Skip to content

StartService FAILED 577 #17

@Acotas

Description

@Acotas

Previously, it worked fine. After a certain update, ssde.sys started normally, but all other drivers signed with localhost-km.pfx failed to start (even with start=auto set). All startup attempts resulted in StartService FAILED 577.

If I run sc stop ssde, ssde.sys also fails to start unless I reboot.

In HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\CI\Protected, Licensed = 0x1, and CustomKernelSignerLockedEnabled = 0x1.

OS Windows 11 25H2
Version 10.0.26200 Build 26200
Kernel DMA Protection On
Virtualization-based security Running
Virtualization-based security Required Security Properties
Virtualization-based security Available Security Properties Base Virtualization Support, Secure Boot, DMA Protection, UEFI Code Readonly, SMM Security Mitigations 1.0, Mode Based Execution Control, APIC Virtualization
Virtualization-based security Services Configured Hypervisor enforced Code Integrity
Virtualization-based security Services Running Hypervisor enforced Code Integrity
App Control for Business policy Enforced
App Control for Business user mode policy Off

The Windows Security Event log contains the following Audit Failure Events:
Log Name: Security
Source: Microsoft-Windows-Security-Auditing
Date: ******
Event ID: 5038
Task Category: System Integrity
Level: Information
Keywords: Audit Failure
User: N/A
Computer: ******
Description:
Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.
File Name: \Device\HarddiskVolume7\test\test.sys

The log file Windows\System32\winevt\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx contains errors and messages.

Microsoft-Windows-CodeIntegrity%4Operational.xml

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions