익명 05:08

Why am I getting this error? “The virtual machine ‘Whonix-Gateway-LXQt’ ha...

Why am I getting this error? “The virtual machine ‘Whonix-Gateway-LXQt’ has terminated unexpectedly during startup with exit code 1 (0x1)”

Virtualbox: Running Version 7.2.6 r172322 (Qt6.8.0 on windows)

Windows: Home. 10.0.26200 Build 26200

I am creating a new VM by importing Whonix. When trying to Start Whonix-Gateway-LXQt I get the following error:

VM Name: Whonix-Gateway-LXQt

The virtual machine ‘Whonix-Gateway-LXQt’ has terminated unexpectedly during startup with exit code 1 (0x1). More details may be available in ‘C:\Users\…\VirtualBox VMs\Whonix-Gateway-LXQt\Logs\VBoxHardening.log’. Result Code: E_FAIL (0x80004005) Component: MachineWrap Interface: IMachine …

Then I've been looking at the VBoxHardening.log but I don't understand it. Could someone look at this log and help me out? I could not fit the whole log in here (30000 chars max). I don't feel comfortable deciding which parts of the log are usefull to you. So I did not remove anything.

Whonix Gateway screenshot

Whonix Workstation screenshot

[...]
8330.74e4: root name: type=Device name=Ntfs
8330.74e4: root name: type=Directory name=FileSystem
8330.74e4: root name: type=Directory name=KernelObjects
8330.74e4: root name: type=FilterConnectionPort name=MicrosoftMalwareProtectionControlPortWD
8330.74e4: root name: type=ALPC Port name=SeLsaCommandPort
8330.74e4: root name: type=Directory name=Callback
8330.74e4: root name: type=FilterConnectionPort name=MicrosoftDataLossPreventionAsyncPort
8330.74e4: root name: type=FilterConnectionPort name=BindFltPort
8330.74e4: root name: type=Directory name=DriverStore
8330.74e4: root name: type=Directory name=Security
8330.74e4: root name: type=Job name=Container_Microsoft.Copilot_1.25121.84.0_x64__8wekyb3d8bbwe-S-1-5-21-2804408188-645829399-1628598736-1001
8330.74e4: root name: type=Event name=LSA_ISO_READY
8330.74e4: root name: type=FilterConnectionPort name=MicrosoftMalwareProtectionAsyncPortWD
8330.74e4: root name: type=Directory name=Device
8330.74e4: root name: type=SymbolicLink name=DriverData
8330.74e4: root name: type=ALPC Port name=SmApiPort
8330.74e4: root name: type=Job name=Container_MicrosoftWindows.Client.CBS_1000.26100.300.0_x64__cw5n1h2txyewy-S-1-5-21-2804408188-645829399-1628598736-1001
8330.74e4: root name: type=FilterConnectionPort name=CLDMSGPORT
8330.74e4: root name: type=FilterConnectionPort name=MicrosoftMalwareProtectionPortWD
8330.74e4: root name: type=SymbolicLink name=OSDataRoot
8330.74e4: root name: type=Event name=SAM_SERVICE_STARTED
8330.74e4: root name: type=Directory name=Driver
8330.74e4: root name: type=SymbolicLink name=DriverStores
8330.74e4: supR3HardenedWinFindAdversaries: 0x0
8330.74e4: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox'
8330.74e4: Calling main()
8330.74e4: SUPR3HardenedMain: pszProgName=VirtualBoxVM fFlags=0x2
8330.74e4: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox'
8330.74e4: '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
8330.74e4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe)
8330.74e4: SUPR3HardenedMain: Respawn #2
8330.74e4: supR3HardNtEnableThreadCreationEx:
8330.74e4: supR3HardenedDllNotificationCallback: load   00007ffc80cb0000 LB 0x000a7000 C:\Windows\System32\sechost.dll [fFlags=0x0]
8330.74e4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\sechost.dll)
8330.74e4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\sechost.dll
8330.74e4: '\Device\HarddiskVolume3\Windows\System32\ntdll.dll' has no imports
8330.74e4: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\ntdll.dll)
8330.74e4: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\ntdll.dll
8330.74e4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\ntdll.dll (Input=ntdll.dll, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
8330.74e4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc82d00000 'C:\Windows\System32\ntdll.dll'
8330.74e4: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\KernelBase.dll [lacks WinVerifyTrust]
8330.74e4: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\KernelBase.dll (Input=KernelBase, rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
8330.74e4: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc7fa20000 'C:\Windows\System32\KernelBase.dll'
8330.74e4: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffc82deb120 pvNtTerminateThread=00007ffc82e624e0 g_LdrInitThunkSelfBackup.cb=10
8330.74e4: supR3HardenedWinDoReSpawn(2): New child 83b8.848c [kernel32].
8330.74e4: supR3HardenedWinReSpawn: NtSetInformationThread/ThreadHideFromDebugger failed: 0xc0000022 (harmless)
8330.74e4: supR3HardNtChildGatherData: PebBaseAddress=0000000100393000 cbPeb=0x388
8330.74e4: supR3HardNtPuChFindNtdll: uNtDllParentAddr=00007ffc82d00000 uNtDllChildAddr=00007ffc82d00000
8330.74e4: supR3HardenedWinSetupChildInit: uLdrInitThunk=00007ffc82deb120
8330.74e4: supR3HardenedWinSetupChildInit: Initial context:
  rax=0000000000000000 rbx=0000000000000000 rcx=00007ff7ddbdbb90 rdx=0000000100393000
  rsi=0000000000000000 rdi=0000000000000000 r8 =0000000000000000 r9 =0000000000000000
  r10=0000000000000000 r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
  r14=0000000000000000 r15=0000000000000000  P1=0000000000000000  P2=0000000000000000
  rip=00007ffc82d8c460 rsp=00000001000ff9c8 rbp=0000000000000000    ctxflags=0010001b
  cs=0033 ss=002b ds=0000 es=0000 fs=0000 gs=0000    eflags=00000200   mxcrx=00001f80
   P3=0000000000000000  P4=0000000000000000  P5=0000000000000000  P6=0000000000000000
  dr0=0000000000000000 dr1=0000000000000000 dr2=0000000000000000 dr3=0000000000000000
  dr6=0000000000000000 dr7=0000000000000000 vcr=0000000000000000 dcr=0000000000000000
  lbt=0000000000000000 lbf=0000000000000000 lxt=0000000000000000 lxf=0000000000000000
8330.74e4: kernel32.dll: timestamp 0x10824ec0 (rc=VINF_SUCCESS)
8330.74e4: supR3HardenedWinSetupChildInit: Start child.
8330.74e4: supR3HardNtChildWaitFor: Found expected request 0 (PurifyChildAndCloseHandles) after 0 ms.
8330.74e4: supR3HardNtChildPurify: Startup delay kludge #1/0: 267 ms, 17 sleeps
8330.74e4: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
8330.74e4: VirtualBoxVM.exe: timestamp 0x697cda2e (rc=VINF_SUCCESS)
8330.74e4: '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
8330.74e4: VirtualBoxVM.exe: Differences in section #8 (.rsrc) between file and memory:
8330.74e4:   Restored 0x490 bytes of original file content at 00007ff7ddcd8b70
8330.74e4: '\Device\HarddiskVolume3\Windows\System32\ntdll.dll' has no imports
8330.74e4: ntdll.dll: Differences in section #12 (.mrdata) between file and memory:
8330.74e4:   Restored 0x118 bytes of original file content at 00007ffc82ee9490
8330.74e4: supR3HardNtChildPurify: cFixes=2 g_fSupAdversaries=0x80000000
8330.74e4: supR3HardNtChildPurify: Startup delay kludge #1/1: 516 ms, 33 sleeps
