Windows 10: Audit failures every reboot - Event 5061 - Cryptographic operation.

Discus and support Audit failures every reboot - Event 5061 - Cryptographic operation. in Windows 10 Support to solve the problem; Audit failures every reboot - Event 5061 - Cryptographic operation. Win 10 Pro 64-bit version 1803. ‎4/‎28/‎2019 Immediately after every reboot of Win... Discussion in 'Windows 10 Support' started by glnz, Apr 28, 2019.

  1. glnz Win User

    Audit failures every reboot - Event 5061 - Cryptographic operation.


    Audit failures every reboot - Event 5061 - Cryptographic operation. Win 10 Pro 64-bit version 1803. ‎4/‎28/‎2019

    Immediately after every reboot of Win 10 Pro 64-bit version 1803, in Event Viewer, there are between two and four Audit Failures for something related to Cryptography. So my Win 10 machine is insecure? I have run sfc /scannow and Dism /Online /Cleanup-Image /RestoreHealth many times, with no luck. And I hardly even use my Win 10 machine - there are almost no apps on it yet. My actual Win 10 build is 17134.706

    Here are the latest five Cryptography-related Audit Failures, from two reboots:

    LATEST OF FIVE:
    Log Name: Security
    Source: Microsoft-Windows-Security-Auditing
    Date: 4/28/2019 12:27:52 PM
    Event ID: 5061
    Task Category: System Integrity
    Level: Information
    Keywords: Audit Failure
    User: N/A
    Computer: DESKTOP-3#####N
    Description:
    Cryptographic operation.

    Subject:
    Security ID: DESKTOP-3#####N\[My user name]
    Account Name: [My user name]
    Account Domain: DESKTOP-3#####N
    Logon ID: 0x3EC24

    Cryptographic Parameters:
    Provider Name: Microsoft Software Key Storage Provider
    Algorithm Name: UNKNOWN
    Key Name: Microsoft Connected Devices Platform device certificate
    Key Type: User key.

    Cryptographic Operation:
    Operation: Open Key.
    Return Code: 0x80090016
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
    <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />
    <EventID>5061</EventID>
    <Version>0</Version>
    <Level>0</Level>
    <Task>12290</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8010000000000000</Keywords>
    <TimeCreated SystemTime="2019-04-28T16:27:52.339705400Z" />
    <EventRecordID>19582</EventRecordID>
    <Correlation />
    <Execution ProcessID="880" ThreadID="948" />
    <Channel>Security</Channel>
    <Computer>DESKTOP-3#####N</Computer>
    <Security />
    </System>
    <EventData>
    <Data Name="SubjectUserSid">S-1-5-21-3591163430-416291016-3566129944-1001</Data>
    <Data Name="SubjectUserName">[My user name]</Data>
    <Data Name="SubjectDomainName">DESKTOP-3#####N</Data>
    <Data Name="SubjectLogonId">0x3ec24</Data>
    <Data Name="ProviderName">Microsoft Software Key Storage Provider</Data>
    <Data Name="AlgorithmName">UNKNOWN</Data>
    <Data Name="KeyName">Microsoft Connected Devices Platform device certificate</Data>
    <Data Name="KeyType">%%2500</Data>
    <Data Name="Operation">%%2480</Data>
    <Data Name="ReturnCode">0x80090016</Data>
    </EventData>
    </Event>

    FOURTH OF FIVE:
    Log Name: Security
    Source: Microsoft-Windows-Security-Auditing
    Date: 4/28/2019 12:26:51 PM
    Event ID: 5061
    Task Category: System Integrity
    Level: Information
    Keywords: Audit Failure
    User: N/A
    Computer: DESKTOP-3#####N
    Description:
    Cryptographic operation.

    Subject:
    Security ID: LOCAL SERVICE
    Account Name: LOCAL SERVICE
    Account Domain: NT AUTHORITY
    Logon ID: 0x3E5

    Cryptographic Parameters:
    Provider Name: Microsoft Software Key Storage Provider
    Algorithm Name: UNKNOWN
    Key Name: 0c405d387aba56ba
    Key Type: User key.

