[SOLVED] SFC and DISM issues on Server 2019

gchq

Well-known member
Joined
Dec 11, 2019
Posts
54
Background
Originally this box was running Server 2016 - at one point last year it BSOD after installing updates and rebooting. I got it running again using DISM /Remove-Package, but thereafter it would always BSOD after updates and either needed /Remove-Package or, in the case of items that could not be removed after installation, a complete restore. After that I stopped updating, and my brandy consumption went down!

Early this year I loaded everything onto different hardware (destined as a new mail server after fixing the problem child) and ran an in-place upgrade to Server 2019 with the existing one - once that was running and applying updates without any errors I just changed the name/IP back.

If you look at updates it happily states 'You're up to date' - but looking at the history there are 50 definition updates that up to date, but only 5 quality updates from 02 Feb 2019

I ran Dism /Online /Cleanup-Image /RestoreHealth

and that produced Error: 0x800f081f - source files

and running sfc /scannow found corrupt files it was unable to fix.

I do have the log files

Any idea what the next plan of attack might be?

Thanks
 
SFCFix Script

Warning: this fix is specific to the user in this thread. No one else should follow these instructions as it may cause more harm than good. If you are after assistance, please start a thread of your own.


  1. Download SFCFix.exe (by niemiro) and save this to your Desktop.
  2. Download the file below, SFCFix.zip, and save this to your Desktop. Ensure that this file is named SFCFix.zip - do not rename it.
  3. Save any open documents and close all open windows.
  4. On your Desktop, you should see two files: SFCFix.exe and SFCFix.zip.
  5. Drag the file SFCFix.zip onto the file SFCFix.exe and release it.
  6. SFCFix will now process the script.
  7. Upon completion, a file should be created on your Desktop: SFCFix.txt.
  8. Copy (Ctrl+C) and Paste (Ctrl+V) the contents of this file into your next post for me to analyse please - put [CODE][/CODE] tags around the log to break up the text.

Afterwards, run DISM again and attach CBS.log.
 

Attachments

Code:
SFCFix version 3.0.2.1 by niemiro.
Start time: 2019-12-11 21:02:17.498
Microsoft Windows Server 10 Build 17763 - amd64
Using .zip script file at C:\Downloads\SysNative\SFCFix.zip [0]