8330.74e4: supHardNtVpScanVirtualMemory: enmKind=CHILD_PURIFICATION
8330.74e4: supR3HardNtChildPurify: Done after 802 ms and 2 fixes (loop #1).
83b8.848c: Log file opened: 7.2.6r172322 g_hStartupLog=0000000000000004 g_uNtVerCombined=0xa0665800
83b8.848c: supR3HardenedVmProcessInit: uNtDllAddr=00007ffc82d00000 g_uNtVerCombined=0xa0665800 (stack ~00000001000fe790)
83b8.848c: ntdll.dll: timestamp 0x5ffc11eb (rc=VINF_SUCCESS)
83b8.848c: New simple heap: #1 000001b066ef0000 LB 0x800000 (for 2519040 allocation)
83b8.848c: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox'
83b8.848c: System32:  \Device\HarddiskVolume3\Windows\System32
83b8.848c: WinSxS:    \Device\HarddiskVolume3\Windows\WinSxS
83b8.848c: KnownDllPath: C:\Windows\System32
83b8.848c: supR3HardenedVmProcessInit: Opening vboxsup...
8330.74e4: supR3HardenedEarlyCompact: Removed heap 1 (0x000215afa60000 LB 0x800000)
8330.74e4: supR3HardNtEnableThreadCreationEx:
83b8.848c: supR3HardenedVmProcessInit: Restoring LdrInitializeThunk...
83b8.848c: supR3HardenedVmProcessInit: Returning to LdrInitializeThunk...
83b8.848c: Registered Dll notification callback with NTDLL.
83b8.848c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\kernel32.dll)
83b8.848c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\kernel32.dll
83b8.848c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\KERNEL32.DLL (Input=KERNEL32.DLL, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000004001:<flags> [calling]
83b8.848c: supR3HardenedDllNotificationCallback: load   00007ffc7fa20000 LB 0x003f1000 C:\Windows\System32\KERNELBASE.dll [fFlags=0x0]
83b8.848c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\KernelBase.dll)
83b8.848c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\KernelBase.dll
83b8.848c: supR3HardenedDllNotificationCallback: load   00007ffc818c0000 LB 0x000c9000 C:\Windows\System32\KERNEL32.DLL [fFlags=0x0]
83b8.848c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\kernel32.dll [lacks WinVerifyTrust]
83b8.848c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc818c0000 'C:\Windows\System32\KERNEL32.DLL'
83b8.848c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Windows\System32\KernelBase.dll [lacks WinVerifyTrust]
83b8.848c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\System32\KERNELBASE.dll (Input=KERNELBASE.dll, rcNtResolve=0xc0150008) *pfFlags=0xffffffff pwszSearchPath=0000000000004001:<flags> [calling]
83b8.848c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc7fa20000 'C:\Windows\System32\KERNELBASE.dll'
83b8.848c: supR3HardenedDllNotificationCallback: load   00007ff7ddbd0000 LB 0x0010b000 C:\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe [fFlags=0x0]
83b8.848c: '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
83b8.848c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe)
83b8.848c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe
83b8.848c: supR3HardNtDisableThreadCreation: pvLdrInitThunk=00007ffc82deb120 pvNtTerminateThread=00007ffc82e624e0 g_LdrInitThunkSelfBackup.cb=0
83b8.848c: supR3HardNtDisableThreadCreationEx: Backup=40 53 48 83 ec 20 48 8b d9 e8 1a 00 00 00 b2 01
83b8.848c: \SystemRoot\System32\ntdll.dll:
83b8.848c:     CreationTime:    2026-02-25T00:54:41.884630100Z
83b8.848c:     LastWriteTime:   2026-02-25T00:54:41.998630500Z
83b8.848c:     ChangeTime:      2026-02-25T11:29:48.777609900Z
83b8.848c:     FileAttributes:  0x20
83b8.848c:     Size:            0x267b98
