile_2016_1019_145744(7916), SVNRev 238ac34d70d0593a5a80e22954eb3a1f6cc7a151 (release/SmallUpdate2016-13_release), av, gbn 16.131.0.7916 36b4.454: PrivateBuild: x64 Release_Unicode_DRIVER 36b4.454: FileDescription: AVG AVI Loader Driver 36b4.454: \SystemRoot\System32\drivers\avgdiska.sys: 36b4.454: CreationTime: 2016-05-13T06:52:10.000000000Z 36b4.454: LastWriteTime: 2016-05-13T06:52:10.000000000Z 36b4.454: ChangeTime: 2016-09-29T09:25:05.851863900Z 36b4.454: FileAttributes: 0x20 36b4.454: Size: 0x27d00 36b4.454: NT Headers: 0xe0 36b4.454: Timestamp: 0x57356b82 36b4.454: Machine: 0x8664 - amd64 36b4.454: Timestamp: 0x57356b82 36b4.454: Image Version: 6.2 36b4.454: SizeOfImage: 0x27000 (159744) 36b4.454: Resource Dir: 0x25000 LB 0x50c 36b4.454: ProductName: AVG Internet Security 36b4.454: ProductVersion: 16.90.0.7664 36b4.454: FileVersion: 16.90.0.7664 36b4.454: SpecialBuild: AvCompile_2016_0513_073811(7664), SVNRev 89c5fd034c9aa09052301d6769ab0e7ab54878fc (av/devel), av, gbn 16.90.2.14599 36b4.454: PrivateBuild: x64 Release_Unicode_DRIVER 36b4.454: FileDescription: AVG File Vault Driver 36b4.454: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox' 36b4.454: Calling main() 36b4.454: SUPR3HardenedMain: pszProgName=VirtualBox fFlags=0x2 36b4.454: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox' 36b4.454: SUPR3HardenedMain: Respawn #1 36b4.454: System32: \Device\HarddiskVolume4\Windows\System32 36b4.454: WinSxS: \Device\HarddiskVolume4\Windows\WinSxS 36b4.454: KnownDllPath: C:\WINDOWS\System32 36b4.454: '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports 36b4.454: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe) 36b4.454: supR3HardNtEnableThreadCreation: 36b4.454: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ff820c09fa0 pvNtTerminateThread=00007ff820c36b20 36b4.454: supR3HardenedWinDoReSpawn(1): New child 31f4.3884 [kernel32]. 36b4.454: supR3HardNtChildGatherData: PebBaseAddress=00000000005c5000 cbPeb=0x388 36b4.454: supR3HardNtPuChFindNtdll: uNtDllParentAddr=00007ff820b90000 uNtDllChildAddr=00007ff820b90000 36b4.454: supR3HardenedWinSetupChildInit: uLdrInitThunk=00007ff820c09fa0 36b4.454: supR3HardenedWinSetupChildInit: Start child. 36b4.454: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms. 36b4.454: supR3HardNtChildPurify: Startup delay kludge #1/0: 520 ms, 60 sleeps 36b4.454: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION 36b4.454: *0000000000000000-ffffffffffdbffff 0x0001/0x0000 0x0000000 36b4.454: *0000000000240000-000000000021ffff 0x0004/0x0004 0x0020000 36b4.454: *0000000000260000-0000000000249fff 0x0002/0x0002 0x0040000 36b4.454: 0000000000276000-000000000026bfff 0x0001/0x0000 0x0000000 36b4.454: *0000000000280000-0000000000184fff 0x0000/0x0004 0x0020000 36b4.454: 000000000037b000-0000000000377fff 0x0104/0x0004 0x0020000 36b4.454: 000000000037e000-000000000037bfff 0x0004/0x0004 0x0020000 36b4.454: *0000000000380000-000000000037bfff 0x0002/0x0002 0x0040000 36b4.454: 0000000000384000-0000000000377fff 0x0001/0x0000 0x0000000 36b4.454: *0000000000390000-000000000038dfff 0x0004/0x0004 0x0020000 36b4.454: 0000000000392000-0000000000323fff 0x0001/0x0000 0x0000000 36b4.454: *0000000000400000-000000000023afff 0x0000/0x0004 0x0020000 36b4.454: 00000000005c5000-00000000005c1fff 0x0004/0x0004 0x0020000 36b4.454: 00000000005c8000-000000000058ffff 0x0000/0x0004 0x0020000 36b4.454: 0000000000600000-ffffffff80c1ffff 0x0001/0x0000 0x0000000 36b4.454: *000000007ffe0000-000000007ffdefff 0x0002/0x0002 0x0020000 36b4.454: 000000007ffe1000-000000007ffd1fff 0x0000/0x0002 0x0020000 36b4.454: 000000007fff0000-ffff8009c018ffff 0x0001/0x0000 0x0000000 36b4.454: *00007ff73fe50000-00007ff73fe2cfff 0x0002/0x0002 0x0040000 36b4.454: 00007ff73fe73000-00007ff73f4e5fff 0x0001/0x0000 0x0000000 36b4.454: *00007ff740800000-00007ff740800fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe 36b4.454: 00007ff740801000-00007ff74086ffff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe 36b4.454: 00007ff740870000-00007ff740870fff 0x0080/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe 36b4.454: 00007ff740871000-00007ff7408b5fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe 36b4.454: 00007ff7408b6000-00007ff7408b6fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe 36b4.454: 00007ff7408b7000-00007ff7408b7fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe 36b4.454: 00007ff7408b8000-00007ff7408bcfff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe 36b4.454: 00007ff7408bd000-00007ff7408bdfff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe 36b4.454: 00007ff7408be000-00007ff7408befff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe 36b4.454: 00007ff7408bf000-00007ff7408c2fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe 36b4.454: 00007ff7408c3000-00007ff74090afff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe 36b4.454: 00007ff74090b000-00007ff660685fff 0x0001/0x0000 0x0000000 36b4.454: *00007ff820b90000-00007ff820b90fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll 36b4.454: 00007ff820b91000-00007ff820c97fff 0x0020/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll 36b4.454: 00007ff820c98000-00007ff820cdbfff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll 36b4.454: 00007ff820cdc000-00007ff820ce4fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll 36b4.454: 00007ff820ce5000-00007ff820cf2fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll 36b4.454: 00007ff820cf3000-00007ff820cf3fff 0x0004/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll 36b4.454: 00007ff820cf4000-00007ff820cf6fff 0x0008/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll 36b4.454: 00007ff820cf7000-00007ff820d60fff 0x0002/0x0080 0x1000000 \Device\HarddiskVolume4\Windows\System32\ntdll.dll 36b4.454: 00007ff820d61000-00007ff041ae1fff 0x0001/0x0000 0x0000000 36b4.454: *00007ffffffe0000-00007ffffffcffff 0x0001/0x0002 0x0020000 36b4.454: VirtualBox.exe: timestamp 0x58594e7b (rc=VINF_SUCCESS) 36b4.454: '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe' has no imports 36b4.454: '\Device\HarddiskVolume4\Windows\System32\ntdll.dll' has no imports 36b4.454: supR3HardNtChildPurify: Done after 622 ms and 0 fixes (loop #0). 31f4.3884: Log file opened: 5.1.12r112440 g_hStartupLog=0000000000000004 g_uNtVerCombined=0xa0383900 31f4.3884: supR3HardenedVmProcessInit: uNtDllAddr=00007ff820b90000 g_uNtVerCombined=0xa0383900 31f4.3884: ntdll.dll: timestamp 0x5825887f (rc=VINF_SUCCESS) 31f4.3884: New simple heap: #1 0000000000700000 LB 0x400000 (for 1904640 allocation) 36b4.454: supR3HardNtEnableThreadCreation: 31f4.3884: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume4\Program Files\Oracle\VirtualBox' 31f4.3884: System32: \Device\HarddiskVolume4\Windows\System32 31f4.3884: WinSxS: \Device\HarddiskVolume4\Windows\WinSxS 31f4.3884: KnownDllPath: C:\WINDOWS\System32 31f4.3884: supR3HardenedVmProcessInit: Opening vboxdrv stub... 31f4.3884: supR3HardenedWinReadErrorInfoDevice: 'Not signed with the build certificate.: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe' 31f4.3884: Error -5657 in supR3HardenedWinReSpawn! (enmWhat=3) 31f4.3884: NtCreateFile(\Device\VBoxDrvStub) failed: Unknown Status -5657 (0xffffe9e7) (rcNt=0xe986e9e7) VBoxDrvStub error: Not signed with the build certificate.: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe 36b4.454: supR3HardenedWinCheckChild: enmRequest=2 rc=-5657 enmWhat=3 supR3HardenedWinReSpawn: NtCreateFile(\Device\VBoxDrvStub) failed: Unknown Status -5657 (0xffffe9e7) (rcNt=0xe986e9e7) VBoxDrvStub error: Not signed with the build certificate.: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe 36b4.454: Error -5657 in supR3HardenedWinReSpawn! (enmWhat=3) 36b4.454: NtCreateFile(\Device\VBoxDrvStub) failed: Unknown Status -5657 (0xffffe9e7) (rcNt=0xe986e9e7) VBoxDrvStub error: Not signed with the build certificate.: \Device\HarddiskVolume4\Program Files\Oracle\VirtualBox\VirtualBox.exe