PowerCopy::
Successfully took permissions for file or folder C:\WINDOWS\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.1_none_d48944eff97b9138\Defender.psd1
Successfully took permissions for file or folder C:\WINDOWS\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.1_none_d48944eff97b9138\MSFT_MpComputerStatus.cdxml
Successfully took permissions for file or folder C:\WINDOWS\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.1_none_d48944eff97b9138\MSFT_MpPreference.cdxml
Successfully took permissions for file or folder C:\WINDOWS\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.1_none_d48944eff97b9138\MSFT_MpScan.cdxml
Successfully took permissions for file or folder C:\WINDOWS\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.1_none_d48944eff97b9138\MSFT_MpSignature.cdxml
Successfully took permissions for file or folder C:\WINDOWS\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.1_none_d48944eff97b9138\MSFT_MpThreat.cdxml
Successfully took permissions for file or folder C:\WINDOWS\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.1_none_d48944eff97b9138\MSFT_MpThreatCatalog.cdxml
Successfully took permissions for file or folder C:\WINDOWS\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.1_none_d48944eff97b9138\MSFT_MpThreatDetection.cdxml
Successfully took permissions for file or folder C:\WINDOWS\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.1_none_d48944eff97b9138\MSFT_MpWDOScan.cdxml
Successfully copied file C:\Users\Dave\AppData\Local\niemiro\Archive\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.1_none_d48944eff97b9138\Defender.psd1 to C:\WINDOWS\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.1_none_d48944eff97b9138\Defender.psd1.
Successfully copied file C:\Users\Dave\AppData\Local\niemiro\Archive\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.1_none_d48944eff97b9138\MSFT_MpComputerStatus.cdxml to C:\WINDOWS\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.1_none_d48944eff97b9138\MSFT_MpComputerStatus.cdxml.
Successfully copied file C:\Users\Dave\AppData\Local\niemiro\Archive\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.1_none_d48944eff97b9138\MSFT_MpPreference.cdxml to C:\WINDOWS\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.1_none_d48944eff97b9138\MSFT_MpPreference.cdxml.
Successfully copied file C:\Users\Dave\AppData\Local\niemiro\Archive\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.1_none_d48944eff97b9138\MSFT_MpScan.cdxml to C:\WINDOWS\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.1_none_d48944eff97b9138\MSFT_MpScan.cdxml.
Successfully copied file C:\Users\Dave\AppData\Local\niemiro\Archive\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.1_none_d48944eff97b9138\MSFT_MpSignature.cdxml to C:\WINDOWS\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.1_none_d48944eff97b9138\MSFT_MpSignature.cdxml.
Successfully copied file C:\Users\Dave\AppData\Local\niemiro\Archive\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.1_none_d48944eff97b9138\MSFT_MpThreat.cdxml to C:\WINDOWS\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.1_none_d48944eff97b9138\MSFT_MpThreat.cdxml.
Successfully copied file C:\Users\Dave\AppData\Local\niemiro\Archive\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.1_none_d48944eff97b9138\MSFT_MpThreatCatalog.cdxml to C:\WINDOWS\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.1_none_d48944eff97b9138\MSFT_MpThreatCatalog.cdxml.
Successfully copied file C:\Users\Dave\AppData\Local\niemiro\Archive\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.1_none_d48944eff97b9138\MSFT_MpThreatDetection.cdxml to C:\WINDOWS\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.1_none_d48944eff97b9138\MSFT_MpThreatDetection.cdxml.
Successfully copied file C:\Users\Dave\AppData\Local\niemiro\Archive\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.1_none_d48944eff97b9138\MSFT_MpWDOScan.cdxml to C:\WINDOWS\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.1_none_d48944eff97b9138\MSFT_MpWDOScan.cdxml.
Successfully restored ownership for C:\WINDOWS\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.1_none_d48944eff97b9138\Defender.psd1
Successfully restored permissions on C:\WINDOWS\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.1_none_d48944eff97b9138\Defender.psd1
Successfully restored ownership for C:\WINDOWS\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.1_none_d48944eff97b9138\MSFT_MpComputerStatus.cdxml
Successfully restored permissions on C:\WINDOWS\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.1_none_d48944eff97b9138\MSFT_MpComputerStatus.cdxml
Successfully restored ownership for C:\WINDOWS\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.1_none_d48944eff97b9138\MSFT_MpPreference.cdxml
Successfully restored permissions on C:\WINDOWS\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.1_none_d48944eff97b9138\MSFT_MpPreference.cdxml
Successfully restored ownership for C:\WINDOWS\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.1_none_d48944eff97b9138\MSFT_MpScan.cdxml
Successfully restored permissions on C:\WINDOWS\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.1_none_d48944eff97b9138\MSFT_MpScan.cdxml
Successfully restored ownership for C:\WINDOWS\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.1_none_d48944eff97b9138\MSFT_MpSignature.cdxml
Successfully restored permissions on C:\WINDOWS\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.1_none_d48944eff97b9138\MSFT_MpSignature.cdxml
Successfully restored ownership for C:\WINDOWS\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.1_none_d48944eff97b9138\MSFT_MpThreat.cdxml
Successfully restored permissions on C:\WINDOWS\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.1_none_d48944eff97b9138\MSFT_MpThreat.cdxml
Successfully restored ownership for C:\WINDOWS\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.1_none_d48944eff97b9138\MSFT_MpThreatCatalog.cdxml
Successfully restored permissions on C:\WINDOWS\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.1_none_d48944eff97b9138\MSFT_MpThreatCatalog.cdxml
Successfully restored ownership for C:\WINDOWS\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.1_none_d48944eff97b9138\MSFT_MpThreatDetection.cdxml
Successfully restored permissions on C:\WINDOWS\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.1_none_d48944eff97b9138\MSFT_MpThreatDetection.cdxml
Successfully restored ownership for C:\WINDOWS\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.1_none_d48944eff97b9138\MSFT_MpWDOScan.cdxml
Successfully restored permissions on C:\WINDOWS\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.1_none_d48944eff97b9138\MSFT_MpWDOScan.cdxml
PowerCopy:: directive completed successfully.