83b8.848c:     NT Headers:      0xe0
83b8.848c:     Timestamp:       0x5ffc11eb
83b8.848c:     Machine:         0x8664 - amd64
83b8.848c:     Timestamp:       0x5ffc11eb
83b8.848c:     Image Version:   10.0
83b8.848c:     SizeOfImage:     0x267000 (2519040)
83b8.848c:     Resource Dir:    0x1eb000 LB 0x7a1b8
83b8.848c:     [Version info resource found at 0xd8! (ID/Name: 0x1; SubID/SubName: 0x409)]
83b8.848c:     [Raw version resource data: 0x1eb0f0 LB 0x380, codepage 0x0 (reserved 0x0)]
83b8.848c:     ProductName:     Microsoft® Windows® Operating System
83b8.848c:     ProductVersion:  10.0.26100.7920
83b8.848c:     FileVersion:     10.0.26100.7920 (WinBuild.160101.0800)
83b8.848c:     FileDescription: NT Layer DLL
8330.74e4: supR3HardNtChildWaitFor: Found expected request 1 (CloseEvents) after 47 ms.
83b8.848c: \SystemRoot\System32\kernel32.dll:
83b8.848c:     CreationTime:    2026-02-25T00:54:41.176086300Z
83b8.848c:     LastWriteTime:   2026-02-25T00:54:41.211086500Z
83b8.848c:     ChangeTime:      2026-02-25T11:29:46.370345700Z
83b8.848c:     FileAttributes:  0x20
83b8.848c:     Size:            0xcc238
83b8.848c:     NT Headers:      0xf0
83b8.848c:     Timestamp:       0x10824ec0
83b8.848c:     Machine:         0x8664 - amd64
83b8.848c:     Timestamp:       0x10824ec0
83b8.848c:     Image Version:   10.0
83b8.848c:     SizeOfImage:     0xc9000 (823296)
83b8.848c:     Resource Dir:    0xc7000 LB 0x520
83b8.848c:     [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
83b8.848c:     [Raw version resource data: 0xc70b0 LB 0x3a4, codepage 0x0 (reserved 0x0)]
83b8.848c:     ProductName:     Microsoft® Windows® Operating System
83b8.848c:     ProductVersion:  10.0.26100.7920
83b8.848c:     FileVersion:     10.0.26100.7920 (WinBuild.160101.0800)
83b8.848c:     FileDescription: Windows NT BASE API Client DLL
83b8.848c: \SystemRoot\System32\KernelBase.dll:
83b8.848c:     CreationTime:    2026-02-25T00:54:41.192086900Z
83b8.848c:     LastWriteTime:   2026-02-25T00:54:41.429634500Z
83b8.848c:     ChangeTime:      2026-02-25T11:29:48.318768300Z
83b8.848c:     FileAttributes:  0x20
83b8.848c:     Size:            0x3f32c8
83b8.848c:     NT Headers:      0x100
83b8.848c:     Timestamp:       0xcc2a083
83b8.848c:     Machine:         0x8664 - amd64
83b8.848c:     Timestamp:       0xcc2a083
83b8.848c:     Image Version:   10.0
83b8.848c:     SizeOfImage:     0x3f1000 (4132864)
83b8.848c:     Resource Dir:    0x3b7000 LB 0x548
83b8.848c:     [Version info resource found at 0x90! (ID/Name: 0x1; SubID/SubName: 0x409)]
83b8.848c:     [Raw version resource data: 0x3b70b0 LB 0x3bc, codepage 0x0 (reserved 0x0)]
83b8.848c:     ProductName:     Microsoft® Windows® Operating System
83b8.848c:     ProductVersion:  10.0.26100.7920
83b8.848c:     FileVersion:     10.0.26100.7920 (WinBuild.160101.0800)
83b8.848c:     FileDescription: Windows NT BASE API Client DLL
83b8.848c: \SystemRoot\System32\apisetschema.dll:
83b8.848c:     CreationTime:    2026-01-30T11:47:37.307744900Z
83b8.848c:     LastWriteTime:   2026-01-30T11:47:37.317825600Z
83b8.848c:     ChangeTime:      2026-02-25T00:58:48.740648000Z
83b8.848c:     FileAttributes:  0x20
83b8.848c:     Size:            0x2f598
83b8.848c:     NT Headers:      0xd8
83b8.848c:     Timestamp:       0xd5983b53
83b8.848c:     Machine:         0x8664 - amd64
83b8.848c:     Timestamp:       0xd5983b53
83b8.848c:     Image Version:   10.0
83b8.848c:     SizeOfImage:     0x2e000 (188416)
