Server 2008 R2 Windows Update Issues

Interesting. Let's try reinstalling them.

KB3003057: Download Cumulative Security Update for Internet Explorer 9 for Windows Server 28 R2 x64 Edition (KB3:(57) from Official Microsoft Download Center
KB3078071: Download Cumulative Security Update for Internet Explorer 9 for Windows Server 28 R2 x64 Edition (KB371) from Official Microsoft Download Center
KB3124275: Download Cumulative Security Update for Internet Explorer 9 for Windows Server 28 R2 x64 Edition (KB3124275) from Official Microsoft Download Center

Install Update with DISM

  1. Download the update MSU listed above.
  2. Copy the MSU file to a convenient location (such as C:\temp).
  3. Click on the Start
    Start%20Orb.jpg
    button and in the search box, type Command Prompt
  4. When you see Command Prompt on the list, right-click on it and select Run as administrator
  5. When command prompt opens, copy and paste the following commands into it, press enter after each

    cd C:\temp

    replace C:\temp with your path if different

    expand {update name}.msu -f:* C:\temp

    replace {update name} with the name of the MSU file downloaded in step 1

    DISM.exe /Online /Add-Package /PackagePath:C:\temp\{update name}.cab

  6. You should receive the message:
    The operation completed successfully.
  7. Make sure to allow the computer to restart if prompted.

    If you receive any other message:
  8. Right-click on the Command Prompt window and click Select All, this will invert all of the colors by selecting the text, now press enter. All of this text is now copied.
  9. Paste (Ctrl+V) it into your next post please.
 
Try removing it instead.

DISM.exe /Online /Remove-Package /PackagePath:C:\temp\{update name}.cab

If that fails, zip and attach C:\Windows\Logs\CBS\CBS.log with your reply.
If CBS.zip is larger than 8MB, upload the file to a file sharing service such as OneDrive, DropBox, SendSpace, etc. and include the link with your reply.
 
I'd like to take a look at the event log:

Event Log Collection

  • Download VEW by Vino Rosso here: VEW.EXE
  • Right click the file and select Run as administrator and click Continue or Allow at the User Account Control Prompt.
  • Click the check boxes next to Application and System located under Select log to query on the upper left.
  • Under Select type to list on the right click the boxes next to Error, Warning and Critical (not XP).
  • Under Number or date of events select Number of events and type 20 in the box next to 1 to 20 and click Run.
  • Once it finishes it will display a log file in notepad.
  • Copy and paste its entire contents into your next reply.
 
Vino's Event Viewer v01c run on Windows 2008 in English
Report run at 09/06/2016 01:44:59


Note: All dates below are in the format dd/mm/yyyy


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - Critical Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - Error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'Application' Date/Time: 09/06/2016 00:14:30
Type: Error Category: 3
Event: 9 Source: Sophos Anti-Virus
Scanning "E:\Private\JN\Back up folder\New job\Team\PIER PMO data\Jan 2014\Finance Management report Jan 2014.xls" returned SAV Interface error 0xa0040212: The file is encrypted.


Log: 'Application' Date/Time: 09/06/2016 00:14:30
Type: Error Category: 3
Event: 9 Source: Sophos Anti-Virus
Scanning "E:\Private\JN\Back up folder\New job\Team\PIER PMO data\Jan 2014\Finance Sickness Jan 2014.xls" returned SAV Interface error 0xa0040212: The file is encrypted.


Log: 'Application' Date/Time: 09/06/2016 00:14:27
Type: Error Category: 3
Event: 9 Source: Sophos Anti-Virus
Scanning "E:\Private\JN\Back up folder\New job\Team\HR data\May 2014\Finance Sickness Absence (May 2014).xlsx" returned SAV Interface error 0xa0040212: The file is encrypted.


Log: 'Application' Date/Time: 09/06/2016 00:14:27
Type: Error Category: 3
Event: 9 Source: Sophos Anti-Virus
Scanning "E:\Private\JN\Back up folder\New job\Team\HR data\May 2014\Financial Services HR Data Suite (May 2014).xlsx" returned SAV Interface error 0xa0040212: The file is encrypted.


Log: 'Application' Date/Time: 09/06/2016 00:14:27
Type: Error Category: 3
Event: 9 Source: Sophos Anti-Virus
Scanning "E:\Private\JN\Back up folder\New job\Team\HR data\Jan 2014\Finance Sickness Absence (Jan 14).xls" returned SAV Interface error 0xa0040212: The file is encrypted.


Log: 'Application' Date/Time: 09/06/2016 00:14:27
Type: Error Category: 3
Event: 9 Source: Sophos Anti-Virus
Scanning "E:\Private\JN\Back up folder\New job\Team\HR data\Jan 2014\Financial Services HR Data Suite (Jan 2014).xls" returned SAV Interface error 0xa0040212: The file is encrypted.


Log: 'Application' Date/Time: 08/06/2016 23:26:34
Type: Error Category: 3
Event: 9 Source: Sophos Anti-Virus
Scanning "E:\Private\AH\BUDGET\2016 17\4 year plan\Spreadsheets\AH 28sept15 Copy of 01 - DRAFT Integrated Service Financial Plan Template v2 (Following DMT 240915) - Adults.xlsx" returned SAV Interface error 0xa0040212: The file is encrypted.


Log: 'Application' Date/Time: 08/06/2016 23:23:42
Type: Error Category: 3
Event: 9 Source: Sophos Anti-Virus
Scanning "E:\Private\JS\Desktop\$RECYCLE.BIN\$R1YIO5W.xls" returned SAV Interface error 0xa0040212: The file is encrypted.


Log: 'Application' Date/Time: 08/06/2016 22:54:27
Type: Error Category: 3
Event: 9 Source: Sophos Anti-Virus
Scanning "E:\Private\WK\Desktop\$RECYCLE.BIN\$RTTBX6V.docx" returned SAV Interface error 0xa0040212: The file is encrypted.


Log: 'Application' Date/Time: 08/06/2016 21:47:01
Type: Error Category: 3
Event: 9 Source: Sophos Anti-Virus
Scanning "E:\Private\JC\recruitment\Recruitment - JDs, Person Specs etc\2002 School ICT Support Team appointments\2002 Senior ICT technical Officer August\Shortlist.xls" returned SAV Interface error 0xa0040212: The file is encrypted.


Log: 'Application' Date/Time: 08/06/2016 21:47:00
Type: Error Category: 3
Event: 9 Source: Sophos Anti-Virus
Scanning "E:\Private\JC\recruitment\2002 Senior ICT technical Officer August\Shortlist2.xls" returned SAV Interface error 0xa0040212: The file is encrypted.


Log: 'Application' Date/Time: 08/06/2016 21:47:00
Type: Error Category: 3
Event: 9 Source: Sophos Anti-Virus
Scanning "E:\Private\JC\recruitment\2002 Senior ICT technical Officer August\Shortlist.xls" returned SAV Interface error 0xa0040212: The file is encrypted.


Log: 'Application' Date/Time: 08/06/2016 21:15:55
Type: Error Category: 3
Event: 9 Source: Sophos Anti-Virus
Scanning "E:\Private\AH\Desktop\$RECYCLE.BIN\$R0ZCAMB\Client closed case files\G\GRAINGER Zachary 21.06.02 - CLOSED\Action Planning and Case Management Template ZG20090103.xls" returned SAV Interface error 0xa0040212: The file is encrypted.


Log: 'Application' Date/Time: 08/06/2016 20:58:15
Type: Error Category: 3
Event: 9 Source: Sophos Anti-Virus
Scanning "E:\Private\AL\Documents\Target Tracker\EYFS\Backups\EYFS_2013_master.eyfs\2015-10-05 140335\EYFS_2013_master.eyfs" returned SAV Interface error 0xa0040202: Scan failed.


Log: 'Application' Date/Time: 08/06/2016 20:56:07
Type: Error Category: 3
Event: 9 Source: Sophos Anti-Virus
Scanning "E:\Private\JS\040209\My Documents\Technical Assistance\Revenues Recovery\Incoming Tel Monitoring Jan 08.xls" returned SAV Interface error 0xa0040212: The file is encrypted.


Log: 'Application' Date/Time: 08/06/2016 20:56:07
Type: Error Category: 3
Event: 9 Source: Sophos Anti-Virus
Scanning "E:\Private\JS\040209\My Documents\Technical Assistance\Revenues Recovery\NOV 08 121's.xls" returned SAV Interface error 0xa0040212: The file is encrypted.


Log: 'Application' Date/Time: 08/06/2016 20:56:06
Type: Error Category: 3
Event: 9 Source: Sophos Anti-Virus
Scanning "E:\Private\JS\040209\My Documents\Technical Assistance\Benefits\homeless proof 24 june 2004 - backup copy 140405.xls" returned SAV Interface error 0xa0040212: The file is encrypted.


Log: 'Application' Date/Time: 08/06/2016 20:50:39
Type: Error Category: 3
Event: 9 Source: Sophos Anti-Virus
Scanning "E:\Private\JCCopy of Copy of Copy of Genius(1).xlsx" returned SAV Interface error 0xa0040212: The file is encrypted.


Log: 'Application' Date/Time: 08/06/2016 20:38:47
Type: Error Category: 3
Event: 9 Source: Sophos Anti-Virus
Scanning "E:\Private\JW\Password protected document re KM doc final copy.docx" returned SAV Interface error 0xa0040212: The file is encrypted.


Log: 'Application' Date/Time: 08/06/2016 20:38:47
Type: Error Category: 3
Event: 9 Source: Sophos Anti-Virus
Scanning "E:\Private\JW\Password protected document re KM doc final copy (3).docx" returned SAV Interface error 0xa0040212: The file is encrypted.


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - Warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'Application' Date/Time: 09/06/2016 00:43:55
Type: Warning Category: 0
Event: 1000 Source: VMware Tools
[ warning] [vmusr:vmtoolsd] Failed registration of app type 2 (Signals) from plugin unity.




Log: 'Application' Date/Time: 08/06/2016 23:58:28
Type: Warning Category: 0
Event: 8215 Source: SRMSVC
The system detected that user ADMIN\HB attempted to save E:\Private\HB\Desktop\Tourism Advisory Board 2014.msg on E:\Private on server WAP-FS03. This file matches the "E-mail Files" file group which is not permitted on the system.


Log: 'Application' Date/Time: 08/06/2016 22:54:40
Type: Warning Category: 0
Event: 8215 Source: SRMSVC
The system detected that user ADMIN\JV attempted to save E:\Private\JV\Desktop\Dist List - All.msg on E:\Private on server WAP-FS03. This file matches the "E-mail Files" file group which is not permitted on the system.


Log: 'Application' Date/Time: 08/06/2016 21:53:27
Type: Warning Category: 0
Event: 8215 Source: SRMSVC
The system detected that user ADMIN\hb attempted to save E:\Private\HB\Desktop\Tourism Advisory Board 2014.msg on E:\Private on server WAP-FS03. This file matches the "E-mail Files" file group which is not permitted on the system.


Log: 'Application' Date/Time: 08/06/2016 20:49:40
Type: Warning Category: 0
Event: 8215 Source: SRMSVC
The system detected that user ADMIN\JV attempted to save E:\Private\JV\Desktop\Dist List - All.msg on E:\Private on server WAP-FS03. This file matches the "E-mail Files" file group which is not permitted on the system.


Log: 'Application' Date/Time: 08/06/2016 19:48:28
Type: Warning Category: 0
Event: 8215 Source: SRMSVC
The system detected that user ADMIN\hb attempted to save E:\Private\HB\Desktop\Tourism Advisory Board 2014.msg on E:\Private on server WAP-FS03. This file matches the "E-mail Files" file group which is not permitted on the system.


Log: 'Application' Date/Time: 08/06/2016 18:44:40
Type: Warning Category: 0
Event: 8215 Source: SRMSVC
The system detected that user ADMIN\JV attempted to save E:\Private\JVDesktop\Dist List - All.msg on E:\Private on server WAP-FS03. This file matches the "E-mail Files" file group which is not permitted on the system.


Log: 'Application' Date/Time: 08/06/2016 17:44:10
Type: Warning Category: 0
Event: 8215 Source: SRMSVC
The system detected that user ADMIN\hb attempted to save E:\Private\HB\Desktop\Tourism Advisory Board 2014.msg on E:\Private on server WAP-FS03. This file matches the "E-mail Files" file group which is not permitted on the system.


Log: 'Application' Date/Time: 08/06/2016 16:44:00
Type: Warning Category: 0
Event: 8215 Source: SRMSVC
The system detected that user ADMIN\CH attempted to save E:\Private\CH\Documents\Benfield valley south of Sainsbury.msg on E:\Private on server WAP-FS03. This file matches the "E-mail Files" file group which is not permitted on the system.


Log: 'Application' Date/Time: 08/06/2016 15:44:00
Type: Warning Category: 0
Event: 8215 Source: SRMSVC
The system detected that user ADMIN\CH attempted to save E:\Private\CH\Documents\Fw 401610307 (NTR) Fm Allotments.msg on E:\Private on server WAP-FS03. This file matches the "E-mail Files" file group which is not permitted on the system.


Log: 'Application' Date/Time: 08/06/2016 14:44:00
Type: Warning Category: 0
Event: 8215 Source: SRMSVC
The system detected that user ADMIN\CH attempted to save E:\Private\CH\Documents\Fw 401610307 (NTR) Fm Allotments.msg on E:\Private on server WAP-FS03. This file matches the "E-mail Files" file group which is not permitted on the system.


Log: 'Application' Date/Time: 08/06/2016 13:44:00
Type: Warning Category: 0
Event: 8215 Source: SRMSVC
The system detected that user ADMIN\CH attempted to save E:\Private\CH\Documents\Benfield valley south of Sainsbury.msg on E:\Private on server WAP-FS03. This file matches the "E-mail Files" file group which is not permitted on the system.


Log: 'Application' Date/Time: 08/06/2016 13:02:38
Type: Warning Category: 1
Event: 8004 Source: Sophos Message Router
Failed to communicate with parent router "10.10.10.11". For more information, see the RMS status report. To open the report, click Start, point to All Programs, point to Sophos, point to Sophos Endpoint Security and Control, and then click View Sophos Network Communications Report.


Log: 'Application' Date/Time: 08/06/2016 12:43:39
Type: Warning Category: 0
Event: 8215 Source: SRMSVC
The system detected that user ADMIN\dp attempted to save E:\Private\DP\Desktop\$RECYCLE.BIN\$RDBOHC6\Northgate\NGModBen\.git\objects\pack\pack-457167a0f8caad8f40c70be7f710794b6f8fed5a.idx on E:\Private on server WAP-FS03. This file matches the "E-mail Files" file group which is not permitted on the system.


Log: 'Application' Date/Time: 08/06/2016 11:43:38
Type: Warning Category: 0
Event: 8215 Source: SRMSVC
The system detected that user ADMIN\dp attempted to save E:\Private\DP\Desktop\$RECYCLE.BIN\$RDBOHC6\Java\BACSTransfer\.git\objects\pack\pack-caf50ed0e294f450332b5c31ee755ac991e34165.idx on E:\Private on server WAP-FS03. This file matches the "E-mail Files" file group which is not permitted on the system.


Log: 'Application' Date/Time: 08/06/2016 10:42:48
Type: Warning Category: 0
Event: 8215 Source: SRMSVC
The system detected that user ADMIN\mb attempted to save E:\Private\MB\Desktop\$RECYCLE.BIN\$RPW9HU8\Ct.msg on E:\Private on server WAP-FS03. This file matches the "E-mail Files" file group which is not permitted on the system.


Log: 'Application' Date/Time: 08/06/2016 09:42:16
Type: Warning Category: 0
Event: 8215 Source: SRMSVC
The system detected that user ADMIN\ke attempted to save E:\Private\KE\Desktop\Personal\Frozen Party\Confirmation Frozen party booking.msg on E:\Private on server WAP-FS03. This file matches the "E-mail Files" file group which is not permitted on the system.


Log: 'Application' Date/Time: 08/06/2016 09:30:41
Type: Warning Category: 0
Event: 1530 Source: Microsoft-Windows-User Profiles Service
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 1 user registry handles leaked from \Registry\User\S-1-5-21-1622503031-706414993-14044502-20962:
Process 444 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1622503031-706414993-14044502-20962\Printers\DevModePerUser




Log: 'Application' Date/Time: 08/06/2016 09:23:52
Type: Warning Category: 0
Event: 1000 Source: VMware Tools
[ warning] [vmusr:vmtoolsd] Failed registration of app type 2 (Signals) from plugin unity.




Log: 'Application' Date/Time: 08/06/2016 08:41:42
Type: Warning Category: 0
Event: 8215 Source: SRMSVC
The system detected that user ADMIN\mb attempted to save E:\Private\MB\Desktop\$RECYCLE.BIN\$IT7PAVT.msg on E:\Private on server WAP-FS03. This file matches the "E-mail Files" file group which is not permitted on the system.


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Critical Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 09/06/2016 00:44:06
Type: Error Category: 0
Event: 1111 Source: Microsoft-Windows-TerminalServices-Printers
Driver Microsoft XPS Document Writer v4 required for printer Microsoft XPS Document Writer is unknown. Contact the administrator to install the driver before you log in again.


Log: 'System' Date/Time: 09/06/2016 00:43:59
Type: Error Category: 0
Event: 1111 Source: Microsoft-Windows-TerminalServices-Printers
Driver Foxit Reader PDF Printer Driver required for printer Foxit Reader PDF Printer is unknown. Contact the administrator to install the driver before you log in again.


Log: 'System' Date/Time: 09/06/2016 00:43:57
Type: Error Category: 0
Event: 1111 Source: Microsoft-Windows-TerminalServices-Printers
Driver Kyocera TASKalfa 5551ci KX required for printer !!WAP-MFD01!Print is unknown. Contact the administrator to install the driver before you log in again.


Log: 'System' Date/Time: 09/06/2016 00:43:56
Type: Error Category: 0
Event: 1111 Source: Microsoft-Windows-TerminalServices-Printers
Driver Kyocera Generic color KX required for printer !!wap-mfd02!Print is unknown. Contact the administrator to install the driver before you log in again.


Log: 'System' Date/Time: 09/06/2016 00:43:55
Type: Error Category: 0
Event: 1111 Source: Microsoft-Windows-TerminalServices-Printers
Driver Kyocera TASKalfa 5551ci KX required for printer !!WAP-MFD02!Print is unknown. Contact the administrator to install the driver before you log in again.


Log: 'System' Date/Time: 08/06/2016 08:23:14
Type: Error Category: 0
Event: 56 Source: TermDD
The Terminal Server security layer detected an error in the protocol stream and has disconnected the client. Client IP: 10.10.10.143.


Log: 'System' Date/Time: 08/06/2016 08:23:14
Type: Error Category: 0
Event: 36888 Source: Schannel
The following fatal alert was generated: 50. The internal error state is 1305.


Log: 'System' Date/Time: 08/06/2016 08:22:32
Type: Error Category: 0
Event: 56 Source: TermDD
The Terminal Server security layer detected an error in the protocol stream and has disconnected the client. Client IP: 10.10.10.43.


Log: 'System' Date/Time: 07/06/2016 08:21:07
Type: Error Category: 0
Event: 1111 Source: Microsoft-Windows-TerminalServices-Printers
Driver Microsoft XPS Document Writer v4 required for printer Microsoft XPS Document Writer is unknown. Contact the administrator to install the driver before you log in again.


Log: 'System' Date/Time: 07/06/2016 08:21:06
Type: Error Category: 0
Event: 1111 Source: Microsoft-Windows-TerminalServices-Printers
Driver Foxit Reader PDF Printer Driver required for printer Foxit Reader PDF Printer is unknown. Contact the administrator to install the driver before you log in again.


Log: 'System' Date/Time: 07/06/2016 08:21:03
Type: Error Category: 0
Event: 1111 Source: Microsoft-Windows-TerminalServices-Printers
Driver Kyocera TASKalfa 5551ci KX required for printer !!WAP-MFD01!Print is unknown. Contact the administrator to install the driver before you log in again.


Log: 'System' Date/Time: 07/06/2016 08:21:02
Type: Error Category: 0
Event: 1111 Source: Microsoft-Windows-TerminalServices-Printers
Driver Kyocera Generic color KX required for printer !!wap-mfd02!Print is unknown. Contact the administrator to install the driver before you log in again.


Log: 'System' Date/Time: 07/06/2016 08:21:00
Type: Error Category: 0
Event: 1111 Source: Microsoft-Windows-TerminalServices-Printers
Driver Kyocera TASKalfa 5551ci KX required for printer !!WAP-MFD02!Print is unknown. Contact the administrator to install the driver before you log in again.


Log: 'System' Date/Time: 07/06/2016 07:32:21
Type: Error Category: 0
Event: 1111 Source: Microsoft-Windows-TerminalServices-Printers
Driver Microsoft XPS Document Writer v4 required for printer Microsoft XPS Document Writer is unknown. Contact the administrator to install the driver before you log in again.


Log: 'System' Date/Time: 07/06/2016 07:32:20
Type: Error Category: 0
Event: 1111 Source: Microsoft-Windows-TerminalServices-Printers
Driver Foxit Reader PDF Printer Driver required for printer Foxit Reader PDF Printer is unknown. Contact the administrator to install the driver before you log in again.


