Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Losing internet connection only on one device


  • Please log in to reply

#1
geekyandhow

geekyandhow

    Member

  • Member
  • PipPip
  • 74 posts

I've recently started noticing a strange problem with my Microsoft Surface Go tablet which is relatively new. It randomly loses internet connectivity for a minute or two and then comes right back up. Happens multiple times a day sometimes and never at all some days. Other devices connected to the same wifi network have perfect connection that time. When my surface go loses connection, I open cmd prompt and ping 8.8.8.8 and it shows an error message (not "request timed out").

 

I don't know if this has anything to do with changing my ISP recently or some problem with my device itself but it's super frustrating when I'm doing something important that needs continuous connectivity.

 

The computer is clean from malware as per assistance from the malware forum: http://www.geekstogo...s/#entry2659495

 

They also asked me to mention here about this error in the FRST logs: Miniport Microsoft Wi-Fi Direct Virtual Adapter #4, {0f1ba590-7440-40c2-9374-af1514bfaf61}, had event 74

 
 
Any assistance is appreciated.

  • 0

Advertisements


#2
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,624 posts
  • MVP

Search for:

device manager

hit Enter.

 

Click on the arrow in front of Network Adapters

 

Right click on your Wireless adapter and select Properties.

 

Click on the Power Management tab

Uncheck

Allow the computer to turn off this device to save power.

 

OK

 

Right click on your Wireless adapter and select Properties.

 

Click on the Driver tab.

Who makes the driver and what date and version is it showing?

 

then click on the Details tab.  
Change Property to Hardware IDs.  Click on the top one then right click and copy.  Paste that into a reply.

 

That will tell me what adapter you have.  Sometimes a newer driver can help but you will seldom get one by asking Windows to update the driver.

 

You have some odd errors in your FRST Addition log.  Best to check your system files:

 

Open an elevated command prompt:

http://www.howtogeek...-in-windows-10/
http://www.eightforu...indows-8-a.html

(If you open an elevated Command Prompt properly it will say Administrator: Command Prompt in the margin at the top of the window)


Once you have an elevated command prompt:

Type:

 DISM  /Online  /Cleanup-Image  /RestoreHealth

 (I use two spaces so you can be sure to see where one space goes.)
Hit Enter.  This will take a while (10-20 minutes) to complete.  Once the prompt returns:

Reboot.  Open an elevated Command Prompt again and type (with an Enter after the line):

sfc  /scannow



This will also take a few minutes.  

When it finishes it will say one of the following:

Windows did not find any integrity violations (a good thing)
Windows Resource Protection found corrupt files and repaired them (a good thing)
Windows Resource Protection found corrupt files but was unable to fix some (or all) of them (not a good thing)

If you get the last result then type:
findstr  /c:"[SR]"  \windows\logs\cbs\cbs.log  >  %UserProfile%\desktop\junk.txt


Hit Enter.  Then type::


notepad %UserProfile%\desktop\junk.txt

Hit Enter.

 Copy the text from notepad and paste it into a reply.


After you finish SFC, regardless of the result:



1. Please download the Event Viewer Tool by Vino Rosso
http://images.malwar...om/vino/VEW.exe
and save it to your Desktop:
2. Right-click VEW.exe and Run AS Administrator
3. Under 'Select log to query', select:

* System
4. Under 'Select type to list', select:
* Error
* Warning


Then use the 'Number of events' as follows:


1. Click the radio button for 'Number of events'
Type 20 in the 1 to 20 box
Then click the Run button.
Notepad will open with the output log.


Please post the Output log in your next reply then repeat but select Application.  (Each time you run VEW it overwrites the log so copy the first one to a Reply or rename it before running it a second time.)


 


  • 0

#3
geekyandhow

geekyandhow

    Member

  • Topic Starter
  • Member
  • PipPip
  • 74 posts

 1) There's no Power Management tab in the adapter's Properties: https://imgur.com/a/rgSRpLF

 

Also, here's a pic of Device Manager just in case: https://imgur.com/a/BpdUu4q

 

2) It's Qualcomm Atheros Communications Inc, 2018-08-24, v12.0.0.722

 

3) There are 4 hardware IDs, here's the top one: PCI\VEN_168C&DEV_003E&SUBSYS_3370168C&REV_32

 
4) Windows found corrupt files and successfully repaired them.
 
5) Notepad logs:
 
Vino's Event Viewer v01c run on Windows 7 in English
Report run at 18/06/2021 10:17:09 PM
 
Note: All dates below are in the format dd/mm/yyyy
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Critical Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 29/05/2021 4:10:50 AM
Type: Critical Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
 
Log: 'System' Date/Time: 23/05/2021 3:22:36 PM
Type: Critical Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
 
Log: 'System' Date/Time: 21/05/2021 6:56:27 PM
Type: Critical Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
 
Log: 'System' Date/Time: 10/05/2021 7:22:17 PM
Type: Critical Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
 
Log: 'System' Date/Time: 26/04/2021 4:20:44 PM
Type: Critical Category: 63
Event: 41 Source: Microsoft-Windows-Kernel-Power
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 19/06/2021 2:06:22 AM
Type: Error Category: 0
Event: 7000 Source: Service Control Manager
The luminati_net_updater_win_hola_in_ext_hola_org service failed to start due to the following error:  The system cannot find the file specified.
 
Log: 'System' Date/Time: 19/06/2021 2:05:43 AM
Type: Error Category: 0
Event: 7034 Source: Service Control Manager
The VyprVPN service terminated unexpectedly. It has done this 1 time(s).
 
Log: 'System' Date/Time: 19/06/2021 2:05:35 AM
Type: Error Category: 0
Event: 10010 Source: Microsoft-Windows-DistributedCOM
The server Microsoft.AAD.BrokerPlugin_1000.19041.1023.0_neutral_neutral_cw5n1h2txyewy!Windows.Security.Authentication.Web.Core.BackgroundGetTokenTask.ClassId.WebAccountProvider did not register with DCOM within the required timeout.
 
Log: 'System' Date/Time: 18/06/2021 4:09:48 AM
Type: Error Category: 0
Event: 7000 Source: Service Control Manager
The VyprVPN WireGuard Tunnel Client connected to USA - Miami service failed to start due to the following error:  The specified service does not exist as an installed service.
 
Log: 'System' Date/Time: 18/06/2021 4:00:29 AM
Type: Error Category: 0
Event: 7000 Source: Service Control Manager
The luminati_net_updater_win_hola_in_ext_hola_org service failed to start due to the following error:  The system cannot find the file specified.
 
Log: 'System' Date/Time: 18/06/2021 3:59:20 AM
Type: Error Category: 2
Event: 10317 Source: Microsoft-Windows-NDIS
Miniport TAP-VyprVPN Adapter V9, {a69e8851-661f-4ef1-a5ab-08b33a94c6c6}, had event Network Interface deleted while PNP Device still exists. Note that this event is provided for informational purpose and might not be an error always (Eg: In case of vSwitch which was recently un-installed or a LBFO team was removed)
 
Log: 'System' Date/Time: 18/06/2021 3:50:20 AM
Type: Error Category: 0
Event: 7000 Source: Service Control Manager
The luminati_net_updater_win_hola_in_ext_hola_org service failed to start due to the following error:  The system cannot find the file specified.
 
Log: 'System' Date/Time: 18/06/2021 3:49:39 AM
Type: Error Category: 0
Event: 10010 Source: Microsoft-Windows-DistributedCOM
The server Microsoft.Windows.ContentDeliveryManager_10.0.19041.1023_neutral_neutral_cw5n1h2txyewy!App.AppXwdz8g2fxr36xz0tdtagygnvemf85s7gg.mca did not register with DCOM within the required timeout.
 
Log: 'System' Date/Time: 17/06/2021 6:48:49 PM
Type: Error Category: 0
Event: 7000 Source: Service Control Manager
The eapihdrv service failed to start due to the following error:  This driver has been blocked from loading
 
Log: 'System' Date/Time: 17/06/2021 6:48:49 PM
Type: Error Category: 0
Event: 1060 Source: Application Popup
The event description cannot be found.
 
Log: 'System' Date/Time: 17/06/2021 6:48:48 PM
Type: Error Category: 0
Event: 7000 Source: Service Control Manager
The eapihdrv service failed to start due to the following error:  This driver has been blocked from loading
 
Log: 'System' Date/Time: 17/06/2021 6:48:48 PM
Type: Error Category: 0
Event: 1060 Source: Application Popup
The event description cannot be found.
 
Log: 'System' Date/Time: 17/06/2021 6:48:48 PM
Type: Error Category: 0
Event: 7000 Source: Service Control Manager
The eapihdrv service failed to start due to the following error:  This driver has been blocked from loading
 
Log: 'System' Date/Time: 17/06/2021 6:48:48 PM
Type: Error Category: 0
Event: 1060 Source: Application Popup
The event description cannot be found.
 
Log: 'System' Date/Time: 17/06/2021 6:48:48 PM
Type: Error Category: 0
Event: 7000 Source: Service Control Manager
The eapihdrv service failed to start due to the following error:  This driver has been blocked from loading
 
Log: 'System' Date/Time: 17/06/2021 6:48:48 PM
Type: Error Category: 0
Event: 1060 Source: Application Popup
The event description cannot be found.
 
Log: 'System' Date/Time: 17/06/2021 6:48:47 PM
Type: Error Category: 0
Event: 7000 Source: Service Control Manager
The eapihdrv service failed to start due to the following error:  This driver has been blocked from loading
 
Log: 'System' Date/Time: 17/06/2021 6:48:47 PM
Type: Error Category: 0
Event: 1060 Source: Application Popup
The event description cannot be found.
 