83b8.848c:     Resource Dir:    0x2d000 LB 0x408
83b8.848c:     [Version info resource found at 0x48! (ID/Name: 0x1; SubID/SubName: 0x409)]
83b8.848c:     [Raw version resource data: 0x2d060 LB 0x3a8, codepage 0x0 (reserved 0x0)]
83b8.848c:     ProductName:     Microsoft® Windows® Operating System
83b8.848c:     ProductVersion:  10.0.26100.7705
83b8.848c:     FileVersion:     10.0.26100.7705 (WinBuild.160101.0800)
83b8.848c:     FileDescription: ApiSet Schema DLL
83b8.848c: root name: type=Job name=Container_Microsoft.WidgetsPlatformRuntime_1.6.14.0_x64__8wekyb3d8bbwe-S-1-5-21-2804408188-645829399-1628598736-1001
83b8.848c: root name: type=FilterConnectionPort name=UnionfsPort
83b8.848c: root name: type=Mutant name=PendingRenameMutex
83b8.848c: root name: type=Directory name=ObjectTypes
83b8.848c: root name: type=FilterConnectionPort name=storqosfltport
83b8.848c: root name: type=Job name=Container_MicrosoftWindows.CrossDevice_1.26012.79.0_x64__cw5n1h2txyewy-S-1-5-21-2804408188-645829399-1628598736-1001
83b8.848c: root name: type=FilterConnectionPort name=MicrosoftMalwareProtectionRemoteIoPortWD
83b8.848c: root name: type=FilterConnectionPort name=MicrosoftDataLossPreventionPort
83b8.848c: root name: type=SymbolicLink name=SystemRoot
83b8.848c: root name: type=Section name=Win32kSiloSessionGlobals
83b8.848c: root name: type=Directory name=Sessions
83b8.848c: root name: type=FilterConnectionPort name=MicrosoftMalwareProtectionVeryLowIoPortWD
83b8.848c: root name: type=ALPC Port name=SleepstudyControlPort
83b8.848c: root name: type=Directory name=ArcName
83b8.848c: root name: type=Job name=Container_Microsoft.GamingApp_2602.1001.5.0_x64__8wekyb3d8bbwe-S-1-5-21-2804408188-645829399-1628598736-1001
83b8.848c: root name: type=FilterConnectionPort name=WcifsPort
83b8.848c: root name: type=Directory name=NLS
83b8.848c: root name: type=Event name=LanmanServerAnnounceEvent
83b8.848c: root name: type=ALPC Port name=ThemeApiPort
83b8.848c: root name: type=Directory name=Windows
83b8.848c: root name: type=Directory name=GLOBAL??
83b8.848c: root name: type=Directory name=RPC Control
83b8.848c: root name: type=FilterConnectionPort name=MicrosoftDataLossPreventionControlPort
83b8.848c: root name: type=ALPC Port name=PdcPort
83b8.848c: root name: type=Job name=Container_Microsoft.StartExperiencesApp_1.229.1.0_x64__8wekyb3d8bbwe-S-1-5-21-2804408188-645829399-1628598736-1001
83b8.848c: root name: type=Event name=EFSInitEvent
83b8.848c: root name: type=SymbolicLink name=Dfs
83b8.848c: root name: type=Device name=clfs
83b8.848c: root name: type=FilterConnectionPort name=MicrosoftDataLossPreventionRemoteIoPort
83b8.848c: root name: type=Event name=CsrSbSyncEvent
83b8.848c: root name: type=ALPC Port name=SeRmCommandPort
83b8.848c: root name: type=Job name=Container_MicrosoftWindows.Client.WebExperience_526.1202.40.0_x64__cw5n1h2txyewy-S-1-5-21-2804408188-645829399-1628598736-1001
83b8.848c: root name: type=SymbolicLink name=DosDevices
83b8.848c: root name: type=Directory name=KnownDlls32
83b8.848c: root name: type=Key name=REGISTRY
83b8.848c: root name: type=Directory name=BaseNamedObjects
83b8.848c: root name: type=FilterConnectionPort name=MicrosoftDataLossPreventionVeryLowIoPort
83b8.848c: root name: type=ALPC Port name=PowerPort
83b8.848c: root name: type=ALPC Port name=SmSsWinStationApiPort
83b8.848c: root name: type=Event name=UniqueInteractiveSessionIdEvent
