Updates Rollback on restart Server 2019 1809 17763.5206

Rich (BB code):
2024/11/26 15:55:02.6119824 5772  8352  Misc            GetUserTickets: No user tickets found. Returning WU_E_NO_USERTOKEN.
2024/11/26 15:55:02.6188374 5772  8352  Misc            *FAILED* [80070057] Method failed [AuthTicketHelper::AddTickets:1236]
2024/11/26 15:55:02.6188423 5772  8352  Misc            *FAILED* [80092004] Method failed [CUpdateEndpointProvider::GenerateSecurityTokenWithAuthTickets:1674]
2024/11/26 15:55:02.6189162 5772  8352  Misc            Acquired new token from Server

Please open an elevated prompt, run the following command and attach services.txt to your next post.
Code:
WMIC SERVICE GET caption, name, startmode, state > "%userprofile%\desktop\services.txt"
 
Please run the following commands in an elevated prompt and post the result:
Code:
sc config wlidsvc start= auto
sc start wlidsvc
Wait a few seconds and run the following commands:
Code:
sc qc wlidsvc
sc query wlidsvc
 
C:\Windows\system32>sc config wlidsvc start= auto
[SC] ChangeServiceConfig SUCCESS

C:\Windows\system32>sc start wlidsvc

SERVICE_NAME: wlidsvc
TYPE : 30 WIN32
STATE : 2 START_PENDING
(NOT_STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
WIN32_EXIT_CODE : 0 (0x0)
SERVICE_EXIT_CODE : 0 (0x0)
CHECKPOINT : 0x0
WAIT_HINT : 0x7d0
PID : 13068
FLAGS :

C:\Windows\system32>sc qc wlidsvc
[SC] QueryServiceConfig SUCCESS

SERVICE_NAME: wlidsvc
TYPE : 20 WIN32_SHARE_PROCESS
START_TYPE : 2 AUTO_START
ERROR_CONTROL : 1 NORMAL
BINARY_PATH_NAME : C:\Windows\system32\svchost.exe -k netsvcs -p
LOAD_ORDER_GROUP :
TAG : 0
DISPLAY_NAME : Microsoft Account Sign-in Assistant
DEPENDENCIES : RpcSs
SERVICE_START_NAME : LocalSystem

C:\Windows\system32>sc query wlidsvc

SERVICE_NAME: wlidsvc
TYPE : 30 WIN32
STATE : 4 RUNNING
(STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
WIN32_EXIT_CODE : 0 (0x0)
SERVICE_EXIT_CODE : 0 (0x0)
CHECKPOINT : 0x0
WAIT_HINT : 0x0
 
Good morning,

Please try to update again and post the result, if it fails attach a new copy of the CBS and WindowsUpdate log.
 
Hi,

Please run the following commands in an elevated prompt and post the result.
Code:
net stop wuauserv
net stop cryptSvc
net stop bits
del /f /q “%ALLUSERSPROFILE%\Application Data\Microsoft\Network\Downloader\qmgr*.dat”
del /f /s /q %SystemRoot%\SoftwareDistribution\*.*
del /f /s /q %SystemRoot%\system32\catroot2\*.*
net start wuauserv
net start cryptSvc
net start bits
 
Thanks Maxstar


C:\Windows\system32>net stop wuauserv
The Windows Update service is stopping.
The Windows Update service could not be stopped.


C:\Windows\system32>net stop cryptSvc
The Cryptographic Services service is stopping..
The Cryptographic Services service could not be stopped.


C:\Windows\system32>net stop bits
The Background Intelligent Transfer Service service is not started.

More help is available by typing NET HELPMSG 3521.


C:\Windows\system32>del /f /q "%ALLUSERSPROFILE%\Application Data\Microsoft\Network\Downloader\qmgr*.dat"
Could Not Find C:\ProgramData\Application Data\Microsoft\Network\Downloader\qmgr*.dat

