Event viewer Errors, Warnings after upgrade to 1803 with two new HDDs

Page 1 of 2 12 LastLast

  1. Posts : 318
    Dual-boot Win 7 & 10, both Pro 64-bit, now with a Hyper-V VM of Win 11
       #1

    Event viewer Errors, Warnings in 1803 - some continue in 21H2 !!


    Edit - SEE MY UPDATES BELOW AFTER THIS FIRST POST BUT OTHERS STILL NOT FIXED EVEN AFTER UPGRADING TO 1903 [AND THREE YEARS LATER CONTINUE IN 21H2 !!! GO TO POST #15 BELOW] - STILL NEED YOUR HELP

    Three weeks ago, I permitted the upgrade from 1709 to 1803 and last week permitted the April Patch Tuesday patches. This past weekend, I also replaced my two Western Digital 500GB hard drives with two new Seagate 2TB hard drives, using Macrium Reflect on a USB stick in Verify mode.

    I have also run sfc /scannow and Dism /Online /Cleanup-Image /RestoreHealth numerous times, and also chkdsk /x (which implies /f fix) in a reboot.

    Things seem to be running well, but I have the following few recurring errors in Event Viewer:

    1. THIS ISSUE HAS BEEN SOLVED BUT SEE NEXT ITEMS First, when I type Win+R, the white box is blank and there is no dropdown box to show me eventvwr, cmd, regedit or anything else. It is not remembering my past utility runs. This is unlike my 7 or even XP, which remember my recent Win+R commands.
      1. I vaguely recall that the Registry normally keeps MRU lists of these things. Why not here?

    2. THIS ISSUE HAS BEEN SOLVED BUT SEE NEXT ITEMS An error in event viewer:
      Event ID 10016: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
      {8BC3F05E-D86B-11D0-A075-00C04FB68820}
      and APPID
      {8BC3F05E-D86B-11D0-A075-00C04FB68820}
      to the user DESKTOP-[XXYYZZ]\[My name] SID (S-1-5-21-3591163430-416291016-3566129944-1001) from address LocalHost (Using LRPC) running in the application container Microsoft.Windows.ContentDeliveryManager_10.0.17134.1_neutral_neutral_cw5n1h2txyewy SID (S-1-15-2-350187224-1905355452-1037786396-3028148496-2624191407-3283318427-1255436723). This security permission can be modified using the Component Services administrative tool.
      1. Update - The above error repeats every few hours - it is NOT limited to bootup.

    3. An error in event viewer:
      Event ID 2: Session "Cloud Files Diagnostic Event Listener" failed to start with the following error: 0xC0000022
      [THIS IS STILL HAPPENING THREE YEARS LATER IN 21H2 !!!]


    4. An error in event viewer:
      Event ID 1001: Your computer was not assigned an address from the network (by the DHCP Server) for the Network Card with network address 0x22151AD96D1B. The following error occurred: 0x79. Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.
      1. NOTE that I am using the dnscrypt-proxy service, which MAYBE is delaying contact to my LAN until it is up and running. Yes, my PC does connect to the network, or I could not post this thread. But what is your advice if this event is NOT caused by dnscrypt-proxy?
      2. ALSO, I had assigned a LAN IP to this computer - fixed in my router. It is NOT getting a new IP number through DHCP every bootup.

    5. An error in event viewer:
      Event ID 1030: 'IpNatHlpStopSharing' : '0x80070032'.
      [THIS IS STILL HAPPENING THREE YEARS LATER IN 21H2 !!!]


    6. A warning in event viewer:
      Event ID 360: Windows Hello for Business provisioning will not be launched.
      Device is AAD joined ( AADJ or DJ++ ): Not Tested
      User has logged on with AAD credentials: No
      Windows Hello for Business policy is enabled: Not Tested
      Windows Hello for Business post-logon provisioning is enabled: Not Tested
      Local computer meets Windows hello for business hardware requirements: Not Tested
      User is not connected to the machine via Remote Desktop: Yes
      User certificate for on premise auth policy is enabled: Not Tested
      Machine is governed by none policy.
      See https://go.microsoft.com/fwlink/?linkid=832647 for more details.
      [THIS IS STILL HAPPENING THREE YEARS LATER IN 21H2 !!!]


    7. A warning in event viewer:
      Event ID 1014: Name resolution for the name wpad timed out after none of the configured DNS servers responded.
      [THIS IS STILL HAPPENING THREE YEARS LATER IN 21H2 !!!]


    8. A warning in event viewer:
      Event ID 14100: Shut down physical computer. Stopping/saving all virtual machines...
      1. This one is odd - I am not aware of any virtual machines running.


