下面是日志内容

解决方案 »

  1.   

    18d4.b48: Log file opened: 5.2.6r120293 g_hStartupLog=0000000000000020 g_uNtVerCombined=0x611db110
    18d4.b48: \SystemRoot\System32\ntdll.dll:
    18d4.b48:     CreationTime:    2016-12-19T13:51:04.197606600Z
    18d4.b48:     LastWriteTime:   2016-12-19T13:51:04.197606600Z
    18d4.b48:     ChangeTime:      2018-01-14T06:02:35.209820700Z
    18d4.b48:     FileAttributes:  0x20
    18d4.b48:     Size:            0x1a7100
    18d4.b48:     NT Headers:      0xe0
    18d4.b48:     Timestamp:       0x5708a857
    18d4.b48:     Machine:         0x8664 - amd64
    18d4.b48:     Timestamp:       0x5708a857
    18d4.b48:     Image Version:   6.1
    18d4.b48:     SizeOfImage:     0x1aa000 (1744896)
    18d4.b48:     Resource Dir:    0x14e000 LB 0x5a028
    18d4.b48:     [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
    18d4.b48:     [Raw version resource data: 0x14e0f0 LB 0x380, codepage 0x0 (reserved 0x0)]
    18d4.b48:     ProductName:     Microsoft® Windows® Operating System
    18d4.b48:     ProductVersion:  6.1.7601.23418
    18d4.b48:     FileVersion:     6.1.7601.23418 (win7sp1_ldr.160408-2045)
    18d4.b48:     FileDescription: NT Layer DLL
    18d4.b48: \SystemRoot\System32\kernel32.dll:
    18d4.b48:     CreationTime:    2016-12-19T13:51:04.197606600Z
    18d4.b48:     LastWriteTime:   2016-12-19T13:51:04.197606600Z
    18d4.b48:     ChangeTime:      2018-01-14T06:02:20.145621000Z
    18d4.b48:     FileAttributes:  0x20
    18d4.b48:     Size:            0x11c000
    18d4.b48:     NT Headers:      0xe0
    18d4.b48:     Timestamp:       0x5708a89b
    18d4.b48:     Machine:         0x8664 - amd64
    18d4.b48:     Timestamp:       0x5708a89b
    18d4.b48:     Image Version:   6.1
    18d4.b48:     SizeOfImage:     0x11f000 (1175552)
    18d4.b48:     Resource Dir:    0x116000 LB 0x528
    18d4.b48:     [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
    18d4.b48:     [Raw version resource data: 0x1160b0 LB 0x3a4, codepage 0x0 (reserved 0x0)]
    18d4.b48:     ProductName:     Microsoft® Windows® Operating System
    18d4.b48:     ProductVersion:  6.1.7601.23418
    18d4.b48:     FileVersion:     6.1.7601.23418 (win7sp1_ldr.160408-2045)
    18d4.b48:     FileDescription: Windows NT BASE API Client DLL
    18d4.b48: \SystemRoot\System32\KernelBase.dll:
    18d4.b48:     CreationTime:    2016-12-19T13:51:04.213206600Z
    18d4.b48:     LastWriteTime:   2016-12-19T13:51:04.213206600Z
    18d4.b48:     ChangeTime:      2018-01-14T06:02:20.114369400Z
    18d4.b48:     FileAttributes:  0x20
    18d4.b48:     Size:            0x66800
    18d4.b48:     NT Headers:      0xe8
    18d4.b48:     Timestamp:       0x5708a89c
    18d4.b48:     Machine:         0x8664 - amd64
    18d4.b48:     Timestamp:       0x5708a89c
    18d4.b48:     Image Version:   6.1
    18d4.b48:     SizeOfImage:     0x6a000 (434176)
    18d4.b48:     Resource Dir:    0x68000 LB 0x530
    18d4.b48:     [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
    18d4.b48:     [Raw version resource data: 0x680b0 LB 0x3ac, codepage 0x0 (reserved 0x0)]
    18d4.b48:     ProductName:     Microsoft® Windows® Operating System
    18d4.b48:     ProductVersion:  6.1.7601.23418
    18d4.b48:     FileVersion:     6.1.7601.23418 (win7sp1_ldr.160408-2045)
    18d4.b48:     FileDescription: Windows NT BASE API Client DLL
    18d4.b48: \SystemRoot\System32\apisetschema.dll:
    18d4.b48:     CreationTime:    2016-12-19T13:51:04.197606600Z
    18d4.b48:     LastWriteTime:   2016-12-19T13:51:04.197606600Z
    18d4.b48:     ChangeTime:      2018-01-14T06:02:11.807888800Z
    18d4.b48:     FileAttributes:  0x20
    18d4.b48:     Size:            0x1a00
    18d4.b48:     NT Headers:      0xc0
    18d4.b48:     Timestamp:       0x5708a835
