# Win11 24H2 下 eNSP 启动异常与 VBS 排查记录
**通过关闭内存完整性、Virtual Machine Platform、HypervisorPlatform、VBS 和 Windows Hypervisor,并在必要时将 `DeviceGuard\Scenarios\WindowsHello\Enabled` 设为 `0`,最终使 `VirtualizationBasedSecurityStatus=0`、`HypervisorPresent=False`,从而解决 eNSP 与旧版 VirtualBox 的虚拟化冲突。**(本文根据本人实际排查过程整理,文字由 AI 辅助总结,仅供遇到类似情况的用户参考)
为了运行华为 eNSP,我在 Windows 11 24H2 上排查了 AR/WLAN 等虚拟设备启动异常的问题。排查过程中发现,Windows 的 **VBS(Virtualization-Based Security)和 Hypervisor 仍处于运行状态**。
## 1. 确认 WinPcap 状态
重新安装 WinPcap 4.1.3 时出现:
```text
Error opening file for writing:
C:\Windows\System32\drivers\npf.sys
```
随后使用管理员 CMD 检查:
```cmd
sc query npf
```
结果:
```text
STATE : 4 RUNNING
```
说明 WinPcap 的 `npf` 驱动已经正常运行,因此没有继续重复安装。(之前安装过但是忘了)
## 2. 检查 VBS 和 Hypervisor
在 `msinfo32` 中发现:
```text
基于虚拟化的安全性:正在运行
```
PowerShell 进一步检查:
```powershell
Get-CimInstance -ClassName Win32_DeviceGuard `
-Namespace root\Microsoft\Windows\DeviceGuard |
Select-Object VirtualizationBasedSecurityStatus
```
结果:
```text
VirtualizationBasedSecurityStatus = 2
```
同时:
```powershell
Get-CimInstance Win32_ComputerSystem |
Select-Object HypervisorPresent
```
结果:
```text
HypervisorPresent = True
```
说明 VBS 和 Windows Hypervisor 当时仍处于运行状态。
## 3. 关闭常见虚拟化相关组件
依次关闭或确认关闭:
```text
内存完整性
Virtual Machine Platform
Windows 虚拟机监控程序平台
WSL
```
并执行:
```cmd
bcdedit /set hypervisorlaunchtype off
bcdedit /set vsmlaunchtype off
```
同时将:
```text
HKLM\SYSTEM\CurrentControlSet\Control\DeviceGuard
EnableVirtualizationBasedSecurity
```
设置为:
```text
0
```
但重启后仍然得到:
```text
VirtualizationBasedSecurityStatus = 2
HypervisorPresent = True
```
说明在这台电脑上,仅关闭上述项目还不足以让 VBS 完全停止。
## 4. 排查 Windows Hello 相关配置
继续检查发现:
```text
HKLM\SYSTEM\CurrentControlSet\Control\DeviceGuard\Scenarios\WindowsHello
```
中的:
```text
Enabled = 1
```
修改前先进行了注册表备份:
```powershell
reg export "HKLM\SYSTEM\CurrentControlSet\Control\DeviceGuard\Scenarios\WindowsHello" "$env:USERPROFILE\Desktop\WindowsHello-backup.reg" /y
```
随后将其设置为:
```text
Enabled = 0
```
重启后再次检查:
```text
VirtualizationBasedSecurityStatus = 0
HypervisorPresent = False
```
此时 VBS 和 Hypervisor 均已停止运行。
## 5. 登录异常
修改 Windows Hello 相关配置后,重启时出现了账户重新验证的情况。我最终通过 **Microsoft Authenticator** 完成身份验证并恢复正常登录,之后 PIN 也可以正常使用。
因此,修改 Windows Hello / Device Guard 相关注册表项前,应:
- 备份相关注册表;
- 确保 Microsoft 账户密码可用;
- 最好准备 Authenticator 或其他身份验证方式。
## 最终结果
最终系统状态为:
```text
VirtualizationBasedSecurityStatus = 0
HypervisorPresent = False
```
同时确认:
```text
VirtualMachinePlatform = Disabled
HypervisorPlatform = Disabled
EnableVirtualizationBasedSecurity = 0
hypervisorlaunchtype = Off
vsmlaunchtype = Off
```
WinPcap 驱动保持:
```text
STATE : 4 RUNNING
```
至此,Windows 的 VBS/Hypervisor 不再运行,可以继续测试 eNSP 和其依赖的虚拟化环境。
## 注意
以上是**我这台 Windows 11 24H2 电脑的实际排查过程**,并不意味着所有 24H2 设备都必须修改:
```text
DeviceGuard\Scenarios\WindowsHello\Enabled
```
如果关闭内存完整性、相关 Windows 可选功能以及 Hypervisor 后,VBS 已经停止,则**没有必要继续修改 Windows Hello 相关注册表项**。
该项修改可能影响 Windows Hello/PIN 登录,因此应作为进一步排查手段,而不是通用的第一步解决方案。