Hello Everyone,
we have problems with cumulative server updates.
2019-11 can't pass, on few we have 2019-10 as last cumulative, and on few we dont have even that.
When it comes to 90-95% there is error and roll back updates "We couldn't complete the updates. Undoing changes. Don't turn off your computer"
C:\Windows\system32>sfc /scannow
Beginning system scan. This process will take some time.
Beginning verification phase of system scan.
Verification 100% complete.
Windows Resource Protection did not find any integrity violations.
Code:
SFCFix version 3.0.2.1 by niemiro.
Start time: 2019-11-18 12:44:30.819
Microsoft Windows Server 10 Build 17763 - amd64
Using .zip script file at C:\Users\goran\Desktop\SFCFix.zip [0]
PowerCopy::
Successfully took permissions for file or folder C:\Windows\WinSxS
Successfully created directory tree \\?\C:\Windows\WinSxS\amd64_microsoft-windows-crypt32-dll_31bf3856ad364e35_10.0.18362.1_none_2dcd31d75b0c35ba.
Successfully copied file C:\Users\goran\AppData\Local\niemiro\Archive\WinSxS\amd64_microsoft-windows-crypt32-dll_31bf3856ad364e35_10.0.18362.1_none_2dcd31d75b0c35ba\crypt32.dll to C:\Windows\WinSxS\amd64_microsoft-windows-crypt32-dll_31bf3856ad364e35_10.0.18362.1_none_2dcd31d75b0c35ba\crypt32.dll.
Successfully copied file C:\Users\goran\AppData\Local\niemiro\Archive\WinSxS\amd64_microsoft-windows-crypt32-dll_31bf3856ad364e35_10.0.18362.1_none_2dcd31d75b0c35ba\crypt32.dll.mun to C:\Windows\WinSxS\amd64_microsoft-windows-crypt32-dll_31bf3856ad364e35_10.0.18362.1_none_2dcd31d75b0c35ba\crypt32.dll.mun.
Successfully restored ownership for C:\Windows\WinSxS
Successfully restored permissions on C:\Windows\WinSxS
PowerCopy:: directive completed successfully.
Successfully processed all directives.
SFCFix version 3.0.2.1 by niemiro has completed.
Currently storing 1 datablocks.
Finish time: 2019-11-18 12:44:33.429
Script hash: qIvoTH2trEPBIgxBKjByO8jyzKu0/qjWI6U6KLqQJjU=
----------------------EOF-----------------------
Can you also provide the following for diagnostic purposes:
Step#1 - FRST Scan
1. Please download Farbar Recovery Scan Tool and save it to your Desktop. Note: You need to run the 64-bit Version so please ensure you download that one.
2. Right-click FRST64.exe and click Run as Administrator to run it as administrator. When the tool opens, click Yes to disclaimer.
3. Please ensure you place a check mark in the Addition.txt check box at the bottom of the form before running (if not already checked).
4. Press Scan button.
5. It will produce a log called FRST.txt in the same directory the tool is run from (which should now be the desktop)
6. Please attach the log back here.
7. Another log (Addition.txt - also located in the same directory as FRST64.exe) will be generated Please also attach that along with the FRST.txt in your reply.
Warning: this fix is specific to the user in this thread. No one else should follow these instructions as it may cause more harm than good. If you are after assistance, please start a thread of your own.
Download SFCFix.exe (by niemiro) and save this to your Desktop.
Download the file below, SFCFix.zip, and save this to your Desktop. Ensure that this file is named SFCFix.zip - do not rename it.
Save any open documents and close all open windows.
On your Desktop, you should see two files: SFCFix.exe and SFCFix.zip.
Drag the file SFCFix.zip onto the file SFCFix.exe and release it.
SFCFix will now process the script.
Upon completion, a file should be created on your Desktop: SFCFix.txt.
Copy (Ctrl+C) and Paste (Ctrl+V) the contents of this file into your next post for me to analyse please - put [CODE][/CODE] tags around the log to break up the text.
Hello sorry for delay.
