cancel
Showing results for 
Search instead for 
Did you mean: 
Reply
offero
Paper Tape
Posts: 2
Registered: ‎03-13-2019
Location: US
Views: 270
Message 1 of 1

Thinkpad X1 Extreme restart when lid closed

I am seeing issues sometimes when I close my lid and come back to my computer later. It restarts instead of resuming from where I left off. It's really annoying to lose my work setup. I had 93% battery left last time so it's not an issue with too low of a battery.

 

Are there any known issues with resuming? Most of the times it works, but sometimes I open my computer and it starts from scratch without any of my previous windows or work there. Are there any recommended settings to check? I need to minimize this from happening.

 

I opened the computer this morning (~7 AM) and it restarted instead of resumed. I'm pasting some Event Viewer logs here that seem relevant. Some are criticals, errors, warns, and infos.

 

Log Name:      System
Source:        Microsoft-Windows-UserModePowerService
Date:          3/12/2019 6:27:02 PM
Event ID:      12
Task Category: (10)
Level:         Information
Keywords:      
User:          SYSTEM
Computer:      Ultra-Magnus
Description:
Process C:\Windows\SysWOW64\Lenovo\PowerMgr\EasyResume.exe (process ID:4944) reset policy scheme from {4fabbc18-ad8d-450e-b9ad-23457a7fedc1} to {4fabbc18-ad8d-450e-b9ad-23457a7fedc1}
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Microsoft-Windows-UserModePowerService" Guid="{ce8dee0b-d539-4000-b0f8-77bed049c590}" />
    <EventID>12</EventID>
    <Version>0</Version>
    <Level>4</Level>
    <Task>10</Task>
    <Opcode>0</Opcode>
    <Keywords>0x4000000000000000</Keywords>
    <TimeCreated SystemTime="2019-03-12T22:27:02.126353400Z" />
    <EventRecordID>23604</EventRecordID>
    <Correlation />
    <Execution ProcessID="1376" ThreadID="5908" />
    <Channel>System</Channel>
    <Computer>Ultra-Magnus</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessPath">C:\Windows\SysWOW64\Lenovo\PowerMgr\EasyResume.exe</Data>
    <Data Name="ProcessPid">4944</Data>
    <Data Name="OldSchemeGuid">{4fabbc18-ad8d-450e-b9ad-23457a7fedc1}</Data>
    <Data Name="NewSchemeGuid">{4fabbc18-ad8d-450e-b9ad-23457a7fedc1}</Data>
  </EventData>
</Event>
Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          3/12/2019 6:13:42 PM
Event ID:      10016
Task Category: None
Level:         Error
Keywords:      Classic
User:          SYSTEM
Computer:      Ultra-Magnus
Description:
The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID 
Windows.SecurityCenter.WscDataProtection
 and APPID 
Unavailable
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10016</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2019-03-12T22:13:42.476890500Z" />
    <EventRecordID>23603</EventRecordID>
    <Correlation />
    <Execution ProcessID="1528" ThreadID="6288" />
    <Channel>System</Channel>
    <Computer>Ultra-Magnus</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="param1">application-specific</Data>
    <Data Name="param2">Local</Data>
    <Data Name="param3">Launch</Data>
    <Data Name="param4">Windows.SecurityCenter.WscDataProtection</Data>
    <Data Name="param5">Unavailable</Data>
    <Data Name="param6">NT AUTHORITY</Data>
    <Data Name="param7">SYSTEM</Data>
    <Data Name="param8">S-1-5-18</Data>
    <Data Name="param9">LocalHost (Using LRPC)</Data>
    <Data Name="param10">Unavailable</Data>
    <Data Name="param11">Unavailable</Data>
  </EventData>
</Event>
Log Name:      System
Source:        Microsoft-Windows-WER-SystemErrorReporting
Date:          3/12/2019 6:11:43 PM
Event ID:      1001
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Ultra-Magnus
Description:
The computer has rebooted from a bugcheck.  The bugcheck was: 0x0000003b (0x00000000c0000005, 0xfffff8025e1ebc9c, 0xffff820bdbcb6850, 0x0000000000000000). A dump was saved in: C:\WINDOWS\MEMORY.DMP. Report Id: 9b9c63f0-f54b-4018-8e51-deddeded2744.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Microsoft-Windows-WER-SystemErrorReporting" Guid="{ABCE23E7-DE45-4366-8631-84FA6C525952}" EventSourceName="BugCheck" />
    <EventID Qualifiers="16384">1001</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2019-03-12T22:11:43.863524500Z" />
    <EventRecordID>23584</EventRecordID>
    <Correlation />
    <Execution ProcessID="0" ThreadID="0" />
    <Channel>System</Channel>
    <Computer>Ultra-Magnus</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">0x0000003b (0x00000000c0000005, 0xfffff8025e1ebc9c, 0xffff820bdbcb6850, 0x0000000000000000)</Data>
    <Data Name="param2">C:\WINDOWS\MEMORY.DMP</Data>
    <Data Name="param3">9b9c63f0-f54b-4018-8e51-deddeded2744</Data>
  </EventData>
</Event>
Log Name:      System
Source:        e1dexpress
Date:          3/12/2019 6:11:37 PM
Event ID:      27
Task Category: None
Level:         Warning
Keywords:      Classic
User:          N/A
Computer:      Ultra-Magnus
Description:
Intel(R) Ethernet Connection (7) I219-LM
 Network link is disconnected.

Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="e1dexpress" />
    <EventID Qualifiers="40964">27</EventID>
    <Level>3</Level>
    <Task>0</Task>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2019-03-12T22:11:37.444023600Z" />
    <EventRecordID>23565</EventRecordID>
    <Channel>System</Channel>
    <Computer>Ultra-Magnus</Computer>
    <Security />
  </System>
  <EventData>
    <Data>
    </Data>
    <Data>Intel(R) Ethernet Connection (7) I219-LM</Data>
    <Binary>0000040002003000000000001B0004A00000000000000000000000000000000000000000000000001B0004A0</Binary>
  </EventData>
</Event>
Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          3/12/2019 6:11:32 PM
Event ID:      219
Task Category: (212)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Ultra-Magnus
Description:
The driver \Driver\WUDFRd failed to load for the device USB\VID_06CB&PID_009A\3e83b4866717.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9c205a39-1250-487d-abd7-e831c6290539}" />
    <EventID>219</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>212</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2019-03-12T22:11:32.264153600Z" />
    <EventRecordID>23558</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="256" />
    <Channel>System</Channel>
    <Computer>Ultra-Magnus</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="DriverNameLength">34</Data>
    <Data Name="DriverName">USB\VID_06CB&amp;PID_009A\3e83b4866717</Data>
    <Data Name="Status">3221226341</Data>
    <Data Name="FailureNameLength">14</Data>
    <Data Name="FailureName">\Driver\WUDFRd</Data>
    <Data Name="Version">0</Data>
  </EventData>
</Event>
Log Name:      System
Source:        Microsoft-Windows-Kernel-Power
Date:          3/12/2019 6:11:30 PM
Event ID:      105
Task Category: (100)
Level:         Information
Keywords:      (1024),(4)
User:          SYSTEM
Computer:      Ultra-Magnus
Description:
Power source change.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-Power" Guid="{331c3b3a-2005-44c2-ac5e-77220c37d6b4}" />
    <EventID>105</EventID>
    <Version>1</Version>
    <Level>4</Level>
    <Task>100</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000404</Keywords>
    <TimeCreated SystemTime="2019-03-12T22:11:30.382280700Z" />
    <EventRecordID>23549</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="476" />
    <Channel>System</Channel>
    <Computer>Ultra-Magnus</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="AcOnline">false</Data>
    <Data Name="RemainingCapacity">0</Data>
    <Data Name="FullChargeCapacity">0</Data>
  </EventData>
</Event>
Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          3/12/2019 6:11:29 PM
Event ID:      219
Task Category: (212)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Ultra-Magnus
Description:
The driver \Driver\WUDFRd failed to load for the device ROOT\SYSTEM\0002.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9c205a39-1250-487d-abd7-e831c6290539}" />
    <EventID>219</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>212</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2019-03-12T22:11:29.813014400Z" />
    <EventRecordID>23525</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="256" />
    <Channel>System</Channel>
    <Computer>Ultra-Magnus</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="DriverNameLength">16</Data>
    <Data Name="DriverName">ROOT\SYSTEM\0002</Data>
    <Data Name="Status">3221226341</Data>
    <Data Name="FailureNameLength">14</Data>
    <Data Name="FailureName">\Driver\WUDFRd</Data>
    <Data Name="Version">0</Data>
  </EventData>
</Event>
Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          3/12/2019 6:11:28 PM
Event ID:      219
Task Category: (212)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Ultra-Magnus
Description:
The driver \Driver\WUDFRd failed to load for the device PCI\VEN_8086&DEV_1903&SUBSYS_226717AA&REV_07\3&11583659&1&20.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9c205a39-1250-487d-abd7-e831c6290539}" />
    <EventID>219</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>212</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2019-03-12T22:11:28.790963100Z" />
    <EventRecordID>23522</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="256" />
    <Channel>System</Channel>
    <Computer>Ultra-Magnus</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="DriverNameLength">60</Data>
    <Data Name="DriverName">PCI\VEN_8086&amp;DEV_1903&amp;SUBSYS_226717AA&amp;REV_07\3&amp;11583659&amp;1&amp;20</Data>
    <Data Name="Status">3221226341</Data>
    <Data Name="FailureNameLength">14</Data>
    <Data Name="FailureName">\Driver\WUDFRd</Data>
    <Data Name="Version">0</Data>
  </EventData>
</Event>
Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          3/12/2019 6:11:27 PM
Event ID:      219
Task Category: (212)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Ultra-Magnus
Description:
The driver \Driver\WUDFRd failed to load for the device ROOT\WindowsHelloFaceSoftwareDriver\0000.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9c205a39-1250-487d-abd7-e831c6290539}" />
    <EventID>219</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>212</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2019-03-12T22:11:27.738392700Z" />
    <EventRecordID>23519</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="256" />
    <Channel>System</Channel>
    <Computer>Ultra-Magnus</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="DriverNameLength">40</Data>
    <Data Name="DriverName">ROOT\WindowsHelloFaceSoftwareDriver\0000</Data>
    <Data Name="Status">3221226341</Data>
    <Data Name="FailureNameLength">14</Data>
    <Data Name="FailureName">\Driver\WUDFRd</Data>
    <Data Name="Version">0</Data>
  </EventData>
</Event>
Log Name:      System
Source:        Microsoft-Windows-Kernel-Power
Date:          3/12/2019 6:11:27 PM
Event ID:      172
Task Category: (203)
Level:         Information
Keywords:      (1024),(4)
User:          SYSTEM
Computer:      Ultra-Magnus
Description:
Connectivity state in standby: Disconnected, Reason: NIC compliance
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-Power" Guid="{331c3b3a-2005-44c2-ac5e-77220c37d6b4}" />
    <EventID>172</EventID>
    <Version>0</Version>
    <Level>4</Level>
    <Task>203</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000404</Keywords>
    <TimeCreated SystemTime="2019-03-12T22:11:27.611538000Z" />
    <EventRecordID>23509</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="284" />
    <Channel>System</Channel>
    <Computer>Ultra-Magnus</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="State">2</Data>
    <Data Name="Reason">6</Data>
  </EventData>
</Event>