    18d4.b48:     Machine:         0x8664 - amd64
    18d4.b48:     Timestamp:       0x5708a835
    18d4.b48:     Image Version:   6.1
    18d4.b48:     SizeOfImage:     0x50000 (327680)
    18d4.b48:     Resource Dir:    0x30000 LB 0x3f8
    18d4.b48:     [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
    18d4.b48:     [Raw version resource data: 0x30060 LB 0x398, codepage 0x0 (reserved 0x0)]
    18d4.b48:     ProductName:     Microsoft® Windows® Operating System
    18d4.b48:     ProductVersion:  6.1.7601.23418
    18d4.b48:     FileVersion:     6.1.7601.23418 (win7sp1_ldr.160408-2045)
    18d4.b48:     FileDescription: ApiSet Schema DLL
    18d4.b48: Found driver NisDrv (0x400)
    18d4.b48: supR3HardenedWinFindAdversaries: 0x400
    18d4.b48: \SystemRoot\System32\drivers\MpFilter.sys:
    18d4.b48:     CreationTime:    2016-08-25T01:46:12.000000000Z
    18d4.b48:     LastWriteTime:   2016-08-25T01:46:12.000000000Z
    18d4.b48:     ChangeTime:      2018-01-28T05:30:09.012700300Z
    18d4.b48:     FileAttributes:  0x2020
    18d4.b48:     Size:            0x48058
    18d4.b48:     NT Headers:      0xe8
    18d4.b48:     Timestamp:       0x57a90f3d
    18d4.b48:     Machine:         0x8664 - amd64
    18d4.b48:     Timestamp:       0x57a90f3d
    18d4.b48:     Image Version:   10.0
    18d4.b48:     SizeOfImage:     0x48000 (294912)
    18d4.b48:     Resource Dir:    0x45000 LB 0x1090
    18d4.b48:     [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
    18d4.b48:     [Raw version resource data: 0x45110 LB 0x37c, codepage 0x0 (reserved 0x0)]
    18d4.b48:     ProductName:     Microsoft Malware Protection
    18d4.b48:     ProductVersion:  4.10.0202.0
    18d4.b48:     FileVersion:     4.10.0202.0
    18d4.b48:     FileDescription: Microsoft antimalware file system filter driver
    18d4.b48: \SystemRoot\System32\drivers\NisDrvWFP.sys:
    18d4.b48:     CreationTime:    2016-08-25T01:46:12.000000000Z
    18d4.b48:     LastWriteTime:   2016-08-25T01:46:12.000000000Z
    18d4.b48:     ChangeTime:      2018-01-28T05:30:08.567200300Z
    18d4.b48:     FileAttributes:  0x2020
    18d4.b48:     Size:            0x212f8
    18d4.b48:     NT Headers:      0xe8
    18d4.b48:     Timestamp:       0x57a90f42
    18d4.b48:     Machine:         0x8664 - amd64
    18d4.b48:     Timestamp:       0x57a90f42
    18d4.b48:     Image Version:   10.0
    18d4.b48:     SizeOfImage:     0x20000 (131072)
    18d4.b48:     Resource Dir:    0x1d000 LB 0x1b90
    18d4.b48:     [Version info resource found at 0x120! (ID/Name: 0x1; SubID/SubName: 0x409)]
    18d4.b48:     [Raw version resource data: 0x1e728 LB 0x380, codepage 0x0 (reserved 0x0)]
    18d4.b48:     ProductName:     Microsoft Malware Protection
    18d4.b48:     ProductVersion:  4.10.0202.0
    18d4.b48:     FileVersion:     4.10.0202.0
    18d4.b48:     FileDescription: Microsoft Network Realtime Inspection Driver
    18d4.b48: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox'
    18d4.b48: Calling main()
    18d4.b48: SUPR3HardenedMain: pszProgName=VBoxHeadless fFlags=0x0
    18d4.b48: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox'
    18d4.b48: SUPR3HardenedMain: Respawn #1
    18d4.b48: System32:  \Device\HarddiskVolume3\Windows\System32
    18d4.b48: WinSxS:    \Device\HarddiskVolume3\Windows\winsxs
    18d4.b48: KnownDllPath: C:\Windows\system32
    18d4.b48: '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxHeadless.exe' has no imports
    18d4.b48: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxHeadless.exe)
    18d4.b48: supR3HardNtEnableThreadCreation:
    18d4.b48: supR3HardNtDisableThreadCreation: pvLdrInitThunk=0000000076f1a0e0 pvNtTerminateThread=0000000076f3c060
    18d4.b48: supR3HardenedWinDoReSpawn(1): New child 1804.c30 [kernel32].