We had issue with wsus so, when we enabled updates, first one was 2019-11 and backward. I dont see that update on the list of the installed updates.
I will send you in private message FRST.txt and Addition.txt as there is a lot of information regarding servers and domains.
SFCFix.txt
Code:
SFCFix version 3.0.2.1 by niemiro.
Start time: 2019-11-18 21:41:31.482
Microsoft Windows Server 10 Build 17763 - amd64
Using .zip script file at C:\Users\goran\Desktop\SFCFix.zip [0]
PowerCopy::
Successfully took permissions for file or folder C:\Windows\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.831_none_5892c02f26f780e5\Defender.psd1
Successfully took permissions for file or folder C:\Windows\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.831_none_5892c02f26f780e5\MSFT_MpComputerStatus.cdxml
Successfully took permissions for file or folder C:\Windows\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.831_none_5892c02f26f780e5\MSFT_MpPreference.cdxml
Successfully took permissions for file or folder C:\Windows\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.831_none_5892c02f26f780e5\MSFT_MpScan.cdxml
Successfully took permissions for file or folder C:\Windows\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.831_none_5892c02f26f780e5\MSFT_MpSignature.cdxml
Successfully took permissions for file or folder C:\Windows\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.831_none_5892c02f26f780e5\MSFT_MpThreat.cdxml
Successfully took permissions for file or folder C:\Windows\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.831_none_5892c02f26f780e5\MSFT_MpThreatCatalog.cdxml
Successfully took permissions for file or folder C:\Windows\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.831_none_5892c02f26f780e5\MSFT_MpThreatDetection.cdxml
Successfully took permissions for file or folder C:\Windows\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.831_none_5892c02f26f780e5\MSFT_MpWDOScan.cdxml
Successfully copied file C:\Users\goran\AppData\Local\niemiro\Archive\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.831_none_5892c02f26f780e5\Defender.psd1 to C:\Windows\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.831_none_5892c02f26f780e5\Defender.psd1.
Successfully copied file C:\Users\goran\AppData\Local\niemiro\Archive\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.831_none_5892c02f26f780e5\MSFT_MpComputerStatus.cdxml to C:\Windows\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.831_none_5892c02f26f780e5\MSFT_MpComputerStatus.cdxml.
Successfully copied file C:\Users\goran\AppData\Local\niemiro\Archive\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.831_none_5892c02f26f780e5\MSFT_MpPreference.cdxml to C:\Windows\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.831_none_5892c02f26f780e5\MSFT_MpPreference.cdxml.
Successfully copied file C:\Users\goran\AppData\Local\niemiro\Archive\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.831_none_5892c02f26f780e5\MSFT_MpScan.cdxml to C:\Windows\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.831_none_5892c02f26f780e5\MSFT_MpScan.cdxml.
Successfully copied file C:\Users\goran\AppData\Local\niemiro\Archive\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.831_none_5892c02f26f780e5\MSFT_MpSignature.cdxml to C:\Windows\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.831_none_5892c02f26f780e5\MSFT_MpSignature.cdxml.
Successfully copied file C:\Users\goran\AppData\Local\niemiro\Archive\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.831_none_5892c02f26f780e5\MSFT_MpThreat.cdxml to C:\Windows\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.831_none_5892c02f26f780e5\MSFT_MpThreat.cdxml.
Successfully copied file C:\Users\goran\AppData\Local\niemiro\Archive\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.831_none_5892c02f26f780e5\MSFT_MpThreatCatalog.cdxml to C:\Windows\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.831_none_5892c02f26f780e5\MSFT_MpThreatCatalog.cdxml.
Successfully copied file C:\Users\goran\AppData\Local\niemiro\Archive\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.831_none_5892c02f26f780e5\MSFT_MpThreatDetection.cdxml to C:\Windows\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.831_none_5892c02f26f780e5\MSFT_MpThreatDetection.cdxml.
Successfully copied file C:\Users\goran\AppData\Local\niemiro\Archive\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.831_none_5892c02f26f780e5\MSFT_MpWDOScan.cdxml to C:\Windows\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.831_none_5892c02f26f780e5\MSFT_MpWDOScan.cdxml.
Successfully restored ownership for C:\Windows\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.831_none_5892c02f26f780e5\Defender.psd1
Successfully restored permissions on C:\Windows\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.831_none_5892c02f26f780e5\Defender.psd1
Successfully restored ownership for C:\Windows\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.831_none_5892c02f26f780e5\MSFT_MpComputerStatus.cdxml
Successfully restored permissions on C:\Windows\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.831_none_5892c02f26f780e5\MSFT_MpComputerStatus.cdxml
Successfully restored ownership for C:\Windows\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.831_none_5892c02f26f780e5\MSFT_MpPreference.cdxml
Successfully restored permissions on C:\Windows\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.831_none_5892c02f26f780e5\MSFT_MpPreference.cdxml
Successfully restored ownership for C:\Windows\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.831_none_5892c02f26f780e5\MSFT_MpScan.cdxml
Successfully restored permissions on C:\Windows\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.831_none_5892c02f26f780e5\MSFT_MpScan.cdxml
Successfully restored ownership for C:\Windows\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.831_none_5892c02f26f780e5\MSFT_MpSignature.cdxml
Successfully restored permissions on C:\Windows\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.831_none_5892c02f26f780e5\MSFT_MpSignature.cdxml
Successfully restored ownership for C:\Windows\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.831_none_5892c02f26f780e5\MSFT_MpThreat.cdxml
Successfully restored permissions on C:\Windows\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.831_none_5892c02f26f780e5\MSFT_MpThreat.cdxml
Successfully restored ownership for C:\Windows\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.831_none_5892c02f26f780e5\MSFT_MpThreatCatalog.cdxml
Successfully restored permissions on C:\Windows\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.831_none_5892c02f26f780e5\MSFT_MpThreatCatalog.cdxml
Successfully restored ownership for C:\Windows\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.831_none_5892c02f26f780e5\MSFT_MpThreatDetection.cdxml
Successfully restored permissions on C:\Windows\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.831_none_5892c02f26f780e5\MSFT_MpThreatDetection.cdxml
Successfully restored ownership for C:\Windows\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.831_none_5892c02f26f780e5\MSFT_MpWDOScan.cdxml
Successfully restored permissions on C:\Windows\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.831_none_5892c02f26f780e5\MSFT_MpWDOScan.cdxml
PowerCopy:: directive completed successfully.
Successfully processed all directives.
SFCFix version 3.0.2.1 by niemiro has completed.
Currently storing 10 datablocks.
Finish time: 2019-11-18 21:41:32.263
Script hash: 5ow7kUSzpyZr9Dx1I9MOtKtDRohAOA1MJwIf4Birxv4=
----------------------EOF-----------------------
While I inspect the logs, please do the following to confirm that the corrupt files have been repaired:
Step#1 - DISM /RestoreHealth Scan Warning:this fix is specific to the user in this thread. No one else should follow these instructions as it may cause more harm than good. If you are after assistance, please start a thread of your own.
Right-click on the Start button and select Command Prompt (Admin)
When command prompt opens, Copy (Ctrl+C) and Paste (Right-click > Paste) the following command into it, then press Enter Dism /Online /Cleanup-Image /RestoreHealth
Once it finishes, copy and paste the following into the command-prompt window and press Enter. If prompted to overwrite the existing file go ahead. copy %windir%\logs\cbs\cbs.log "%userprofile%\Desktop\cbs.txt"
Once this has completed please go to your Desktop and you will find CBS.txt => Please zip/upload to this thread. Please Note:: if the file is too big (over 7MB) to upload to your next post, please upload via a service such as Dropbox or One Drive or SendSpace and just provide the link.
Could we try disabling them one by one as a test at some point to test. I'm suspecting that one of them is causing the issues. If you'd like more evidence or for me to solidify my claims, let me know and we can inspect more logs prior to doing this.