Log: 'System' Date/Time: 07/06/2016 07:32:16
Type: Error Category: 0
Event: 1111 Source: Microsoft-Windows-TerminalServices-Printers
Driver Kyocera TASKalfa 5551ci KX required for printer !!WAP-MFD01!Print is unknown. Contact the administrator to install the driver before you log in again.


Log: 'System' Date/Time: 07/06/2016 07:32:15
Type: Error Category: 0
Event: 1111 Source: Microsoft-Windows-TerminalServices-Printers
Driver Kyocera Generic color KX required for printer !!wap-mfd02!Print is unknown. Contact the administrator to install the driver before you log in again.


Log: 'System' Date/Time: 07/06/2016 07:32:11
Type: Error Category: 0
Event: 1111 Source: Microsoft-Windows-TerminalServices-Printers
Driver Kyocera TASKalfa 5551ci KX required for printer !!WAP-MFD02!Print is unknown. Contact the administrator to install the driver before you log in again.


Log: 'System' Date/Time: 03/06/2016 17:09:50
Type: Error Category: 0
Event: 1111 Source: Microsoft-Windows-TerminalServices-Printers
Driver Microsoft XPS Document Writer v4 required for printer Microsoft XPS Document Writer is unknown. Contact the administrator to install the driver before you log in again.


Log: 'System' Date/Time: 03/06/2016 17:09:49
Type: Error Category: 0
Event: 1111 Source: Microsoft-Windows-TerminalServices-Printers
Driver Kyocera TASKalfa 5551ci KX required for printer !!WAP-MFD01!Print is unknown. Contact the administrator to install the driver before you log in again.


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 08/06/2016 12:27:57
Type: Warning Category: 0
Event: 141 Source: Ntfs
The event description cannot be found.


Log: 'System' Date/Time: 08/06/2016 12:27:53
Type: Warning Category: 0
Event: 141 Source: Ntfs
The event description cannot be found.


Log: 'System' Date/Time: 08/06/2016 12:27:49
Type: Warning Category: 0
Event: 141 Source: Ntfs
The event description cannot be found.


Log: 'System' Date/Time: 26/05/2016 21:17:28
Type: Warning Category: 0
Event: 2511 Source: Server
The server service was unable to recreate the share ToDelete because the directory D:\ToDelete no longer exists. Please run "net share ToDelete /delete" to delete the share, or recreate the directory D:\ToDelete.


Log: 'System' Date/Time: 26/05/2016 21:16:43
Type: Warning Category: 0
Event: 11 Source: Microsoft-Windows-Wininit
Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications.


Log: 'System' Date/Time: 26/05/2016 21:15:34
Type: Warning Category: 0
Event: 2511 Source: Server
The server service was unable to recreate the share ToDelete because the directory D:\ToDelete no longer exists. Please run "net share ToDelete /delete" to delete the share, or recreate the directory D:\ToDelete.


Log: 'System' Date/Time: 26/05/2016 21:14:48
Type: Warning Category: 0
Event: 11 Source: Microsoft-Windows-Wininit
Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications.


Log: 'System' Date/Time: 26/05/2016 21:13:45
Type: Warning Category: 0
Event: 2511 Source: Server
The server service was unable to recreate the share ToDelete because the directory D:\ToDelete no longer exists. Please run "net share ToDelete /delete" to delete the share, or recreate the directory D:\ToDelete.


Log: 'System' Date/Time: 26/05/2016 21:12:58
Type: Warning Category: 0
Event: 11 Source: Microsoft-Windows-Wininit
Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications.


Log: 'System' Date/Time: 24/05/2016 16:52:49
Type: Warning Category: 0
Event: 1014 Source: Microsoft-Windows-DNS-Client
Name resolution for the name _kerberos._tcp.domain._sites.dc._msdcs.co.UK timed out after none of the configured DNS servers responded.


Log: 'System' Date/Time: 23/05/2016 22:07:00
Type: Warning Category: 0
Event: 10154 Source: Microsoft-Windows-WinRM
The WinRM service failed to create the following SPNs: WSMAN/WAP-FS03. WSMAN/WAP-FS03. Additional Data The error received was 8235: %%8235. User Action The SPNs can be created by an administrator using setspn.exe utility.