    Cryptographic Operation:
    Operation: Open Key.
    Return Code: 0x80090016
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
    <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />
    <EventID>5061</EventID>
    <Version>0</Version>
    <Level>0</Level>
    <Task>12290</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8010000000000000</Keywords>
    <TimeCreated SystemTime="2019-04-28T16:26:51.704606400Z" />
    <EventRecordID>19552</EventRecordID>
    <Correlation />
    <Execution ProcessID="880" ThreadID="1004" />
    <Channel>Security</Channel>
    <Computer>DESKTOP-3#####N</Computer>
    <Security />
    </System>
    <EventData>
    <Data Name="SubjectUserSid">S-1-5-19</Data>
    <Data Name="SubjectUserName">LOCAL SERVICE</Data>
    <Data Name="SubjectDomainName">NT AUTHORITY</Data>
    <Data Name="SubjectLogonId">0x3e5</Data>
    <Data Name="ProviderName">Microsoft Software Key Storage Provider</Data>
    <Data Name="AlgorithmName">UNKNOWN</Data>
    <Data Name="KeyName">0c405d387aba56ba</Data>
    <Data Name="KeyType">%%2500</Data>
    <Data Name="Operation">%%2480</Data>
    <Data Name="ReturnCode">0x80090016</Data>
    </EventData>
    </Event>

    THIRD OF FIVE:
    Log Name: Security
    Source: Microsoft-Windows-Security-Auditing
    Date: 4/28/2019 11:29:28 AM
    Event ID: 5061
    Task Category: System Integrity
    Level: Information
    Keywords: Audit Failure
    User: N/A
    Computer: DESKTOP-3#####N
    Description:
    Cryptographic operation.

    Subject:
    Security ID: DESKTOP-3#####N\[My user name]
    Account Name: [My user name]
    Account Domain: DESKTOP-3#####N
    Logon ID: 0x3EF94

    Cryptographic Parameters:
    Provider Name: Microsoft Software Key Storage Provider
    Algorithm Name: UNKNOWN
    Key Name: Microsoft Connected Devices Platform device certificate
    Key Type: User key.

    Cryptographic Operation:
    Operation: Open Key.
    Return Code: 0x80090016
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
    <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />
    <EventID>5061</EventID>
    <Version>0</Version>
    <Level>0</Level>
    <Task>12290</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8010000000000000</Keywords>
    <TimeCreated SystemTime="2019-04-28T15:29:28.196237300Z" />
    <EventRecordID>19387</EventRecordID>
    <Correlation />
    <Execution ProcessID="884" ThreadID="928" />
    <Channel>Security</Channel>
    <Computer>DESKTOP-3#####N</Computer>
    <Security />
    </System>
    <EventData>
    <Data Name="SubjectUserSid">S-1-5-21-3591163430-416291016-3566129944-1001</Data>
    <Data Name="SubjectUserName">[My user name]</Data>
    <Data Name="SubjectDomainName">DESKTOP-3#####N</Data>
    <Data Name="SubjectLogonId">0x3ef94</Data>
    <Data Name="ProviderName">Microsoft Software Key Storage Provider</Data>
    <Data Name="AlgorithmName">UNKNOWN</Data>
    <Data Name="KeyName">Microsoft Connected Devices Platform device certificate</Data>
    <Data Name="KeyType">%%2500</Data>
    <Data Name="Operation">%%2480</Data>
    <Data Name="ReturnCode">0x80090016</Data>
    </EventData>
    </Event>

    SECOND OF FIVE:
    Log Name: Security
    Source: Microsoft-Windows-Security-Auditing
    Date: 4/28/2019 11:28:27 AM
    Event ID: 5061
    Task Category: System Integrity
    Level: Information
    Keywords: Audit Failure
    User: N/A
    Computer: DESKTOP-3#####N
    Description:
    Cryptographic operation.

    Subject:
    Security ID: LOCAL SERVICE
    Account Name: LOCAL SERVICE
    Account Domain: NT AUTHORITY
    Logon ID: 0x3E5

    Cryptographic Parameters:
    Provider Name: Microsoft Software Key Storage Provider
    Algorithm Name: UNKNOWN
    Key Name: 0c405d387aba56ba
    Key Type: User key.