Successfully processed all directives.

Failed to generate a complete zip file. Upload aborted.

SFCFix version 3.0.2.1 by niemiro has completed.
Currently storing 9 datablocks.
Finish time: 2019-12-11 21:04:50.395
Script hash: 0ml7SvmOVG7KO0KzmRNDDjO1fr6Wb3UUcJIMavXQ0wY=
----------------------EOF-----------------------
 
SFCFix Script

Warning: this fix is specific to the user in this thread. No one else should follow these instructions as it may cause more harm than good. If you are after assistance, please start a thread of your own.


  1. Download SFCFix.exe (by niemiro) and save this to your Desktop.
  2. Download the file below, SFCFix.zip, and save this to your Desktop. Ensure that this file is named SFCFix.zip - do not rename it.
  3. Save any open documents and close all open windows.
  4. On your Desktop, you should see two files: SFCFix.exe and SFCFix.zip.
  5. Drag the file SFCFix.zip onto the file SFCFix.exe and release it.
  6. SFCFix will now process the script.
  7. Upon completion, a file should be created on your Desktop: SFCFix.txt.
  8. Copy (Ctrl+C) and Paste (Ctrl+V) the contents of this file into your next post for me to analyse please - put [CODE][/CODE] tags around the log to break up the text.



SFC Scan


  1. Click on the Start button and in the search box, type Command Prompt
  2. When you see Command Prompt on the list, right-click on it and select Run as administrator
  3. When command prompt opens, copy and paste the following commands into it, press enter after each

    sfc /scannow


    Wait for this to finish before you continue

    copy %windir%\logs\cbs\cbs.log "%userprofile%\Desktop\cbs.txt"
  4. This will create a file, cbs.txt on your Desktop. Please attach this to your next post.
 

Attachments

Code:
SFCFix version 3.0.2.1 by niemiro.
Start time: 2019-12-11 22:53:24.484
Microsoft Windows Server 10 Build 17763 - amd64
Using .zip script file at C:\Downloads\SysNative\2\SFCFix.zip [0]