C:\Windows\system32>del /f /s /q %SystemRoot%\SoftwareDistribution\*.*
C:\Windows\SoftwareDistribution\ReportingEvents.log
The process cannot access the file because it is being used by another process.
C:\Windows\SoftwareDistribution\DataStore\DataStore.edb
The process cannot access the file because it is being used by another process.
C:\Windows\SoftwareDistribution\DataStore\DataStore.jfm
The process cannot access the file because it is being used by another process.
Deleted file - C:\Windows\SoftwareDistribution\DataStore\Logs\edb.chk
C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log
The process cannot access the file because it is being used by another process.
Deleted file - C:\Windows\SoftwareDistribution\DataStore\Logs\edb000A4.log
Deleted file - C:\Windows\SoftwareDistribution\DataStore\Logs\edb000A5.log
Deleted file - C:\Windows\SoftwareDistribution\DataStore\Logs\edb000A6.log
Deleted file - C:\Windows\SoftwareDistribution\DataStore\Logs\edbres00001.jrs
Deleted file - C:\Windows\SoftwareDistribution\DataStore\Logs\edbres00002.jrs
Deleted file - C:\Windows\SoftwareDistribution\DataStore\Logs\edbtmp.log
Deleted file - C:\Windows\SoftwareDistribution\Download\01c78fa81ee787e3a5bf7d82e21f449c3d17245a
Deleted file - C:\Windows\SoftwareDistribution\Download\06a7af6244b1ef24de21ac0d7be0114cf3a493a4
Deleted file - C:\Windows\SoftwareDistribution\Download\1bdfdc9f5fccdfedbc9f85c8541d80c6fb081ae8
Deleted file - C:\Windows\SoftwareDistribution\Download\21b9c2b5c4d512c01e94536f12f75235f8cd5cc1
Deleted file - C:\Windows\SoftwareDistribution\Download\247e398a0d85447cb33099cac9f0f7896893673a
Deleted file - C:\Windows\SoftwareDistribution\Download\2b284e4acfe475c83931e08f7e6fc462abd49bbe
Deleted file - C:\Windows\SoftwareDistribution\Download\3247d4240bdedfd74ef356a757bd85b66ea397f3
Deleted file - C:\Windows\SoftwareDistribution\Download\3257aeb1d14b3ad9158d19244355aef1a718d108
Deleted file - C:\Windows\SoftwareDistribution\Download\4beb411bf3020b92dbdda487be858423bbeabe95
Deleted file - C:\Windows\SoftwareDistribution\Download\53a858ae5e57fd8c5b3ea2c85b89ecacd5ecdbe6
Deleted file - C:\Windows\SoftwareDistribution\Download\61e083fdb94f4e2304775c9808984b6fbbd821f2
Deleted file - C:\Windows\SoftwareDistribution\Download\6df0e98274e2c557cfde53e845093b922d69cf60
Deleted file - C:\Windows\SoftwareDistribution\Download\734043637ea130dbf756d8559201796473716696
Deleted file - C:\Windows\SoftwareDistribution\Download\758945451588477f3c05553c9343213d0f3b3c86
Deleted file - C:\Windows\SoftwareDistribution\Download\7599d8eae5720c562ca61403f7cd5cbb855e7591
Deleted file - C:\Windows\SoftwareDistribution\Download\76d3dfb52cbf57ec15be86c0f0e8c56d28f1bbb0
Deleted file - C:\Windows\SoftwareDistribution\Download\786d390f84d1b2b6bd8fa21b23d67b77f00c75bb
Deleted file - C:\Windows\SoftwareDistribution\Download\7e124162b65a8f0e78c40fa814d10a4acb4ce5a0
Deleted file - C:\Windows\SoftwareDistribution\Download\82acb6b77f994cae726450f6003738adf2b8d853
Deleted file - C:\Windows\SoftwareDistribution\Download\82edaec24eb01042abfe83de0dcc33b0b4f58ef9
Deleted file - C:\Windows\SoftwareDistribution\Download\8319126f6fb49a9b56b9dc8eff0a60b81be6aa8d
Deleted file - C:\Windows\SoftwareDistribution\Download\90b84e0298040b7795efefe75419cc2f4d4fd9e1
Deleted file - C:\Windows\SoftwareDistribution\Download\98ccd814ccd6c534614f0a08344decc35f49a518
Deleted file - C:\Windows\SoftwareDistribution\Download\9d25a59e472907ddaa7b189b5c563d28978b38c8