    Cryptographic Operation:
    Operation: Open Key.
    Return Code: 0x80090016
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
    <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />
    <EventID>5061</EventID>
    <Version>0</Version>
    <Level>0</Level>
    <Task>12290</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8010000000000000</Keywords>
    <TimeCreated SystemTime="2019-04-28T15:28:27.709849300Z" />
    <EventRecordID>19363</EventRecordID>
    <Correlation />
    <Execution ProcessID="884" ThreadID="992" />
    <Channel>Security</Channel>
    <Computer>DESKTOP-3#####N</Computer>
    <Security />
    </System>
    <EventData>
    <Data Name="SubjectUserSid">S-1-5-19</Data>
    <Data Name="SubjectUserName">LOCAL SERVICE</Data>
    <Data Name="SubjectDomainName">NT AUTHORITY</Data>
    <Data Name="SubjectLogonId">0x3e5</Data>
    <Data Name="ProviderName">Microsoft Software Key Storage Provider</Data>
    <Data Name="AlgorithmName">UNKNOWN</Data>
    <Data Name="KeyName">0c405d387aba56ba</Data>
    <Data Name="KeyType">%%2500</Data>
    <Data Name="Operation">%%2480</Data>
    <Data Name="ReturnCode">0x80090016</Data>
    </EventData>
    </Event>

    FIRST OF FIVE:
    Log Name: Security
    Source: Microsoft-Windows-Security-Auditing
    Date: 4/28/2019 11:28:27 AM
    Event ID: 5061
    Task Category: System Integrity
    Level: Information
    Keywords: Audit Failure
    User: N/A
    Computer: DESKTOP-3#####N
    Description:
    Cryptographic operation.

    Subject:
    Security ID: LOCAL SERVICE
    Account Name: LOCAL SERVICE
    Account Domain: NT AUTHORITY
    Logon ID: 0x3E5

    Cryptographic Parameters:
    Provider Name: Microsoft Software Key Storage Provider
    Algorithm Name: UNKNOWN
    Key Name: 0c405d387aba56ba
    Key Type: User key.

    Cryptographic Operation:
    Operation: Open Key.
    Return Code: 0x80090016
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
    <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />
    <EventID>5061</EventID>
    <Version>0</Version>
    <Level>0</Level>
    <Task>12290</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8010000000000000</Keywords>
    <TimeCreated SystemTime="2019-04-28T15:28:27.709849300Z" />
    <EventRecordID>19363</EventRecordID>
    <Correlation />
    <Execution ProcessID="884" ThreadID="992" />
    <Channel>Security</Channel>
    <Computer>DESKTOP-3#####N</Computer>
    <Security />
    </System>
    <EventData>
    <Data Name="SubjectUserSid">S-1-5-19</Data>
    <Data Name="SubjectUserName">LOCAL SERVICE</Data>
    <Data Name="SubjectDomainName">NT AUTHORITY</Data>
    <Data Name="SubjectLogonId">0x3e5</Data>
    <Data Name="ProviderName">Microsoft Software Key Storage Provider</Data>
    <Data Name="AlgorithmName">UNKNOWN</Data>
    <Data Name="KeyName">0c405d387aba56ba</Data>
    <Data Name="KeyType">%%2500</Data>
    <Data Name="Operation">%%2480</Data>
    <Data Name="ReturnCode">0x80090016</Data>
    </EventData>
    </Event>
    So, what the *** are these, and how do we fix? No guesses - just the real fix.

    Thanks.

    :)
     
  2. danwhocan Win User

    Security Audit Failure Event 5061 In Windows 10

    I'm seeing these in my event log too. The failures happen four seconds before my video driver crashes (and restarts) while playing World of Warcraft. Could these two issues be related? I'm using onboard Intel HD 4600.

    Audit Failure | Microsoft Windows security auditing.
    | 5061 | System Integrity

    Cryptographic operation.

    Subject:

    Security ID: SYSTEM

    Account Name: XXXXXX$

    Account Domain: WORKGROUP

    Logon ID: 0x3E7

    Cryptographic Parameters:

    Provider Name: Microsoft Software Key Storage Provider

    Algorithm Name: RSA

    Key Name: 51a92691-66f1-280f-d0db-59fad4f73491

    Key Type: User key.

    Cryptographic Operation:

    Operation: Open Key.

    Return Code: 0x80090016
     
    danwhocan, Apr 28, 2019
    #2
  3. DrSysop Win User
    Audit Failure 5061


    I keep getting this Audit failure 5061.

    Cryptographic operation.


    Subject:
    Security ID: SYSTEM
    Account Name: DOCOMO$
    Account Domain: WORKGROUP
    Logon ID: 0x3E7


    Cryptographic Parameters:
    Provider Name: Microsoft Software Key Storage Provider
    Algorithm Name: RSA
    Key Name: 51a92691-66f1-280f-d0db-59fad4f73491
    Key Type: User key.