      1. UPDATE - #9 AND 10 BELOW HAVE BEEN FIXED BY UPGRADING TO VERSION 1903 OF WIN 10.

    9. An audit failure in event viewer:
      Event ID 5061: Cryptographic operation.
      Subject:
      Security ID: DESKTOP-XXYYZZ\[My Name]
      Account Name: [My Name]
      Account Domain: DESKTOP-XXYYZZ
      Logon ID: 0x442D4
      Cryptographic Parameters:
      Provider Name: Microsoft Software Key Storage Provider
      Algorithm Name: UNKNOWN
      Key Name: Microsoft Connected Devices Platform device certificate
      Key Type: User key.
      Cryptographic Operation:
      Operation: Open Key.
      Return Code: 0x80090016
    10. An audit failure in event viewer:
      Event ID 5061: Cryptographic operation.
      Subject:
      Security ID: LOCAL SERVICE
      Account Name: LOCAL SERVICE
      Account Domain: NT AUTHORITY
      Logon ID: 0x3E5
      Cryptographic Parameters:
      Provider Name: Microsoft Software Key Storage Provider
      Algorithm Name: UNKNOWN
      Key Name: Microsoft Connected Devices Platform device certificate
      Key Type: User key.
      Cryptographic Operation:
      Operation: Open Key.
      Return Code: 0x80090016


    On # 9 and 10 above, I have posted great detail at Audit failures every reboot - Event 5061 - Cryptographic operation. It's a very worrisome problem - security? - and so I would MUCH appreciate your thoughts on this.

    What do you think? Please feel free to just post links to solutions for these separate items.

    Thanks.
    Last edited by glnz; 19 Jul 2022 at 07:31.
      My Computer


  2. Posts : 30,124
    Windows 11 Pro x64 Version 23H2
       #2

    For item 1

    In privacy turn on

    Event viewer Errors, Warnings after upgrade to 1803 with two new HDDs-image.png

    Item 4, Windows is still using DHCP, it is asking for address. Yes you reserved address in router which it gives each time to this device.

    I would shut off service, dnscrypt, assuming it is simple, I don't know and see what errors clear.
      My Computer


  3. Posts : 318
    Dual-boot Win 7 & 10, both Pro 64-bit, now with a Hyper-V VM of Win 11
    Thread Starter
       #3

    Caledon - thanks for suggestion, but I did that a LONG time ago.

    I like dnscrypt-proxy and encrypting my DNS lookups so they cannot be tracked by Verizon or others. See the great Ars Technica article at https://arstechnica.com/information-...encrypted-dns/
      My Computer


  4. Posts : 30,124
    Windows 11 Pro x64 Version 23H2
       #4

    Just suggesting you run a test, no abandon it.

    Do you have any other privacy tools that may be influencing run box?
      My Computer


  5. Posts : 318
    Dual-boot Win 7 & 10, both Pro 64-bit, now with a Hyper-V VM of Win 11
    Thread Starter
       #5

    Caledon - I just rebooted twice, first with and then without the dnscrypt-proxy service.

    The error, warning and audit failure messages are the same, except that maybe #7 didn't recur, although hard to tell because it occurred twice apparently with dnscrypt-proxy on but maybe one of those was actually the second boot with it off.

    But dnscrypt-proxy is a valuable service, so even if it triggers #7 (not confirmed), I want to keep dnscrypt-proxy on and also fix #7.

    Reminder that I want to fix ALL these error, warning and audit failure messages - they have almost nothing to do with dnscrypt-proxy.

    Looking for tips. Thanks.
      My Computer


  6. Posts : 318
    Dual-boot Win 7 & 10, both Pro 64-bit, now with a Hyper-V VM of Win 11
    Thread Starter
       #6

    Update - Error #1 above is now solved, but error #2 repeats every few hours - it is NOT limited to bootup. And the other items remain an issue.

    Hope the savvy readers of this forum can chime in on some of these. Thanks.
      My Computer


  7. Posts : 856
    Windows 10 Pro 21H2 build 19045.2193 Dual Boot Linux Mint
       #7

    Event 1016 is a known issue which you can ignore https://support.microsoft.com/en-gb/...windows-server
      My Computers


  8. Posts : 318
    Dual-boot Win 7 & 10, both Pro 64-bit, now with a Hyper-V VM of Win 11
    Thread Starter
       #8

    UPDATE - I have fixed and deleted #2 above, but #9 and 10 remain an issue and are very worrisome. See the link to full details at the end of my first post above. Would much appreciate your help.
      My Computer


  9. Posts : 318
    Dual-boot Win 7 & 10, both Pro 64-bit, now with a Hyper-V VM of Win 11
    Thread Starter
       #9

    IMPORTANT INFO ABOUT # 9 AND 10:

    By checking my logs carefully, I can see that the Audit Failures start on the same day that I upgraded from Win 10 Version 1709 to Version 1803 - this past March 17.

    So is this problem baked into 1803?

    But why haven;t more people been complaining about it?

    Still need to know how to fix. Thanks.
      My Computer


  10. Posts : 318
    Dual-boot Win 7 & 10, both Pro 64-bit, now with a Hyper-V VM of Win 11
    Thread Starter
       #10

    Updating to 1903 has solved problems # 9 and 10. Too bad MS won't fix those in 1803 or 1809.
    I'll try to remember to get back here about the others.
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 10:35.
Find Us




Windows 10 Forums