New
#1
Event viewer Errors, Warnings in 1803 - some continue in 21H2 !!
Edit - SEE MY UPDATES BELOW AFTER THIS FIRST POST BUT OTHERS STILL NOT FIXED EVEN AFTER UPGRADING TO 1903 [AND THREE YEARS LATER CONTINUE IN 21H2 !!! GO TO POST #15 BELOW] - STILL NEED YOUR HELP
Three weeks ago, I permitted the upgrade from 1709 to 1803 and last week permitted the April Patch Tuesday patches. This past weekend, I also replaced my two Western Digital 500GB hard drives with two new Seagate 2TB hard drives, using Macrium Reflect on a USB stick in Verify mode.
I have also run sfc /scannow and Dism /Online /Cleanup-Image /RestoreHealth numerous times, and also chkdsk /x (which implies /f fix) in a reboot.
Things seem to be running well, but I have the following few recurring errors in Event Viewer:
- THIS ISSUE HAS BEEN SOLVED BUT SEE NEXT ITEMS
First, when I type Win+R, the white box is blank and there is no dropdown box to show me eventvwr, cmd, regedit or anything else. It is not remembering my past utility runs. This is unlike my 7 or even XP, which remember my recent Win+R commands.
- I vaguely recall that the Registry normally keeps MRU lists of these things. Why not here?
- THIS ISSUE HAS BEEN SOLVED BUT SEE NEXT ITEMS
An error in event viewer:
Event ID 10016: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{8BC3F05E-D86B-11D0-A075-00C04FB68820}
and APPID
{8BC3F05E-D86B-11D0-A075-00C04FB68820}
to the user DESKTOP-[XXYYZZ]\[My name] SID (S-1-5-21-3591163430-416291016-3566129944-1001) from address LocalHost (Using LRPC) running in the application container Microsoft.Windows.ContentDeliveryManager_10.0.17134.1_neutral_neutral_cw5n1h2txyewy SID (S-1-15-2-350187224-1905355452-1037786396-3028148496-2624191407-3283318427-1255436723). This security permission can be modified using the Component Services administrative tool.
- Update - The above error repeats every few hours - it is NOT limited to bootup.
- An error in event viewer:
[THIS IS STILL HAPPENING THREE YEARS LATER IN 21H2 !!!]Event ID 2: Session "Cloud Files Diagnostic Event Listener" failed to start with the following error: 0xC0000022
An error in event viewer:
Event ID 1001: Your computer was not assigned an address from the network (by the DHCP Server) for the Network Card with network address 0x22151AD96D1B. The following error occurred: 0x79. Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.
- NOTE that I am using the dnscrypt-proxy service, which MAYBE is delaying contact to my LAN until it is up and running. Yes, my PC does connect to the network, or I could not post this thread. But what is your advice if this event is NOT caused by dnscrypt-proxy?
- ALSO, I had assigned a LAN IP to this computer - fixed in my router. It is NOT getting a new IP number through DHCP every bootup.
- An error in event viewer:
[THIS IS STILL HAPPENING THREE YEARS LATER IN 21H2 !!!]Event ID 1030: 'IpNatHlpStopSharing' : '0x80070032'.
- A warning in event viewer:
[THIS IS STILL HAPPENING THREE YEARS LATER IN 21H2 !!!]Event ID 360: Windows Hello for Business provisioning will not be launched.
Device is AAD joined ( AADJ or DJ++ ): Not Tested
User has logged on with AAD credentials: No
Windows Hello for Business policy is enabled: Not Tested
Windows Hello for Business post-logon provisioning is enabled: Not Tested
Local computer meets Windows hello for business hardware requirements: Not Tested
User is not connected to the machine via Remote Desktop: Yes
User certificate for on premise auth policy is enabled: Not Tested
Machine is governed by none policy.
See https://go.microsoft.com/fwlink/?linkid=832647 for more details.
- A warning in event viewer:
[THIS IS STILL HAPPENING THREE YEARS LATER IN 21H2 !!!]Event ID 1014: Name resolution for the name wpad timed out after none of the configured DNS servers responded.
A warning in event viewer:
Event ID 14100: Shut down physical computer. Stopping/saving all virtual machines...
- This one is odd - I am not aware of any virtual machines running.
- UPDATE - #9 AND 10 BELOW HAVE BEEN FIXED BY UPGRADING TO VERSION 1903 OF WIN 10.
An audit failure in event viewer:
Event ID 5061: Cryptographic operation.
Subject:
Security ID: DESKTOP-XXYYZZ\[My Name]
Account Name: [My Name]
Account Domain: DESKTOP-XXYYZZ
Logon ID: 0x442D4
Cryptographic Parameters:
Provider Name: Microsoft Software Key Storage Provider
Algorithm Name: UNKNOWN
Key Name: Microsoft Connected Devices Platform device certificate
Key Type: User key.
Cryptographic Operation:
Operation: Open Key.
Return Code: 0x80090016An audit failure in event viewer:
Event ID 5061: Cryptographic operation.
Subject:
Security ID: LOCAL SERVICE
Account Name: LOCAL SERVICE
Account Domain: NT AUTHORITY
Logon ID: 0x3E5
Cryptographic Parameters:
Provider Name: Microsoft Software Key Storage Provider
Algorithm Name: UNKNOWN
Key Name: Microsoft Connected Devices Platform device certificate
Key Type: User key.
Cryptographic Operation:
Operation: Open Key.
Return Code: 0x80090016
On # 9 and 10 above, I have posted great detail at Audit failures every reboot - Event 5061 - Cryptographic operation. It's a very worrisome problem - security? - and so I would MUCH appreciate your thoughts on this.
What do you think? Please feel free to just post links to solutions for these separate items.
Thanks.
Last edited by glnz; 19 Jul 2022 at 07:31.