 

Log Name:      System
Source:        Microsoft-Windows-Kernel-Power
Date:          3/12/2019 6:11:27 PM
Event ID:      41
Task Category: (63)
Level:         Critical
Keywords:      (70368744177664),(2)
User:          SYSTEM
Computer:      Ultra-Magnus
Description:
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-Power" Guid="{331c3b3a-2005-44c2-ac5e-77220c37d6b4}" />
    <EventID>41</EventID>
    <Version>6</Version>
    <Level>1</Level>
    <Task>63</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000400000000002</Keywords>
    <TimeCreated SystemTime="2019-03-12T22:11:27.607211600Z" />
    <EventRecordID>23508</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="8" />
    <Channel>System</Channel>
    <Computer>Ultra-Magnus</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="BugcheckCode">59</Data>
    <Data Name="BugcheckParameter1">0xc0000005</Data>
    <Data Name="BugcheckParameter2">0xfffff8025e1ebc9c</Data>
    <Data Name="BugcheckParameter3">0xffff820bdbcb6850</Data>
    <Data Name="BugcheckParameter4">0x0</Data>
    <Data Name="SleepInProgress">0</Data>
    <Data Name="PowerButtonTimestamp">0</Data>
    <Data Name="BootAppStatus">0</Data>
    <Data Name="Checkpoint">41</Data>
    <Data Name="ConnectedStandbyInProgress">false</Data>
    <Data Name="SystemSleepTransitionsToOn">23</Data>
    <Data Name="CsEntryScenarioInstanceId">0</Data>
    <Data Name="BugcheckInfoFromEFI">false</Data>
    <Data Name="CheckpointStatus">0</Data>
  </EventData>
</Event>
Log Name:      System
Source:        Microsoft-Windows-Hyper-V-Hypervisor
Date:          3/12/2019 6:11:19 PM
Event ID:      157
Task Category: None
Level:         Warning
Keywords:      (70368744177664)
User:          SYSTEM
Computer:      Ultra-Magnus
Description:
The hypervisor did not enable mitigations for CVE-2018-3646 for virtual machines because HyperThreading is enabled and the hypervisor core scheduler is not enabled. To enable mitigations for CVE-2018-3646 for virtual machines, enable the core scheduler by running "bcdedit /set hypervisorschedulertype core" from an elevated command prompt and reboot.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Microsoft-Windows-Hyper-V-Hypervisor" Guid="{52fc89f8-995e-434c-a91e-199986449890}" />
    <EventID>157</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000400000000000</Keywords>
    <TimeCreated SystemTime="2019-03-12T22:11:19.899218600Z" />
    <EventRecordID>23494</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="8" />
    <Channel>System</Channel>
    <Computer>Ultra-Magnus</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
  </EventData>
</Event>

 

Check out current deals!


Shop current deals

Top Kudoed Authors