Log: 'System' Date/Time: 17/06/2021 6:48:47 PM
Type: Error Category: 0
Event: 7000 Source: Service Control Manager
The eapihdrv service failed to start due to the following error:  This driver has been blocked from loading
 
Log: 'System' Date/Time: 17/06/2021 6:48:47 PM
Type: Error Category: 0
Event: 1060 Source: Application Popup
The event description cannot be found.
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 19/06/2021 2:07:15 AM
Type: Warning Category: 0
Event: 10016 Source: Microsoft-Windows-DistributedCOM
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID  {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}  and APPID  {15C20B67-12E7-4BB6-92BB-7AFF07997402}  to the user DESKTOP-AKN8A88\katra SID (S-1-5-21-481405570-3132218789-2497384090-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Log: 'System' Date/Time: 19/06/2021 2:07:03 AM
Type: Warning Category: 0
Event: 10016 Source: Microsoft-Windows-DistributedCOM
The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID  Windows.SecurityCenter.WscBrokerManager  and APPID  Unavailable  to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Log: 'System' Date/Time: 19/06/2021 2:07:03 AM
Type: Warning Category: 0
Event: 10016 Source: Microsoft-Windows-DistributedCOM
The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID  Windows.SecurityCenter.WscDataProtection  and APPID  Unavailable  to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Log: 'System' Date/Time: 19/06/2021 2:07:03 AM
Type: Warning Category: 0
Event: 10016 Source: Microsoft-Windows-DistributedCOM
The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID  Windows.SecurityCenter.SecurityAppBroker  and APPID  Unavailable  to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Log: 'System' Date/Time: 19/06/2021 2:06:28 AM
Type: Warning Category: 0
Event: 10016 Source: Microsoft-Windows-DistributedCOM
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID  {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}  and APPID  {4839DDB7-58C2-48F5-8283-E1D1807D0D7D}  to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Log: 'System' Date/Time: 19/06/2021 2:06:27 AM
Type: Warning Category: 0
Event: 10016 Source: Microsoft-Windows-DistributedCOM
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID  {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}  and APPID  {4839DDB7-58C2-48F5-8283-E1D1807D0D7D}  to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Log: 'System' Date/Time: 19/06/2021 2:06:27 AM
Type: Warning Category: 0
Event: 10016 Source: Microsoft-Windows-DistributedCOM
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID  {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}  and APPID  {4839DDB7-58C2-48F5-8283-E1D1807D0D7D}  to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Log: 'System' Date/Time: 19/06/2021 2:06:27 AM
Type: Warning Category: 0
Event: 10016 Source: Microsoft-Windows-DistributedCOM
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID  {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}  and APPID  {4839DDB7-58C2-48F5-8283-E1D1807D0D7D}  to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Log: 'System' Date/Time: 19/06/2021 2:06:09 AM
Type: Warning Category: 212
Event: 219 Source: Microsoft-Windows-Kernel-PnP
The driver \Driver\WudfRd failed to load for the device {6c8abe47-dac0-4b99-affa-4fff050e3cdc}\SurfaceDigitizerPenPairing\6&32c5adbb&0&0.
 
Log: 'System' Date/Time: 19/06/2021 2:06:08 AM
Type: Warning Category: 212
Event: 219 Source: Microsoft-Windows-Kernel-PnP
The driver \Driver\WudfRd failed to load for the device ACPI\NXP3001\1.
 
Log: 'System' Date/Time: 19/06/2021 2:06:08 AM
Type: Warning Category: 212
Event: 219 Source: Microsoft-Windows-Kernel-PnP
The driver \Driver\WudfRd failed to load for the device HID\Vid_8087&Pid_0AC3\6&2c7fdda&0&0000.
 
Log: 'System' Date/Time: 19/06/2021 2:06:08 AM
Type: Warning Category: 212
Event: 219 Source: Microsoft-Windows-Kernel-PnP
The driver \Driver\WudfRd failed to load for the device HID\Vid_8087&Pid_0AC2\6&b7ce40e&0&0000.
 
Log: 'System' Date/Time: 19/06/2021 2:06:08 AM
Type: Warning Category: 212
Event: 219 Source: Microsoft-Windows-Kernel-PnP
The driver \Driver\WudfRd failed to load for the device {DD8E82AE-334B-49A2-AEAE-AEB0FD5C40DD}\DetectionVerification\5&ae253ce&0&0.
 
Log: 'System' Date/Time: 19/06/2021 2:06:07 AM
Type: Warning Category: 212
Event: 219 Source: Microsoft-Windows-Kernel-PnP
The driver \Driver\WudfRd failed to load for the device ACPI\INT3400\2&daba3ff&0.
 
Log: 'System' Date/Time: 19/06/2021 2:06:05 AM
Type: Warning Category: 212
Event: 219 Source: Microsoft-Windows-Kernel-PnP
The driver \Driver\WudfRd failed to load for the device ROOT\WindowsHelloFaceSoftwareDriver\0000.
 