Deleted file - C:\Windows\SoftwareDistribution\Download\a3c898e5370d2bd96262a47a1ab438c03a266f71
Deleted file - C:\Windows\SoftwareDistribution\Download\a465e90557a135d302e3930327b560d9ba846b12
Deleted file - C:\Windows\SoftwareDistribution\Download\a743b06a4132b2c9ab25df378097bae83d9254cc
Deleted file - C:\Windows\SoftwareDistribution\Download\acb38d66466232b6ab1697b29d3561deb1f9fefd
Deleted file - C:\Windows\SoftwareDistribution\Download\ad954b058e39b91002d096f88b1efc521f5367c6
Deleted file - C:\Windows\SoftwareDistribution\Download\b268019e922b08c35d0ebe5c0ac16b92730ebc71
Deleted file - C:\Windows\SoftwareDistribution\Download\b3b97f1667649ccc24309165ae55d1e423b48a1b
Deleted file - C:\Windows\SoftwareDistribution\Download\b5820e796c53cec5c3c30143d7e557c652120fd0
Deleted file - C:\Windows\SoftwareDistribution\Download\bea2bd2c87de9c2e2504bdb535fd75ad9f98d0a8
Deleted file - C:\Windows\SoftwareDistribution\Download\cbb6689322a2773c0374a1e9d0552ed28d1a5c42
Deleted file - C:\Windows\SoftwareDistribution\Download\d1d202f6756a57d51ffe34de6d76652b7fe938c6
Deleted file - C:\Windows\SoftwareDistribution\Download\d1e375e4fc4dd5f3fce7c67167a25a47ae23a66a
Deleted file - C:\Windows\SoftwareDistribution\Download\d4958ed4d5aa7b06d2b512bee435d576def40d01
Deleted file - C:\Windows\SoftwareDistribution\Download\dbef55e1c0fd32acf6e575faca06bff93321ac25
Deleted file - C:\Windows\SoftwareDistribution\Download\dc94f189f0d93dbe32411d376d47a07ff6c2a95c
Deleted file - C:\Windows\SoftwareDistribution\Download\f182607f03eac8dc3389f2df4c070cc1b6ca085b
Deleted file - C:\Windows\SoftwareDistribution\Download\f212858bcd196b78952a32a7507be300da7b5eb7
Deleted file - C:\Windows\SoftwareDistribution\Download\f86a81e29742ca4167d3d6723a76b7ad9b890f9c
Deleted file - C:\Windows\SoftwareDistribution\Download\0f550c2473b32197e95a4616755ecd6e\07a02b7a7e18b5de71c6bb20c10bc51567d1ce7d
Deleted file - C:\Windows\SoftwareDistribution\Download\8e1df472dc36ec4b5ea59c9eb46d4edd\053af8cf-d663-4055-a297-3f429f770b4f.AggregatedMetadata.cab
Deleted file - C:\Windows\SoftwareDistribution\Download\8e1df472dc36ec4b5ea59c9eb46d4edd\DesktopDeployment.cab
Deleted file - C:\Windows\SoftwareDistribution\Download\aa30ff3a1824660dae68d7849dfe0a22\Windows10.0-KB5041913-x64.cab
Deleted file - C:\Windows\SoftwareDistribution\Download\aa30ff3a1824660dae68d7849dfe0a22\cbshandler\state
Deleted file - C:\Windows\SoftwareDistribution\Download\b8773c0cc66a51dcd35e3c5c84fcd034\88468fc2d155f02b29caf6b169ec1c0cc5ea13fa
Deleted file - C:\Windows\SoftwareDistribution\Download\c1ea952b79f9a47af2b990798ec58958\Windows10.0-KB5046268-x64.cab
Deleted file - C:\Windows\SoftwareDistribution\Download\c1ea952b79f9a47af2b990798ec58958\cbshandler\state
Deleted file - C:\Windows\SoftwareDistribution\Download\d60b5d2a434ad7815d849c27d1b7610b\c569fe3c47c28d5f831cd0324367d4325f1fb95e
Deleted file - C:\Windows\SoftwareDistribution\SLS\2B81F1BF-356C-4FA1-90F1-7581A62C6764\sls.cab
Deleted file - C:\Windows\SoftwareDistribution\SLS\7971F918-A847-4430-9279-4A52D1EFE18D\sls.cab
Deleted file - C:\Windows\SoftwareDistribution\SLS\855E8A7C-ECB4-4CA3-B045-1DFA50104289\sls.cab
Deleted file - C:\Windows\SoftwareDistribution\SLS\8B24B027-1DEE-BABB-9A95-3517DFB9C552\sls.cab
Deleted file - C:\Windows\SoftwareDistribution\SLS\9482F4B4-E343-43B6-B170-9A65BC822C77\sls.cab
Deleted file - C:\Windows\SoftwareDistribution\SLS\E7A50285-D08D-499D-9FF8-180FDC2332BC\sls.cab