Log: 'System' Date/Time: 23/05/2016 22:04:59
Type: Warning Category: 0
Event: 2511 Source: Server
The server service was unable to recreate the share ToDelete because the directory D:\ToDelete no longer exists. Please run "net share ToDelete /delete" to delete the share, or recreate the directory D:\ToDelete.


Log: 'System' Date/Time: 23/05/2016 22:04:13
Type: Warning Category: 0
Event: 11 Source: Microsoft-Windows-Wininit
Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications.


Log: 'System' Date/Time: 23/05/2016 21:08:12
Type: Warning Category: 0
Event: 2511 Source: Server
The server service was unable to recreate the share ToDelete because the directory D:\ToDelete no longer exists. Please run "net share ToDelete /delete" to delete the share, or recreate the directory D:\ToDelete.


Log: 'System' Date/Time: 23/05/2016 21:07:27
Type: Warning Category: 0
Event: 11 Source: Microsoft-Windows-Wininit
Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications.


Log: 'System' Date/Time: 23/05/2016 21:06:09
Type: Warning Category: 0
Event: 2511 Source: Server
The server service was unable to recreate the share ToDelete because the directory D:\ToDelete no longer exists. Please run "net share ToDelete /delete" to delete the share, or recreate the directory D:\ToDelete.


Log: 'System' Date/Time: 23/05/2016 21:05:22
Type: Warning Category: 0
Event: 11 Source: Microsoft-Windows-Wininit
Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications.


Log: 'System' Date/Time: 23/05/2016 20:58:31
Type: Warning Category: 0
Event: 40960 Source: LsaSrv
The Security System detected an authentication error for the server cifs/wif-4.co.uk. The failure code from authentication protocol Kerberos was "{Buffer Too Small} The buffer is too small to contain the entry. No information has been written to the buffer. (0xc0000023)".


Log: 'System' Date/Time: 23/05/2016 20:58:31
Type: Warning Category: 0
Event: 15 Source: Microsoft-Windows-Security-Kerberos
The kerberos SSPI package generated an output token of size 22078 bytes, which was too large to fit in the token buffer of size 12000 bytes, provided by process id 4. The application needs to be fixed to supply a token buffer of size at least 65535 bytes.


Log: 'System' Date/Time: 23/05/2016 20:42:02
Type: Warning Category: 0
Event: 40960 Source: LsaSrv
The Security System detected an authentication error for the server cifs/wif-1.co.uk. The failure code from authentication protocol Kerberos was "{Buffer Too Small} The buffer is too small to contain the entry. No information has been written to the buffer. (0xc0000023)".
 
Last edited:
Would you mind uploading the entire System and Application log files?

Gather System Event Logs

1. Left-click your Start button and type Event Viewer in the search box. Left-click on Event Viewer when it appears in the list.
2. Expand Windows Logs , then locate and click on the System log.
3. Right-click on System and select Save All Events As...
4. Name the file System and save to your desktop.
You may be prompted to add Display information. If you are please ensure that you include English display information.​
5. You should now see a file on your desktop named System.evtx. Right-click on this file and select Send To Compressed (zipped) folder.
6. Repeat steps 2 - 5 for the Application log.

Please attach the zip files with your next reply.
 
I think I may have found something, but I'll need the latest CBS log to confirm.

Please zip and attach C:\Windows\Logs\CBS\CBS.log
If the zip is larger than 8MB, please use a file sharing service such as OneDrive, DropBox, SendSpace, etc. and include the link with your reply.
 
What roles are configured on this server? (IIS, DC, etc)

Please try setting the TrustedInstaller service to Automatic startup using services.msc and restart the server.
After the restart, check for Windows Updates and install any that are offered. If the installation fails, zip and attach CBS.log with your reply.
 
The only role on this server is File Services.

Will post again when services amended and server restarted
 
The service in question is already started/automatic.

Will schedule a reboot and post again later today.
 
Let's check for corrupt system files with System File Checker (SFC):

SFC Scan

  1. Click on the Start
    Start%20Orb.jpg
    button and in the search box, type Command Prompt
  2. When you see Command Prompt on the list, right-click on it and select Run as administrator
  3. When command prompt opens, copy and paste the following commands into it, press enter after each

    sfc /scannow

    Wait for this to finish before you continue

    copy %windir%\logs\cbs\cbs.log %userprofile%\Desktop\cbs.txt

  4. This will create a file, cbs.txt on your Desktop. Please zip and attach this to your next post.
 
Back
Top