    Cryptographic Operation:
    Operation: Open Key.
    Return Code: 0x80090016

    I reinstalled my AVG thinking it was that & wasn't same for my Realtek & nvidia drivers & not it. I click on the
    Event Online Help & there is no info on this error.
     
    DrSysop, Apr 28, 2019
    #3
  4. balittle Win User

    Audit failures every reboot - Event 5061 - Cryptographic operation.

    event 5061, microsoft windows security auditing failure

    event 5061, microsoft windows security auditing failure

    Have no idea how to fix, but its provided by Microsoft and an unknown alogorithm name?
     
    balittle, Apr 28, 2019
    #4
Thema:

Audit failures every reboot - Event 5061 - Cryptographic operation.

Loading...
  1. Audit failures every reboot - Event 5061 - Cryptographic operation. - Similar Threads - Audit failures every

  2. Audit failures every reboot - Event 5061 - Cryptographic operation. Win 10 Pro 64-bit

    in Windows 10 BSOD Crashes and Debugging
    Audit failures every reboot - Event 5061 - Cryptographic operation. Win 10 Pro 64-bit: Audit failures every reboot - Event 5061 - Cryptographic operation. Win 10 Pro 64-bit version 1803. ‎4/‎28/‎2019 Immediately after every reboot of Win 10 Pro 64-bit version 1803, in Event Viewer, there are between two and four Audit Failures for something related to...
  3. Unexpected Audit Failure in Event Viewer

    in Windows 10 BSOD Crashes and Debugging
    Unexpected Audit Failure in Event Viewer: Even with years of experience with Windows operating systems I am in the unenviable position of trying to diagnose an Audit Failure in the Event Viewer for Windows 10 on my Toshiba laptop that just reared its ugly head recently. It is perhaps noteworthy that I am not seeing...
  4. Weird events: 5058 5059 and 5061

    in AntiVirus, Firewalls and System Security
    Weird events: 5058 5059 and 5061: Hello, today I saw those event ids in the log viewer, it happened in a moment I was sleeping. 5058 5059 5061 I see these have to do with windows credentials, with the backup/transfer/storage of them, but not sure exactly what happened. The PID was related to Xbox...
  5. Audit Failure reports in Event Viewer

    in Windows 10 Performance & Maintenance
    Audit Failure reports in Event Viewer: Since the PC upgraded to Windows 10 version 1803 build 17134.191, the event log on start up repeatedly gives the three different audit failures below. I have managed to clear all the other problems the event log has displayed but with these three I am at a lost as to the...
  6. Event ID 5061 Audit Failure after April Update.

    in Windows 10 Support
    Event ID 5061 Audit Failure after April Update.: Okay so this morning I began getting these messages in my event viewer after my PC decided to update to April update. They seem to happen after reboot and boot up. Also trying to updated Defender definitions is kinda not happening. I even tried through cmd line and it said...
  7. Audit Failure 5061

    in Windows 10 Support
    Audit Failure 5061: I keep getting this Audit failure 5061. Cryptographic operation. Subject: Security ID: SYSTEM Account Name: DOCOMO$ Account Domain: WORKGROUP Logon ID: 0x3E7 Cryptographic Parameters: Provider Name: Microsoft Software Key Storage Provider Algorithm Name:...
  8. Event ID 5061 Audit Failure after April Update.

    in Windows 10 Support
    Event ID 5061 Audit Failure after April Update.: Not surprised. Let MS fix it. I wonder if people who did a clean install have the issue? Since the certutil command says " Private key is NOT exportable " it may be an issue for those who updated? I myself updated. Well like I said my PC decided to update to April update....
  9. Event Viewer -- Audit Failure 5061

    in Windows 10 Performance & Maintenance
    Event Viewer -- Audit Failure 5061: I continue to get this event in the Event Log under Audit Failure. I never had in Windows 8.1 and it started after upgrading to 10. Does anyone have a clue about it? Cryptographic operation. Subject: Security ID: SYSTEM Account Name: xxxx Account Domain: xxxx...
  10. Event ID 5061

    in Windows 10 Support
    Event ID 5061: Alright so both today and on June 23 I had gotten these audit failures that go like this. Cryptographic operation.Subject: Security ID: DESKTOP-7V82FOC\Owner Account Name: Owner Account Domain: DESKTOP-7V82FOC Logon ID: 0x3DB3FCryptographic Parameters: Provider Name:...