83b8.848c: root name: type=Directory name=UMDFCommunicationPorts
83b8.848c: root name: type=Device name=FatCdrom
83b8.848c: root name: type=Device name=Fat
83b8.848c: root name: type=Directory name=KnownDlls
83b8.848c: root name: type=ALPC Port name=PowerMonitorPort
83b8.848c: root name: type=Job name=Container_Microsoft.YourPhone_1.26012.101.0_x64__8wekyb3d8bbwe-S-1-5-21-2804408188-645829399-1628598736-1001
83b8.848c: root name: type=Job name=Container_AppUp.IntelArcSoftware_25.52.2110.0_x64__8j3eq9eme6ctt-PackagedService
83b8.848c: root name: type=Device name=Ntfs
83b8.848c: root name: type=Directory name=FileSystem
83b8.848c: root name: type=Directory name=KernelObjects
83b8.848c: root name: type=FilterConnectionPort name=MicrosoftMalwareProtectionControlPortWD
83b8.848c: root name: type=ALPC Port name=SeLsaCommandPort
83b8.848c: root name: type=Directory name=Callback
83b8.848c: root name: type=FilterConnectionPort name=MicrosoftDataLossPreventionAsyncPort
83b8.848c: root name: type=FilterConnectionPort name=BindFltPort
83b8.848c: root name: type=Directory name=DriverStore
83b8.848c: root name: type=Directory name=Security
83b8.848c: root name: type=Job name=Container_Microsoft.Copilot_1.25121.84.0_x64__8wekyb3d8bbwe-S-1-5-21-2804408188-645829399-1628598736-1001
83b8.848c: root name: type=Event name=LSA_ISO_READY
83b8.848c: root name: type=FilterConnectionPort name=MicrosoftMalwareProtectionAsyncPortWD
83b8.848c: root name: type=Directory name=Device
83b8.848c: root name: type=SymbolicLink name=DriverData
83b8.848c: root name: type=ALPC Port name=SmApiPort
83b8.848c: root name: type=Job name=Container_MicrosoftWindows.Client.CBS_1000.26100.300.0_x64__cw5n1h2txyewy-S-1-5-21-2804408188-645829399-1628598736-1001
83b8.848c: root name: type=FilterConnectionPort name=CLDMSGPORT
83b8.848c: root name: type=FilterConnectionPort name=MicrosoftMalwareProtectionPortWD
83b8.848c: root name: type=SymbolicLink name=OSDataRoot
83b8.848c: root name: type=Event name=SAM_SERVICE_STARTED
83b8.848c: root name: type=Directory name=Driver
83b8.848c: root name: type=SymbolicLink name=DriverStores
83b8.848c: supR3HardenedWinFindAdversaries: 0x0
83b8.848c: supR3HardenedWinInitAppBin(0x0): '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox'
83b8.848c: Calling main()
83b8.848c: SUPR3HardenedMain: pszProgName=VirtualBoxVM fFlags=0x2
83b8.848c: supR3HardenedWinInitAppBin(0x2): '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox'
83b8.848c: '\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe' has no imports
83b8.848c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VirtualBoxVM.exe)
83b8.848c: SUPR3HardenedMain: Final process, opening VBoxDrv...
83b8.848c: supR3HardenedEarlyCompact: Removed heap 1 (0x0001b066ef0000 LB 0x800000)
83b8.848c: supR3HardNtEnableThreadCreationEx:
83b8.848c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSupLib.dll)
83b8.848c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSupLib.dll
83b8.848c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
83b8.848c: supR3HardenedScreenImage/NtCreateSection: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
83b8.848c: supR3HardenedDllNotificationCallback: load   00007ffc7aa60000 LB 0x00005000 C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL [fFlags=0x0]
83b8.848c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
83b8.848c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
83b8.848c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
