A
AlexLeadingEdge
Guest
We have three computers, at three different locations, all running Windows 10 Pro, all three with a UPS. Two of the three run as MUs using ThinStuff, RDP connections drop when it happens. While working on these machines they will go to a black screen and cannot be restored without a restart. It is like it has gone to sleep, but the CPU fan, hard drive light and network lights are still going, just no visuals, no mouse, no keyboard (that we can tell). Pressing the power button doesn't send the shutdown command to the OS, so we have to hold down the power button for 4 seconds or press the reset button.
Looking at the Event Viewer we see "The System Could Not Sucessfully Load The Crash Dump Driver" and messages about CLSID / COM, BONJOUR and MBAM (Malwarebytes):
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Bonjour Service (285 of them!!!):
Task Scheduling Error: Continuously busy for more than a second
Task Scheduling Error: m->NextScheduledEvent 367407
Malwarebytes:
Mbamchameleon Failed to obtain file name information - C01C0005
More...
Looking at the Event Viewer we see "The System Could Not Sucessfully Load The Crash Dump Driver" and messages about CLSID / COM, BONJOUR and MBAM (Malwarebytes):
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Bonjour Service (285 of them!!!):
Task Scheduling Error: Continuously busy for more than a second
Task Scheduling Error: m->NextScheduledEvent 367407
Malwarebytes:
Mbamchameleon Failed to obtain file name information - C01C0005
More...