C:\Windows\system32>del /f /s /q %SystemRoot%\system32\catroot2\*.*
Deleted file - C:\Windows\system32\catroot2\dberr.txt
C:\Windows\system32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb
The process cannot access the file because it is being used by another process.
C:\Windows\system32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb.jfm
The process cannot access the file because it is being used by another process.
C:\Windows\system32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb
The process cannot access the file because it is being used by another process.
C:\Windows\system32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb.jfm
The process cannot access the file because it is being used by another process.

C:\Windows\system32>net start wuauserv
The requested service has already been started.

More help is available by typing NET HELPMSG 2182.


C:\Windows\system32>net start cryptSvc
The requested service has already been started.

More help is available by typing NET HELPMSG 2182.


C:\Windows\system32>net start bits
The Background Intelligent Transfer Service service is starting.
The Background Intelligent Transfer Service service was started successfully.


C:\Windows\system32>





=================
Manually stopped the services and re-ran the commands
=================


C:\Windows\system32>net stop wuauserv
The Windows Update service is not started.

More help is available by typing NET HELPMSG 3521.


C:\Windows\system32>net stop cryptSvc
The Cryptographic Services service is stopping..
The Cryptographic Services service was stopped successfully.


C:\Windows\system32>net stop bits
The Background Intelligent Transfer Service service is not started.

More help is available by typing NET HELPMSG 3521.


C:\Windows\system32>del /f /q "%ALLUSERSPROFILE%\Application Data\Microsoft\Network\Downloader\qmgr*.dat"
Could Not Find C:\ProgramData\Application Data\Microsoft\Network\Downloader\qmgr*.dat

C:\Windows\system32>del /f /s /q %SystemRoot%\SoftwareDistribution\*.*
Deleted file - C:\Windows\SoftwareDistribution\ReportingEvents.log
Deleted file - C:\Windows\SoftwareDistribution\DataStore\DataStore.edb
Deleted file - C:\Windows\SoftwareDistribution\DataStore\DataStore.jfm
Deleted file - C:\Windows\SoftwareDistribution\DataStore\Logs\edb.chk
Deleted file - C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log

C:\Windows\system32>del /f /s /q %SystemRoot%\system32\catroot2\*.*
Deleted file - C:\Windows\system32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb
Deleted file - C:\Windows\system32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb.jfm
Deleted file - C:\Windows\system32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb
Deleted file - C:\Windows\system32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb.jfm

C:\Windows\system32>net start wuauserv
The Windows Update service is starting.
The Windows Update service was started successfully.


C:\Windows\system32>net start cryptSvc
The Cryptographic Services service is starting.
The Cryptographic Services service was started successfully.


C:\Windows\system32>net start bits
The Background Intelligent Transfer Service service is starting.
The Background Intelligent Transfer Service service was started successfully.


============
I am not able to restart at the moment but did try windows update which displays updates with error 0x80248014 attached CBS and windowsupdate.log
 

Attachments

Was this server connected to an WSUS server?
Which security software is installed and other third party software like NetSkope?
 
Last edited:
Potentially in past it was connected to a WSUS server, we have a SCCM server but have never used it with our servers to my knowledge. In term of security products we rely on defender.
 
Hi,

Please run the following command in an elevated prompt and copy paste the result.
Code:
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols" /s
 
Thanks Maxstar, have a great weekend.

C:\Windows\system32>reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols" /s

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.0\Client
Enabled REG_DWORD 0x1
DisabledByDefault REG_DWORD 0x0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.0\Server
Enabled REG_DWORD 0x1
DisabledByDefault REG_DWORD 0x0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.1

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.1\Client
DisabledByDefault REG_DWORD 0x0
Enabled REG_DWORD 0x1

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.1\Server
Enabled REG_DWORD 0x1
DisabledByDefault REG_DWORD 0x0
 
We actually have a gpo setting these the opposite way round, this was implemented a year or so ago in response to a security audit. This gpo is disabled on the problem server and I manually set them to allow the weaker protocols.

1732892995107.webp
 
Yes the server is already excluded from the GPO. The GPO sets the settings as they are on the config above on the working server (second output, screenshot). The configuration from the broken server is set the opposite way to test if it made a difference.
 
That's fine and it seems there are some new errors this time. I will also take a look at them over the weekend as well..
 

Has Sysnative Forums helped you? Please consider donating to help us support the site!

Back
Top