PowerCopy::
Successfully took permissions for file or folder C:\WINDOWS\WinSxS\x86_microsoft-windows-p..inscripts.resources_31bf3856ad364e35_10.0.17763.107_en-us_27848dcd197a9515\prncnfg.vbs
Successfully took permissions for file or folder C:\WINDOWS\WinSxS\x86_microsoft-windows-p..inscripts.resources_31bf3856ad364e35_10.0.17763.107_en-us_27848dcd197a9515\prndrvr.vbs
Successfully took permissions for file or folder C:\WINDOWS\WinSxS\x86_microsoft-windows-p..inscripts.resources_31bf3856ad364e35_10.0.17763.107_en-us_27848dcd197a9515\prnjobs.vbs
Successfully took permissions for file or folder C:\WINDOWS\WinSxS\x86_microsoft-windows-p..inscripts.resources_31bf3856ad364e35_10.0.17763.107_en-us_27848dcd197a9515\prnmngr.vbs
Successfully took permissions for file or folder C:\WINDOWS\WinSxS\x86_microsoft-windows-p..inscripts.resources_31bf3856ad364e35_10.0.17763.107_en-us_27848dcd197a9515\prnport.vbs
Successfully took permissions for file or folder C:\WINDOWS\WinSxS\x86_microsoft-windows-p..inscripts.resources_31bf3856ad364e35_10.0.17763.107_en-us_27848dcd197a9515\prnqctl.vbs
Successfully took permissions for file or folder C:\WINDOWS\WinSxS\x86_microsoft-windows-p..inscripts.resources_31bf3856ad364e35_10.0.17763.107_en-us_27848dcd197a9515\pubprn.vbs
Successfully copied file C:\Users\Dave\AppData\Local\niemiro\Archive\WinSxS\x86_microsoft-windows-p..inscripts.resources_31bf3856ad364e35_10.0.17763.107_en-us_27848dcd197a9515\prncnfg.vbs to C:\WINDOWS\WinSxS\x86_microsoft-windows-p..inscripts.resources_31bf3856ad364e35_10.0.17763.107_en-us_27848dcd197a9515\prncnfg.vbs.
Successfully copied file C:\Users\Dave\AppData\Local\niemiro\Archive\WinSxS\x86_microsoft-windows-p..inscripts.resources_31bf3856ad364e35_10.0.17763.107_en-us_27848dcd197a9515\prndrvr.vbs to C:\WINDOWS\WinSxS\x86_microsoft-windows-p..inscripts.resources_31bf3856ad364e35_10.0.17763.107_en-us_27848dcd197a9515\prndrvr.vbs.
Successfully copied file C:\Users\Dave\AppData\Local\niemiro\Archive\WinSxS\x86_microsoft-windows-p..inscripts.resources_31bf3856ad364e35_10.0.17763.107_en-us_27848dcd197a9515\prnjobs.vbs to C:\WINDOWS\WinSxS\x86_microsoft-windows-p..inscripts.resources_31bf3856ad364e35_10.0.17763.107_en-us_27848dcd197a9515\prnjobs.vbs.
Successfully copied file C:\Users\Dave\AppData\Local\niemiro\Archive\WinSxS\x86_microsoft-windows-p..inscripts.resources_31bf3856ad364e35_10.0.17763.107_en-us_27848dcd197a9515\prnmngr.vbs to C:\WINDOWS\WinSxS\x86_microsoft-windows-p..inscripts.resources_31bf3856ad364e35_10.0.17763.107_en-us_27848dcd197a9515\prnmngr.vbs.
Successfully copied file C:\Users\Dave\AppData\Local\niemiro\Archive\WinSxS\x86_microsoft-windows-p..inscripts.resources_31bf3856ad364e35_10.0.17763.107_en-us_27848dcd197a9515\prnport.vbs to C:\WINDOWS\WinSxS\x86_microsoft-windows-p..inscripts.resources_31bf3856ad364e35_10.0.17763.107_en-us_27848dcd197a9515\prnport.vbs.
Successfully copied file C:\Users\Dave\AppData\Local\niemiro\Archive\WinSxS\x86_microsoft-windows-p..inscripts.resources_31bf3856ad364e35_10.0.17763.107_en-us_27848dcd197a9515\prnqctl.vbs to C:\WINDOWS\WinSxS\x86_microsoft-windows-p..inscripts.resources_31bf3856ad364e35_10.0.17763.107_en-us_27848dcd197a9515\prnqctl.vbs.
Successfully copied file C:\Users\Dave\AppData\Local\niemiro\Archive\WinSxS\x86_microsoft-windows-p..inscripts.resources_31bf3856ad364e35_10.0.17763.107_en-us_27848dcd197a9515\pubprn.vbs to C:\WINDOWS\WinSxS\x86_microsoft-windows-p..inscripts.resources_31bf3856ad364e35_10.0.17763.107_en-us_27848dcd197a9515\pubprn.vbs.
Successfully restored ownership for C:\WINDOWS\WinSxS\x86_microsoft-windows-p..inscripts.resources_31bf3856ad364e35_10.0.17763.107_en-us_27848dcd197a9515\prncnfg.vbs
Successfully restored permissions on C:\WINDOWS\WinSxS\x86_microsoft-windows-p..inscripts.resources_31bf3856ad364e35_10.0.17763.107_en-us_27848dcd197a9515\prncnfg.vbs
Successfully restored ownership for C:\WINDOWS\WinSxS\x86_microsoft-windows-p..inscripts.resources_31bf3856ad364e35_10.0.17763.107_en-us_27848dcd197a9515\prndrvr.vbs
Successfully restored permissions on C:\WINDOWS\WinSxS\x86_microsoft-windows-p..inscripts.resources_31bf3856ad364e35_10.0.17763.107_en-us_27848dcd197a9515\prndrvr.vbs
Successfully restored ownership for C:\WINDOWS\WinSxS\x86_microsoft-windows-p..inscripts.resources_31bf3856ad364e35_10.0.17763.107_en-us_27848dcd197a9515\prnjobs.vbs
Successfully restored permissions on C:\WINDOWS\WinSxS\x86_microsoft-windows-p..inscripts.resources_31bf3856ad364e35_10.0.17763.107_en-us_27848dcd197a9515\prnjobs.vbs
Successfully restored ownership for C:\WINDOWS\WinSxS\x86_microsoft-windows-p..inscripts.resources_31bf3856ad364e35_10.0.17763.107_en-us_27848dcd197a9515\prnmngr.vbs
Successfully restored permissions on C:\WINDOWS\WinSxS\x86_microsoft-windows-p..inscripts.resources_31bf3856ad364e35_10.0.17763.107_en-us_27848dcd197a9515\prnmngr.vbs
Successfully restored ownership for C:\WINDOWS\WinSxS\x86_microsoft-windows-p..inscripts.resources_31bf3856ad364e35_10.0.17763.107_en-us_27848dcd197a9515\prnport.vbs
Successfully restored permissions on C:\WINDOWS\WinSxS\x86_microsoft-windows-p..inscripts.resources_31bf3856ad364e35_10.0.17763.107_en-us_27848dcd197a9515\prnport.vbs
Successfully restored ownership for C:\WINDOWS\WinSxS\x86_microsoft-windows-p..inscripts.resources_31bf3856ad364e35_10.0.17763.107_en-us_27848dcd197a9515\prnqctl.vbs
Successfully restored permissions on C:\WINDOWS\WinSxS\x86_microsoft-windows-p..inscripts.resources_31bf3856ad364e35_10.0.17763.107_en-us_27848dcd197a9515\prnqctl.vbs
Successfully restored ownership for C:\WINDOWS\WinSxS\x86_microsoft-windows-p..inscripts.resources_31bf3856ad364e35_10.0.17763.107_en-us_27848dcd197a9515\pubprn.vbs
Successfully restored permissions on C:\WINDOWS\WinSxS\x86_microsoft-windows-p..inscripts.resources_31bf3856ad364e35_10.0.17763.107_en-us_27848dcd197a9515\pubprn.vbs
PowerCopy:: directive completed successfully.


Successfully processed all directives.
SFCFix version 3.0.2.1 by niemiro has completed.
Currently storing 16 datablocks.
Finish time: 2019-12-11 22:53:26.312
Script hash: ppnH72yurXAr/2r3skdRzeLo9z6X+P1hCnY3UBDIrJs=
----------------------EOF----------
 
Please run SFC Scan twice.

If it still reports that it repaired something, please do the following:

Retrieve Components Hive
1. Navigate to C:\Windows\System32\Config and locate the COMPONENTS file.
2. Please copy this file to your desktop.
Note: If you receive an error that this file is in-use, simply reboot your computer and try again.
3. Right-click on this file on your desktop and select Send To...Compressed (zipped) folder. This will create a file named COMPONENTS.ZIP on your desktop.
4. The file will likely be too large to upload here so please upload to a file sharing service. Examples of services to upload to are Dropbox or OneDrive or SendSpace and then just provide the link in your reply.
 
SFC_image3.png

Components is too large - I will place on one of our servers and PM you a link
 

Attachments

Thank you for your PM. I got the link.


Step#1 - FRST Fix
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
1. Please download Farbar Recovery Scan Tool and save it to your Desktop.
Note: You need to run the 64-bit Version so please ensure you download that one.
2. Download the attached fixlist.txt and save it to the Desktop.
Note. It's important that both files, FRST64 and fixlist.txt are in the same location or the fix will not work (in this case...the desktop).
3. Run FRST64 by Right-Clicking on the file and choosing Run as administrator.
4. Press the Fix button just once and wait. If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
5. When finished FRST64 will generate a log on the Desktop (Fixlog.txt). Please post the contents of it in your reply.
 

Attachments

AVs in general don't like it as it was developed to remove and detect malware, so it employs some mechanisms that are similar to those used by malware processes, thus triggering the alerts.

Reboot and run another SFC Scan please.
 

Has Sysnative Forums helped you? Please consider donating to help us support the site!

Back
Top