Log: 'System' Date/Time: 18/06/2021 11:36:29 PM
Type: Warning Category: 0
Event: 10016 Source: Microsoft-Windows-DistributedCOM
The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID  {C2F03A33-21F5-47FA-B4BB-156362A2F239}  and APPID  {316CDED5-E4AE-4B15-9113-7055D84DCC97}  to the user DESKTOP-AKN8A88\katra SID (S-1-5-21-481405570-3132218789-2497384090-1001) from address LocalHost (Using LRPC) running in the application container Microsoft.Windows.ShellExperienceHost_10.0.19041.1023_neutral_neutral_cw5n1h2txyewy SID (S-1-15-2-155514346-2573954481-755741238-1654018636-1233331829-3075935687-2861478708). This security permission can be modified using the Component Services administrative tool.
 
Log: 'System' Date/Time: 18/06/2021 3:40:38 PM
Type: Warning Category: 1014
Event: 1014 Source: Microsoft-Windows-DNS-Client
Name resolution for the name bam-cell.nr-data.net timed out after none of the configured DNS servers responded.
 
Log: 'System' Date/Time: 18/06/2021 4:10:06 AM
Type: Warning Category: 1014
Event: 1014 Source: Microsoft-Windows-DNS-Client
Name resolution for the name client.wns.windows.com timed out after none of the configured DNS servers responded.
 
Log: 'System' Date/Time: 18/06/2021 4:10:01 AM
Type: Warning Category: 0
Event: 10016 Source: Microsoft-Windows-DistributedCOM
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID  {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}  and APPID  {15C20B67-12E7-4BB6-92BB-7AFF07997402}  to the user DESKTOP-AKN8A88\katra SID (S-1-5-21-481405570-3132218789-2497384090-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Log: 'System' Date/Time: 18/06/2021 4:08:32 AM
Type: Warning Category: 0
Event: 10016 Source: Microsoft-Windows-DistributedCOM
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID  {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}  and APPID  {15C20B67-12E7-4BB6-92BB-7AFF07997402}  to the user DESKTOP-AKN8A88\katra SID (S-1-5-21-481405570-3132218789-2497384090-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
 
Vino's Event Viewer v01c run on Windows 7 in English
Report run at 18/06/2021 10:18:46 PM
 
Note: All dates below are in the format dd/mm/yyyy
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - Critical Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - Error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'Application' Date/Time: 19/06/2021 2:06:19 AM
Type: Error Category: 100
Event: 1000 Source: Application Error
Faulting application name: AUDIODG.EXE, version: 10.0.19041.1023, time stamp: 0x4507cb5a Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000 Exception code: 0xc0000005 Fault offset: 0x0000000000000000 Faulting process ID: 0xe04 Faulting application start time: 0x01d764afb1421b3c Faulting application path: C:\WINDOWS\system32\AUDIODG.EXE Faulting module path: unknown Report ID: 3294ad01-d69a-492a-88cf-faa467fb2739 Faulting package full name:  Faulting package-relative application ID: 
 
Log: 'Application' Date/Time: 19/06/2021 1:40:11 AM
Type: Error Category: 0
Event: 513 Source: Microsoft-Windows-CAPI2
Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.
 
Details:
AddLegacyDriverFiles: Unable to back up image of binary MsQuic.
 
System Error:
The resource loader failed to find MUI file. .
 
Log: 'Application' Date/Time: 18/06/2021 3:49:16 AM
Type: Error Category: 100
Event: 1000 Source: Application Error
Faulting application name: net_updater64.exe, version: 1.240.55.0, time stamp: 0x60c3cd22 Faulting module name: net_updater64.exe, version: 1.240.55.0, time stamp: 0x60c3cd22 Exception code: 0xc0000005 Fault offset: 0x000000000003171a Faulting process ID: 0x104 Faulting application start time: 0x01d763f405704b42 Faulting application path: C:\Program Files\Hola\app\net_updater64.exe Faulting module path: C:\Program Files\Hola\app\net_updater64.exe Report ID: 64a74bce-0612-4c5e-978a-4b739afa727c Faulting package full name:  Faulting package-relative application ID: 
 
Log: 'Application' Date/Time: 17/06/2021 6:41:18 PM
Type: Error Category: 0
Event: 513 Source: Microsoft-Windows-CAPI2
Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.
 
Details:
AddLegacyDriverFiles: Unable to back up image of binary MsQuic.
 
System Error:
The resource loader failed to find MUI file. .
 
