Skip to content

Instantly share code, notes, and snippets.

@dennythecoder
Last active January 11, 2022 01:06
Show Gist options
  • Save dennythecoder/1771e00731e2cd536168eae00ca11588 to your computer and use it in GitHub Desktop.
Save dennythecoder/1771e00731e2cd536168eae00ca11588 to your computer and use it in GitHub Desktop.
LSASS Smartcard Error - Windows Logs

Application

Faulting application name: lsass.exe, version: 10.0.19041.1266, time stamp: 0x17c94394 Faulting module name: KERNELBASE.dll, version: 10.0.19041.1387, time stamp: 0x0b9a844a Exception code: 0xc000027b Fault offset: 0x000000000010b302 Faulting process id: 0x340 Faulting application start time: 0x01d8035af911766b Faulting application path: C:\Windows\system32\lsass.exe Faulting module path: C:\Windows\System32\KERNELBASE.dll Report Id: 11cddee3-68c6-444f-a6b5-a56921bbd272 Faulting package full name: Faulting package-relative application ID:


System

The Smartcard reader reported the following class descriptor (part 1).


The Smartcard reader reported the following class descriptor (part 2).


WudfUsbccidDrv A Request has returned failure. MsgType: 0x80 ICCStatus: 0x1 CmdStatus: 0x1 Error: 0xFE SW1: 0x0 SW2: 0x0


WudfUsbccidDrv A Request has returned failure. MsgType: 0x80 ICCStatus: 0x1 CmdStatus: 0x1 Error: 0xFE SW1: 0x0 SW2: 0x0


Security Audit Failures 4673

A privileged service was called.

Subject: Security ID: DOMAIN\sid Account Name: sid Account Domain: DOMAIN Logon ID: 0x24BD20

Service: Server: Security Service Name: -

Process: Process ID: 0x47c Process Name: C:\Windows\System32\svchost.exe

Service Request Information: Privileges: SeTcbPrivilege


A privileged service was called.

Subject: Security ID: DOMAIN\sid Account Name: sid Account Domain: DOMAIN Logon ID: 0x24BD20

Service: Server: Security Service Name: -

Process: Process ID: 0x4c28 Process Name: C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe

Service Request Information: Privileges: SeTcbPrivilege


A privileged service was called.

Subject: Security ID: DOMAIN\sid Account Name: sid Account Domain: DOMAIN Logon ID: 0x24BD20

Service: Server: Security Service Name: -

Process: Process ID: 0x4c28 Process Name: C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe

Service Request Information: Privileges: SeTcbPrivilege


An operation was attempted on a privileged object.

Subject: Security ID: DOMAIN\sid Account Name: sid Account Domain: DOMAIN Logon ID: 0x24BD20

Object: Object Server: Security Object Type: - Object Name: - Object Handle: 0x0

Process Information: Process ID: 0x3a8 Process Name: C:\Windows\System32\winlogon.exe

Requested Operation: Desired Access: 0 Privileges: SeTcbPrivilege


A privileged service was called.

Subject: Security ID: DOMAIN\sid Account Name: sid Account Domain: DOMAIN Logon ID: 0x24BD20

Service: Server: Security Service Name: -

Process: Process ID: 0x1310 Process Name: C:\Program Files\Google\Chrome\Application\chrome.exe

Service Request Information: Privileges: SeTcbPrivilege


A privileged service was called.

Subject: Security ID: SYSTEM Account Name: COMPUTERNAME$ Account Domain: DOMAIN Logon ID: 0x3E7

Service: Server: Security Account Manager Service Name: Security Account Manager

Process: Process ID: 0x340 Process Name: C:\Windows\System32\lsass.exe

Service Request Information: Privileges: SeTcbPrivilege


A privileged service was called.

Subject: Security ID: SYSTEM Account Name: COMPUTERNAME$ Account Domain: DOMAIN Logon ID: 0x3E7

Service: Server: Security Account Manager Service Name: Security Account Manager

Process: Process ID: 0x340 Process Name: C:\Windows\System32\lsass.exe

Service Request Information: Privileges: SeTcbPrivilege


A privileged service was called.

Subject: Security ID: DOMAIN\sid Account Name: sid Account Domain: DOMAIN Logon ID: 0x24BD20

Service: Server: Security Service Name: -

Process: Process ID: 0x280 Process Name: C:\Windows\System32\backgroundTaskHost.exe

Service Request Information: Privileges: SeTcbPrivilege


A privileged service was called.

Subject: Security ID: DOMAIN\sid Account Name: sid Account Domain: DOMAIN Logon ID: 0x24BD20

Service: Server: Security Service Name: -

Process: Process ID: 0x47c Process Name: C:\Windows\System32\svchost.exe

Service Request Information: Privileges: SeTcbPrivilege

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment