How to Prevent Audit Failure Logs from Causing Issues when trying to access Guest account
Hello. I've been dealing with an extremely frustrating issue over the last month, and I'm starting to run out of hope that I'll be able to fix it. But I wanted to see if anyone here has any ideas that Google Gemini did not.
I primarily use my Windows 11 Home PC (currently on OS build 26200.8457) to play iRacing in VR. Over the past month, I've been dealing with a mysterious issue in Windows that is causing the application to close at around 11:11 pm - 11:12 pm every night (the exact time keeps shifting back a bit every day, so its probably going to start happening at 11:13 pm soon). I tried to look for any crash logs from the game or my VR headset, but I couldn't find anything there. I tried things like upgrading my BIOS & graphics card firmware to the latest versions and making sure that my AT&T fiber box assigns a static IP address to my PC (all suggestions from Google Gemini), but none of that helped. There were no logs in the Application Event Viewer of Windows; however, I did end up finding that whenever this happened, there was an Audit Failure log in the Security tab of the Event Viewer at the exact time I was being booted out of the game.
The Audit Failures were originally happening because some unknown process or task was trying to log into the guest account on my PC, which I had disabled. So, I tried enabling the guest account to see if that would make it go away, but now I just get the same failure with "The user has not been granted the requested logon type at this machine." instead.
I know that the process that is resulting in this audit failure is svchost.exe, but its extremely difficult to actually get info about what is actually trying to log in with the guest account. Whatever it is, its something that I don't care about or want running on my PC, so I want to know if there's anything I can better do to actually figure out what is causing this and how to stop it. I've tried using ProcMon.exe, but that is so busy that its hard to actual sift through the logs, and its still pretty vague about what is actually triggering the problematic svchost.exe process. Gemini thought it could be caused by the DmClient.exe program, so I disabled those scheduled tasks and that didn't help. I also tried disabling the SoftLanding scheduled tasks, and any of the OneDrive tasks as well (since I don't even use OneDrive), but those didn't work either (and frustratingly enough, the OneDrive tasks seem to be able to re-enable themselves).
This week, I ended up inadvertently shifting when the error happens to around 7:14 pm. I shut my PC down before the 11:11 pm window on Monday and when I turned my PC on the next day, I got this Audit Failure to happen right when my PC started at 6:59 pm. Then it happened again on Wednesday when I started my PC at around 7:13 pm. It didn't happen on Thursday, and it happened today at 7:14 pm. There wasn't any Scheduled Task that fired off when this issue happened, so I don't think its a Scheduled Task (or if it is, the OS is preventing me from seeing this information, which is annoying).
I apologize if this information is a bit vague, but I'm really struggling here. I'm attaching a screenshot of the full error message and my PC's specs. There has to be a way to tell my PC to stop trying to access the guest account for something that I don't even know is running, isn't there? If there isn't, then that's a major flaw in Microsoft Windows, and it would be very upsetting. If I have to reinstall Windows, then I'm not opposed to that either, though I'm not entirely confident that will resolve the issue if this is being caused by some process that Windows is just going to install and run unbeknownst to me.