Log: 'Application' Date/Time: 16/06/2021 7:41:49 PM
Type: Error Category: 100
Event: 1000 Source: Application Error
Faulting application name: IntelAudioService.exe, version: 1.0.120.0, time stamp: 0x5addd40b Faulting module name: KERNELBASE.dll, version: 10.0.19041.1023, time stamp: 0x924f9cdb Exception code: 0xe0434352 Fault offset: 0x0000000000034b89 Faulting process ID: 0x1044 Faulting application start time: 0x01d762e7a0d96a89 Faulting application path: C:\WINDOWS\system32\cAVS\Intel® Audio Service\IntelAudioService.exe Faulting module path: C:\WINDOWS\System32\KERNELBASE.dll Report ID: c629ae59-16cd-4b15-8c49-b87a09a67af0 Faulting package full name:  Faulting package-relative application ID: 
 
Log: 'Application' Date/Time: 16/06/2021 7:41:47 PM
Type: Error Category: 0
Event: 1026 Source: .NET Runtime
Application: IntelAudioService.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: System.ObjectDisposedException
   at System.Runtime.InteropServices.SafeHandle.DangerousAddRef(Boolean ByRef)
   at System.StubHelpers.StubHelpers.SafeHandleAddRef(System.Runtime.InteropServices.SafeHandle, Boolean ByRef)
   at Microsoft.Win32.Win32Native.SetEvent(Microsoft.Win32.SafeHandles.SafeWaitHandle)
   at System.Threading.EventWaitHandle.Set()
   at IntelAudioService.Controllers.StreamAndNotificationReader.ThreadLogErrorAndDie(System.String)
   at IntelAudioService.Controllers.StreamAndNotificationReader.ThreadRun()
   at System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object)
   at System.Threading.ThreadHelper.ThreadStart()
 
 
 
Log: 'Application' Date/Time: 16/06/2021 7:40:02 PM
Type: Error Category: 0
Event: 8193 Source: VSS
Volume Shadow Copy Service error: Unexpected error calling routine QueryFullProcessImageNameW.  hr = 0x80070006, The handle is invalid. . 
 
Operation:
   Executing Asynchronous Operation
 
Context:
   Current State: DoSnapshotSet
 
Log: 'Application' Date/Time: 16/06/2021 7:39:47 PM
Type: Error Category: 0
Event: 513 Source: Microsoft-Windows-CAPI2
Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.
 
Details:
AddLegacyDriverFiles: Unable to back up image of binary MsQuic.
 
System Error:
The resource loader failed to find MUI file. .
 
Log: 'Application' Date/Time: 16/06/2021 7:39:35 PM
Type: Error Category: 0
Event: 8194 Source: VSS
Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface.  hr = 0x80070005, Access is denied. . This is often caused by incorrect security settings in either the writer or requestor process. 
 
Operation:
   Gathering Writer Data
 
Context:
   Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
   Writer Name: System Writer
   Writer Instance ID: {c41930d8-454e-4a0b-ae51-1d3e98bddc22}
 
Log: 'Application' Date/Time: 16/06/2021 4:27:47 AM
Type: Error Category: 101
Event: 1002 Source: Application Hang
The program TextInputHost.exe version 2001.22012.0.2020 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.  Process ID: 1fb4  Start Time: 01d7620c7fced685  Termination Time: 4294967295  Application Path: C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\InputApp\TextInputHost.exe  Report Id: d1ead664-e960-4def-8150-7a1586d99178  Faulting package full name: MicrosoftWindows.Client.CBS_120.2212.2020.0_x64__cw5n1h2txyewy  Faulting package-relative application ID: InputApp  Hang type: Quiesce 
 
Log: 'Application' Date/Time: 14/06/2021 1:39:17 AM
Type: Error Category: 100
Event: 1000 Source: Application Error
Faulting application name: IntelAudioService.exe, version: 1.0.120.0, time stamp: 0x5addd40b Faulting module name: KERNELBASE.dll, version: 10.0.19041.1023, time stamp: 0x924f9cdb Exception code: 0xe0434352 Fault offset: 0x0000000000034b89 Faulting process ID: 0x1428 Faulting application start time: 0x01d760be142c97bc Faulting application path: C:\WINDOWS\system32\cAVS\Intel® Audio Service\IntelAudioService.exe Faulting module path: C:\WINDOWS\System32\KERNELBASE.dll Report ID: c4abb888-0069-403d-9141-c4dbe653dd27 Faulting package full name:  Faulting package-relative application ID: 
 
Log: 'Application' Date/Time: 14/06/2021 1:39:16 AM
Type: Error Category: 0
Event: 1026 Source: .NET Runtime
Application: IntelAudioService.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: System.ObjectDisposedException
   at System.Runtime.InteropServices.SafeHandle.DangerousAddRef(Boolean ByRef)
   at System.StubHelpers.StubHelpers.SafeHandleAddRef(System.Runtime.InteropServices.SafeHandle, Boolean ByRef)
   at Microsoft.Win32.Win32Native.SetEvent(Microsoft.Win32.SafeHandles.SafeWaitHandle)
   at System.Threading.EventWaitHandle.Set()
   at IntelAudioService.Controllers.StreamAndNotificationReader.ThreadLogErrorAndDie(System.String)
   at IntelAudioService.Controllers.StreamAndNotificationReader.ThreadRun()
   at System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object)
   at System.Threading.ThreadHelper.ThreadStart()
 
 
 
Log: 'Application' Date/Time: 13/06/2021 4:20:19 AM
Type: Error Category: 101
Event: 1002 Source: Application Hang
The program TextInputHost.exe version 2001.22012.0.2020 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.  Process ID: 2f94  Start Time: 01d75f8e2987b244  Termination Time: 4294967295  Application Path: C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\InputApp\TextInputHost.exe  Report Id: d3d2a706-f677-4404-9a71-9b623c1c42c7  Faulting package full name: MicrosoftWindows.Client.CBS_120.2212.2020.0_x64__cw5n1h2txyewy  Faulting package-relative application ID: InputApp  Hang type: Quiesce 
 
Log: 'Application' Date/Time: 12/06/2021 8:17:03 AM
Type: Error Category: 101
Event: 1002 Source: Application Hang
The program TextInputHost.exe version 2001.22012.0.2020 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.  Process ID: de4  Start Time: 01d75f4c75d5c412  Termination Time: 4294967295  Application Path: C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\InputApp\TextInputHost.exe  Report Id: 0334b144-ce05-41c9-b97f-c5d88f09f130  Faulting package full name: MicrosoftWindows.Client.CBS_120.2212.2020.0_x64__cw5n1h2txyewy  Faulting package-relative application ID: InputApp  Hang type: Quiesce 
 
Log: 'Application' Date/Time: 12/06/2021 5:31:55 AM
Type: Error Category: 100
Event: 1000 Source: Application Error
Faulting application name: dwm.exe, version: 10.0.19041.746, time stamp: 0x6be51595 Faulting module name: KERNELBASE.dll, version: 10.0.19041.1023, time stamp: 0x924f9cdb Exception code: 0xc00001ad Fault offset: 0x000000000010b39c Faulting process ID: 0x49c Faulting application start time: 0x01d75d6f15bde802 Faulting application path: C:\WINDOWS\system32\dwm.exe Faulting module path: C:\WINDOWS\System32\KERNELBASE.dll Report ID: db544b1a-4cb3-4670-b19a-057bfb1295e3 Faulting package full name:  Faulting package-relative application ID: 
 
Log: 'Application' Date/Time: 12/06/2021 5:31:51 AM
Type: Error Category: 100
Event: 1000 Source: Application Error
Faulting application name: poker.exe, version: 0.53.0.0, time stamp: 0x5f7956d0 Faulting module name: KERNELBASE.dll, version: 10.0.19041.1023, time stamp: 0x924f9cdb Exception code: 0xe0000008 Fault offset: 0x0000000000034b89 Faulting process ID: 0x2960 Faulting application start time: 0x01d75f4b88809076 Faulting application path: C:\Program Files (x86)\Adda52Poker\poker.exe Faulting module path: C:\WINDOWS\System32\KERNELBASE.dll Report ID: 0f0385a6-936a-4f55-aa52-ecac288814f6 Faulting package full name:  Faulting package-relative application ID: 
 
Log: 'Application' Date/Time: 12/06/2021 5:26:15 AM
Type: Error Category: 100
Event: 1000 Source: Application Error
Faulting application name: poker.exe, version: 0.53.0.0, time stamp: 0x5f7956d0 Faulting module name: KERNELBASE.dll, version: 10.0.19041.1023, time stamp: 0x924f9cdb Exception code: 0xe0000008 Fault offset: 0x0000000000034b89 Faulting process ID: 0x2e30 Faulting application start time: 0x01d75f4b5200b27a Faulting application path: C:\Program Files (x86)\Adda52Poker\poker.exe Faulting module path: C:\WINDOWS\System32\KERNELBASE.dll Report ID: 6824472e-8a31-471f-99e4-555a6d42fc30 Faulting package full name:  Faulting package-relative application ID: 
 
Log: 'Application' Date/Time: 06/06/2021 10:15:50 PM
Type: Error Category: 100
Event: 1000 Source: Application Error
Faulting application name: IntelAudioService.exe, version: 1.0.120.0, time stamp: 0x5addd40b Faulting module name: KERNELBASE.dll, version: 10.0.19041.964, time stamp: 0x812662a7 Exception code: 0xe0434352 Fault offset: 0x0000000000034b89 Faulting process ID: 0xfc8 Faulting application start time: 0x01d75b217ea2b4e9 Faulting application path: C:\WINDOWS\system32\cAVS\Intel® Audio Service\IntelAudioService.exe Faulting module path: C:\WINDOWS\System32\KERNELBASE.dll Report ID: d44edeca-b157-44ee-8ca8-1ce9d84079a7 Faulting package full name:  Faulting package-relative application ID: 
 
Log: 'Application' Date/Time: 06/06/2021 10:15:49 PM
Type: Error Category: 0
Event: 1026 Source: .NET Runtime
Application: IntelAudioService.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: System.ObjectDisposedException
   at System.Runtime.InteropServices.SafeHandle.DangerousAddRef(Boolean ByRef)
   at System.StubHelpers.StubHelpers.SafeHandleAddRef(System.Runtime.InteropServices.SafeHandle, Boolean ByRef)
   at Microsoft.Win32.Win32Native.SetEvent(Microsoft.Win32.SafeHandles.SafeWaitHandle)
   at System.Threading.EventWaitHandle.Set()
   at IntelAudioService.Controllers.StreamAndNotificationReader.ThreadLogErrorAndDie(System.String)
   at IntelAudioService.Controllers.StreamAndNotificationReader.ThreadRun()
   at System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object)
   at System.Threading.ThreadHelper.ThreadStart()
 
