question

VCIAMSA-9655 avatar image
0 Votes"
VCIAMSA-9655 asked ·

Windows 2016 windows update error 0x80070006 on several servers

I'm receiving this error on several servers on my network.
There is no WSUS set.
I've executed the attached script on all servers without any results. The error persists.
Here is the tail of the windowsupdatelog from one of my server:


2021/03/09 08:02:06.6305940 4120 2416 ComApi START Init Search ClientId = NULL
2021/03/09 08:02:06.6305985 4120 2416 ComApi START Search ClientId = NULL
2021/03/09 08:02:06.9424559 17636 5732 Agent START Queueing Finding updates [CallerId = <<PROCESS>>: wsmprovhost.exe Id = 1]
2021/03/09 08:02:06.9424629 17636 5732 Agent Added service 00000000-0000-0000-0000-000000000000 to sequential scan list
2021/03/09 08:02:06.9428979 4120 2416 ComApi Search ClientId = NULL
2021/03/09 08:02:06.9473042 17636 22696 Agent END Queueing Finding updates [CallerId = <<PROCESS>>: wsmprovhost.exe Id = 1]
2021/03/09 08:02:06.9522013 17636 22696 Agent START Finding updates CallerId = <<PROCESS>>: wsmprovhost.exe Id = 1
2021/03/09 08:02:06.9522032 17636 22696 Agent Online = Yes; AllowCachedResults = No; Ignore download priority = No
2021/03/09 08:02:06.9522045 17636 22696 Agent Criteria = Type='Software'""
2021/03/09 08:02:06.9522083 17636 22696 Agent ServiceID = {00000000-0000-0000-0000-000000000000} Third party service
2021/03/09 08:02:06.9522090 17636 22696 Agent Search Scope = {Machine}
2021/03/09 08:02:06.9522147 17636 22696 Agent Caller SID for Applicability: S-1-5-21-2718076-3659178023-1883436687-500
2021/03/09 08:02:06.9522160 17636 22696 Agent RegisterService is set
2021/03/09 08:02:06.9632579 17636 22696 Misc Got 9482F4B4-E343-43B6-B170-9A65BC822C77 redir SecondaryServiceAuth URL: 117cab2d-82b1-4b5a-a08c-4d62dbee7782""
2021/03/09 08:02:06.9650354 17636 22696 SLS CoCreateInstance Failed: hr = 0x80040154
2021/03/09 08:02:06.9650393 17636 22696 Agent Failed to retrieve SLS response data for service 117cab2d-82b1-4b5a-a08c-4d62dbee7782, error = 0x80040154
2021/03/09 08:02:06.9650444 17636 22696 Agent Caller Service Recovery failed to opt in to service 117cab2d-82b1-4b5a-a08c-4d62dbee7782, hr=0X80040154
2021/03/09 08:02:06.9695816 17636 22696 Misc Got 9482F4B4-E343-43B6-B170-9A65BC822C77 redir Client/Server URL: https://fe2.update.microsoft.com/v6/ClientWebService/client.asmx""
2021/03/09 08:02:07.3894563 17636 22696 ProtocolTalker ServiceId = {9482F4B4-E343-43B6-B170-9A65BC822C77}, Server URL = https://fe2.update.microsoft.com/v6/ClientWebService/client.asmx
2021/03/09 08:02:07.3894710 17636 22696 Misc Failed to get proxy settings token, not impersonating user. hr=800703f0
2021/03/09 08:02:07.3894813 17636 22696 ProtocolTalker OK to reuse existing configuration
2021/03/09 08:02:07.3894858 17636 22696 ProtocolTalker Existing cookie is valid, just use it
2021/03/09 08:02:08.4933655 17636 22696 WebServices Auto proxy settings for this web service call.
2021/03/09 08:02:09.0707113 17636 22696 ProtocolTalker PTInfo: syncing with server using normal query
2021/03/09 08:02:09.3783349 17636 22696 ProtocolTalker SyncUpdates round trips: 2
2021/03/09 08:02:20.3352568 17636 22696 Agent Added update BE7A2C76-FA29-49C8-8AA8-2C0D4D6D6D00.201 to search result
2021/03/09 08:02:20.3352619 17636 22696 Agent Update D2DA3EF9-502F-4C4C-B0A4-F3ECEE3792A8.201 is pruned out due to potential supersedence
2021/03/09 08:02:20.3352658 17636 22696 Agent Update 260ABDF7-BA14-4DE7-A744-78BF0F8490DF.200 is pruned out due to potential supersedence
2021/03/09 08:02:20.3352690 17636 22696 Agent Update 67EAB6A6-099B-42C5-86CE-63681F58EBD2.200 is pruned out due to potential supersedence
2021/03/09 08:02:20.3352722 17636 22696 Agent Update 6DFD8427-7F58-4BCA-B6AF-F3A334233F36.200 is pruned out due to potential supersedence
2021/03/09 08:02:20.3352767 17636 22696 Agent Added update 8A0B74E5-7A74-4095-91A8-F445032477ED.200 to search result
2021/03/09 08:02:20.3352811 17636 22696 Agent Added update D8A0FEE3-4158-43FF-AFC2-C937FAA84A98.200 to search result
2021/03/09 08:02:20.3352863 17636 22696 Agent Added update 7FC75501-1B97-4DF1-932E-55C7451A14AA.200 to search result
2021/03/09 08:02:20.3352901 17636 22696 Agent Added update 99E788AD-3A4D-4D49-A4D5-802BFA4B593C.201 to search result
2021/03/09 08:02:20.3376482 17636 22696 Agent Found 5 updates and 22 categories in search; evaluated appl. rules of 651 out of 930 deployed entities
2021/03/09 08:02:20.3992171 17636 22696 Agent END Finding updates CallerId = <<PROCESS>>: wsmprovhost.exe Id = 1
2021/03/09 08:02:20.4125516 4120 12888 ComApi RESUMED Search ClientId = NULL
2021/03/09 08:02:20.9655601 4120 12888 ComApi Updates found = 5
2021/03/09 08:02:20.9655614 4120 12888 ComApi END Search ClientId = NULL
2021/03/09 08:02:20.9670676 4120 2416 ComApi ISusInternal:: DisconnectCall failed, hr=8024000C
2021/03/09 08:12:22.2919978 17636 6824 Agent Earliest future timer found:
2021/03/09 08:12:22.2920266 17636 6824 Agent Timer: 29A863E7-8609-4D1E-B7CD-5668F857F1DB, Expires 2021-03-09 15:36:15, not idle-only, not network-only
2021/03/09 08:12:23.2930382 17636 18480 Agent Earliest future timer found:
2021/03/09 08:12:23.2930543 17636 18480 Agent Timer: 29A863E7-8609-4D1E-B7CD-5668F857F1DB, Expires 2021-03-09 15:36:15, not idle-only, not network-only
2021/03/09 08:12:23.3206117 17636 18480 Misc CreateSessionStateChangeTrigger, TYPE:2, Enable:No
2021/03/09 08:12:23.3206175 17636 18480 Misc CreateSessionStateChangeTrigger, TYPE:4, Enable:No
2021/03/09 08:12:23.3473391 17636 18480 Handler CUHCbsHandler::CancelDownloadRequest called
2021/03/09 08:12:24.4640017 17636 18480 Shared END Service exit Exit code = 0x240001
2021/03/09 08:29:29.9631167 25684 26420 Agent WU client version 10.0.14393.4104
2021/03/09 08:29:29.9635683 25684 26420 Agent SleepStudyTracker: Machine is non-AOAC. Sleep study tracker disabled.
2021/03/09 08:29:29.9637409 25684 26420 Agent Base directory: C:\Windows\SoftwareDistribution
2021/03/09 08:29:29.9646075 25684 26420 Agent Datastore directory: C:\Windows\SoftwareDistribution\DataStore\DataStore.edb
2021/03/09 08:29:30.0663261 25684 26420 Shared UpdateNetworkState Ipv6, cNetworkInterfaces = 1.
2021/03/09 08:29:30.0666244 25684 26420 Shared UpdateNetworkState Ipv4, cNetworkInterfaces = 1.
2021/03/09 08:29:30.0687368 25684 26420 Shared Network state: Connected
2021/03/09 08:29:30.0902939 25684 26420 Misc LoadHistoryEventFromRegistry completed, hr = 8024000C
2021/03/09 08:29:30.0933704 25684 26420 Shared UpdateNetworkState Ipv6, cNetworkInterfaces = 1.
2021/03/09 08:29:30.0933807 25684 26420 Shared UpdateNetworkState Ipv4, cNetworkInterfaces = 1.
2021/03/09 08:29:30.0933903 25684 26420 Shared Power status changed
2021/03/09 08:29:30.0998096 25684 26420 Agent Timer: 29A863E7-8609-4D1E-B7CD-5668F857F1DB, Expires 2021-03-09 15:36:15, not idle-only, not network-only
2021/03/09 08:29:30.1071482 25684 5784 Agent Initializing global settings cache
2021/03/09 08:29:30.1071494 25684 5784 Agent WSUS server: NULL
2021/03/09 08:29:30.1071501 25684 5784 Agent WSUS status server: NULL
2021/03/09 08:29:30.1071507 25684 5784 Agent Alternate Download Server: NULL
2021/03/09 08:29:30.1071507 25684 5784 Agent Fill Empty Content Urls: No
2021/03/09 08:29:30.1071514 25684 5784 Agent Target group: (Unassigned Computers)
2021/03/09 08:29:30.1071520 25684 5784 Agent Windows Update access disabled: No
2021/03/09 08:29:30.1416522 25684 26420 Agent Initializing Windows Update Agent
2021/03/09 08:29:30.1449905 25684 26420 DownloadManager Download manager restoring 0 downloads
2021/03/09 08:29:30.1490273 25684 26420 Agent CPersistentTimeoutScheduler | GetTimer, returned hr = 0x00000000
2021/03/09 08:29:30.1796415 25684 20448 Shared Effective power state: AC
2021/03/09 08:29:30.1796434 25684 20448 DownloadManager Power state change detected. Source now: AC
2021/03/09 08:40:35.6157739 25684 4540 Agent Earliest future timer found:
2021/03/09 08:40:35.6158168 25684 4540 Agent Timer: 29A863E7-8609-4D1E-B7CD-5668F857F1DB, Expires 2021-03-09 15:36:15, not idle-only, not network-only
2021/03/09 08:40:36.6175591 25684 26420 Agent Earliest future timer found:
2021/03/09 08:40:36.6175771 25684 26420 Agent Timer: 29A863E7-8609-4D1E-B7CD-5668F857F1DB, Expires 2021-03-09 15:36:15, not idle-only, not network-only
2021/03/09 08:40:36.6503369 25684 26420 Misc CreateSessionStateChangeTrigger, TYPE:2, Enable:No
2021/03/09 08:40:36.6503433 25684 26420 Misc CreateSessionStateChangeTrigger, TYPE:4, Enable:No
2021/03/09 08:40:36.6612665 25684 26420 Handler CUHCbsHandler::CancelDownloadRequest called
2021/03/09 08:40:37.8162962 25684 26420 Shared END Service exit Exit code = 0x240001