83b8.848c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc7aa60000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
83b8.848c: supR3HardenedScreenImage/LdrLoadDll: cache hit (VINF_SUCCESS) on \Device\HarddiskVolume3\Program Files\Oracle\VirtualBox\VBoxSupLib.dll [lacks WinVerifyTrust]
83b8.848c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000001:<flags> [calling]
83b8.848c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc7aa60000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
83b8.848c: supR3HardenedMonitor_LdrLoadDll: returns rcNt=0x0 hMod=00007ffc7aa60000 'C:\Program Files\Oracle\VirtualBox\VBoxSupLib.DLL'
83b8.848c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #0 'msvcrt.dll'.
83b8.848c: supR3HardenedWinVerifyCacheScheduleImports: Import todo: #30 'rpcrt4.dll'.
83b8.848c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\wintrust.dll)
83b8.848c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\wintrust.dll
83b8.848c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'rpcrt4.dll'...
83b8.848c: supR3HardenedWinVerifyCacheProcessImportTodos: 'rpcrt4.dll' -> '\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll' [rcNtRedir=0xc0150008]
83b8.848c: supHardenedWinVerifyImageByHandle: -> 0 (\Device\HarddiskVolume3\Windows\System32\rpcrt4.dll)
83b8.848c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\rpcrt4.dll
83b8.848c: supR3HardenedWinVerifyCacheProcessImportTodos: Processing 'msvcrt.dll'...
83b8.848c: supR3HardenedWinVerifyCacheProcessImportTodos: 'msvcrt.dll' -> '\Device\HarddiskVolume3\Windows\System32\msvcrt.dll' [rcNtRedir=0xc0150008]
83b8.848c: \Device\HarddiskVolume3\Windows\System32\msvcrt.dll: Signature #1/1: -23509 w/ timestamp=0xf9219683/link.
83b8.848c: supHardenedWinVerifyImageByHandle: -> -23509 (\Device\HarddiskVolume3\Windows\System32\msvcrt.dll)
83b8.848c: Error (rc=0):
83b8.848c: supR3HardenedScreenImage/Imports: rc=-23509 fImage=1 fProtect=0x0 fAccess=0x0 \Device\HarddiskVolume3\Windows\System32\msvcrt.dll: RTCrPkixSignatureVerifyBitString failed: \Device\HarddiskVolume3\Windows\System32\msvcrt.dll
83b8.848c: supR3HardenedWinVerifyCacheInsert: \Device\HarddiskVolume3\Windows\System32\msvcrt.dll
83b8.848c: supR3HardenedMonitor_LdrLoadDll: pName=C:\Windows\system32\Wintrust.dll (rcNtResolve=0xc0150008) *pfFlags=0x0 pwszSearchPath=0000000000000801:<flags> [calling]
83b8.848c: supR3HardenedDllNotificationCallback: load   00007ffc826b0000 LB 0x000a9000 C:\Windows\System32\msvcrt.dll [fFlags=0x0]
83b8.848c: supR3HardenedScreenImage/LdrLoadDll: cache hit (-23509) on \Device\HarddiskVolume3\Windows\System32\msvcrt.dll [lacks WinVerifyTrust]
83b8.848c: Error (rc=0):
83b8.848c: supR3HardenedScreenImage/LdrLoadDll: cached rc=-23509 fImage=1 fProtect=0x0 fAccess=0x0 cHits=1 \Device\HarddiskVolume3\Windows\System32\msvcrt.dll
83b8.848c: Fatal error:
83b8.848c: supR3HardenedDllNotificationCallback: supR3HardenedScreenImage failed on 'C:\Windows\System32\msvcrt.dll' / '\??\C:\Windows\System32\msvcrt.dll': 0xc0000190
8330.74e4: supR3HardNtChildWaitFor[2]: Quitting: ExitCode=0x1 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 33 ms, the end);
25ec.da0: supR3HardNtChildWaitFor[1]: Quitting: ExitCode=0x1 (rcNtWait=0x0, rcNt1=0x0, rcNt2=0x103, rcNt3=0x103, 924 ms, the end);

Very much appreciated



Top Answer/Comment:

The signature verification of msvcrt.dll was failing causing this error.

상단 광고의 [X] 버튼을 누르면 내용이 보입니다