 
 
Log: 'Application' Date/Time: 06/06/2021 10:15:05 PM
Type: Error Category: 0
Event: 8193 Source: VSS
Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance.  hr = 0x8007045b, A system shutdown is in progress. . 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - Warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'Application' Date/Time: 19/06/2021 2:06:55 AM
Type: Warning Category: 0
Event: 64 Source: Microsoft-Windows-CertificateServicesClient-AutoEnrollment
Certificate for local system with Thumbprint b9 38 e7 e7 40 29 6c 59 ba eb 94 b7 77 a6 95 16 5c 90 a4 32 is about to expire or already expired.
 
Log: 'Application' Date/Time: 18/06/2021 8:00:46 PM
Type: Warning Category: 0
Event: 64 Source: Microsoft-Windows-CertificateServicesClient-AutoEnrollment
Certificate for local system with Thumbprint b9 38 e7 e7 40 29 6c 59 ba eb 94 b7 77 a6 95 16 5c 90 a4 32 is about to expire or already expired.
 
Log: 'Application' Date/Time: 18/06/2021 12:00:46 PM
Type: Warning Category: 0
Event: 64 Source: Microsoft-Windows-CertificateServicesClient-AutoEnrollment
Certificate for local system with Thumbprint b9 38 e7 e7 40 29 6c 59 ba eb 94 b7 77 a6 95 16 5c 90 a4 32 is about to expire or already expired.
 
Log: 'Application' Date/Time: 18/06/2021 4:00:46 AM
Type: Warning Category: 0
Event: 64 Source: Microsoft-Windows-CertificateServicesClient-AutoEnrollment
Certificate for local system with Thumbprint b9 38 e7 e7 40 29 6c 59 ba eb 94 b7 77 a6 95 16 5c 90 a4 32 is about to expire or already expired.
 
Log: 'Application' Date/Time: 18/06/2021 3:58:36 AM
Type: Warning Category: 0
Event: 10010 Source: Microsoft-Windows-RestartManager
Application 'C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AdobeCollabSync.exe' (pid 9600) cannot be restarted - Application SID does not match Conductor SID..
 
Log: 'Application' Date/Time: 17/06/2021 6:42:04 PM
Type: Warning Category: 0
Event: 10010 Source: Microsoft-Windows-RestartManager
Application 'C:\Program Files (x86)\ExpressVPN\expressvpnd\expressvpnd.exe' (pid 5216) cannot be restarted - Application SID does not match Conductor SID..
 
Log: 'Application' Date/Time: 13/06/2021 4:37:28 AM
Type: Warning Category: 18
Event: 4627 Source: Microsoft-Windows-EventSystem
The COM+ Event System timed out attempting to fire the DisplayLock method on event class {D5978630-5B9F-11D1-8DD2-00AA004ABD5E} for publisher  and subscriber .  The subscriber failed to respond within 180 seconds. The display name of the subscription is "SENS Logon Subscription". The HRESULT was 800705b4.
 
Log: 'Application' Date/Time: 12/06/2021 5:32:09 AM
Type: Warning Category: 0
Event: 0 Source: Dwminit
The Desktop Window Manager process has exited. (Process exit code: 0xc00001ad, Restart count: 1, Primary display device ID: Intel® HD Graphics 615)
 
Log: 'Application' Date/Time: 05/06/2021 1:06:21 AM
Type: Warning Category: 3
Event: 3036 Source: Microsoft-Windows-Search
Crawl could not be completed on content source <iehistory://{S-1-5-21-481405570-3132218789-2497384090-1001}/>.
 
Context:  Application, SystemIndex Catalogue
 
Details:
An internal error occurred in the Microsoft Windows HTTP Services  (HRESULT : 0x80072ee4) (0x80072ee4)
 
 
Log: 'Application' Date/Time: 04/06/2021 3:00:23 AM
Type: Warning Category: 0
Event: 10010 Source: Microsoft-Windows-RestartManager
Application 'C:\Program Files (x86)\ExpressVPN\expressvpn-ui\ExpressVPNNotificationService.exe' (pid 9248) cannot be restarted - Application SID does not match Conductor SID..
 
Log: 'Application' Date/Time: 18/05/2021 5:06:05 AM
Type: Warning Category: 5
Event: 643 Source: ESENT
msedge (8524,D,50) EdgeDataImporter:  Out of date NLS sort version detected on the database 'C:\Users\katra\AppData\Local\Temp\Importer_6_Default_4\spartan.edb' for Locale 'en-US', index sort version: (SortId=00000001-57ee-1e5c-00b4-d0000bb1e11e, Version=0006020F0006020F), current sort version: (SortId=00000001-57ee-1e5c-00b4-d0000bb1e11e, Version=0006030500060305).
 