75735-windowupdatereset.txt



When I run the script and restart the server, on windows update I read 'Latest update check on 04 january 2021". On all server ther eis the same date.

Thanks

windows-10-generalwindows-serverwindows-server-update-services
10 |1000 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

VCIAMSA-9655 avatar image
0 Votes"
VCIAMSA-9655 answered ·

After some reasearch I've found that is Kaspersky Endpoint Security for Windows Server 11 that is causing this behaviour. Simply disabling the protection does not fix. I have uninstalled the application and now all the updates has been downloaded and installed.
I've open a ticket wirth Kaspersky support to understand better and solve the problem.

·
10 |1000 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

JennyFeng-MSFT avatar image
1 Vote"
JennyFeng-MSFT answered ·

@VCIAMSA-9655
Hi,

The following are some basic troubleshooting suggestions for reference:
https://www.earthslab.com/computer-science/windows-update-error-code-0x80070006/#:~:text=Error%20code%200x80070006%20is%20a,computer%20from%20malware%2C%20virus%20attacks.
https://superuser.com/questions/1195688/windows-update-error-0x80070006#

Please note: Information posted in the given link is hosted by a third party. Microsoft does not guarantee the accuracy and effectiveness of information.

If the methods mentioned in the link don't work, you can check if there is a conflict with 'Windows Update' Group Policy. If the policy is configured to not update, this error should appear as well.

Hope above information can help you.

============================================
If the Answer is helpful, please click "Accept Answer" and upvote it.
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread

·
10 |1000 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

JuanSobrado-3258 avatar image
0 Votes"
JuanSobrado-3258 answered ·

Hello @VCIAMSA-9655

Can you detail a bit more about the issue. From the script and results you describe it seems you are noticing an inconsistency with the date and updates detected for your system by WU? After resetting the windows components you are still seeing the same results, correct?

How are you triggering the scan? It seems wsmprovhost.exe is the one making the call for scan which apparently is working but it would be good to test scanning directly from Windows Update UI. Do you get the same results?
What policies do you have configured in: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate

Thanks,

Juan S.

· 1 ·
10 |1000 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Yes after applying script and restart the error persist.
The error is returned every time I try to start windows update manually, Ootherwise I don't receive any update available Alertt. there's always the latest check date of 04 januyry 2021 and the System is up to date.
I have no policies aplied for windows update. I have only 20 server (VM) on my network and I manage update manually.

0 Votes 0 ·