    18d4.b48: supR3HardNtChildGatherData: PebBaseAddress=000007fffffd4000 cbPeb=0x380
    18d4.b48: supR3HardNtPuChFindNtdll: uNtDllParentAddr=0000000076ef0000 uNtDllChildAddr=0000000076ef0000
    18d4.b48: supR3HardenedWinSetupChildInit: uLdrInitThunk=0000000076f1a0e0
    18d4.b48: supR3HardenedWinSetupChildInit: Start child.
    18d4.b48: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
    18d4.b48: supR3HardNtChildPurify: Startup delay kludge #1/0: 515 ms, 33 sleeps
    18d4.b48: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
    18d4.b48:  *0000000000000000-000000000000ffff 0x0001/0x0000 0x0000000
    18d4.b48:  *0000000000010000-000000000002ffff 0x0004/0x0004 0x0020000
    18d4.b48:  *0000000000030000-0000000000033fff 0x0002/0x0002 0x0040000
    18d4.b48:   0000000000034000-000000000003ffff 0x0001/0x0000 0x0000000
    18d4.b48:  *0000000000040000-0000000000040fff 0x0004/0x0004 0x0020000
    18d4.b48:   0000000000041000-00000000000dffff 0x0001/0x0000 0x0000000
    18d4.b48:  *00000000000e0000-00000000001dbfff 0x0000/0x0004 0x0020000
    18d4.b48:   00000000001dc000-00000000001ddfff 0x0104/0x0004 0x0020000
    18d4.b48:   00000000001de000-00000000001dffff 0x0004/0x0004 0x0020000
    18d4.b48:   00000000001e0000-0000000076eeffff 0x0001/0x0000 0x0000000
    18d4.b48:  *0000000076ef0000-0000000076ef0fff 0x0002/0x0080 0x1000000  \Device\HarddiskVolume3\Windows\System32\ntdll.dll
    18d4.b48:   0000000076ef1000-0000000076fedfff 0x0020/0x0080 0x1000000  \Device\HarddiskVolume3\Windows\System32\ntdll.dll
    18d4.b48:   0000000076fee000-000000007701cfff 0x0002/0x0080 0x1000000  \Device\HarddiskVolume3\Windows\System32\ntdll.dll
    18d4.b48:   000000007701d000-0000000077026fff 0x0008/0x0080 0x1000000  \Device\HarddiskVolume3\Windows\System32\ntdll.dll
    18d4.b48:   0000000077027000-0000000077027fff 0x0004/0x0080 0x1000000  \Device\HarddiskVolume3\Windows\System32\ntdll.dll
    18d4.b48:   0000000077028000-000000007702afff 0x0008/0x0080 0x1000000  \Device\HarddiskVolume3\Windows\System32\ntdll.dll
    18d4.b48:   000000007702b000-0000000077099fff 0x0002/0x0080 0x1000000  \Device\HarddiskVolume3\Windows\System32\ntdll.dll
    18d4.b48:   000000007709a000-000000007efdffff 0x0001/0x0000 0x0000000
    18d4.b48:  *000000007efe0000-000000007ffdffff 0x0000/0x0002 0x0020000
    18d4.b48:  *000000007ffe0000-000000007ffe0fff 0x0002/0x0002 0x0020000