Log: 'Application' Date/Time: 18/05/2021 5:06:05 AM
Type: Warning Category: 5
Event: 643 Source: ESENT
msedge (8524,D,50) EdgeDataImporter:  Out of date NLS sort version detected on the database 'C:\Users\katra\AppData\Local\Temp\Importer_6_Default_4\spartan.edb' for Locale 'en-CA', index sort version: (SortId=00000001-57ee-1e5c-00b4-d0000bb1e11e, Version=0006020F0006020F), current sort version: (SortId=00000001-57ee-1e5c-00b4-d0000bb1e11e, Version=0006030500060305).
 
Log: 'Application' Date/Time: 27/04/2021 1:43:46 PM
Type: Warning Category: 3
Event: 3036 Source: Microsoft-Windows-Search
Crawl could not be completed on content source <iehistory://{S-1-5-21-481405570-3132218789-2497384090-1001}/>.
 
Context:  Application, SystemIndex Catalogue
 
Details:
An internal error occurred in the Microsoft Windows HTTP Services  (HRESULT : 0x80072ee4) (0x80072ee4)
 
 
Log: 'Application' Date/Time: 27/04/2021 2:28:00 AM
Type: Warning Category: 18
Event: 4627 Source: Microsoft-Windows-EventSystem
The COM+ Event System timed out attempting to fire the DisplayLock method on event class {D5978630-5B9F-11D1-8DD2-00AA004ABD5E} for publisher  and subscriber .  The subscriber failed to respond within 180 seconds. The display name of the subscription is "SENS Logon Subscription". The HRESULT was 800705b4.
 
Log: 'Application' Date/Time: 26/04/2021 4:19:16 PM
Type: Warning Category: 0
Event: 0 Source: Dwminit
The Desktop Window Manager process has exited. (Process exit code: 0xc00001ad, Restart count: 8, Primary display device ID: Intel® HD Graphics 615)
 
Log: 'Application' Date/Time: 26/04/2021 4:19:15 PM
Type: Warning Category: 0
Event: 0 Source: Dwminit
The Desktop Window Manager process has exited. (Process exit code: 0xc00001ad, Restart count: 7, Primary display device ID: Intel® HD Graphics 615)
 
Log: 'Application' Date/Time: 26/04/2021 4:19:14 PM
Type: Warning Category: 0
Event: 0 Source: Dwminit
The Desktop Window Manager process has exited. (Process exit code: 0x8007001f, Restart count: 6, Primary display device ID: Intel® HD Graphics 615)
 
Log: 'Application' Date/Time: 26/04/2021 4:19:14 PM
Type: Warning Category: 0
Event: 0 Source: Dwminit
The Desktop Window Manager process has exited. (Process exit code: 0x8007001f, Restart count: 5, Primary display device ID: Intel® HD Graphics 615)
 
Log: 'Application' Date/Time: 26/04/2021 4:19:13 PM
Type: Warning Category: 0
Event: 0 Source: Dwminit
The Desktop Window Manager process has exited. (Process exit code: 0xc00001ad, Restart count: 4, Primary display device ID: Intel® HD Graphics 615)
 
Log: 'Application' Date/Time: 26/04/2021 4:19:09 PM
Type: Warning Category: 0
Event: 0 Source: Dwminit
The Desktop Window Manager process has exited. (Process exit code: 0xc00001ad, Restart count: 3, Primary display device ID: Intel® HD Graphics 615)
 

  • 0

#4
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,624 posts
  • MVP

What is the model number of your Surface?

 

Sometimes it helps to right click on the Wireless adapter and Uninstall  (do not let it remove any files if it asks) then reboot.  Windows will reload the adapter driver and that often fixes odd problems.


  • 0

#5
geekyandhow

geekyandhow

    Member

  • Topic Starter
  • Member
  • PipPip
  • 74 posts

It's 1824.

 

I'll try that.


  • 0

#6
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,624 posts
  • MVP

I'm not having much luck finding drivers for your Surface.  Apparently they have dumbed down the driver installation so that you can't get just one driver.  Have to get the full set at one time.  Do you have the latest batch?

You might try the manual installation of drivers:

 

https://support.micr...51-078a7739e120

 

https://surfacetip.c...ivers-firmware/

 

Also make sure you have the latest version of Windows.  Settings, Update & Security,  Check for Updates.


  • 0

#7
geekyandhow

geekyandhow

    Member

  • Topic Starter
  • Member
  • PipPip
  • 74 posts

I'm not having much luck finding drivers for your Surface.  Apparently they have dumbed down the driver installation so that you can't get just one driver.  Have to get the full set at one time.  Do you have the latest batch?

You might try the manual installation of drivers:

 

https://support.micr...51-078a7739e120

 

https://surfacetip.c...ivers-firmware/

 

Also make sure you have the latest version of Windows.  Settings, Update & Security,  Check for Updates.

 

My Windows 10 is up to date but I'm not able to find the drivers for my model on the sites you listed.


  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP