none
WSUS 3 SP2: Windows 7 clients have not reported status in 4 days and can not get updates RRS feed

  • Question

  • Greetings,

     

    I have run into a problem where all of my organization's machines are receiving updates via our WSUS server, except for the Windows 7 machines.  This includes: XP Pro, Vista, Server 2003, Server 2008 R2.  Windows 7 is the oddball.  Whenever you try and initiate the Windows Update application to go looking for updates, you are told: "An error occurred while checking for new updates for your computer.  Error(s) found: Code 80072EFD".  From researching this error code, it seems that it means the client can't find or access the WSUS server.

     

    I checked my WindowsUpdate.log file for any clues, and this is what happens when I click "Try again" to force it to look for more updates:

    2011-11-22	18:13:11:455	1004	f6c	Misc	WARNING: SendRequest failed with hr = 80072efd. Proxy List used: <127.0.0.1:80> Bypass List used : <(null)> Auth Schemes used : <>
    2011-11-22	18:13:11:455	1004	f6c	PT	  + Last proxy send request failed with hr = 0x80072EFD, HTTP status code = 0
    2011-11-22	18:13:11:455	1004	f6c	PT	  + Caller provided proxy = No
    2011-11-22	18:13:11:455	1004	f6c	PT	  + Proxy list used = 127.0.0.1:80
    2011-11-22	18:13:11:455	1004	f6c	PT	  + Bypass list used = <NULL>
    2011-11-22	18:13:11:455	1004	f6c	PT	  + Caller provided credentials = No
    2011-11-22	18:13:11:455	1004	f6c	PT	  + Impersonate flags = 0
    2011-11-22	18:13:11:455	1004	f6c	PT	  + Possible authorization schemes used = 
    2011-11-22	18:13:11:455	1004	f6c	PT	WARNING: GetConfig failure, error = 0x80072EFD, soap client error = 5, soap error code = 0, HTTP status code = 200
    2011-11-22	18:13:11:455	1004	f6c	PT	WARNING: PTError: 0x80072efd
    2011-11-22	18:13:11:455	1004	f6c	PT	WARNING: GetConfig_WithRecovery failed: 0x80072efd
    2011-11-22	18:13:11:455	1004	f6c	PT	WARNING: RefreshConfig failed: 0x80072efd
    2011-11-22	18:13:11:455	1004	f6c	PT	WARNING: RefreshPTState failed: 0x80072efd
    2011-11-22	18:13:11:455	1004	f6c	PT	WARNING: PTError: 0x80072efd
    2011-11-22	18:13:11:455	1004	f6c	Report	WARNING: Reporter failed to upload events with hr = 80072efd.
    2011-11-22	18:13:16:585	1004	c5c	AU	Triggering AU detection through DetectNow API
    2011-11-22	18:13:16:585	1004	c5c	AU	Triggering Online detection (interactive)
    2011-11-22	18:13:16:585	1004	138c	AU	#############
    2011-11-22	18:13:16:585	1004	138c	AU	## START ##  AU: Search for updates
    2011-11-22	18:13:16:585	1004	138c	AU	#########
    2011-11-22	18:13:16:662	1004	138c	AU	<<## SUBMITTED ## AU: Search for updates [CallId = {026C8E11-D3B5-4D00-84E3-0BA44B37EC55}]
    2011-11-22	18:13:16:662	1004	f6c	Agent	*************
    2011-11-22	18:13:16:662	1004	f6c	Agent	** START **  Agent: Finding updates [CallerId = AutomaticUpdates]
    2011-11-22	18:13:16:662	1004	f6c	Agent	*********
    2011-11-22	18:13:16:662	1004	f6c	Agent	  * Online = Yes; Ignore download priority = No
    2011-11-22	18:13:16:662	1004	f6c	Agent	  * Criteria = "IsInstalled=0 and DeploymentAction='Installation' or IsPresent=1 and DeploymentAction='Uninstallation' or IsInstalled=1 and DeploymentAction='Installation' and RebootRequired=1 or IsInstalled=0 and DeploymentAction='Uninstallation' and RebootRequired=1"
    2011-11-22	18:13:16:662	1004	f6c	Agent	  * ServiceID = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7} Managed
    2011-11-22	18:13:16:662	1004	f6c	Agent	  * Search Scope = {Machine}
    2011-11-22	18:13:16:662	1004	f6c	Setup	Checking for agent SelfUpdate
    2011-11-22	18:13:16:683	1004	f6c	Setup	Client version: Core: 7.5.7601.17514  Aux: 7.5.7601.17514
    2011-11-22	18:13:16:703	1004	f6c	Misc	Validating signature for C:\Windows\SoftwareDistribution\SelfUpdate\wuident.cab:
    2011-11-22	18:13:16:715	1004	f6c	Misc	 Microsoft signed: Yes
    2011-11-22	18:13:17:724	1004	f6c	Misc	WARNING: SendRequest failed with hr = 80072efd. Proxy List used: <127.0.0.1:80> Bypass List used : <(null)> Auth Schemes used : <>
    2011-11-22	18:13:17:724	1004	f6c	Misc	WARNING: WinHttp: SendRequestUsingProxy failed for <http://10.0.0.25/selfupdate/wuident.cab>. error 0x80072efd
    2011-11-22	18:13:17:724	1004	f6c	Misc	WARNING: WinHttp: SendRequestToServerForFileInformation MakeRequest failed. error 0x80072efd
    2011-11-22	18:13:17:724	1004	f6c	Misc	WARNING: WinHttp: SendRequestToServerForFileInformation failed with 0x80072efd
    2011-11-22	18:13:17:724	1004	f6c	Misc	WARNING: WinHttp: ShouldFileBeDownloaded failed with 0x80072efd
    2011-11-22	18:13:18:732	1004	f6c	Misc	WARNING: SendRequest failed with hr = 80072efd. Proxy List used: <127.0.0.1:80> Bypass List used : <(null)> Auth Schemes used : <>
    2011-11-22	18:13:18:732	1004	f6c	Misc	WARNING: WinHttp: SendRequestUsingProxy failed for <http://10.0.0.25/selfupdate/wuident.cab>. error 0x80072efd
    2011-11-22	18:13:18:732	1004	f6c	Misc	WARNING: WinHttp: SendRequestToServerForFileInformation MakeRequest failed. error 0x80072efd
    2011-11-22	18:13:18:732	1004	f6c	Misc	WARNING: WinHttp: SendRequestToServerForFileInformation failed with 0x80072efd
    2011-11-22	18:13:18:732	1004	f6c	Misc	WARNING: WinHttp: ShouldFileBeDownloaded failed with 0x80072efd
    2011-11-22	18:13:19:750	1004	f6c	Misc	WARNING: SendRequest failed with hr = 80072efd. Proxy List used: <127.0.0.1:80> Bypass List used : <(null)> Auth Schemes used : <>
    2011-11-22	18:13:19:750	1004	f6c	Misc	WARNING: WinHttp: SendRequestUsingProxy failed for <http://10.0.0.25/selfupdate/wuident.cab>. error 0x80072efd
    2011-11-22	18:13:19:750	1004	f6c	Misc	WARNING: WinHttp: SendRequestToServerForFileInformation MakeRequest failed. error 0x80072efd
    2011-11-22	18:13:19:750	1004	f6c	Misc	WARNING: WinHttp: SendRequestToServerForFileInformation failed with 0x80072efd
    2011-11-22	18:13:19:750	1004	f6c	Misc	WARNING: WinHttp: ShouldFileBeDownloaded failed with 0x80072efd
    2011-11-22	18:13:20:760	1004	f6c	Misc	WARNING: SendRequest failed with hr = 80072efd. Proxy List used: <127.0.0.1:80> Bypass List used : <(null)> Auth Schemes used : <>
    2011-11-22	18:13:20:760	1004	f6c	Misc	WARNING: WinHttp: SendRequestUsingProxy failed for <http://10.0.0.25/selfupdate/wuident.cab>. error 0x80072efd
    2011-11-22	18:13:20:760	1004	f6c	Misc	WARNING: WinHttp: SendRequestToServerForFileInformation MakeRequest failed. error 0x80072efd
    2011-11-22	18:13:20:760	1004	f6c	Misc	WARNING: WinHttp: SendRequestToServerForFileInformation failed with 0x80072efd
    2011-11-22	18:13:20:760	1004	f6c	Misc	WARNING: WinHttp: ShouldFileBeDownloaded failed with 0x80072efd
    2011-11-22	18:13:20:760	1004	f6c	Misc	WARNING: DownloadFileInternal failed for http://10.0.0.25/selfupdate/wuident.cab: error 0x80072efd
    2011-11-22	18:13:20:760	1004	f6c	Setup	WARNING: SelfUpdate check failed to download package information, error = 0x80072EFD
    2011-11-22	18:13:20:760	1004	f6c	Setup	FATAL: SelfUpdate check failed, err = 0x80072EFD
    2011-11-22	18:13:20:760	1004	f6c	Agent	  * WARNING: Skipping scan, self-update check returned 0x80072EFD
    2011-11-22	18:13:20:773	1004	f6c	Agent	  * WARNING: Exit code = 0x80072EFD
    2011-11-22	18:13:20:773	1004	f6c	Agent	*********
    2011-11-22	18:13:20:773	1004	f6c	Agent	**  END  **  Agent: Finding updates [CallerId = AutomaticUpdates]
    2011-11-22	18:13:20:773	1004	f6c	Agent	*************
    2011-11-22	18:13:20:773	1004	f6c	Agent	WARNING: WU client failed Searching for update with error 0x80072efd
    2011-11-22	18:13:20:773	1004	12ac	AU	>>##  RESUMED  ## AU: Search for updates [CallId = {026C8E11-D3B5-4D00-84E3-0BA44B37EC55}]
    2011-11-22	18:13:20:774	1004	12ac	AU	  # WARNING: Search callback failed, result = 0x80072EFD
    2011-11-22	18:13:20:774	1004	12ac	AU	  # WARNING: Failed to find updates with error code 80072EFD
    2011-11-22	18:13:20:774	1004	12ac	AU	#########
    2011-11-22	18:13:20:774	1004	12ac	AU	##  END  ##  AU: Search for updates [CallId = {026C8E11-D3B5-4D00-84E3-0BA44B37EC55}]
    2011-11-22	18:13:20:774	1004	12ac	AU	#############
    2011-11-22	18:13:20:774	1004	12ac	AU	Successfully wrote event for AU health state:0
    2011-11-22	18:13:20:774	1004	12ac	AU	AU setting next detection timeout to 2011-11-23 00:05:09
    2011-11-22	18:13:20:774	1004	12ac	AU	Setting AU scheduled install time to 2011-11-24 21:00:00
    2011-11-22	18:13:20:774	1004	12ac	AU	Successfully wrote event for AU health state:0
    2011-11-22	18:13:20:795	1792	88c	COMAPI	-------------
    2011-11-22	18:13:20:795	1792	88c	COMAPI	-- START --  COMAPI: Search [ClientId = <NULL>]
    2011-11-22	18:13:20:795	1792	88c	COMAPI	---------
    2011-11-22	18:13:20:797	1004	f6c	Agent	*************
    2011-11-22	18:13:20:797	1004	f6c	Agent	** START **  Agent: Finding updates [CallerId = ]
    2011-11-22	18:13:20:797	1004	f6c	Agent	*********
    2011-11-22	18:13:20:797	1792	88c	COMAPI	<<-- SUBMITTED -- COMAPI: Search [ClientId = <NULL>]
    2011-11-22	18:13:20:797	1004	f6c	Agent	  * Online = Yes; Ignore download priority = No
    2011-11-22	18:13:20:797	1004	f6c	Agent	  * Criteria = "IsInstalled = 0 AND IsHidden = 0"
    2011-11-22	18:13:20:797	1004	f6c	Agent	  * ServiceID = {00000000-0000-0000-0000-000000000000} Third party service
    2011-11-22	18:13:20:797	1004	f6c	Agent	  * Search Scope = {Machine}
    2011-11-22	18:13:20:801	1004	12ac	AU	Successfully wrote event for AU health state:0
    2011-11-22	18:13:20:917	1004	f6c	PT	+++++++++++  PT: Synchronizing server updates  +++++++++++
    2011-11-22	18:13:20:917	1004	f6c	PT	  + ServiceId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}, Server URL = http://10.0.0.25/ClientWebService/client.asmx
    2011-11-22	18:13:21:916	1004	f6c	Misc	WARNING: SendRequest failed with hr = 80072efd. Proxy List used: <127.0.0.1:80> Bypass List used : <(null)> Auth Schemes used : <>
    2011-11-22	18:13:21:916	1004	f6c	PT	  + Last proxy send request failed with hr = 0x80072EFD, HTTP status code = 0
    2011-11-22	18:13:21:916	1004	f6c	PT	  + Caller provided proxy = No
    2011-11-22	18:13:21:916	1004	f6c	PT	  + Proxy list used = 127.0.0.1:80
    2011-11-22	18:13:21:916	1004	f6c	PT	  + Bypass list used = <NULL>
    2011-11-22	18:13:21:916	1004	f6c	PT	  + Caller provided credentials = No
    2011-11-22	18:13:21:916	1004	f6c	PT	  + Impersonate flags = 0
    2011-11-22	18:13:21:916	1004	f6c	PT	  + Possible authorization schemes used = 
    2011-11-22	18:13:21:916	1004	f6c	PT	WARNING: GetConfig failure, error = 0x80072EFD, soap client error = 5, soap error code = 0, HTTP status code = 200
    2011-11-22	18:13:21:916	1004	f6c	PT	WARNING: PTError: 0x80072efd
    2011-11-22	18:13:21:916	1004	f6c	PT	WARNING: GetConfig_WithRecovery failed: 0x80072efd
    2011-11-22	18:13:21:916	1004	f6c	PT	WARNING: RefreshConfig failed: 0x80072efd
    2011-11-22	18:13:21:916	1004	f6c	PT	WARNING: RefreshPTState failed: 0x80072efd
    2011-11-22	18:13:21:916	1004	f6c	PT	WARNING: Sync of Updates: 0x80072efd
    2011-11-22	18:13:21:916	1004	f6c	PT	WARNING: SyncServerUpdatesInternal failed: 0x80072efd
    2011-11-22	18:13:21:916	1004	f6c	Agent	  * WARNING: Failed to synchronize, error = 0x80072EFD
    2011-11-22	18:13:21:917	1004	f6c	Agent	  * WARNING: Exit code = 0x80072EFD
    2011-11-22	18:13:21:917	1004	f6c	Agent	*********
    2011-11-22	18:13:21:917	1004	f6c	Agent	**  END  **  Agent: Finding updates [CallerId = ]
    2011-11-22	18:13:21:917	1004	f6c	Agent	*************
    2011-11-22	18:13:21:917	1004	f6c	Agent	WARNING: WU client failed Searching for update with error 0x80072efd
    2011-11-22	18:13:21:934	1792	16a0	COMAPI	>>--  RESUMED  -- COMAPI: Search [ClientId = <NULL>]
    2011-11-22	18:13:21:934	1792	16a0	COMAPI	  - Updates found = 0
    2011-11-22	18:13:21:935	1792	16a0	COMAPI	  - WARNING: Exit code = 0x00000000, Result code = 0x80072EFD
    2011-11-22	18:13:21:935	1792	16a0	COMAPI	---------
    2011-11-22	18:13:21:935	1792	16a0	COMAPI	--  END  --  COMAPI: Search [ClientId = <NULL>]
    2011-11-22	18:13:21:935	1792	16a0	COMAPI	-------------
    2011-11-22	18:13:21:935	1792	88c	COMAPI	WARNING: Operation failed due to earlier error, hr=80072EFD
    2011-11-22	18:13:21:935	1792	88c	COMAPI	FATAL: Unable to perform synchronous search. (hr=80072EFD)
    2011-11-22	18:13:25:760	1004	f6c	Report	REPORT EVENT: {908AA20C-544F-4103-8044-8B3A658020E5}	2011-11-22 18:13:20:760-0500	1	148	101	{D67661EB-2423-451D-BF5D-13199E37DF28}	1	80072efd	SelfUpdate	Failure	Software Synchronization	Windows Update Client failed to detect with error 0x80072efd.
    2011-11-22	18:13:25:760	1004	f6c	Report	REPORT EVENT: {54A15F30-721E-4F96-B7FC-5173D39C9B93}	2011-11-22 18:13:21:917-0500	1	148	101	{00000000-0000-0000-0000-000000000000}	0	80072efd		Failure	Software Synchronization	Windows Update Client failed to detect with error 0x80072efd.
    2011-11-22	18:13:25:766	1004	f6c	Report	CWERReporter::HandleEvents - WER report upload completed with status 0x8
    2011-11-22	18:13:25:766	1004	f6c	Report	WER Report sent: 7.5.7601.17514 0x80072efd D67661EB-2423-451D-BF5D-13199E37DF28 Scan 101 Managed
    2011-11-22	18:13:25:770	1004	f6c	Report	CWERReporter::HandleEvents - WER report upload completed with status 0x8
    2011-11-22	18:13:25:771	1004	f6c	Report	WER Report sent: 7.5.7601.17514 0x80072efd 00000000-0000-0000-0000-000000000000 Scan 101 Managed
    2011-11-22	18:13:25:771	1004	f6c	Report	CWERReporter finishing event handling. (00000000)
    

    The 10.0.0.25 is our WSUS server.  I am able to ping the server from my client.  Also, if I try and access one of those .cab files in my web browser (http://10.0.0.25/selfupdate/wuident.cab for example), I am prompted to download the cab file, so I can access the site through my browser.  It seems to me, the references to Proxy List used and the 127.0.0.1:80, are indicative of the problem as none of the other non-windows 7 machines have anything about that in their respective WindowsUpdate.log files.

     

    For Antivirus we use Symantec Endpoint Protection, but nothing has changed on that front for quite a while, and this new not receiving updates started only a few days ago.  I even tried disabling Symantec, and tried getting updates, and that didn't work either.  The Windows Firewall and Defender are also disabled, as those functions are managed by Endpoint.

     

    According to the WSUS server, the Windows 7 clients have not reported their status since Nov 18 (4 days ago).  I authorized the latest batch of updates to go out yesterday, so they downloaded over the night and would be installed today.  When I got in this morning, I realized that the latest batch of updates had filled up the server's hard drive, so I had to clean up some space.  I wanted to throw this out there in case it gave someone a clue, but I'd like to repeat the Windows 7 clients have not reported their status in 4 days, and the disk space problem happened over the night into this morning.

     

    Can anyone provide some insight, or point me in the right direction?  It is very strange the other Operating Systems are reporting and receiving their updates, and Windows 7 is not.  The WSUS server is running WSUS 3 SP2 on Server 2008 R2.  Thank you very much in advance for any help you can provide.

    Tuesday, November 22, 2011 11:23 PM

Answers

  • Not sure if this will help, but I was having a similar issue, and what I found as the root cause is potentially an extremely ugly hack...

    While researching the error, I was running a network monitor and found that although I have no proxy server in the domain, it was, like in your case setting the proxy to localhost. WPAD was searching for a wpad server, and finding none in the network, starts reaching out... Someone has put up a server and somehow managed to get domains without a TLD into dns (it appears to be hosted at a rackspace farm in Dallas)... for example your domain is example.com... they have put in a server that answers to wpad.example, with a wpad.dat file that points back to localhost, effectively highjacking anything that uses winhttp, although without help in the middle the net result is to prevent windows update and other functions that use winhttp as their primary protocol.

    To fix this, I simply added an example forwarding zone to my domain dns... Not the ideal solution, but as a workaround it solved several issues I was seeing on the clients network... next step, go back and fix all the crap left behind by my predecessor that would have prevented this in the first place...

    Hope this helps and is looked into further.

    John


    • Edited by jlmcjrsyt Monday, December 5, 2011 4:53 PM
    • Marked as answer by RockAdmin Friday, December 9, 2011 3:03 PM
    Monday, December 5, 2011 11:35 AM

All replies

  • Hi,

    Thank you for posting here.

     "An error occurred while checking for new updates for your computer. Error(s) found: Code 80072EFD".

    If you continue to receive this error, it might mean that a program running on your computer is preventing Windows Update Services (SVCHOST) from accessing the Internet. Programs that might do this include firewalls, anti-spyware software, web accelerators, Internet security or antivirus programs, and proxy servers.

    Did you have a correct Policy setting on the WIN7 client?Have you ever installed Firewall Client on win7? If so,uninstall it to see whether it works.

    Best regards,

    Clarence


    Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.
    Wednesday, November 23, 2011 10:01 AM
    Moderator
  •  Hi,

     

    I believe your issue is being caused by this setting:

     

    2011-11-22 18:13:11:455 1004 f6c PT + Proxy list used = 127.0.0.1:80  

     

    To remove a proxy server by using the Proxycfg.exe tool

    To use the Proxycfg.exe tool to remove a proxy server and to configure "direct access" to the Internet, follow these steps:

    1. Click Start, click Run, type cmd, and then click OK.
    2. At the command prompt, type proxycfg -D, and then press ENTER.

    Most of the clients will have the proxycgf utility but if not then you can download it here:

    KB830605 - The Proxycfg.exe configuration tool is available for WinHTTP 5.1

     

    I'm not sure if you have to restart the Update Agent service after modifying this proxycfg setting, but i'd give it a go, just in case.

     

    When having problems with WU Agents, this link becomes handy:

    http://blogs.technet.com/b/sus/archive/2009/11/17/tips-for-troubleshooting-wsus-agents-that-are-not-reporting-to-the-wsus-server.aspx

     


    Tiago Viana, MCITP:SA
    Wednesday, November 23, 2011 11:12 AM
  • Hi Clarence,

    Thanks so much for responding.

    We do run Symantec Endpoint for our antivirus, which also acts as the firewall (and disables Windows Firewall).  I've tried disabling the Symantec client, and trying to get updates to no avail.  Maybe I need to uninstall it to be sure?

    As far as web accelerators, do you mean the "Accelerators" within IE?  Could settings within IE really be a cause for Windows Update not to work?  We run IE9 here, and any accelerators that are installed, came with IE.  For example: E-mail with Windows Live, Map with Bing, and Translate with Bing are all installed, but also all listed as disabled.  "Search Providers" are just Bing and Google.  As far as "Toolbars and Extensions", see the below screen capture for the list.

    As for anti-spyware software, we do use Spybot S&D as well as Malwarebytes, but on an as needed basis.

    The LAN Settings within IE are nothing fancy, just what comes out of the box:

    We use Group Policy to deploy the WSUS settings to the clients.  The same GP is used for XP/Vista/7, which is confusing why only 7 is affected.  The settings for the Group Policy are below:  EDIT: It appears I'm only allowed 2 images per post.  I will respond to this post in a minute with the remainder.

     

    Wednesday, November 23, 2011 1:17 PM
  • Below are the Group Policy settings:

    The 10.0.0.25 is that of my WSUS server.

    So hopefully that gives you a little more info Clarence.  Thanks for taking the time to look into my problem.

    Wednesday, November 23, 2011 1:21 PM
  • Thanks for responding Tiago.  I too thought the whole proxy list 127.0.0.1:80 was weird when I saw it in my WindowsUpdate.log.

    When I try to follow your instructions of running proxycfg -D, I am given the following result: 'proxycfg' is not recognized as an internal or external command, operable program or batch file.

    According to this page (http://www.bohack.com/2010/08/windows-server-2008-replacement-of-proxycfg-exe/), it appears proxycfg.exe is no longer included with newer versions of Windows (including 7), and has been replaced with netsh.  From what I can tell from that article, the proxycfg -D equivalent with netsh is netsh winhttp reset proxy.  When I run that, I am told the following:

    If I try and get updates again, I am still told of error 80072EFD.

    Wednesday, November 23, 2011 1:38 PM
  • After re-reading your post Tiago, I see you gave me a link to the proxycfg hotfix.  I have since downloaded and have run it.  This is what I get from it:


    After running this, I restart my Windows Update service, and try again to get updates, same thing, an error occured with 80072EFD.

    I re-checked my WindowsUpdate.log, and this appeared to be from the latest attempt to collect updates:

     

    2011-11-23	08:41:01:753	1004	16cc	AU	###########  AU: Uninitializing Automatic Updates  ###########
    2011-11-23	08:41:01:758	1004	16cc	Report	CWERReporter finishing event handling. (00000000)
    2011-11-23	08:41:02:113	1004	16cc	Service	*********
    2011-11-23	08:41:02:113	1004	16cc	Service	**  END  **  Service: Service exit [Exit code = 0x240001]
    2011-11-23	08:41:02:113	1004	16cc	Service	*************
    2011-11-23	08:41:03:065	1004	1814	Misc	===========  Logging initialized (build: 7.5.7601.17514, tz: -0500)  ===========
    2011-11-23	08:41:03:065	1004	1814	Misc	  = Process: C:\Windows\system32\svchost.exe
    2011-11-23	08:41:03:066	1004	1814	Misc	  = Module: c:\windows\system32\wuaueng.dll
    2011-11-23	08:41:03:065	1004	1814	Service	*************
    2011-11-23	08:41:03:066	1004	1814	Service	** START **  Service: Service startup
    2011-11-23	08:41:03:066	1004	1814	Service	*********
    2011-11-23	08:41:03:067	1004	1814	Agent	  * WU client version 7.5.7601.17514
    2011-11-23	08:41:03:067	1004	1814	Agent	  * Base directory: C:\Windows\SoftwareDistribution
    2011-11-23	08:41:03:067	1004	1814	Agent	  * Access type: No proxy
    2011-11-23	08:41:03:067	1004	1814	Agent	  * Network state: Connected
    2011-11-23	08:41:03:097	1004	914	Report	CWERReporter::Init succeeded
    2011-11-23	08:41:03:097	1004	914	Agent	***********  Agent: Initializing Windows Update Agent  ***********
    2011-11-23	08:41:03:097	1004	914	Agent	***********  Agent: Initializing global settings cache  ***********
    2011-11-23	08:41:03:097	1004	914	Agent	  * WSUS server: http://10.0.0.25
    2011-11-23	08:41:03:097	1004	914	Agent	  * WSUS status server: http://10.0.0.25
    2011-11-23	08:41:03:097	1004	914	Agent	  * Target group: RIG Workstations
    2011-11-23	08:41:03:097	1004	914	Agent	  * Windows Update access disabled: No
    2011-11-23	08:41:03:097	1004	914	DnldMgr	Download manager restoring 0 downloads
    2011-11-23	08:41:03:100	1792	88c	COMAPI	-------------
    2011-11-23	08:41:03:100	1792	88c	COMAPI	-- START --  COMAPI: Search [ClientId = <NULL>]
    2011-11-23	08:41:03:100	1792	88c	COMAPI	---------
    2011-11-23	08:41:03:102	1792	88c	COMAPI	<<-- SUBMITTED -- COMAPI: Search [ClientId = <NULL>]
    2011-11-23	08:41:03:375	1004	1814	Report	***********  Report: Initializing static reporting data  ***********
    2011-11-23	08:41:03:375	1004	1814	Report	  * OS Version = 6.1.7601.1.0.65792
    2011-11-23	08:41:03:375	1004	1814	Report	  * OS Product Type = 0x00000030
    2011-11-23	08:41:03:385	1004	1814	Report	  * Computer Brand = Dell Inc.
    2011-11-23	08:41:03:385	1004	1814	Report	  * Computer Model = OptiPlex 780                 
    2011-11-23	08:41:03:387	1004	1814	Report	  * Bios Revision = A08
    2011-11-23	08:41:03:387	1004	1814	Report	  * Bios Name = Phoenix ROM BIOS PLUS Version 1.10 A08
    2011-11-23	08:41:03:387	1004	1814	Report	  * Bios Release Date = 2011-01-21T00:00:00
    2011-11-23	08:41:03:387	1004	1814	Report	  * Locale ID = 1033
    2011-11-23	08:41:03:388	1004	1990	Agent	*************
    2011-11-23	08:41:03:388	1004	1990	Agent	** START **  Agent: Finding updates [CallerId = ]
    2011-11-23	08:41:03:388	1004	1990	Agent	*********
    2011-11-23	08:41:03:388	1004	1990	Agent	  * Online = Yes; Ignore download priority = No
    2011-11-23	08:41:03:388	1004	1990	Agent	  * Criteria = "IsInstalled = 0 AND IsHidden = 0"
    2011-11-23	08:41:03:388	1004	1990	Agent	  * ServiceID = {00000000-0000-0000-0000-000000000000} Third party service
    2011-11-23	08:41:03:388	1004	1990	Agent	  * Search Scope = {Machine}
    2011-11-23	08:41:03:484	1004	1990	PT	+++++++++++  PT: Synchronizing server updates  +++++++++++
    2011-11-23	08:41:03:484	1004	1990	PT	  + ServiceId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}, Server URL = http://10.0.0.25/ClientWebService/client.asmx
    2011-11-23	08:41:04:486	1004	1990	Misc	WARNING: SendRequest failed with hr = 80072efd. Proxy List used: <127.0.0.1:80> Bypass List used : <(null)> Auth Schemes used : <>
    2011-11-23	08:41:04:486	1004	1990	PT	  + Last proxy send request failed with hr = 0x80072EFD, HTTP status code = 0
    2011-11-23	08:41:04:486	1004	1990	PT	  + Caller provided proxy = No
    2011-11-23	08:41:04:486	1004	1990	PT	  + Proxy list used = 127.0.0.1:80
    2011-11-23	08:41:04:486	1004	1990	PT	  + Bypass list used = <NULL>
    2011-11-23	08:41:04:486	1004	1990	PT	  + Caller provided credentials = No
    2011-11-23	08:41:04:486	1004	1990	PT	  + Impersonate flags = 0
    2011-11-23	08:41:04:486	1004	1990	PT	  + Possible authorization schemes used = 
    2011-11-23	08:41:04:486	1004	1990	PT	WARNING: GetConfig failure, error = 0x80072EFD, soap client error = 5, soap error code = 0, HTTP status code = 200
    2011-11-23	08:41:04:486	1004	1990	PT	WARNING: PTError: 0x80072efd
    2011-11-23	08:41:04:486	1004	1990	PT	WARNING: GetConfig_WithRecovery failed: 0x80072efd
    2011-11-23	08:41:04:486	1004	1990	PT	WARNING: RefreshConfig failed: 0x80072efd
    2011-11-23	08:41:04:486	1004	1990	PT	WARNING: RefreshPTState failed: 0x80072efd
    2011-11-23	08:41:04:486	1004	1990	PT	WARNING: Sync of Updates: 0x80072efd
    2011-11-23	08:41:04:486	1004	1990	PT	WARNING: SyncServerUpdatesInternal failed: 0x80072efd
    2011-11-23	08:41:04:486	1004	1990	Agent	  * WARNING: Failed to synchronize, error = 0x80072EFD
    2011-11-23	08:41:04:487	1004	1990	Agent	  * WARNING: Exit code = 0x80072EFD
    2011-11-23	08:41:04:487	1004	1990	Agent	*********
    2011-11-23	08:41:04:487	1004	1990	Agent	**  END  **  Agent: Finding updates [CallerId = ]
    2011-11-23	08:41:04:487	1004	1990	Agent	*************
    2011-11-23	08:41:04:487	1004	1990	Agent	WARNING: WU client failed Searching for update with error 0x80072efd
    2011-11-23	08:41:04:488	1792	f10	COMAPI	>>--  RESUMED  -- COMAPI: Search [ClientId = <NULL>]
    2011-11-23	08:41:04:488	1792	f10	COMAPI	  - Updates found = 0
    2011-11-23	08:41:04:488	1792	f10	COMAPI	  - WARNING: Exit code = 0x00000000, Result code = 0x80072EFD
    2011-11-23	08:41:04:488	1792	f10	COMAPI	---------
    2011-11-23	08:41:04:488	1792	f10	COMAPI	--  END  --  COMAPI: Search [ClientId = <NULL>]
    2011-11-23	08:41:04:488	1792	f10	COMAPI	-------------
    2011-11-23	08:41:04:488	1792	88c	COMAPI	WARNING: Operation failed due to earlier error, hr=80072EFD
    2011-11-23	08:41:04:488	1792	88c	COMAPI	FATAL: Unable to perform synchronous search. (hr=80072EFD)
    2011-11-23	08:41:05:483	1004	1990	Misc	WARNING: SendRequest failed with hr = 80072efd. Proxy List used: <127.0.0.1:80> Bypass List used : <(null)> Auth Schemes used : <>
    2011-11-23	08:41:05:483	1004	1990	PT	  + Last proxy send request failed with hr = 0x80072EFD, HTTP status code = 0
    2011-11-23	08:41:05:483	1004	1990	PT	  + Caller provided proxy = No
    2011-11-23	08:41:05:483	1004	1990	PT	  + Proxy list used = 127.0.0.1:80
    2011-11-23	08:41:05:483	1004	1990	PT	  + Bypass list used = <NULL>
    2011-11-23	08:41:05:483	1004	1990	PT	  + Caller provided credentials = No
    2011-11-23	08:41:05:483	1004	1990	PT	  + Impersonate flags = 0
    2011-11-23	08:41:05:483	1004	1990	PT	  + Possible authorization schemes used = 
    2011-11-23	08:41:05:483	1004	1990	PT	WARNING: GetConfig failure, error = 0x80072EFD, soap client error = 5, soap error code = 0, HTTP status code = 200
    2011-11-23	08:41:05:483	1004	1990	PT	WARNING: PTError: 0x80072efd
    2011-11-23	08:41:05:483	1004	1990	PT	WARNING: GetConfig_WithRecovery failed: 0x80072efd
    2011-11-23	08:41:05:483	1004	1990	PT	WARNING: RefreshConfig failed: 0x80072efd
    2011-11-23	08:41:05:483	1004	1990	PT	WARNING: RefreshPTState failed: 0x80072efd
    2011-11-23	08:41:05:483	1004	1990	PT	WARNING: PTError: 0x80072efd
    2011-11-23	08:41:05:483	1004	1990	Report	WARNING: Reporter failed to upload events with hr = 80072efd.
    2011-11-23	08:41:06:485	1004	1990	Misc	WARNING: SendRequest failed with hr = 80072efd. Proxy List used: <127.0.0.1:80> Bypass List used : <(null)> Auth Schemes used : <>
    2011-11-23	08:41:06:485	1004	1990	PT	  + Last proxy send request failed with hr = 0x80072EFD, HTTP status code = 0
    2011-11-23	08:41:06:485	1004	1990	PT	  + Caller provided proxy = No
    2011-11-23	08:41:06:485	1004	1990	PT	  + Proxy list used = 127.0.0.1:80
    2011-11-23	08:41:06:485	1004	1990	PT	  + Bypass list used = <NULL>
    2011-11-23	08:41:06:485	1004	1990	PT	  + Caller provided credentials = No
    2011-11-23	08:41:06:485	1004	1990	PT	  + Impersonate flags = 0
    2011-11-23	08:41:06:485	1004	1990	PT	  + Possible authorization schemes used = 
    2011-11-23	08:41:06:485	1004	1990	PT	WARNING: GetConfig failure, error = 0x80072EFD, soap client error = 5, soap error code = 0, HTTP status code = 200
    2011-11-23	08:41:06:485	1004	1990	PT	WARNING: PTError: 0x80072efd
    2011-11-23	08:41:06:485	1004	1990	PT	WARNING: GetConfig_WithRecovery failed: 0x80072efd
    2011-11-23	08:41:06:485	1004	1990	PT	WARNING: RefreshConfig failed: 0x80072efd
    2011-11-23	08:41:06:485	1004	1990	PT	WARNING: RefreshPTState failed: 0x80072efd
    2011-11-23	08:41:06:485	1004	1990	PT	WARNING: PTError: 0x80072efd
    2011-11-23	08:41:06:485	1004	1990	Report	WARNING: Reporter failed to upload events with hr = 80072efd.
    2011-11-23	08:41:08:387	1004	1990	Report	REPORT EVENT: {BDE43ADA-8DF7-44D1-8010-DF8797511263}	2011-11-23 08:41:04:487-0500	1	148	101	{00000000-0000-0000-0000-000000000000}	0	80072efd		Failure	Software Synchronization	Windows Update Client failed to detect with error 0x80072efd.
    2011-11-23	08:41:08:396	1004	1990	Report	CWERReporter::HandleEvents - WER report upload completed with status 0x8
    2011-11-23	08:41:08:396	1004	1990	Report	WER Report sent: 7.5.7601.17514 0x80072efd 00000000-0000-0000-0000-000000000000 Scan 101 Managed
    2011-11-23	08:41:08:396	1004	1990	Report	CWERReporter finishing event handling. (00000000)
    2011-11-23	08:41:18:093	1004	1a3c	AU	###########  AU: Initializing Automatic Updates  ###########
    2011-11-23	08:41:18:094	1004	1a3c	AU	  # WSUS server: http://10.0.0.25
    2011-11-23	08:41:18:094	1004	1a3c	AU	  # Detection frequency: 1
    2011-11-23	08:41:18:094	1004	1a3c	AU	  # Target group: RIG Workstations
    2011-11-23	08:41:18:094	1004	1a3c	AU	  # Approval type: Scheduled (Policy)
    2011-11-23	08:41:18:094	1004	1a3c	AU	  # Scheduled install day/time: Thursday at 16:00
    2011-11-23	08:41:18:094	1004	1a3c	AU	  # Auto-install minor updates: Yes (Policy)
    2011-11-23	08:41:18:094	1004	1a3c	AU	  # Will interact with non-admins (Non-admins are elevated (Policy))
    2011-11-23	08:41:18:094	1004	1a3c	AU	Setting AU scheduled install time to 2011-11-24 21:00:00
    2011-11-23	08:41:18:095	1004	1a3c	AU	Successfully wrote event for AU health state:0
    2011-11-23	08:41:18:095	1004	1a3c	AU	Initializing featured updates
    2011-11-23	08:41:18:095	1004	1a3c	AU	Found 0 cached featured updates
    2011-11-23	08:41:18:095	1004	1a3c	AU	Successfully wrote event for AU health state:0
    2011-11-23	08:41:18:096	1004	1a3c	AU	Successfully wrote event for AU health state:0
    2011-11-23	08:41:18:096	1004	1a3c	AU	AU finished delayed initialization
    2011-11-23	08:41:18:097	1004	1a3c	AU	Triggering AU detection through DetectNow API
    2011-11-23	08:41:18:097	1004	1a3c	AU	Triggering Online detection (interactive)
    2011-11-23	08:41:18:097	1004	1814	AU	#############
    2011-11-23	08:41:18:097	1004	1814	AU	## START ##  AU: Search for updates
    2011-11-23	08:41:18:097	1004	1814	AU	#########
    2011-11-23	08:41:18:100	1792	88c	COMAPI	-------------
    2011-11-23	08:41:18:100	1792	88c	COMAPI	-- START --  COMAPI: Search [ClientId = <NULL>]
    2011-11-23	08:41:18:100	1792	88c	COMAPI	---------
    2011-11-23	08:41:18:101	1004	1814	AU	<<## SUBMITTED ## AU: Search for updates [CallId = {6C676D9B-F9CB-447E-BC1B-2CAAC4FD0732}]
    2011-11-23	08:41:18:101	1004	1990	Agent	*************
    2011-11-23	08:41:18:101	1004	1990	Agent	** START **  Agent: Finding updates [CallerId = AutomaticUpdates]
    2011-11-23	08:41:18:101	1004	1990	Agent	*********
    2011-11-23	08:41:18:101	1004	1990	Agent	  * Online = Yes; Ignore download priority = No
    2011-11-23	08:41:18:101	1004	1990	Agent	  * Criteria = "IsInstalled=0 and DeploymentAction='Installation' or IsPresent=1 and DeploymentAction='Uninstallation' or IsInstalled=1 and DeploymentAction='Installation' and RebootRequired=1 or IsInstalled=0 and DeploymentAction='Uninstallation' and RebootRequired=1"
    2011-11-23	08:41:18:101	1004	1990	Agent	  * ServiceID = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7} Managed
    2011-11-23	08:41:18:101	1004	1990	Agent	  * Search Scope = {Machine}
    2011-11-23	08:41:18:101	1004	1990	Setup	Checking for agent SelfUpdate
    2011-11-23	08:41:18:101	1004	1990	Setup	Client version: Core: 7.5.7601.17514  Aux: 7.5.7601.17514
    2011-11-23	08:41:18:101	1004	1990	Misc	Validating signature for C:\Windows\SoftwareDistribution\SelfUpdate\wuident.cab:
    2011-11-23	08:41:18:103	1792	88c	COMAPI	<<-- SUBMITTED -- COMAPI: Search [ClientId = <NULL>]
    2011-11-23	08:41:18:105	1004	1990	Misc	 Microsoft signed: Yes
    2011-11-23	08:41:19:113	1004	1990	Misc	WARNING: SendRequest failed with hr = 80072efd. Proxy List used: <127.0.0.1:80> Bypass List used : <(null)> Auth Schemes used : <>
    2011-11-23	08:41:19:113	1004	1990	Misc	WARNING: WinHttp: SendRequestUsingProxy failed for <http://10.0.0.25/selfupdate/wuident.cab>. error 0x80072efd
    2011-11-23	08:41:19:113	1004	1990	Misc	WARNING: WinHttp: SendRequestToServerForFileInformation MakeRequest failed. error 0x80072efd
    2011-11-23	08:41:19:113	1004	1990	Misc	WARNING: WinHttp: SendRequestToServerForFileInformation failed with 0x80072efd
    2011-11-23	08:41:19:113	1004	1990	Misc	WARNING: WinHttp: ShouldFileBeDownloaded failed with 0x80072efd
    2011-11-23	08:41:20:131	1004	1990	Misc	WARNING: SendRequest failed with hr = 80072efd. Proxy List used: <127.0.0.1:80> Bypass List used : <(null)> Auth Schemes used : <>
    2011-11-23	08:41:20:131	1004	1990	Misc	WARNING: WinHttp: SendRequestUsingProxy failed for <http://10.0.0.25/selfupdate/wuident.cab>. error 0x80072efd
    2011-11-23	08:41:20:131	1004	1990	Misc	WARNING: WinHttp: SendRequestToServerForFileInformation MakeRequest failed. error 0x80072efd
    2011-11-23	08:41:20:131	1004	1990	Misc	WARNING: WinHttp: SendRequestToServerForFileInformation failed with 0x80072efd
    2011-11-23	08:41:20:131	1004	1990	Misc	WARNING: WinHttp: ShouldFileBeDownloaded failed with 0x80072efd
    2011-11-23	08:41:21:140	1004	1990	Misc	WARNING: SendRequest failed with hr = 80072efd. Proxy List used: <127.0.0.1:80> Bypass List used : <(null)> Auth Schemes used : <>
    2011-11-23	08:41:21:140	1004	1990	Misc	WARNING: WinHttp: SendRequestUsingProxy failed for <http://10.0.0.25/selfupdate/wuident.cab>. error 0x80072efd
    2011-11-23	08:41:21:140	1004	1990	Misc	WARNING: WinHttp: SendRequestToServerForFileInformation MakeRequest failed. error 0x80072efd
    2011-11-23	08:41:21:140	1004	1990	Misc	WARNING: WinHttp: SendRequestToServerForFileInformation failed with 0x80072efd
    2011-11-23	08:41:21:140	1004	1990	Misc	WARNING: WinHttp: ShouldFileBeDownloaded failed with 0x80072efd
    2011-11-23	08:41:22:150	1004	1990	Misc	WARNING: SendRequest failed with hr = 80072efd. Proxy List used: <127.0.0.1:80> Bypass List used : <(null)> Auth Schemes used : <>
    2011-11-23	08:41:22:150	1004	1990	Misc	WARNING: WinHttp: SendRequestUsingProxy failed for <http://10.0.0.25/selfupdate/wuident.cab>. error 0x80072efd
    2011-11-23	08:41:22:150	1004	1990	Misc	WARNING: WinHttp: SendRequestToServerForFileInformation MakeRequest failed. error 0x80072efd
    2011-11-23	08:41:22:150	1004	1990	Misc	WARNING: WinHttp: SendRequestToServerForFileInformation failed with 0x80072efd
    2011-11-23	08:41:22:150	1004	1990	Misc	WARNING: WinHttp: ShouldFileBeDownloaded failed with 0x80072efd
    2011-11-23	08:41:22:150	1004	1990	Misc	WARNING: DownloadFileInternal failed for http://10.0.0.25/selfupdate/wuident.cab: error 0x80072efd
    2011-11-23	08:41:22:150	1004	1990	Setup	WARNING: SelfUpdate check failed to download package information, error = 0x80072EFD
    2011-11-23	08:41:22:150	1004	1990	Setup	FATAL: SelfUpdate check failed, err = 0x80072EFD
    2011-11-23	08:41:22:150	1004	1990	Agent	  * WARNING: Skipping scan, self-update check returned 0x80072EFD
    2011-11-23	08:41:22:150	1004	1990	Agent	  * WARNING: Exit code = 0x80072EFD
    2011-11-23	08:41:22:151	1004	1990	Agent	*********
    2011-11-23	08:41:22:151	1004	1990	Agent	**  END  **  Agent: Finding updates [CallerId = AutomaticUpdates]
    2011-11-23	08:41:22:151	1004	1990	Agent	*************
    2011-11-23	08:41:22:151	1004	1990	Agent	WARNING: WU client failed Searching for update with error 0x80072efd
    2011-11-23	08:41:22:151	1004	1990	Agent	*************
    2011-11-23	08:41:22:151	1004	1990	Agent	** START **  Agent: Finding updates [CallerId = ]
    2011-11-23	08:41:22:151	1004	1990	Agent	*********
    2011-11-23	08:41:22:151	1004	1990	Agent	  * Online = Yes; Ignore download priority = No
    2011-11-23	08:41:22:151	1004	1990	Agent	  * Criteria = "IsInstalled = 0 AND IsHidden = 0"
    2011-11-23	08:41:22:151	1004	1990	Agent	  * ServiceID = {00000000-0000-0000-0000-000000000000} Third party service
    2011-11-23	08:41:22:151	1004	1990	Agent	  * Search Scope = {Machine}
    2011-11-23	08:41:22:151	1004	1ba0	AU	>>##  RESUMED  ## AU: Search for updates [CallId = {6C676D9B-F9CB-447E-BC1B-2CAAC4FD0732}]
    2011-11-23	08:41:22:151	1004	1ba0	AU	  # WARNING: Search callback failed, result = 0x80072EFD
    2011-11-23	08:41:22:151	1004	1ba0	AU	  # WARNING: Failed to find updates with error code 80072EFD
    2011-11-23	08:41:22:151	1004	1ba0	AU	#########
    2011-11-23	08:41:22:151	1004	1ba0	AU	##  END  ##  AU: Search for updates [CallId = {6C676D9B-F9CB-447E-BC1B-2CAAC4FD0732}]
    2011-11-23	08:41:22:151	1004	1ba0	AU	#############
    2011-11-23	08:41:22:151	1004	1ba0	AU	Successfully wrote event for AU health state:0
    2011-11-23	08:41:22:151	1004	1ba0	AU	AU setting next detection timeout to 2011-11-23 14:30:48
    2011-11-23	08:41:22:152	1004	1ba0	AU	Setting AU scheduled install time to 2011-11-24 21:00:00
    2011-11-23	08:41:22:152	1004	1ba0	AU	Successfully wrote event for AU health state:0
    2011-11-23	08:41:22:152	1004	1ba0	AU	Successfully wrote event for AU health state:0
    2011-11-23	08:41:22:244	1004	1990	PT	+++++++++++  PT: Synchronizing server updates  +++++++++++
    2011-11-23	08:41:22:244	1004	1990	PT	  + ServiceId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}, Server URL = http://10.0.0.25/ClientWebService/client.asmx
    2011-11-23	08:41:23:246	1004	1990	Misc	WARNING: SendRequest failed with hr = 80072efd. Proxy List used: <127.0.0.1:80> Bypass List used : <(null)> Auth Schemes used : <>
    2011-11-23	08:41:23:246	1004	1990	PT	  + Last proxy send request failed with hr = 0x80072EFD, HTTP status code = 0
    2011-11-23	08:41:23:246	1004	1990	PT	  + Caller provided proxy = No
    2011-11-23	08:41:23:246	1004	1990	PT	  + Proxy list used = 127.0.0.1:80
    2011-11-23	08:41:23:246	1004	1990	PT	  + Bypass list used = <NULL>
    2011-11-23	08:41:23:246	1004	1990	PT	  + Caller provided credentials = No
    2011-11-23	08:41:23:246	1004	1990	PT	  + Impersonate flags = 0
    2011-11-23	08:41:23:246	1004	1990	PT	  + Possible authorization schemes used = 
    2011-11-23	08:41:23:246	1004	1990	PT	WARNING: GetConfig failure, error = 0x80072EFD, soap client error = 5, soap error code = 0, HTTP status code = 200
    2011-11-23	08:41:23:246	1004	1990	PT	WARNING: PTError: 0x80072efd
    2011-11-23	08:41:23:246	1004	1990	PT	WARNING: GetConfig_WithRecovery failed: 0x80072efd
    2011-11-23	08:41:23:246	1004	1990	PT	WARNING: RefreshConfig failed: 0x80072efd
    2011-11-23	08:41:23:246	1004	1990	PT	WARNING: RefreshPTState failed: 0x80072efd
    2011-11-23	08:41:23:246	1004	1990	PT	WARNING: Sync of Updates: 0x80072efd
    2011-11-23	08:41:23:246	1004	1990	PT	WARNING: SyncServerUpdatesInternal failed: 0x80072efd
    2011-11-23	08:41:23:246	1004	1990	Agent	  * WARNING: Failed to synchronize, error = 0x80072EFD
    2011-11-23	08:41:23:247	1004	1990	Agent	  * WARNING: Exit code = 0x80072EFD
    2011-11-23	08:41:23:247	1004	1990	Agent	*********
    2011-11-23	08:41:23:247	1004	1990	Agent	**  END  **  Agent: Finding updates [CallerId = ]
    2011-11-23	08:41:23:247	1004	1990	Agent	*************
    2011-11-23	08:41:23:247	1004	1990	Agent	WARNING: WU client failed Searching for update with error 0x80072efd
    2011-11-23	08:41:23:247	1004	1990	Report	REPORT EVENT: {8AE02A8F-F354-42D4-8483-7255C31233D5}	2011-11-23 08:41:22:150-0500	1	148	101	{D67661EB-2423-451D-BF5D-13199E37DF28}	1	80072efd	SelfUpdate	Failure	Software Synchronization	Windows Update Client failed to detect with error 0x80072efd.
    2011-11-23	08:41:23:247	1792	f10	COMAPI	>>--  RESUMED  -- COMAPI: Search [ClientId = <NULL>]
    2011-11-23	08:41:23:248	1792	f10	COMAPI	  - Updates found = 0
    2011-11-23	08:41:23:248	1792	f10	COMAPI	  - WARNING: Exit code = 0x00000000, Result code = 0x80072EFD
    2011-11-23	08:41:23:248	1792	f10	COMAPI	---------
    2011-11-23	08:41:23:248	1792	f10	COMAPI	--  END  --  COMAPI: Search [ClientId = <NULL>]
    2011-11-23	08:41:23:248	1792	f10	COMAPI	-------------
    2011-11-23	08:41:23:248	1792	88c	COMAPI	WARNING: Operation failed due to earlier error, hr=80072EFD
    2011-11-23	08:41:23:248	1792	88c	COMAPI	FATAL: Unable to perform synchronous search. (hr=80072EFD)
    2011-11-23	08:41:23:253	1004	1990	Report	CWERReporter::HandleEvents - WER report upload completed with status 0x8
    2011-11-23	08:41:23:253	1004	1990	Report	WER Report sent: 7.5.7601.17514 0x80072efd D67661EB-2423-451D-BF5D-13199E37DF28 Scan 101 Managed
    2011-11-23	08:41:23:253	1004	1990	Report	CWERReporter finishing event handling. (00000000)
    2011-11-23	08:41:23:253	1792	88c	COMAPI	-------------
    2011-11-23	08:41:23:253	1792	88c	COMAPI	-- START --  COMAPI: Search [ClientId = <NULL>]
    2011-11-23	08:41:23:253	1792	88c	COMAPI	---------
    2011-11-23	08:41:23:255	1004	1990	Agent	*************
    2011-11-23	08:41:23:255	1004	1990	Agent	** START **  Agent: Finding updates [CallerId = ]
    2011-11-23	08:41:23:255	1004	1990	Agent	*********
    2011-11-23	08:41:23:255	1004	1990	Agent	  * Online = Yes; Ignore download priority = No
    2011-11-23	08:41:23:255	1792	88c	COMAPI	<<-- SUBMITTED -- COMAPI: Search [ClientId = <NULL>]
    2011-11-23	08:41:23:255	1004	1990	Agent	  * Criteria = "IsInstalled = 0 AND IsHidden = 0"
    2011-11-23	08:41:23:255	1004	1990	Agent	  * ServiceID = {00000000-0000-0000-0000-000000000000} Third party service
    2011-11-23	08:41:23:255	1004	1990	Agent	  * Search Scope = {Machine}
    2011-11-23	08:41:23:350	1004	1990	PT	+++++++++++  PT: Synchronizing server updates  +++++++++++
    2011-11-23	08:41:23:350	1004	1990	PT	  + ServiceId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}, Server URL = http://10.0.0.25/ClientWebService/client.asmx
    2011-11-23	08:41:24:362	1004	1990	Misc	WARNING: SendRequest failed with hr = 80072efd. Proxy List used: <127.0.0.1:80> Bypass List used : <(null)> Auth Schemes used : <>
    2011-11-23	08:41:24:362	1004	1990	PT	  + Last proxy send request failed with hr = 0x80072EFD, HTTP status code = 0
    2011-11-23	08:41:24:362	1004	1990	PT	  + Caller provided proxy = No
    2011-11-23	08:41:24:362	1004	1990	PT	  + Proxy list used = 127.0.0.1:80
    2011-11-23	08:41:24:362	1004	1990	PT	  + Bypass list used = <NULL>
    2011-11-23	08:41:24:362	1004	1990	PT	  + Caller provided credentials = No
    2011-11-23	08:41:24:362	1004	1990	PT	  + Impersonate flags = 0
    2011-11-23	08:41:24:362	1004	1990	PT	  + Possible authorization schemes used = 
    2011-11-23	08:41:24:362	1004	1990	PT	WARNING: GetConfig failure, error = 0x80072EFD, soap client error = 5, soap error code = 0, HTTP status code = 200
    2011-11-23	08:41:24:362	1004	1990	PT	WARNING: PTError: 0x80072efd
    2011-11-23	08:41:24:362	1004	1990	PT	WARNING: GetConfig_WithRecovery failed: 0x80072efd
    2011-11-23	08:41:24:362	1004	1990	PT	WARNING: RefreshConfig failed: 0x80072efd
    2011-11-23	08:41:24:362	1004	1990	PT	WARNING: RefreshPTState failed: 0x80072efd
    2011-11-23	08:41:24:362	1004	1990	PT	WARNING: Sync of Updates: 0x80072efd
    2011-11-23	08:41:24:362	1004	1990	PT	WARNING: SyncServerUpdatesInternal failed: 0x80072efd
    2011-11-23	08:41:24:362	1004	1990	Agent	  * WARNING: Failed to synchronize, error = 0x80072EFD
    2011-11-23	08:41:24:363	1004	1990	Agent	  * WARNING: Exit code = 0x80072EFD
    2011-11-23	08:41:24:363	1004	1990	Agent	*********
    2011-11-23	08:41:24:363	1004	1990	Agent	**  END  **  Agent: Finding updates [CallerId = ]
    2011-11-23	08:41:24:363	1004	1990	Agent	*************
    2011-11-23	08:41:24:363	1004	1990	Agent	WARNING: WU client failed Searching for update with error 0x80072efd
    2011-11-23	08:41:24:363	1792	f10	COMAPI	>>--  RESUMED  -- COMAPI: Search [ClientId = <NULL>]
    2011-11-23	08:41:24:364	1792	f10	COMAPI	  - Updates found = 0
    2011-11-23	08:41:24:364	1792	f10	COMAPI	  - WARNING: Exit code = 0x00000000, Result code = 0x80072EFD
    2011-11-23	08:41:24:364	1792	f10	COMAPI	---------
    2011-11-23	08:41:24:364	1792	f10	COMAPI	--  END  --  COMAPI: Search [ClientId = <NULL>]
    2011-11-23	08:41:24:364	1792	f10	COMAPI	-------------
    2011-11-23	08:41:24:364	1792	88c	COMAPI	WARNING: Operation failed due to earlier error, hr=80072EFD
    2011-11-23	08:41:24:364	1792	88c	COMAPI	FATAL: Unable to perform synchronous search. (hr=80072EFD)
    2011-11-23	08:41:27:150	1004	1990	Report	REPORT EVENT: {34F60A0A-945B-4482-85F7-ED7FB69B9B4B}	2011-11-23 08:41:23:247-0500	1	148	101	{00000000-0000-0000-0000-000000000000}	0	80072efd		Failure	Software Synchronization	Windows Update Client failed to detect with error 0x80072efd.
    2011-11-23	08:41:27:150	1004	1990	Report	REPORT EVENT: {B10408FD-7B84-4A0F-BBB4-94360927E254}	2011-11-23 08:41:24:363-0500	1	148	101	{00000000-0000-0000-0000-000000000000}	0	80072efd		Failure	Software Synchronization	Windows Update Client failed to detect with error 0x80072efd.
    2011-11-23	08:41:27:155	1004	1990	Report	CWERReporter::HandleEvents - WER report upload completed with status 0x8
    2011-11-23	08:41:27:155	1004	1990	Report	WER Report sent: 7.5.7601.17514 0x80072efd 00000000-0000-0000-0000-000000000000 Scan 101 Managed
    2011-11-23	08:41:27:160	1004	1990	Report	CWERReporter::HandleEvents - WER report upload completed with status 0x8
    2011-11-23	08:41:27:160	1004	1990	Report	WER Report sent: 7.5.7601.17514 0x80072efd 00000000-0000-0000-0000-000000000000 Scan 101 Managed
    2011-11-23	08:41:27:160	1004	1990	Report	CWERReporter finishing event handling. (00000000)
    

     

    The 127.0.0.1:80 stuff is still in there.

     

    I'll check the article you suggest and see if I find anything in there.  If I do I'll write back.  Maybe this new WindowsUpdate.log file provides any new clues?  Again thanks for the help.


    • Edited by RockAdmin Wednesday, November 23, 2011 1:46 PM
    Wednesday, November 23, 2011 1:45 PM
  • Another tidbit, is while I am able to access and download cab files (http://10.0.0.25/iuident.cab for example), I am unable to access my http://10.0.0.25/ClientWebService/client.asmx page from any machine I've tried, including from the WSUS server.  The reason I tried it, as I noticed going through my WindowsUpdate.log, that seems to be the first problem that shows up:

     

    2011-11-23	09:48:01:727	1004	1af0	PT	  + ServiceId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}, Server URL = http://10.0.0.25:80/ClientWebService/client.asmx
    2011-11-23	09:48:02:729	1004	1af0	Misc	WARNING: SendRequest failed with hr = 80072efd. Proxy List used: <127.0.0.1:80> Bypass List used : <(null)> Auth Schemes used : <>
    2011-11-23	09:48:02:729	1004	1af0	PT	  + Last proxy send request failed with hr = 0x80072EFD, HTTP status code = 0

     


    So if I try and access it, I get the following runtime error page in my browser:

    Server Error in '/ClientWebService' Application.

    Runtime Error

    Description: An application error occurred on the server. The current custom error settings for this application prevent the details of the application error from being viewed remotely (for security reasons). It could, however, be viewed by browsers running on the local server machine.

    Details: To enable the details of this specific error message to be viewable on remote machines, please create a <customErrors> tag within a "web.config" configuration file located in the root directory of the current web application. This <customErrors> tag should then have its "mode" attribute set to "Off".

    <!-- Web.Config Configuration File -->
    
    <configuration>
        <system.web>
            <customErrors mode="Off"/>
        </system.web>
    </configuration>


    Notes: The current error page you are seeing can be replaced by a custom error page by modifying the "defaultRedirect" attribute of the application's <customErrors> configuration tag to point to a custom error page URL.

    <!-- Web.Config Configuration File -->
    
    <configuration>
        <system.web>
            <customErrors mode="RemoteOnly" defaultRedirect="mycustompage.htm"/>
        </system.web>
    </configuration>

    Is being able to access this page important?  Maybe I'm looking at an IIS problem.

    Wednesday, November 23, 2011 3:16 PM
  • Is being able to access this page important?  Maybe I'm looking at an IIS problem.


    Nope, that's not the problem... I've the same behaviour because WSUS site is not browsable...

    I also find it strange that you still have proxy info on the log.

    Maybe I'm insisting on the wrong possible cause, but can you try the following:

    • Run on a elevated command line the proxycfg.exe -D again
    • Run "net stop wuauserv"
    • Run "net start wuauserv"
    • Run "wuauclt /detectnow /resetauthorization"
    • Post the results here, please.

     

     


    Tiago Viana, MCITP:SA
    Wednesday, November 23, 2011 3:30 PM
  • I followed your instructions, and here is the WindowsUpdate.log after doing that, and trying to get updates:

    2011-11-23	10:47:04:909	1004	1a08	Misc	===========  Logging initialized (build: 7.5.7601.17514, tz: -0500)  ===========
    2011-11-23	10:47:04:909	1004	1a08	Misc	  = Process: C:\Windows\system32\svchost.exe
    2011-11-23	10:47:04:909	1004	1a08	Misc	  = Module: c:\windows\system32\wuaueng.dll
    2011-11-23	10:47:04:909	1004	1a08	Service	*************
    2011-11-23	10:47:04:909	1004	1a08	Service	** START **  Service: Service startup
    2011-11-23	10:47:04:909	1004	1a08	Service	*********
    2011-11-23	10:47:04:910	1004	1a08	Agent	  * WU client version 7.5.7601.17514
    2011-11-23	10:47:04:910	1004	1a08	Agent	  * Base directory: C:\Windows\SoftwareDistribution
    2011-11-23	10:47:04:910	1004	1a08	Agent	  * Access type: No proxy
    2011-11-23	10:47:04:911	1004	1a08	Agent	  * Network state: Connected
    2011-11-23	10:47:04:946	1004	738	Report	CWERReporter::Init succeeded
    2011-11-23	10:47:04:946	1004	738	Agent	***********  Agent: Initializing Windows Update Agent  ***********
    2011-11-23	10:47:04:946	1004	738	Agent	***********  Agent: Initializing global settings cache  ***********
    2011-11-23	10:47:04:946	1004	738	Agent	  * WSUS server: http://10.0.0.25
    2011-11-23	10:47:04:946	1004	738	Agent	  * WSUS status server: http://10.0.0.25
    2011-11-23	10:47:04:946	1004	738	Agent	  * Target group: RIG Workstations
    2011-11-23	10:47:04:946	1004	738	Agent	  * Windows Update access disabled: No
    2011-11-23	10:47:04:947	1004	738	DnldMgr	Download manager restoring 0 downloads
    2011-11-23	10:47:05:230	1004	1a08	Report	***********  Report: Initializing static reporting data  ***********
    2011-11-23	10:47:05:230	1004	1a08	Report	  * OS Version = 6.1.7601.1.0.65792
    2011-11-23	10:47:05:230	1004	1a08	Report	  * OS Product Type = 0x00000030
    2011-11-23	10:47:05:239	1004	1a08	Report	  * Computer Brand = Dell Inc.
    2011-11-23	10:47:05:239	1004	1a08	Report	  * Computer Model = OptiPlex 780                 
    2011-11-23	10:47:05:242	1004	1a08	Report	  * Bios Revision = A08
    2011-11-23	10:47:05:242	1004	1a08	Report	  * Bios Name = Phoenix ROM BIOS PLUS Version 1.10 A08
    2011-11-23	10:47:05:242	1004	1a08	Report	  * Bios Release Date = 2011-01-21T00:00:00
    2011-11-23	10:47:05:242	1004	1a08	Report	  * Locale ID = 1033
    2011-11-23	10:47:05:242	1004	1084	Agent	*************
    2011-11-23	10:47:05:242	1004	1084	Agent	** START **  Agent: Finding updates [CallerId = ]
    2011-11-23	10:47:05:242	1004	1084	Agent	*********
    2011-11-23	10:47:05:242	1004	1084	Agent	  * Online = Yes; Ignore download priority = No
    2011-11-23	10:47:05:242	1004	1084	Agent	  * Criteria = "IsInstalled = 0 AND IsHidden = 0"
    2011-11-23	10:47:05:242	1004	1084	Agent	  * ServiceID = {00000000-0000-0000-0000-000000000000} Third party service
    2011-11-23	10:47:05:243	1004	1084	Agent	  * Search Scope = {Machine}
    2011-11-23	10:47:05:320	1004	1084	PT	+++++++++++  PT: Synchronizing server updates  +++++++++++
    2011-11-23	10:47:05:320	1004	1084	PT	  + ServiceId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}, Server URL = http://10.0.0.25/ClientWebService/client.asmx
    2011-11-23	10:47:06:326	1004	1084	Misc	WARNING: SendRequest failed with hr = 80072efd. Proxy List used: <127.0.0.1:80> Bypass List used : <(null)> Auth Schemes used : <>
    2011-11-23	10:47:06:326	1004	1084	PT	  + Last proxy send request failed with hr = 0x80072EFD, HTTP status code = 0
    2011-11-23	10:47:06:326	1004	1084	PT	  + Caller provided proxy = No
    2011-11-23	10:47:06:326	1004	1084	PT	  + Proxy list used = 127.0.0.1:80
    2011-11-23	10:47:06:326	1004	1084	PT	  + Bypass list used = <NULL>
    2011-11-23	10:47:06:326	1004	1084	PT	  + Caller provided credentials = No
    2011-11-23	10:47:06:326	1004	1084	PT	  + Impersonate flags = 0
    2011-11-23	10:47:06:326	1004	1084	PT	  + Possible authorization schemes used = 
    2011-11-23	10:47:06:326	1004	1084	PT	WARNING: GetConfig failure, error = 0x80072EFD, soap client error = 5, soap error code = 0, HTTP status code = 200
    2011-11-23	10:47:06:326	1004	1084	PT	WARNING: PTError: 0x80072efd
    2011-11-23	10:47:06:326	1004	1084	PT	WARNING: GetConfig_WithRecovery failed: 0x80072efd
    2011-11-23	10:47:06:326	1004	1084	PT	WARNING: RefreshConfig failed: 0x80072efd
    2011-11-23	10:47:06:326	1004	1084	PT	WARNING: RefreshPTState failed: 0x80072efd
    2011-11-23	10:47:06:326	1004	1084	PT	WARNING: Sync of Updates: 0x80072efd
    2011-11-23	10:47:06:326	1004	1084	PT	WARNING: SyncServerUpdatesInternal failed: 0x80072efd
    2011-11-23	10:47:06:326	1004	1084	Agent	  * WARNING: Failed to synchronize, error = 0x80072EFD
    2011-11-23	10:47:06:327	1004	1084	Agent	  * WARNING: Exit code = 0x80072EFD
    2011-11-23	10:47:06:327	1004	1084	Agent	*********
    2011-11-23	10:47:06:327	1004	1084	Agent	**  END  **  Agent: Finding updates [CallerId = ]
    2011-11-23	10:47:06:327	1004	1084	Agent	*************
    2011-11-23	10:47:06:327	1004	1084	Agent	WARNING: WU client failed Searching for update with error 0x80072efd
    2011-11-23	10:47:07:336	1004	1084	Misc	WARNING: SendRequest failed with hr = 80072efd. Proxy List used: <127.0.0.1:80> Bypass List used : <(null)> Auth Schemes used : <>
    2011-11-23	10:47:07:336	1004	1084	PT	  + Last proxy send request failed with hr = 0x80072EFD, HTTP status code = 0
    2011-11-23	10:47:07:336	1004	1084	PT	  + Caller provided proxy = No
    2011-11-23	10:47:07:336	1004	1084	PT	  + Proxy list used = 127.0.0.1:80
    2011-11-23	10:47:07:336	1004	1084	PT	  + Bypass list used = <NULL>
    2011-11-23	10:47:07:336	1004	1084	PT	  + Caller provided credentials = No
    2011-11-23	10:47:07:336	1004	1084	PT	  + Impersonate flags = 0
    2011-11-23	10:47:07:336	1004	1084	PT	  + Possible authorization schemes used = 
    2011-11-23	10:47:07:336	1004	1084	PT	WARNING: GetConfig failure, error = 0x80072EFD, soap client error = 5, soap error code = 0, HTTP status code = 200
    2011-11-23	10:47:07:336	1004	1084	PT	WARNING: PTError: 0x80072efd
    2011-11-23	10:47:07:336	1004	1084	PT	WARNING: GetConfig_WithRecovery failed: 0x80072efd
    2011-11-23	10:47:07:336	1004	1084	PT	WARNING: RefreshConfig failed: 0x80072efd
    2011-11-23	10:47:07:336	1004	1084	PT	WARNING: RefreshPTState failed: 0x80072efd
    2011-11-23	10:47:07:336	1004	1084	PT	WARNING: PTError: 0x80072efd
    2011-11-23	10:47:07:337	1004	1084	Report	WARNING: Reporter failed to upload events with hr = 80072efd.
    2011-11-23	10:47:08:339	1004	1084	Misc	WARNING: SendRequest failed with hr = 80072efd. Proxy List used: <127.0.0.1:80> Bypass List used : <(null)> Auth Schemes used : <>
    2011-11-23	10:47:08:339	1004	1084	PT	  + Last proxy send request failed with hr = 0x80072EFD, HTTP status code = 0
    2011-11-23	10:47:08:339	1004	1084	PT	  + Caller provided proxy = No
    2011-11-23	10:47:08:339	1004	1084	PT	  + Proxy list used = 127.0.0.1:80
    2011-11-23	10:47:08:339	1004	1084	PT	  + Bypass list used = <NULL>
    2011-11-23	10:47:08:339	1004	1084	PT	  + Caller provided credentials = No
    2011-11-23	10:47:08:339	1004	1084	PT	  + Impersonate flags = 0
    2011-11-23	10:47:08:339	1004	1084	PT	  + Possible authorization schemes used = 
    2011-11-23	10:47:08:339	1004	1084	PT	WARNING: GetConfig failure, error = 0x80072EFD, soap client error = 5, soap error code = 0, HTTP status code = 200
    2011-11-23	10:47:08:339	1004	1084	PT	WARNING: PTError: 0x80072efd
    2011-11-23	10:47:08:339	1004	1084	PT	WARNING: GetConfig_WithRecovery failed: 0x80072efd
    2011-11-23	10:47:08:339	1004	1084	PT	WARNING: RefreshConfig failed: 0x80072efd
    2011-11-23	10:47:08:339	1004	1084	PT	WARNING: RefreshPTState failed: 0x80072efd
    2011-11-23	10:47:08:339	1004	1084	PT	WARNING: PTError: 0x80072efd
    2011-11-23	10:47:08:339	1004	1084	Report	WARNING: Reporter failed to upload events with hr = 80072efd.
    2011-11-23	10:47:10:242	1004	1084	Report	REPORT EVENT: {BF6CB15D-D4EE-46E6-81B2-5BF4B257BC3D}	2011-11-23 10:47:06:327-0500	1	148	101	{00000000-0000-0000-0000-000000000000}	0	80072efd		Failure	Software Synchronization	Windows Update Client failed to detect with error 0x80072efd.
    2011-11-23	10:47:10:260	1004	1084	Report	CWERReporter::HandleEvents - WER report upload completed with status 0x8
    2011-11-23	10:47:10:260	1004	1084	Report	WER Report sent: 7.5.7601.17514 0x80072efd 00000000-0000-0000-0000-000000000000 Scan 101 Managed
    2011-11-23	10:47:10:260	1004	1084	Report	CWERReporter finishing event handling. (00000000)
    2011-11-23	10:47:20:756	1004	738	AU	###########  AU: Initializing Automatic Updates  ###########
    2011-11-23	10:47:20:757	1004	738	AU	  # WSUS server: http://10.0.0.25
    2011-11-23	10:47:20:757	1004	738	AU	  # Detection frequency: 1
    2011-11-23	10:47:20:757	1004	738	AU	  # Target group: RIG Workstations
    2011-11-23	10:47:20:757	1004	738	AU	  # Approval type: Scheduled (Policy)
    2011-11-23	10:47:20:757	1004	738	AU	  # Scheduled install day/time: Thursday at 16:00
    2011-11-23	10:47:20:757	1004	738	AU	  # Auto-install minor updates: Yes (Policy)
    2011-11-23	10:47:20:757	1004	738	AU	  # Will interact with non-admins (Non-admins are elevated (Policy))
    2011-11-23	10:47:20:757	1004	738	AU	Setting AU scheduled install time to 2011-11-24 21:00:00
    2011-11-23	10:47:20:757	1004	738	AU	Successfully wrote event for AU health state:0
    2011-11-23	10:47:20:758	1004	738	AU	Initializing featured updates
    2011-11-23	10:47:20:758	1004	738	AU	Found 0 cached featured updates
    2011-11-23	10:47:20:758	1004	738	AU	Successfully wrote event for AU health state:0
    2011-11-23	10:47:20:758	1004	738	AU	Successfully wrote event for AU health state:0
    2011-11-23	10:47:20:759	1004	738	AU	AU finished delayed initialization
    2011-11-23	10:47:20:759	1004	738	AU	Triggering AU detection through DetectNow API
    2011-11-23	10:47:20:759	1004	738	AU	Triggering Online detection (non-interactive)
    2011-11-23	10:47:20:759	1004	1a08	AU	#############
    2011-11-23	10:47:20:759	1004	1a08	AU	## START ##  AU: Search for updates
    2011-11-23	10:47:20:759	1004	1a08	AU	#########
    2011-11-23	10:47:20:760	1004	1a08	AU	<<## SUBMITTED ## AU: Search for updates [CallId = {0F88FF8A-419C-4C52-B511-B5ED6BAF311D}]
    2011-11-23	10:47:20:760	1004	1084	Agent	*************
    2011-11-23	10:47:20:760	1004	1084	Agent	** START **  Agent: Finding updates [CallerId = AutomaticUpdates]
    2011-11-23	10:47:20:760	1004	1084	Agent	*********
    2011-11-23	10:47:20:760	1004	1084	Agent	  * Online = Yes; Ignore download priority = No
    2011-11-23	10:47:20:760	1004	1084	Agent	  * Criteria = "IsInstalled=0 and DeploymentAction='Installation' or IsPresent=1 and DeploymentAction='Uninstallation' or IsInstalled=1 and DeploymentAction='Installation' and RebootRequired=1 or IsInstalled=0 and DeploymentAction='Uninstallation' and RebootRequired=1"
    2011-11-23	10:47:20:760	1004	1084	Agent	  * ServiceID = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7} Managed
    2011-11-23	10:47:20:760	1004	1084	Agent	  * Search Scope = {Machine}
    2011-11-23	10:47:20:760	1004	1084	Setup	Checking for agent SelfUpdate
    2011-11-23	10:47:20:761	1004	1084	Setup	Client version: Core: 7.5.7601.17514  Aux: 7.5.7601.17514
    2011-11-23	10:47:20:771	1004	1084	Misc	Validating signature for C:\Windows\SoftwareDistribution\SelfUpdate\wuident.cab:
    2011-11-23	10:47:20:774	1004	1084	Misc	 Microsoft signed: Yes
    2011-11-23	10:47:21:774	1004	1084	Misc	WARNING: SendRequest failed with hr = 80072efd. Proxy List used: <127.0.0.1:80> Bypass List used : <(null)> Auth Schemes used : <>
    2011-11-23	10:47:21:774	1004	1084	Misc	WARNING: WinHttp: SendRequestUsingProxy failed for <http://10.0.0.25/selfupdate/wuident.cab>. error 0x80072efd
    2011-11-23	10:47:21:774	1004	1084	Misc	WARNING: WinHttp: SendRequestToServerForFileInformation MakeRequest failed. error 0x80072efd
    2011-11-23	10:47:21:774	1004	1084	Misc	WARNING: WinHttp: SendRequestToServerForFileInformation failed with 0x80072efd
    2011-11-23	10:47:21:774	1004	1084	Misc	WARNING: WinHttp: ShouldFileBeDownloaded failed with 0x80072efd
    2011-11-23	10:47:22:776	1004	1084	Misc	WARNING: SendRequest failed with hr = 80072efd. Proxy List used: <127.0.0.1:80> Bypass List used : <(null)> Auth Schemes used : <>
    2011-11-23	10:47:22:776	1004	1084	Misc	WARNING: WinHttp: SendRequestUsingProxy failed for <http://10.0.0.25/selfupdate/wuident.cab>. error 0x80072efd
    2011-11-23	10:47:22:776	1004	1084	Misc	WARNING: WinHttp: SendRequestToServerForFileInformation MakeRequest failed. error 0x80072efd
    2011-11-23	10:47:22:776	1004	1084	Misc	WARNING: WinHttp: SendRequestToServerForFileInformation failed with 0x80072efd
    2011-11-23	10:47:22:776	1004	1084	Misc	WARNING: WinHttp: ShouldFileBeDownloaded failed with 0x80072efd
    2011-11-23	10:47:23:778	1004	1084	Misc	WARNING: SendRequest failed with hr = 80072efd. Proxy List used: <127.0.0.1:80> Bypass List used : <(null)> Auth Schemes used : <>
    2011-11-23	10:47:23:778	1004	1084	Misc	WARNING: WinHttp: SendRequestUsingProxy failed for <http://10.0.0.25/selfupdate/wuident.cab>. error 0x80072efd
    2011-11-23	10:47:23:778	1004	1084	Misc	WARNING: WinHttp: SendRequestToServerForFileInformation MakeRequest failed. error 0x80072efd
    2011-11-23	10:47:23:778	1004	1084	Misc	WARNING: WinHttp: SendRequestToServerForFileInformation failed with 0x80072efd
    2011-11-23	10:47:23:778	1004	1084	Misc	WARNING: WinHttp: ShouldFileBeDownloaded failed with 0x80072efd
    2011-11-23	10:47:24:780	1004	1084	Misc	WARNING: SendRequest failed with hr = 80072efd. Proxy List used: <127.0.0.1:80> Bypass List used : <(null)> Auth Schemes used : <>
    2011-11-23	10:47:24:780	1004	1084	Misc	WARNING: WinHttp: SendRequestUsingProxy failed for <http://10.0.0.25/selfupdate/wuident.cab>. error 0x80072efd
    2011-11-23	10:47:24:780	1004	1084	Misc	WARNING: WinHttp: SendRequestToServerForFileInformation MakeRequest failed. error 0x80072efd
    2011-11-23	10:47:24:780	1004	1084	Misc	WARNING: WinHttp: SendRequestToServerForFileInformation failed with 0x80072efd
    2011-11-23	10:47:24:780	1004	1084	Misc	WARNING: WinHttp: ShouldFileBeDownloaded failed with 0x80072efd
    2011-11-23	10:47:24:780	1004	1084	Misc	WARNING: DownloadFileInternal failed for http://10.0.0.25/selfupdate/wuident.cab: error 0x80072efd
    2011-11-23	10:47:24:780	1004	1084	Setup	WARNING: SelfUpdate check failed to download package information, error = 0x80072EFD
    2011-11-23	10:47:24:780	1004	1084	Setup	FATAL: SelfUpdate check failed, err = 0x80072EFD
    2011-11-23	10:47:24:780	1004	1084	Agent	  * WARNING: Skipping scan, self-update check returned 0x80072EFD
    2011-11-23	10:47:24:780	1004	1084	Agent	  * WARNING: Exit code = 0x80072EFD
    2011-11-23	10:47:24:781	1004	1084	Agent	*********
    2011-11-23	10:47:24:781	1004	1084	Agent	**  END  **  Agent: Finding updates [CallerId = AutomaticUpdates]
    2011-11-23	10:47:24:781	1004	1084	Agent	*************
    2011-11-23	10:47:24:781	1004	1084	Agent	WARNING: WU client failed Searching for update with error 0x80072efd
    2011-11-23	10:47:24:781	1004	1084	Agent	*************
    2011-11-23	10:47:24:781	1004	1084	Agent	** START **  Agent: Finding updates [CallerId = ]
    2011-11-23	10:47:24:781	1004	1084	Agent	*********
    2011-11-23	10:47:24:781	1004	1084	Agent	  * Online = Yes; Ignore download priority = No
    2011-11-23	10:47:24:781	1004	1084	Agent	  * Criteria = "IsInstalled = 0 AND IsHidden = 0"
    2011-11-23	10:47:24:781	1004	1084	Agent	  * ServiceID = {00000000-0000-0000-0000-000000000000} Third party service
    2011-11-23	10:47:24:781	1004	1084	Agent	  * Search Scope = {Machine}
    2011-11-23	10:47:24:781	1004	914	AU	>>##  RESUMED  ## AU: Search for updates [CallId = {0F88FF8A-419C-4C52-B511-B5ED6BAF311D}]
    2011-11-23	10:47:24:781	1004	914	AU	  # WARNING: Search callback failed, result = 0x80072EFD
    2011-11-23	10:47:24:781	1004	914	AU	  # WARNING: Failed to find updates with error code 80072EFD
    2011-11-23	10:47:24:781	1004	914	AU	#########
    2011-11-23	10:47:24:781	1004	914	AU	##  END  ##  AU: Search for updates [CallId = {0F88FF8A-419C-4C52-B511-B5ED6BAF311D}]
    2011-11-23	10:47:24:781	1004	914	AU	#############
    2011-11-23	10:47:24:781	1004	914	AU	Successfully wrote event for AU health state:0
    2011-11-23	10:47:24:781	1004	914	AU	AU setting next detection timeout to 2011-11-23 16:46:29
    2011-11-23	10:47:24:781	1004	914	AU	Setting AU scheduled install time to 2011-11-24 21:00:00
    2011-11-23	10:47:24:781	1004	914	AU	Successfully wrote event for AU health state:0
    2011-11-23	10:47:24:782	1004	914	AU	Successfully wrote event for AU health state:0
    2011-11-23	10:47:24:892	1004	1084	PT	+++++++++++  PT: Synchronizing server updates  +++++++++++
    2011-11-23	10:47:24:892	1004	1084	PT	  + ServiceId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}, Server URL = http://10.0.0.25/ClientWebService/client.asmx
    2011-11-23	10:47:25:894	1004	1084	Misc	WARNING: SendRequest failed with hr = 80072efd. Proxy List used: <127.0.0.1:80> Bypass List used : <(null)> Auth Schemes used : <>
    2011-11-23	10:47:25:894	1004	1084	PT	  + Last proxy send request failed with hr = 0x80072EFD, HTTP status code = 0
    2011-11-23	10:47:25:894	1004	1084	PT	  + Caller provided proxy = No
    2011-11-23	10:47:25:894	1004	1084	PT	  + Proxy list used = 127.0.0.1:80
    2011-11-23	10:47:25:894	1004	1084	PT	  + Bypass list used = <NULL>
    2011-11-23	10:47:25:894	1004	1084	PT	  + Caller provided credentials = No
    2011-11-23	10:47:25:894	1004	1084	PT	  + Impersonate flags = 0
    2011-11-23	10:47:25:894	1004	1084	PT	  + Possible authorization schemes used = 
    2011-11-23	10:47:25:894	1004	1084	PT	WARNING: GetConfig failure, error = 0x80072EFD, soap client error = 5, soap error code = 0, HTTP status code = 200
    2011-11-23	10:47:25:894	1004	1084	PT	WARNING: PTError: 0x80072efd
    2011-11-23	10:47:25:894	1004	1084	PT	WARNING: GetConfig_WithRecovery failed: 0x80072efd
    2011-11-23	10:47:25:894	1004	1084	PT	WARNING: RefreshConfig failed: 0x80072efd
    2011-11-23	10:47:25:894	1004	1084	PT	WARNING: RefreshPTState failed: 0x80072efd
    2011-11-23	10:47:25:894	1004	1084	PT	WARNING: Sync of Updates: 0x80072efd
    2011-11-23	10:47:25:894	1004	1084	PT	WARNING: SyncServerUpdatesInternal failed: 0x80072efd
    2011-11-23	10:47:25:894	1004	1084	Agent	  * WARNING: Failed to synchronize, error = 0x80072EFD
    2011-11-23	10:47:25:895	1004	1084	Agent	  * WARNING: Exit code = 0x80072EFD
    2011-11-23	10:47:25:895	1004	1084	Agent	*********
    2011-11-23	10:47:25:895	1004	1084	Agent	**  END  **  Agent: Finding updates [CallerId = ]
    2011-11-23	10:47:25:895	1004	1084	Agent	*************
    2011-11-23	10:47:25:895	1004	1084	Agent	WARNING: WU client failed Searching for update with error 0x80072efd
    2011-11-23	10:47:25:895	1004	1084	Report	REPORT EVENT: {7FA36D4F-AB8E-4F4C-A730-47B822BDB86C}	2011-11-23 10:47:24:780-0500	1	148	101	{D67661EB-2423-451D-BF5D-13199E37DF28}	1	80072efd	SelfUpdate	Failure	Software Synchronization	Windows Update Client failed to detect with error 0x80072efd.
    2011-11-23	10:47:25:901	1004	1084	Report	CWERReporter::HandleEvents - WER report upload completed with status 0x8
    2011-11-23	10:47:25:901	1004	1084	Report	WER Report sent: 7.5.7601.17514 0x80072efd D67661EB-2423-451D-BF5D-13199E37DF28 Scan 101 Managed
    2011-11-23	10:47:25:901	1004	1084	Report	CWERReporter finishing event handling. (00000000)
    2011-11-23	10:47:25:903	1004	1084	Agent	*************
    2011-11-23	10:47:25:903	1004	1084	Agent	** START **  Agent: Finding updates [CallerId = ]
    2011-11-23	10:47:25:903	1004	1084	Agent	*********
    2011-11-23	10:47:25:903	1004	1084	Agent	  * Online = Yes; Ignore download priority = No
    2011-11-23	10:47:25:903	1004	1084	Agent	  * Criteria = "IsInstalled = 0 AND IsHidden = 0"
    2011-11-23	10:47:25:903	1004	1084	Agent	  * ServiceID = {00000000-0000-0000-0000-000000000000} Third party service
    2011-11-23	10:47:25:903	1004	1084	Agent	  * Search Scope = {Machine}
    2011-11-23	10:47:26:013	1004	1084	PT	+++++++++++  PT: Synchronizing server updates  +++++++++++
    2011-11-23	10:47:26:013	1004	1084	PT	  + ServiceId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}, Server URL = http://10.0.0.25/ClientWebService/client.asmx
    2011-11-23	10:47:27:008	1004	1084	Misc	WARNING: SendRequest failed with hr = 80072efd. Proxy List used: <127.0.0.1:80> Bypass List used : <(null)> Auth Schemes used : <>
    2011-11-23	10:47:27:008	1004	1084	PT	  + Last proxy send request failed with hr = 0x80072EFD, HTTP status code = 0
    2011-11-23	10:47:27:008	1004	1084	PT	  + Caller provided proxy = No
    2011-11-23	10:47:27:008	1004	1084	PT	  + Proxy list used = 127.0.0.1:80
    2011-11-23	10:47:27:008	1004	1084	PT	  + Bypass list used = <NULL>
    2011-11-23	10:47:27:008	1004	1084	PT	  + Caller provided credentials = No
    2011-11-23	10:47:27:008	1004	1084	PT	  + Impersonate flags = 0
    2011-11-23	10:47:27:008	1004	1084	PT	  + Possible authorization schemes used = 
    2011-11-23	10:47:27:008	1004	1084	PT	WARNING: GetConfig failure, error = 0x80072EFD, soap client error = 5, soap error code = 0, HTTP status code = 200
    2011-11-23	10:47:27:008	1004	1084	PT	WARNING: PTError: 0x80072efd
    2011-11-23	10:47:27:008	1004	1084	PT	WARNING: GetConfig_WithRecovery failed: 0x80072efd
    2011-11-23	10:47:27:008	1004	1084	PT	WARNING: RefreshConfig failed: 0x80072efd
    2011-11-23	10:47:27:008	1004	1084	PT	WARNING: RefreshPTState failed: 0x80072efd
    2011-11-23	10:47:27:008	1004	1084	PT	WARNING: Sync of Updates: 0x80072efd
    2011-11-23	10:47:27:008	1004	1084	PT	WARNING: SyncServerUpdatesInternal failed: 0x80072efd
    2011-11-23	10:47:27:008	1004	1084	Agent	  * WARNING: Failed to synchronize, error = 0x80072EFD
    2011-11-23	10:47:27:009	1004	1084	Agent	  * WARNING: Exit code = 0x80072EFD
    2011-11-23	10:47:27:009	1004	1084	Agent	*********
    2011-11-23	10:47:27:009	1004	1084	Agent	**  END  **  Agent: Finding updates [CallerId = ]
    2011-11-23	10:47:27:009	1004	1084	Agent	*************
    2011-11-23	10:47:27:009	1004	1084	Agent	WARNING: WU client failed Searching for update with error 0x80072efd
    2011-11-23	10:47:28:073	1004	738	AU	Triggering AU detection through DetectNow API
    2011-11-23	10:47:28:073	1004	738	AU	Triggering Online detection (interactive)
    2011-11-23	10:47:28:073	1004	1a08	AU	#############
    2011-11-23	10:47:28:073	1004	1a08	AU	## START ##  AU: Search for updates
    2011-11-23	10:47:28:073	1004	1a08	AU	#########
    2011-11-23	10:47:28:074	1004	1a08	AU	<<## SUBMITTED ## AU: Search for updates [CallId = {F37DC9E0-257A-4CB6-8535-F503EA3EC94F}]
    2011-11-23	10:47:28:074	1004	1084	Agent	*************
    2011-11-23	10:47:28:074	1004	1084	Agent	** START **  Agent: Finding updates [CallerId = AutomaticUpdates]
    2011-11-23	10:47:28:074	1004	1084	Agent	*********
    2011-11-23	10:47:28:074	1004	1084	Agent	  * Online = Yes; Ignore download priority = No
    2011-11-23	10:47:28:074	1004	1084	Agent	  * Criteria = "IsInstalled=0 and DeploymentAction='Installation' or IsPresent=1 and DeploymentAction='Uninstallation' or IsInstalled=1 and DeploymentAction='Installation' and RebootRequired=1 or IsInstalled=0 and DeploymentAction='Uninstallation' and RebootRequired=1"
    2011-11-23	10:47:28:074	1004	1084	Agent	  * ServiceID = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7} Managed
    2011-11-23	10:47:28:074	1004	1084	Agent	  * Search Scope = {Machine}
    2011-11-23	10:47:28:074	1004	1084	Setup	Checking for agent SelfUpdate
    2011-11-23	10:47:28:075	1004	1084	Setup	Client version: Core: 7.5.7601.17514  Aux: 7.5.7601.17514
    2011-11-23	10:47:28:075	1004	1084	Misc	Validating signature for C:\Windows\SoftwareDistribution\SelfUpdate\wuident.cab:
    2011-11-23	10:47:28:078	1004	1084	Misc	 Microsoft signed: Yes
    2011-11-23	10:47:28:086	1004	1084	Misc	Validating signature for C:\Windows\SoftwareDistribution\SelfUpdate\wuident.cab:
    2011-11-23	10:47:28:089	1004	1084	Misc	 Microsoft signed: Yes
    2011-11-23	10:47:28:108	1004	1084	Misc	Validating signature for C:\Windows\SoftwareDistribution\SelfUpdate\wsus3setup.cab:
    2011-11-23	10:47:28:111	1004	1084	Misc	 Microsoft signed: Yes
    2011-11-23	10:47:28:134	1004	1084	Misc	Validating signature for C:\Windows\SoftwareDistribution\SelfUpdate\wsus3setup.cab:
    2011-11-23	10:47:28:137	1004	1084	Misc	 Microsoft signed: Yes
    2011-11-23	10:47:28:154	1004	1084	Setup	Determining whether a new setup handler needs to be downloaded
    2011-11-23	10:47:28:155	1004	1084	Setup	SelfUpdate handler is not found.  It will be downloaded
    2011-11-23	10:47:28:155	1004	1084	Setup	Evaluating applicability of setup package "WUClient-SelfUpdate-ActiveX~31bf3856ad364e35~amd64~~7.4.7600.226"
    2011-11-23	10:47:28:157	1004	1084	Setup	Setup package "WUClient-SelfUpdate-ActiveX~31bf3856ad364e35~amd64~~7.4.7600.226" is already installed.
    2011-11-23	10:47:28:157	1004	1084	Setup	Evaluating applicability of setup package "WUClient-SelfUpdate-Aux-TopLevel~31bf3856ad364e35~amd64~~7.4.7600.226"
    2011-11-23	10:47:28:176	1004	1084	Setup	Setup package "WUClient-SelfUpdate-Aux-TopLevel~31bf3856ad364e35~amd64~~7.4.7600.226" is already installed.
    2011-11-23	10:47:28:176	1004	1084	Setup	Evaluating applicability of setup package "WUClient-SelfUpdate-Core-TopLevel~31bf3856ad364e35~amd64~~7.4.7600.226"
    2011-11-23	10:47:28:204	1004	1084	Setup	Setup package "WUClient-SelfUpdate-Core-TopLevel~31bf3856ad364e35~amd64~~7.4.7600.226" is already installed.
    2011-11-23	10:47:28:205	1004	1084	Setup	SelfUpdate check completed.  SelfUpdate is NOT required.
    2011-11-23	10:47:28:311	1004	1084	PT	+++++++++++  PT: Synchronizing server updates  +++++++++++
    2011-11-23	10:47:28:311	1004	1084	PT	  + ServiceId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}, Server URL = http://10.0.0.25/ClientWebService/client.asmx
    2011-11-23	10:47:28:443	1004	1084	PT	WARNING: Cached cookie has expired or new PID is available
    2011-11-23	10:47:28:443	1004	1084	PT	Initializing simple targeting cookie, clientId = 1dd18056-361d-44bd-ac87-d5331a993fc0, target group = RIG Workstations, DNS name = blockz-7.rockinst.org
    2011-11-23	10:47:28:443	1004	1084	PT	  Server URL = http://10.0.0.25/SimpleAuthWebService/SimpleAuth.asmx
    2011-11-23	10:47:29:445	1004	1084	Misc	WARNING: SendRequest failed with hr = 80072efd. Proxy List used: <127.0.0.1:80> Bypass List used : <(null)> Auth Schemes used : <>
    2011-11-23	10:47:29:445	1004	1084	PT	  + Last proxy send request failed with hr = 0x80072EFD, HTTP status code = 0
    2011-11-23	10:47:29:445	1004	1084	PT	  + Caller provided proxy = No
    2011-11-23	10:47:29:445	1004	1084	PT	  + Proxy list used = 127.0.0.1:80
    2011-11-23	10:47:29:445	1004	1084	PT	  + Bypass list used = <NULL>
    2011-11-23	10:47:29:445	1004	1084	PT	  + Caller provided credentials = No
    2011-11-23	10:47:29:445	1004	1084	PT	  + Impersonate flags = 0
    2011-11-23	10:47:29:445	1004	1084	PT	  + Possible authorization schemes used = 
    2011-11-23	10:47:29:445	1004	1084	PT	WARNING: GetAuthorizationCookie failure, error = 0x80072EFD, soap client error = 5, soap error code = 0, HTTP status code = 200
    2011-11-23	10:47:29:445	1004	1084	PT	WARNING: Failed to initialize Simple Targeting Cookie: 0x80072efd
    2011-11-23	10:47:29:445	1004	1084	PT	WARNING: PopulateAuthCookies failed: 0x80072efd
    2011-11-23	10:47:29:445	1004	1084	PT	WARNING: RefreshCookie failed: 0x80072efd
    2011-11-23	10:47:29:445	1004	1084	PT	WARNING: RefreshPTState failed: 0x80072efd
    2011-11-23	10:47:29:445	1004	1084	PT	WARNING: Sync of Updates: 0x80072efd
    2011-11-23	10:47:29:445	1004	1084	PT	WARNING: SyncServerUpdatesInternal failed: 0x80072efd
    2011-11-23	10:47:29:445	1004	1084	Agent	  * WARNING: Failed to synchronize, error = 0x80072EFD
    2011-11-23	10:47:29:446	1004	1084	Agent	  * WARNING: Exit code = 0x80072EFD
    2011-11-23	10:47:29:446	1004	1084	Agent	*********
    2011-11-23	10:47:29:446	1004	1084	Agent	**  END  **  Agent: Finding updates [CallerId = AutomaticUpdates]
    2011-11-23	10:47:29:446	1004	1084	Agent	*************
    2011-11-23	10:47:29:446	1004	1084	Agent	WARNING: WU client failed Searching for update with error 0x80072efd
    2011-11-23	10:47:29:446	1004	1084	Report	REPORT EVENT: {02FCDB7F-14E7-4A47-96B9-BBB189DC51AA}	2011-11-23 10:47:25:895-0500	1	148	101	{00000000-0000-0000-0000-000000000000}	0	80072efd		Failure	Software Synchronization	Windows Update Client failed to detect with error 0x80072efd.
    2011-11-23	10:47:29:446	1004	914	AU	>>##  RESUMED  ## AU: Search for updates [CallId = {F37DC9E0-257A-4CB6-8535-F503EA3EC94F}]
    2011-11-23	10:47:29:446	1004	914	AU	  # WARNING: Search callback failed, result = 0x80072EFD
    2011-11-23	10:47:29:446	1004	1084	Report	REPORT EVENT: {A96BEC66-676F-42CF-BB23-99AE7EF02915}	2011-11-23 10:47:27:009-0500	1	148	101	{00000000-0000-0000-0000-000000000000}	0	80072efd		Failure	Software Synchronization	Windows Update Client failed to detect with error 0x80072efd.
    2011-11-23	10:47:29:446	1004	914	AU	  # WARNING: Failed to find updates with error code 80072EFD
    2011-11-23	10:47:29:446	1004	914	AU	#########
    2011-11-23	10:47:29:446	1004	914	AU	##  END  ##  AU: Search for updates [CallId = {F37DC9E0-257A-4CB6-8535-F503EA3EC94F}]
    2011-11-23	10:47:29:446	1004	1084	Report	REPORT EVENT: {8F256011-9A9B-410D-B426-92DE26060E87}	2011-11-23 10:47:29:446-0500	1	148	101	{00000000-0000-0000-0000-000000000000}	0	80072efd	AutomaticUpdates	Failure	Software Synchronization	Windows Update Client failed to detect with error 0x80072efd.
    2011-11-23	10:47:29:446	1004	914	AU	#############
    2011-11-23	10:47:29:446	1004	914	AU	Successfully wrote event for AU health state:0
    2011-11-23	10:47:29:447	1004	914	AU	AU setting next detection timeout to 2011-11-23 16:46:16
    2011-11-23	10:47:29:447	1004	914	AU	Setting AU scheduled install time to 2011-11-24 21:00:00
    2011-11-23	10:47:29:447	1004	914	AU	Successfully wrote event for AU health state:0
    2011-11-23	10:47:29:447	1004	914	AU	Successfully wrote event for AU health state:0
    2011-11-23	10:47:29:452	1004	1084	Report	CWERReporter::HandleEvents - WER report upload completed with status 0x8
    2011-11-23	10:47:29:452	1004	1084	Report	WER Report sent: 7.5.7601.17514 0x80072efd 00000000-0000-0000-0000-000000000000 Scan 101 Managed
    2011-11-23	10:47:29:457	1004	1084	Report	CWERReporter::HandleEvents - WER report upload completed with status 0x8
    2011-11-23	10:47:29:457	1004	1084	Report	WER Report sent: 7.5.7601.17514 0x80072efd 00000000-0000-0000-0000-000000000000 Scan 101 Managed
    2011-11-23	10:47:29:465	1004	1084	Report	CWERReporter::HandleEvents - WER report upload completed with status 0x8
    2011-11-23	10:47:29:465	1004	1084	Report	WER Report sent: 7.5.7601.17514 0x80072efd 00000000-0000-0000-0000-000000000000 Scan 101 Managed
    2011-11-23	10:47:29:465	1004	1084	Report	CWERReporter finishing event handling. (00000000)
    2011-11-23	10:47:29:465	1004	1084	Agent	*************
    2011-11-23	10:47:29:465	1004	1084	Agent	** START **  Agent: Finding updates [CallerId = ]
    2011-11-23	10:47:29:465	1004	1084	Agent	*********
    2011-11-23	10:47:29:465	1004	1084	Agent	  * Online = Yes; Ignore download priority = No
    2011-11-23	10:47:29:465	1004	1084	Agent	  * Criteria = "IsInstalled = 0 AND IsHidden = 0"
    2011-11-23	10:47:29:465	1004	1084	Agent	  * ServiceID = {00000000-0000-0000-0000-000000000000} Third party service
    2011-11-23	10:47:29:465	1004	1084	Agent	  * Search Scope = {Machine}
    2011-11-23	10:47:29:570	1004	1084	PT	+++++++++++  PT: Synchronizing server updates  +++++++++++
    2011-11-23	10:47:29:570	1004	1084	PT	  + ServiceId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}, Server URL = http://10.0.0.25/ClientWebService/client.asmx
    2011-11-23	10:47:30:567	1004	1084	Misc	WARNING: SendRequest failed with hr = 80072efd. Proxy List used: <127.0.0.1:80> Bypass List used : <(null)> Auth Schemes used : <>
    2011-11-23	10:47:30:567	1004	1084	PT	  + Last proxy send request failed with hr = 0x80072EFD, HTTP status code = 0
    2011-11-23	10:47:30:567	1004	1084	PT	  + Caller provided proxy = No
    2011-11-23	10:47:30:567	1004	1084	PT	  + Proxy list used = 127.0.0.1:80
    2011-11-23	10:47:30:567	1004	1084	PT	  + Bypass list used = <NULL>
    2011-11-23	10:47:30:567	1004	1084	PT	  + Caller provided credentials = No
    2011-11-23	10:47:30:567	1004	1084	PT	  + Impersonate flags = 0
    2011-11-23	10:47:30:567	1004	1084	PT	  + Possible authorization schemes used = 
    2011-11-23	10:47:30:567	1004	1084	PT	WARNING: GetConfig failure, error = 0x80072EFD, soap client error = 5, soap error code = 0, HTTP status code = 200
    2011-11-23	10:47:30:567	1004	1084	PT	WARNING: PTError: 0x80072efd
    2011-11-23	10:47:30:567	1004	1084	PT	WARNING: GetConfig_WithRecovery failed: 0x80072efd
    2011-11-23	10:47:30:567	1004	1084	PT	WARNING: RefreshConfig failed: 0x80072efd
    2011-11-23	10:47:30:567	1004	1084	PT	WARNING: RefreshPTState failed: 0x80072efd
    2011-11-23	10:47:30:567	1004	1084	PT	WARNING: Sync of Updates: 0x80072efd
    2011-11-23	10:47:30:567	1004	1084	PT	WARNING: SyncServerUpdatesInternal failed: 0x80072efd
    2011-11-23	10:47:30:567	1004	1084	Agent	  * WARNING: Failed to synchronize, error = 0x80072EFD
    2011-11-23	10:47:30:568	1004	1084	Agent	  * WARNING: Exit code = 0x80072EFD
    2011-11-23	10:47:30:568	1004	1084	Agent	*********
    2011-11-23	10:47:30:568	1004	1084	Agent	**  END  **  Agent: Finding updates [CallerId = ]
    2011-11-23	10:47:30:568	1004	1084	Agent	*************
    2011-11-23	10:47:30:568	1004	1084	Agent	WARNING: WU client failed Searching for update with error 0x80072efd
    2011-11-23	10:47:34:446	1004	1084	Report	REPORT EVENT: {C5252887-1B1F-4B6E-A1A9-53480DF15456}	2011-11-23 10:47:30:568-0500	1	148	101	{00000000-0000-0000-0000-000000000000}	0	80072efd		Failure	Software Synchronization	Windows Update Client failed to detect with error 0x80072efd.
    2011-11-23	10:47:34:451	1004	1084	Report	CWERReporter::HandleEvents - WER report upload completed with status 0x8
    2011-11-23	10:47:34:451	1004	1084	Report	WER Report sent: 7.5.7601.17514 0x80072efd 00000000-0000-0000-0000-000000000000 Scan 101 Managed
    2011-11-23	10:47:34:451	1004	1084	Report	CWERReporter finishing event handling. (00000000)
    


    Wednesday, November 23, 2011 3:49 PM
  • Hi,

    i've just read some articles regarding "similar" problems... can you test removing the tick from the box on the "Automatically detect settings", on IE's LAN Settings? This could be the culprit causing the problem...

    If not, try running the WSUS Client Diagnostics tool.

    It's available for download on http://technet.microsoft.com/en-us/wsus/bb466192 (maybe this should have been our starting point)

     


    Tiago Viana, MCITP:SA
    Wednesday, November 23, 2011 4:40 PM
  • I was looking through the list of computers again, and when their last status report time was, and there actually is 1 Windows 7 machine that reported a status update yesterday (2011-11-22 around 13:07).  The computer had since been shut down, so I went over to turn it on this morning and before it got to the logon page, it began installing updates, like it had some to do the next time it started up.  I thought this might be a good sign.  So I wait for it to finish, log in, and try to force an update check, it comes up with the same error as the others.  Why it reported yesterday when none of the others did, I don't know, but it doesn't appear it wants to anymore.  Anyway I grabbed the WindowsUpdate.log from this machine, so here is yesterday's log from that machine around the time it reported it's status to WSUS (13:07).  Maybe there is a clue in here of why this computer was successful yesterday?

    2011-11-22	13:02:00:441	 924	32c	AU	#############
    2011-11-22	13:02:00:441	 924	32c	AU	## START ##  AU: Search for updates
    2011-11-22	13:02:00:441	 924	32c	AU	#########
    2011-11-22	13:02:00:488	 924	32c	AU	<<## SUBMITTED ## AU: Search for updates [CallId = {9E13863E-1D97-400E-9813-F9F2B172BB1B}]
    2011-11-22	13:02:00:488	 924	334	Agent	*************
    2011-11-22	13:02:00:488	 924	334	Agent	** START **  Agent: Finding updates [CallerId = AutomaticUpdates]
    2011-11-22	13:02:00:488	 924	334	Agent	*********
    2011-11-22	13:02:00:488	 924	334	Agent	  * Online = Yes; Ignore download priority = No
    2011-11-22	13:02:00:488	 924	334	Agent	  * Criteria = "IsInstalled=0 and DeploymentAction='Installation' or IsPresent=1 and DeploymentAction='Uninstallation' or IsInstalled=1 and DeploymentAction='Installation' and RebootRequired=1 or IsInstalled=0 and DeploymentAction='Uninstallation' and RebootRequired=1"
    2011-11-22	13:02:00:488	 924	334	Agent	  * ServiceID = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7} Managed
    2011-11-22	13:02:00:488	 924	334	Agent	  * Search Scope = {Machine}
    2011-11-22	13:02:00:535	 924	334	Setup	Checking for agent SelfUpdate
    2011-11-22	13:02:00:644	 924	334	Setup	Client version: Core: 7.5.7601.17514  Aux: 7.5.7601.17514
    2011-11-22	13:02:00:644	 924	334	Misc	Validating signature for C:\Windows\SoftwareDistribution\SelfUpdate\wuident.cab:
    2011-11-22	13:02:00:644	 924	334	Misc	 Microsoft signed: Yes
    2011-11-22	13:02:10:504	 924	334	Misc	Validating signature for C:\Windows\SoftwareDistribution\SelfUpdate\wuident.cab:
    2011-11-22	13:02:10:504	 924	334	Misc	 Microsoft signed: Yes
    2011-11-22	13:02:10:645	 924	334	Misc	Validating signature for C:\Windows\SoftwareDistribution\SelfUpdate\wsus3setup.cab:
    2011-11-22	13:02:10:645	 924	334	Misc	 Microsoft signed: Yes
    2011-11-22	13:02:10:660	 924	334	Misc	Validating signature for C:\Windows\SoftwareDistribution\SelfUpdate\wsus3setup.cab:
    2011-11-22	13:02:10:691	 924	334	Misc	 Microsoft signed: Yes
    2011-11-22	13:02:11:269	 924	334	Setup	Determining whether a new setup handler needs to be downloaded
    2011-11-22	13:02:11:331	 924	334	Misc	Validating signature for C:\Windows\SoftwareDistribution\SelfUpdate\Handler\WuSetupV.exe:
    2011-11-22	13:02:11:378	 924	334	Misc	 Microsoft signed: Yes
    2011-11-22	13:02:11:378	 924	334	Setup	SelfUpdate handler update NOT required: Current version: 7.4.7600.226, required version: 7.4.7600.226
    2011-11-22	13:02:11:378	 924	334	Setup	Evaluating applicability of setup package "WUClient-SelfUpdate-ActiveX~31bf3856ad364e35~amd64~~7.4.7600.226"
    2011-11-22	13:02:14:389	 924	334	Setup	Setup package "WUClient-SelfUpdate-ActiveX~31bf3856ad364e35~amd64~~7.4.7600.226" is already installed.
    2011-11-22	13:02:14:389	 924	334	Setup	Evaluating applicability of setup package "WUClient-SelfUpdate-Aux-TopLevel~31bf3856ad364e35~amd64~~7.4.7600.226"
    2011-11-22	13:02:14:436	 924	334	Setup	Setup package "WUClient-SelfUpdate-Aux-TopLevel~31bf3856ad364e35~amd64~~7.4.7600.226" is already installed.
    2011-11-22	13:02:14:436	 924	334	Setup	Evaluating applicability of setup package "WUClient-SelfUpdate-Core-TopLevel~31bf3856ad364e35~amd64~~7.4.7600.226"
    2011-11-22	13:02:14:498	 924	334	Setup	Setup package "WUClient-SelfUpdate-Core-TopLevel~31bf3856ad364e35~amd64~~7.4.7600.226" is already installed.
    2011-11-22	13:02:14:498	 924	334	Setup	SelfUpdate check completed.  SelfUpdate is NOT required.
    2011-11-22	13:02:18:165	 924	334	PT	+++++++++++  PT: Synchronizing server updates  +++++++++++
    2011-11-22	13:02:18:165	 924	334	PT	  + ServiceId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}, Server URL = http://10.0.0.25/ClientWebService/client.asmx
    2011-11-22	13:02:18:336	 924	334	PT	WARNING: Cached cookie has expired or new PID is available
    2011-11-22	13:02:18:336	 924	334	PT	Initializing simple targeting cookie, clientId = e4055ddd-2b82-42bf-81fa-f1939aacfa63, target group = RIG Workstations, DNS name = dadayanstu-7.rockinst.org
    2011-11-22	13:02:18:336	 924	334	PT	  Server URL = http://10.0.0.25/SimpleAuthWebService/SimpleAuth.asmx
    2011-11-22	13:02:26:544	 924	334	Agent	WARNING: Failed to evaluate Installed rule, updateId = {189A8F50-0C3A-4FDF-8BC2-BC23A3EB11FB}.101, hr = 80242013
    2011-11-22	13:02:29:617	 924	334	PT	+++++++++++  PT: Synchronizing extended update info  +++++++++++
    2011-11-22	13:02:29:617	 924	334	PT	  + ServiceId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}, Server URL = http://10.0.0.25/ClientWebService/client.asmx
    2011-11-22	13:02:31:068	 924	334	Agent	  * Added update {91C80095-4B18-4BCC-BA46-18B3D4AD7124}.100 to search result
    2011-11-22	13:02:31:084	 924	334	Agent	  * Added update {A0340EAE-0732-4B92-98AA-FDD786D37252}.100 to search result
    2011-11-22	13:02:31:084	 924	334	Agent	  * Found 2 updates and 57 categories in search; evaluated appl. rules of 772 out of 1083 deployed entities
    2011-11-22	13:02:31:099	 924	334	Agent	*********
    2011-11-22	13:02:31:099	 924	334	Agent	**  END  **  Agent: Finding updates [CallerId = AutomaticUpdates]
    2011-11-22	13:02:31:099	 924	334	Agent	*************
    2011-11-22	13:02:31:115	 924	e68	AU	>>##  RESUMED  ## AU: Search for updates [CallId = {9E13863E-1D97-400E-9813-F9F2B172BB1B}]
    2011-11-22	13:02:31:115	 924	e68	AU	  # 2 updates detected
    2011-11-22	13:02:31:130	 924	e68	AU	#########
    2011-11-22	13:02:31:130	 924	e68	AU	##  END  ##  AU: Search for updates [CallId = {9E13863E-1D97-400E-9813-F9F2B172BB1B}]
    2011-11-22	13:02:31:130	 924	e68	AU	#############
    2011-11-22	13:02:31:146	 924	e68	AU	Successfully wrote event for AU health state:0
    2011-11-22	13:02:31:146	 924	e68	AU	Featured notifications is disabled.
    2011-11-22	13:02:31:146	 924	e68	AU	AU setting next detection timeout to 2011-11-22 19:01:35
    2011-11-22	13:02:31:146	 924	e68	AU	Setting AU scheduled install time to 2011-11-24 21:00:00
    2011-11-22	13:02:31:146	 924	e68	AU	Successfully wrote event for AU health state:0
    2011-11-22	13:02:31:146	 924	e68	AU	Auto-approving update for download, updateId = {91C80095-4B18-4BCC-BA46-18B3D4AD7124}.100, ForUx=0, IsOwnerUx=0, HasDeadline=0, IsMinor=0
    2011-11-22	13:02:31:146	 924	e68	AU	Auto-approving update for download, updateId = {A0340EAE-0732-4B92-98AA-FDD786D37252}.100, ForUx=0, IsOwnerUx=0, HasDeadline=0, IsMinor=0
    2011-11-22	13:02:31:146	 924	e68	AU	Auto-approved 2 update(s) for download (NOT for Ux)
    2011-11-22	13:02:31:146	 924	e68	AU	#############
    2011-11-22	13:02:31:146	 924	e68	AU	## START ##  AU: Download updates
    2011-11-22	13:02:31:146	 924	e68	AU	#########
    2011-11-22	13:02:31:146	 924	e68	AU	  # Approved updates = 2
    2011-11-22	13:02:31:208	 924	e68	AU	AU initiated download, updateId = {91C80095-4B18-4BCC-BA46-18B3D4AD7124}.100, callId = {09F6F1A5-6296-4330-9F7D-D740FDD93B97}
    2011-11-22	13:02:31:208	 924	e68	AU	AU initiated download, updateId = {A0340EAE-0732-4B92-98AA-FDD786D37252}.100, callId = {51182C9D-A774-42AF-8A50-052CC4D2A2E4}
    2011-11-22	13:02:31:208	 924	e68	AU	Setting AU scheduled install time to 2011-11-24 21:00:00
    2011-11-22	13:02:31:208	 924	e68	AU	Successfully wrote event for AU health state:0
    2011-11-22	13:02:31:208	 924	e68	AU	AU setting pending client directive to 'Download Progress'
    2011-11-22	13:02:31:208	 924	334	DnldMgr	*************
    2011-11-22	13:02:31:208	 924	334	DnldMgr	** START **  DnldMgr: Downloading updates [CallerId = AutomaticUpdates]
    2011-11-22	13:02:31:208	 924	334	DnldMgr	*********
    2011-11-22	13:02:31:208	 924	334	DnldMgr	  * Call ID = {09F6F1A5-6296-4330-9F7D-D740FDD93B97}
    2011-11-22	13:02:31:208	 924	334	DnldMgr	  * Priority = 2, Interactive = 0, Owner is system = 1, Explicit proxy = 0, Proxy session id = -1, ServiceId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
    2011-11-22	13:02:31:208	 924	334	DnldMgr	  * Updates to download = 1
    2011-11-22	13:02:31:208	 924	334	Agent	  *   Title = Update for Windows 7 for x64-based Systems (KB2603229)
    2011-11-22	13:02:31:208	 924	334	Agent	  *   UpdateId = {91C80095-4B18-4BCC-BA46-18B3D4AD7124}.100
    2011-11-22	13:02:31:208	 924	334	Agent	  *     Bundles 1 updates:
    2011-11-22	13:02:31:208	 924	334	Agent	  *       {314DD625-95D7-4076-BD7D-688DB4E40AA0}.100
    2011-11-22	13:02:31:224	 924	334	PT	+++++++++++  PT: Synchronizing file locations  +++++++++++
    2011-11-22	13:02:31:224	 924	334	PT	  + ServiceId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}, Server URL = http://10.0.0.25/ClientWebService/client.asmx
    2011-11-22	13:02:31:224	 924	e68	AU	Successfully wrote event for AU health state:0
    2011-11-22	13:02:31:224	 924	e68	AU	  # Pending download calls = 2
    2011-11-22	13:02:31:224	 924	e68	AU	<<## SUBMITTED ## AU: Download updates
    2011-11-22	13:02:31:224	 924	e68	AU	Successfully wrote event for AU health state:0
    2011-11-22	13:02:31:598	 924	334	DnldMgr	***********  DnldMgr: New download job [UpdateId = {314DD625-95D7-4076-BD7D-688DB4E40AA0}.100]  ***********
    2011-11-22	13:02:31:598	 924	334	DnldMgr	  * Queueing update for download handler request generation.
    2011-11-22	13:02:31:598	 924	334	DnldMgr	Generating download request for update {314DD625-95D7-4076-BD7D-688DB4E40AA0}.100
    2011-11-22	13:02:31:739	 924	334	Handler	Generating request for CBS update 314DD625-95D7-4076-BD7D-688DB4E40AA0 in sandbox C:\Windows\SoftwareDistribution\Download\f5183e2d1ad2335f9b606b4b29ba17b3
    2011-11-22	13:02:31:739	 924	334	Handler	Selecting self-contained because update has express payload but server doesn't support it.
    2011-11-22	13:02:31:739	 924	334	Handler	Selected payload type is ptSelfContained
    2011-11-22	13:02:31:739	 924	334	Handler	Detected download state is dsStart
    2011-11-22	13:02:31:739	 924	334	Handler	Adding windows6.1-kb2603229-x64.cab (entire file) to request list.
    2011-11-22	13:02:31:770	 924	334	Handler	Request generation for CBS update complete with hr=0x0 and pfResetSandbox=0 
    2011-11-22	13:02:31:770	 924	334	DnldMgr	***********  DnldMgr: New download job [UpdateId = {314DD625-95D7-4076-BD7D-688DB4E40AA0}.100]  ***********
    2011-11-22	13:02:31:817	 924	334	DnldMgr	  * BITS job initialized, JobId = {E3BFAF3F-1D99-4D69-BF9E-C03355EAC7DD}
    2011-11-22	13:02:31:879	 924	334	DnldMgr	  * Downloading from http://10.0.0.25/Content/86/F1FE6D0A3DECAF7256BA6979A94A8DFCAB882C86.cab to C:\Windows\SoftwareDistribution\Download\f5183e2d1ad2335f9b606b4b29ba17b3\windows6.1-kb2603229-x64.cab (full file).
    2011-11-22	13:02:31:973	 924	334	Agent	*********
    2011-11-22	13:02:31:973	 924	334	Agent	**  END  **  Agent: Downloading updates [CallerId = AutomaticUpdates]
    2011-11-22	13:02:31:973	 924	334	Agent	*************
    2011-11-22	13:02:31:989	 924	334	DnldMgr	*************
    2011-11-22	13:02:31:989	 924	334	DnldMgr	** START **  DnldMgr: Downloading updates [CallerId = AutomaticUpdates]
    2011-11-22	13:02:31:989	 924	334	DnldMgr	*********
    2011-11-22	13:02:31:989	 924	334	DnldMgr	  * Call ID = {51182C9D-A774-42AF-8A50-052CC4D2A2E4}
    2011-11-22	13:02:31:989	 924	334	DnldMgr	  * Priority = 2, Interactive = 0, Owner is system = 1, Explicit proxy = 0, Proxy session id = -1, ServiceId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
    2011-11-22	13:02:31:989	 924	334	DnldMgr	  * Updates to download = 1
    2011-11-22	13:02:31:989	 924	334	Agent	  *   Title = Update for Windows 7 for x64-based Systems (KB2607576)
    2011-11-22	13:02:31:989	 924	334	Agent	  *   UpdateId = {A0340EAE-0732-4B92-98AA-FDD786D37252}.100
    2011-11-22	13:02:31:989	 924	334	Agent	  *     Bundles 1 updates:
    2011-11-22	13:02:31:989	 924	334	Agent	  *       {47F797BE-A84B-4C60-947A-1807419FC7B8}.100
    2011-11-22	13:02:31:989	 924	334	PT	+++++++++++  PT: Synchronizing file locations  +++++++++++
    2011-11-22	13:02:31:989	 924	334	PT	  + ServiceId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}, Server URL = http://10.0.0.25/ClientWebService/client.asmx
    2011-11-22	13:02:32:067	 924	334	DnldMgr	***********  DnldMgr: New download job [UpdateId = {47F797BE-A84B-4C60-947A-1807419FC7B8}.100]  ***********
    2011-11-22	13:02:32:067	 924	334	DnldMgr	  * Queueing update for download handler request generation.
    2011-11-22	13:02:32:067	 924	334	DnldMgr	Generating download request for update {47F797BE-A84B-4C60-947A-1807419FC7B8}.100
    2011-11-22	13:02:32:254	 924	334	Handler	Generating request for CBS update 47F797BE-A84B-4C60-947A-1807419FC7B8 in sandbox C:\Windows\SoftwareDistribution\Download\cef75faabdc358063ea8929a3e9949a0
    2011-11-22	13:02:32:254	 924	334	Handler	Selecting self-contained because update has express payload but server doesn't support it.
    2011-11-22	13:02:32:254	 924	334	Handler	Selected payload type is ptSelfContained
    2011-11-22	13:02:32:254	 924	334	Handler	Detected download state is dsStart
    2011-11-22	13:02:32:254	 924	334	Handler	Adding windows6.1-kb2607576-x64.cab (entire file) to request list.
    2011-11-22	13:02:32:285	 924	334	Handler	Request generation for CBS update complete with hr=0x0 and pfResetSandbox=0 
    2011-11-22	13:02:32:285	 924	334	DnldMgr	***********  DnldMgr: New download job [UpdateId = {47F797BE-A84B-4C60-947A-1807419FC7B8}.100]  ***********
    2011-11-22	13:02:32:332	 924	334	DnldMgr	  * BITS job initialized, JobId = {2BD1E8D0-17BD-4317-817F-106AE6F43BAE}
    2011-11-22	13:02:32:379	 924	334	DnldMgr	  * Downloading from http://10.0.0.25/Content/F7/12CF9EE4CCCAF51C705EAC9A63E80749477306F7.cab to C:\Windows\SoftwareDistribution\Download\cef75faabdc358063ea8929a3e9949a0\windows6.1-kb2607576-x64.cab (full file).
    2011-11-22	13:02:32:410	 924	334	Agent	*********
    2011-11-22	13:02:32:410	 924	334	Agent	**  END  **  Agent: Downloading updates [CallerId = AutomaticUpdates]
    2011-11-22	13:02:32:410	 924	334	Agent	*************
    2011-11-22	13:02:36:092	 924	334	Report	REPORT EVENT: {8FC93E9E-4EE4-4B86-AFE7-274B09347FF4}	2011-11-22 13:02:31:084-0500	1	147	101	{00000000-0000-0000-0000-000000000000}	0	0	AutomaticUpdates	Success	Software Synchronization	Windows Update Client successfully detected 2 updates.
    2011-11-22	13:02:36:092	 924	334	Report	REPORT EVENT: {ECDE48CB-5EE3-444D-B7B6-82A25CDB2921}	2011-11-22 13:02:31:099-0500	1	156	101	{00000000-0000-0000-0000-000000000000}	0	0	AutomaticUpdates	Success	Pre-Deployment Check	Reporting client status.
    2011-11-22	13:02:36:092	 924	334	Report	CWERReporter finishing event handling. (00000000)
    2011-11-22	13:02:46:295	 924	32c	AU	Launched new AU client for directive 'Download Progress', session id = 0x1
    2011-11-22	13:02:47:262	 924	698	DnldMgr	BITS job {E3BFAF3F-1D99-4D69-BF9E-C03355EAC7DD} completed successfully
    2011-11-22	13:02:47:294	 924	698	Misc	Validating signature for C:\Windows\SoftwareDistribution\Download\f5183e2d1ad2335f9b606b4b29ba17b3\windows6.1-kb2603229-x64.cab:
    2011-11-22	13:02:47:325	 924	698	Misc	 Microsoft signed: Yes
    2011-11-22	13:02:47:340	 924	698	DnldMgr	  Download job bytes total = 36671, bytes transferred = 36671
    2011-11-22	13:02:47:340	 924	698	DnldMgr	***********  DnldMgr: New download job [UpdateId = {314DD625-95D7-4076-BD7D-688DB4E40AA0}.100]  ***********
    2011-11-22	13:02:47:340	 924	698	DnldMgr	  * Queueing update for download handler request generation.
    2011-11-22	13:02:47:340	 924	698	DnldMgr	Generating download request for update {314DD625-95D7-4076-BD7D-688DB4E40AA0}.100
    2011-11-22	13:02:47:418	 924	698	Handler	Generating request for CBS update 314DD625-95D7-4076-BD7D-688DB4E40AA0 in sandbox C:\Windows\SoftwareDistribution\Download\f5183e2d1ad2335f9b606b4b29ba17b3
    2011-11-22	13:02:47:418	 924	698	Handler	Selecting self-contained because update has express payload but server doesn't support it.
    2011-11-22	13:02:47:418	 924	698	Handler	Selected payload type is ptSelfContained
    2011-11-22	13:02:47:418	 924	698	Handler	Detected download state is dsHavePackage
    2011-11-22	13:02:47:418	 924	698	Handler	Request generation for CBS update complete with hr=0x0 and pfResetSandbox=0 
    2011-11-22	13:02:47:434	 924	698	DnldMgr	***********  DnldMgr: New download job [UpdateId = {314DD625-95D7-4076-BD7D-688DB4E40AA0}.100]  ***********
    2011-11-22	13:02:47:434	 924	698	DnldMgr	  * All files for update were already downloaded and are valid.
    2011-11-22	13:02:47:450	 924	e68	AU	>>##  RESUMED  ## AU: Download update [UpdateId = {91C80095-4B18-4BCC-BA46-18B3D4AD7124}, succeeded]
    2011-11-22	13:02:47:465	 924	e68	AU	Setting AU scheduled install time to 2011-11-24 21:00:00
    2011-11-22	13:02:47:465	 924	e68	AU	Successfully wrote event for AU health state:0
    2011-11-22	13:02:47:481	 924	e68	AU	Successfully wrote event for AU health state:0
    2011-11-22	13:02:52:458	 924	334	Report	REPORT EVENT: {78B68285-DA90-499D-A2DE-AEDE321E9681}	2011-11-22 13:02:47:450-0500	1	162	101	{91C80095-4B18-4BCC-BA46-18B3D4AD7124}	100	0	AutomaticUpdates	Success	Content Download	Download succeeded.
    2011-11-22	13:02:52:458	 924	334	Report	REPORT EVENT: {7059EBCA-05D6-4BB3-B2BC-557C8974826B}	2011-11-22 13:02:47:465-0500	1	188	102	{00000000-0000-0000-0000-000000000000}	0	0	AutomaticUpdates	Success	Content Install	Installation Ready: The following updates are downloaded and ready for installation. This computer is currently scheduled to install these updates on ‎Thursday, ‎November ‎24, ‎2011 at 4:00 PM:  - Update for Windows 7 for x64-based Systems (KB2603229)
    2011-11-22	13:02:52:458	 924	334	Report	CWERReporter finishing event handling. (00000000)
    2011-11-22	13:02:55:110	 924	fe8	DnldMgr	BITS job {2BD1E8D0-17BD-4317-817F-106AE6F43BAE} completed successfully
    2011-11-22	13:02:55:188	 924	fe8	Misc	Validating signature for C:\Windows\SoftwareDistribution\Download\cef75faabdc358063ea8929a3e9949a0\windows6.1-kb2607576-x64.cab:
    2011-11-22	13:02:55:266	 924	fe8	Misc	 Microsoft signed: Yes
    2011-11-22	13:02:55:266	 924	fe8	DnldMgr	  Download job bytes total = 7517123, bytes transferred = 7517123
    2011-11-22	13:02:55:266	 924	fe8	DnldMgr	***********  DnldMgr: New download job [UpdateId = {47F797BE-A84B-4C60-947A-1807419FC7B8}.100]  ***********
    2011-11-22	13:02:55:266	 924	fe8	DnldMgr	  * Queueing update for download handler request generation.
    2011-11-22	13:02:55:266	 924	fe8	DnldMgr	Generating download request for update {47F797BE-A84B-4C60-947A-1807419FC7B8}.100
    2011-11-22	13:02:55:344	 924	fe8	Handler	Generating request for CBS update 47F797BE-A84B-4C60-947A-1807419FC7B8 in sandbox C:\Windows\SoftwareDistribution\Download\cef75faabdc358063ea8929a3e9949a0
    2011-11-22	13:02:55:344	 924	fe8	Handler	Selecting self-contained because update has express payload but server doesn't support it.
    2011-11-22	13:02:55:344	 924	fe8	Handler	Selected payload type is ptSelfContained
    2011-11-22	13:02:55:344	 924	fe8	Handler	Detected download state is dsHavePackage
    2011-11-22	13:02:55:344	 924	fe8	Handler	Request generation for CBS update complete with hr=0x0 and pfResetSandbox=0 
    2011-11-22	13:02:55:360	 924	fe8	DnldMgr	***********  DnldMgr: New download job [UpdateId = {47F797BE-A84B-4C60-947A-1807419FC7B8}.100]  ***********
    2011-11-22	13:02:55:360	 924	fe8	DnldMgr	  * All files for update were already downloaded and are valid.
    2011-11-22	13:02:55:360	 924	e68	AU	>>##  RESUMED  ## AU: Download update [UpdateId = {A0340EAE-0732-4B92-98AA-FDD786D37252}, succeeded]
    2011-11-22	13:02:55:360	 924	e68	AU	#########
    2011-11-22	13:02:55:360	 924	e68	AU	##  END  ##  AU: Download updates
    2011-11-22	13:02:55:360	 924	e68	AU	#############
    2011-11-22	13:02:55:360	 924	e68	AU	Setting AU scheduled install time to 2011-11-24 21:00:00
    2011-11-22	13:02:55:360	 924	e68	AU	Successfully wrote event for AU health state:0
    2011-11-22	13:02:55:360	 924	e68	AU	AU setting pending client directive to 'Install Approval'
    2011-11-22	13:02:55:360	 924	e68	AU	Changing existing AU client directive from 'Download Progress' to 'Install Approval', session id = 0x1
    2011-11-22	13:02:55:360	 924	e68	AU	Successfully wrote event for AU health state:0
    2011-11-22	13:03:00:368	 924	334	Report	REPORT EVENT: {5F4585F3-E718-4C82-B185-40ABF0D9AB4E}	2011-11-22 13:02:55:360-0500	1	162	101	{A0340EAE-0732-4B92-98AA-FDD786D37252}	100	0	AutomaticUpdates	Success	Content Download	Download succeeded.
    2011-11-22	13:03:00:368	 924	334	Report	REPORT EVENT: {72FB967D-E15B-46C8-85C9-8D72E295D2C6}	2011-11-22 13:02:55:360-0500	1	188	102	{00000000-0000-0000-0000-000000000000}	0	0	AutomaticUpdates	Success	Content Install	Installation Ready: The following updates are downloaded and ready for installation. This computer is currently scheduled to install these updates on ‎Thursday, ‎November ‎24, ‎2011 at 4:00 PM:  - Update for Windows 7 for x64-based Systems (KB2603229) - Update for Windows 7 for x64-based Systems (KB2607576)
    2011-11-22	13:03:00:368	 924	334	Report	CWERReporter finishing event handling. (00000000)
    2011-11-22	13:07:24:074	 924	334	Report	Uploading 1 events using cached cookie, reporting URL = http://10.0.0.25/ReportingWebService/ReportingWebService.asmx
    2011-11-22	13:07:24:089	 924	334	Report	Reporter successfully uploaded 1 events.
    2011-11-22	13:07:24:121	 924	334	Report	Uploading 1 events using cached cookie, reporting URL = http://10.0.0.25/ReportingWebService/ReportingWebService.asmx
    2011-11-22	13:07:24:121	 924	334	Report	Reporter successfully uploaded 1 events.
    2011-11-22	13:07:24:152	 924	334	Report	Uploading 1 events using cached cookie, reporting URL = http://10.0.0.25/ReportingWebService/ReportingWebService.asmx
    2011-11-22	13:07:24:152	 924	334	Report	Reporter successfully uploaded 1 events.
    2011-11-22	13:07:24:183	 924	334	Report	Uploading 1 events using cached cookie, reporting URL = http://10.0.0.25/ReportingWebService/ReportingWebService.asmx
    2011-11-22	13:07:24:183	 924	334	Report	Reporter successfully uploaded 1 events.
    2011-11-22	13:07:24:199	 924	334	Report	Uploading 4 events using cached cookie, reporting URL = http://10.0.0.25/ReportingWebService/ReportingWebService.asmx
    2011-11-22	13:07:24:214	 924	334	Report	Reporter successfully uploaded 4 events.

    thanks

    Wednesday, November 23, 2011 4:46 PM
  • I'm really beginning to think this is something server-side.  I just took a spare freshly installed windows 7 machine that has been sitting on a shelf for months, hooked it up with no network cable.  I logged in, opened the windows update application, tried to find updates, and was immediately told I need a network connection.  I plug in the ethernet cable just long enough to click "Try again", error code 80072EFD immediately comes up, I pull the network cable back out, check the WindowsUpdate.log, and from the point I plugged in the network cable and clicked try again, the error looked the same as the other machines I am having the problem on (127.0.0.1:80 stuff).  I know no root-kits or spyware was installed on this machine, and it hasn't received any updates for months as it has been sitting on the shelf.
    Wednesday, November 23, 2011 5:13 PM
  • Hi,

    i've just read some articles regarding "similar" problems... can you test removing the tick from the box on the "Automatically detect settings", on IE's LAN Settings? This could be the culprit causing the problem...

    If not, try running the WSUS Client Diagnostics tool.

    It's available for download on http://technet.microsoft.com/en-us/wsus/bb466192 (maybe this should have been our starting point)

     


    Tiago Viana, MCITP:SA

    Tiago,

    I must have skipped over this response while I was posting.  Anyway, I did try removing the "Automatically detect settings" per your suggestion, and it didn't seem to make a difference.

    Also, before I started posting on this forum yesterday, I did try the ClientDiag.exe tool, though I have read it does not work on 64 bit systems, which might be the reason for the error below?

    I'm going to look and see if there is a 64 bit compatible version of this.  Thanks

    Wednesday, November 23, 2011 5:23 PM
  • Yeah, looks there is no x64 tool unfortunately..

    http://social.technet.microsoft.com/Forums/ar/winserverwsus/thread/0bf1fc8f-2078-41fd-8bfd-2e5b34d1603d

    Wednesday, November 23, 2011 5:35 PM
  • Tiago,

     

    Do you think my problem is similar to this one? http://social.technet.microsoft.com/Forums/en-US/winserverwsus/thread/758a01ca-10c0-4e53-afbc-863482b51857

    I was just reading through it, and while some of the errors are different, the gist is his Windows 7 machines are not getting updates while his XP SP3 machines are.  Lawrence suggests if it is happening to more than one computer, it is more likely a server side issue.  He suggests uninstalling and reinstalling WSUS & IIS, while keeping the database and content.

    The thread starter eventually answered that that fixed his problem.  If I don't end up making much more progress on this, that might be the next avenue I go down.  These things always seem to happen around the holidays... last year it was the controller card on the file server that died the week of Christmas.. ugh

    Wednesday, November 23, 2011 6:23 PM
  • I'm really beginning to think this is something server-side. 

    Let me shed some light here. This is most likely not a server-side issue. If the server were involved you would get back a legitimate HTTP error from IIS.

    In the instant case, however, you are getting an 0x80072EFD "CANNOT CONNECT" error message. This is what the WUAgent logs when NOTHING answers the connection request.

    This issue is a network infrastructure or configuration issue, and is generally caused because something is blocking the network connection request (HTTP GET) and not responding with an appropriate HTTP error response.

    When IE works, and the WUAgent does not -- this places the cause squarely in the seat of WinHTTP. The reason the machine that worked (DNS name = dadayanstu-7.rockinst.org), did so, is because it did not try to use a proxy connection. As of 10:47am this morning (local time), the failing machine (DNS name = blockz-7.rockinst.org) was still trying to proxy through itself -- guaranteed to fail.

    2011-11-23 10:47:30:567 1004 1084 PT   + Last proxy send request failed with hr = 0x80072EFD, HTTP status code = 0
    2011-11-23 10:47:30:567 1004 1084 PT   + Proxy list used = 127.0.0.1:80

    Since this problem occurred simultaneously on all Windows 7 system -- I would venture an educated guess that the root cause is an errant Group Policy that is configuring every one of those systems (except blockz-7). Any chance that blockz-7 is in a different orgUnit than the other machines?


    Lawrence Garvin, M.S., MCITP:EA, MCDBA, MCSA
    Principal/CTO, Onsite Technology Solutions, Houston, Texas
    Microsoft MVP - Software Distribution (2005-2011)
    My MVP Profile: http://mvp.support.microsoft.com/profile/Lawrence.Garvin
    My Blog: http://onsitechsolutions.spaces.live.com
    Wednesday, November 23, 2011 6:32 PM
    Moderator
  • Yeah, looks there is no x64 tool unfortunately..

    No real loss.. the CDT would not have given us anything we didn't already have from the WindowsUpdate.log.

    Sometimes the CDT can prevent the need to go log surfing, but that's its only real contribution to the process.


    Lawrence Garvin, M.S., MCITP:EA, MCDBA, MCSA
    Principal/CTO, Onsite Technology Solutions, Houston, Texas
    Microsoft MVP - Software Distribution (2005-2011)
    My MVP Profile: http://mvp.support.microsoft.com/profile/Lawrence.Garvin
    My Blog: http://onsitechsolutions.spaces.live.com
    Wednesday, November 23, 2011 6:34 PM
    Moderator
  • I'm really beginning to think this is something server-side. 

    Let me shed some light here. This is most likely not a server-side issue. If the server were involved you would get back a legitimate HTTP error from IIS.

    In the instant case, however, you are getting an 0x80072EFD "CANNOT CONNECT" error message. This is what the WUAgent logs when NOTHING answers the connection request.

    This issue is a network infrastructure or configuration issue, and is generally caused because something is blocking the network connection request (HTTP GET) and not responding with an appropriate HTTP error response.

    When IE works, and the WUAgent does not -- this places the cause squarely in the seat of WinHTTP. The reason the machine that worked (DNS name = dadayanstu-7.rockinst.org), did so, is because it did not try to use a proxy connection. As of 10:47am this morning (local time), the failing machine (DNS name = blockz-7.rockinst.org) was still trying to proxy through itself -- guaranteed to fail.

    2011-11-23 10:47:30:567 1004 1084 PT   + Last proxy send request failed with hr = 0x80072EFD, HTTP status code = 0
    2011-11-23 10:47:30:567 1004 1084 PT   + Proxy list used = 127.0.0.1:80

    Since this problem occurred simultaneously on all Windows 7 system -- I would venture an educated guess that the root cause is an errant Group Policy that is configuring every one of those systems (except blockz-7). Any chance that blockz-7 is in a different orgUnit than the other machines?


    Lawrence Garvin, M.S., MCITP:EA, MCDBA, MCSA
    Principal/CTO, Onsite Technology Solutions, Houston, Texas
    Microsoft MVP - Software Distribution (2005-2011)
    My MVP Profile: http://mvp.support.microsoft.com/profile/Lawrence.Garvin
    My Blog: http://onsitechsolutions.spaces.live.com

    Hi Lawrence,

    Thanks for the response.  Let me try and clear this up a little bit.  Firstly, all Windows 7 machines (including blockz-7 and dadayanstu-7) are in the same OU having the same Group Policies applied.  Also in this same OU are the XP and Vista machines that are having no trouble receiving updates.  I only posted the part of the WindowsUpdate.log for dadayanstu-7 in which it gave a status report to WSUS.  If I go further down in the log file, it has the same 127.0.0.1:80 entries as the other Windows 7 machines.

    I mentioned this earlier, but I had a newly formatted Windows 7 machine that has been on the shelf for several months.  I fired it up while unconnected to the network, and waited to plug it in until right before I clicked "try again" to force an update check.  It immediately came back with the 80072EFD error, and I unplugged it from the network.  In the WindowsUpdate.log, it had the entries about 127.0.0.1:80 from when I tried to force an update.  Would group policy have had time to change whatever changed on this machine?  This is a machine that has been on the shelf for months, and received updates fine before it was turned off.

    I also know that I can confirm no Group Policy changes or changes in network infrastructure have been made, at least by a member of the IT staff.  The only IT people on staff are myself and my boss, so it isn't like someone else could have made changes.  What Group Policy change do you think could have been made to instigate this behavior?

    Coincidentally or not, the past couple of days we have had reports from a few Windows 7 users that their IE9 browsers were acting strange.  By strange, I mean sometimes the back button could not be used, and if you were to right click a link and select for it to open in a new tab, it would not work.  We found the fix to this to be un-checking "Enable Protected Mode" for the Internet zone in the Security Tab of the Internet options.  After un-checking this, and restarting the browser, and quirky behavior exhibited seemed fixed.  Do you know if this "Protected Mode" issue could be related to the WSUS issue we are having?

    Thanks for your help on this so far, we appreciate it.


    • Edited by RockAdmin Wednesday, November 23, 2011 7:10 PM added additional info
    Wednesday, November 23, 2011 7:01 PM
  • If I go further down in the log file, it has the same 127.0.0.1:80 entries as the other Windows 7 machines.

    Are these same proxy server entries present in the Vista or XP machines?

    Would group policy have had time to change whatever changed on this machine?

    Well, yes, because group policy is going to be applied as soon as the machine first obtains its network connection. There's a myriad of other background things that happen in the blink of an eye as well; for example, most likely this machine also updated the domain computer account password -- all of which happened subsequent to the machine obtaining a DHCP address and registring with DNS when you plugged in the network cable.

    What Group Policy change do you think could have been made to instigate this behavior?

    I don't know that it is a GPO, but that is one possibility to consider.

    In any event it's all going to revolve around finding the source of that errant proxy configuration.

    Any chance all of these Windows 7 machines are built from the same image and the configuration is in the master image?


    Lawrence Garvin, M.S., MCITP:EA, MCDBA, MCSA
    Principal/CTO, Onsite Technology Solutions, Houston, Texas
    Microsoft MVP - Software Distribution (2005-2011)
    My MVP Profile: http://mvp.support.microsoft.com/profile/Lawrence.Garvin
    My Blog: http://onsitechsolutions.spaces.live.com
    Thursday, November 24, 2011 2:57 PM
    Moderator
  • Hi Lawrence, hope you had a nice holiday.

    To answer your questions:

    1. Are these same proxy server entries present in the Vista or XP machines?

    No, below I've pasted the log from an XP machine right after bootup, and wuauclt /detectnow.  There is no mention of 127.0.0.1.  Maybe there's something helpful in it though.

     

    2011-11-28	08:03:53:671	1408	2c4	Misc	===========  Logging initialized (build: 7.4.7600.226, tz: -0500)  ===========
    2011-11-28	08:03:53:671	1408	2c4	Misc	  = Process: C:\WINDOWS\System32\svchost.exe
    2011-11-28	08:03:53:671	1408	2c4	Misc	  = Module: C:\WINDOWS\system32\wuaueng.dll
    2011-11-28	08:03:53:671	1408	2c4	Service	*************
    2011-11-28	08:03:53:671	1408	2c4	Service	** START **  Service: Service startup
    2011-11-28	08:03:53:671	1408	2c4	Service	*********
    2011-11-28	08:03:56:609	1408	2c4	Agent	  * WU client version 7.4.7600.226
    2011-11-28	08:03:56:609	1408	2c4	Agent	  * Base directory: C:\WINDOWS\SoftwareDistribution
    2011-11-28	08:03:56:625	1408	2c4	Agent	  * Access type: No proxy
    2011-11-28	08:03:56:625	1408	2c4	Agent	  * Network state: Connected
    2011-11-28	08:04:43:257	1408	2c4	Agent	***********  Agent: Initializing Windows Update Agent  ***********
    2011-11-28	08:04:43:257	1408	2c4	Agent	***********  Agent: Initializing global settings cache  ***********
    2011-11-28	08:04:43:273	1408	2c4	Agent	  * WSUS server: http://10.0.0.25
    2011-11-28	08:04:43:273	1408	2c4	Agent	  * WSUS status server: http://10.0.0.25
    2011-11-28	08:04:43:273	1408	2c4	Agent	  * Target group: RIG Workstations
    2011-11-28	08:04:43:273	1408	2c4	Agent	  * Windows Update access disabled: No
    2011-11-28	08:04:43:288	1408	2c4	DnldMgr	Download manager restoring 0 downloads
    2011-11-28	08:04:43:352	1408	2c4	AU	###########  AU: Initializing Automatic Updates  ###########
    2011-11-28	08:04:43:352	1408	2c4	AU	AU setting next detection timeout to 2011-11-28 13:04:43
    2011-11-28	08:04:43:352	1408	2c4	AU	AU setting next sqm report timeout to 2011-11-28 13:04:43
    2011-11-28	08:04:43:352	1408	2c4	AU	  # WSUS server: http://10.0.0.25
    2011-11-28	08:04:43:352	1408	2c4	AU	  # Detection frequency: 1
    2011-11-28	08:04:43:352	1408	2c4	AU	  # Target group: RIG Workstations
    2011-11-28	08:04:43:352	1408	2c4	AU	  # Approval type: Scheduled (Policy)
    2011-11-28	08:04:43:352	1408	2c4	AU	  # Scheduled install day/time: Thursday at 16:00
    2011-11-28	08:04:43:352	1408	2c4	AU	  # Auto-install minor updates: Yes (Policy)
    2011-11-28	08:04:43:352	1408	2c4	AU	  # Will interact with non-admins (Non-admins are elevated (Policy))
    2011-11-28	08:04:43:352	1408	2c4	AU	Initializing featured updates
    2011-11-28	08:04:43:352	1408	2c4	AU	Found 0 cached featured updates
    2011-11-28	08:04:44:584	1408	2c4	Report	***********  Report: Initializing static reporting data  ***********
    2011-11-28	08:04:44:584	1408	2c4	Report	  * OS Version = 5.1.2600.3.0.65792
    2011-11-28	08:04:44:648	1408	2c4	Report	  * Computer Brand = Dell Inc.                
    2011-11-28	08:04:44:648	1408	2c4	Report	  * Computer Model = OptiPlex 745                 
    2011-11-28	08:04:44:648	1408	2c4	Report	  * Bios Revision = 1.0.3 
    2011-11-28	08:04:44:648	1408	2c4	Report	  * Bios Name = Phoenix ROM BIOS PLUS Version 1.10 1.0.3 
    2011-11-28	08:04:44:648	1408	2c4	Report	  * Bios Release Date = 2006-08-31T00:00:00
    2011-11-28	08:04:44:648	1408	2c4	Report	  * Locale ID = 1033
    2011-11-28	08:04:45:074	1408	2c4	AU	AU finished delayed initialization
    2011-11-28	08:04:45:074	1408	2c4	AU	#############
    2011-11-28	08:04:45:074	1408	2c4	AU	## START ##  AU: Search for updates
    2011-11-28	08:04:45:074	1408	2c4	AU	#########
    2011-11-28	08:04:45:074	1408	d68	Agent	*************
    2011-11-28	08:04:45:074	1408	d68	Agent	** START **  Agent: Finding updates [CallerId = AutomaticUpdates]
    2011-11-28	08:04:45:074	1408	d68	Agent	*********
    2011-11-28	08:04:45:074	1408	d68	Agent	  * Online = No; Ignore download priority = No
    2011-11-28	08:04:45:074	1408	d68	Agent	  * Criteria = "IsHidden=0 and IsInstalled=0 and DeploymentAction='Installation' and IsAssigned=1 or IsHidden=0 and IsPresent=1 and DeploymentAction='Uninstallation' and IsAssigned=1 or IsHidden=0 and IsInstalled=1 and DeploymentAction='Installation' and IsAssigned=1 and RebootRequired=1 or IsHidden=0 and IsInstalled=0 and DeploymentAction='Uninstallation' and IsAssigned=1 and RebootRequired=1"
    2011-11-28	08:04:45:074	1408	d68	Agent	  * ServiceID = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7} Managed
    2011-11-28	08:04:45:074	1408	d68	Agent	  * Search Scope = {Machine}
    2011-11-28	08:04:45:074	1408	2c4	AU	<<## SUBMITTED ## AU: Search for updates [CallId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}]
    2011-11-28	08:05:06:806	1408	2c4	AU	Forced install timer expired for scheduled install
    2011-11-28	08:05:06:806	1408	2c4	AU	UpdateDownloadProperties: 0 download(s) are still in progress.
    2011-11-28	08:05:11:010	1408	2c4	AU	Setting AU scheduled install time to 2011-12-01 21:00:00
    2011-11-28	08:05:34:859	1408	5c4	AU	Triggering AU detection through DetectNow API
    2011-11-28	08:05:34:859	1408	5c4	AU	Will do the detection after current detection completes
    2011-11-28	08:05:48:957	1408	d68	Agent	  * Found 0 updates and 58 categories in search; evaluated appl. rules of 892 out of 2340 deployed entities
    2011-11-28	08:05:49:352	1408	d68	Agent	*********
    2011-11-28	08:05:49:352	1408	d68	Agent	**  END  **  Agent: Finding updates [CallerId = AutomaticUpdates]
    2011-11-28	08:05:49:352	1408	d68	Agent	*************
    2011-11-28	08:05:49:384	1408	9a0	AU	>>##  RESUMED  ## AU: Search for updates [CallId = {B659AED6-B32A-4DCF-9775-2222E2D1D7E7}]
    2011-11-28	08:05:49:384	1408	9a0	AU	  # 0 updates detected
    2011-11-28	08:05:49:384	1408	9a0	AU	#########
    2011-11-28	08:05:49:384	1408	9a0	AU	##  END  ##  AU: Search for updates [CallId = {B659AED6-B32A-4DCF-9775-2222E2D1D7E7}]
    2011-11-28	08:05:49:384	1408	9a0	AU	#############
    2011-11-28	08:05:49:384	1408	9a0	AU	Featured notifications is disabled.
    2011-11-28	08:05:49:384	1408	9a0	AU	Setting AU scheduled install time to 2011-12-01 21:00:00
    2011-11-28	08:05:49:384	1408	2c4	AU	#############
    2011-11-28	08:05:49:384	1408	2c4	AU	## START ##  AU: Search for updates
    2011-11-28	08:05:49:384	1408	2c4	AU	#########
    2011-11-28	08:05:49:384	1408	2c4	AU	<<## SUBMITTED ## AU: Search for updates [CallId = {11FF2A2A-00CA-45AC-82C2-00B1BB14FD3D}]
    2011-11-28	08:05:49:652	1408	d68	PT	WARNING: Cached cookie has expired or new PID is available
    2011-11-28	08:05:49:652	1408	d68	PT	Initializing simple targeting cookie, clientId = da027ded-05c6-4e19-b48d-edb280d37294, target group = RIG Workstations, DNS name = abaref-xp.rockinst.org
    2011-11-28	08:05:49:652	1408	d68	PT	  Server URL = http://10.0.0.25/SimpleAuthWebService/SimpleAuth.asmx
    2011-11-28	08:05:49:874	1408	d68	Report	Uploading 3 events using cached cookie, reporting URL = http://10.0.0.25/ReportingWebService/ReportingWebService.asmx
    2011-11-28	08:05:49:874	1408	d68	Report	Reporter successfully uploaded 3 events.
    2011-11-28	08:05:49:874	1408	d68	Report	REPORT EVENT: {C994F6FA-54B7-4D91-AA3F-A00D2D5C2B4E}	2011-11-28 08:04:43:352-0500	1	202	102	{00000000-0000-0000-0000-000000000000}	0	0	AutomaticUpdates	Success	Content Install	Reboot completed.
    2011-11-28	08:05:49:874	1408	d68	Agent	*************
    2011-11-28	08:05:49:889	1408	d68	Agent	** START **  Agent: Finding updates [CallerId = AutomaticUpdates]
    2011-11-28	08:05:49:889	1408	d68	Agent	*********
    2011-11-28	08:05:49:889	1408	d68	Agent	  * Online = Yes; Ignore download priority = No
    2011-11-28	08:05:49:889	1408	d68	Agent	  * Criteria = "IsHidden=0 and IsInstalled=0 and DeploymentAction='Installation' and IsAssigned=1 or IsHidden=0 and IsPresent=1 and DeploymentAction='Uninstallation' and IsAssigned=1 or IsHidden=0 and IsInstalled=1 and DeploymentAction='Installation' and IsAssigned=1 and RebootRequired=1 or IsHidden=0 and IsInstalled=0 and DeploymentAction='Uninstallation' and IsAssigned=1 and RebootRequired=1"
    2011-11-28	08:05:49:889	1408	d68	Agent	  * ServiceID = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7} Managed
    2011-11-28	08:05:49:889	1408	d68	Agent	  * Search Scope = {Machine}
    2011-11-28	08:05:49:937	1408	d68	Misc	Validating signature for C:\WINDOWS\SoftwareDistribution\SelfUpdate\Default\wuident.cab:
    2011-11-28	08:05:50:016	1408	d68	Misc	 Microsoft signed: Yes
    2011-11-28	08:05:50:079	1408	d68	Misc	Validating signature for C:\WINDOWS\SoftwareDistribution\SelfUpdate\Default\wuident.cab:
    2011-11-28	08:05:50:079	1408	d68	Misc	 Microsoft signed: Yes
    2011-11-28	08:05:50:474	1408	d68	Misc	Validating signature for C:\WINDOWS\SoftwareDistribution\SelfUpdate\Default\wsus3setup.cab:
    2011-11-28	08:05:50:490	1408	d68	Misc	 Microsoft signed: Yes
    2011-11-28	08:05:50:522	1408	d68	Setup	***********  Setup: Checking whether self-update is required  ***********
    2011-11-28	08:05:50:522	1408	d68	Setup	  * Inf file: C:\WINDOWS\SoftwareDistribution\SelfUpdate\Default\wsus3setup.inf
    2011-11-28	08:05:50:553	1408	d68	Setup	Update NOT required for C:\WINDOWS\system32\cdm.dll: target version = 7.4.7600.226, required version = 7.4.7600.226
    2011-11-28	08:05:50:553	1408	d68	Setup	Update NOT required for C:\WINDOWS\system32\wuapi.dll: target version = 7.4.7600.226, required version = 7.4.7600.226
    2011-11-28	08:05:50:585	1408	d68	Setup	Update NOT required for C:\WINDOWS\system32\wuapi.dll.mui: target version = 7.4.7600.226, required version = 7.4.7600.226
    2011-11-28	08:05:50:585	1408	d68	Setup	Update NOT required for C:\WINDOWS\system32\wuauclt.exe: target version = 7.4.7600.226, required version = 7.4.7600.226
    2011-11-28	08:05:50:585	1408	d68	Setup	Update NOT required for C:\WINDOWS\system32\wuaucpl.cpl: target version = 7.4.7600.226, required version = 7.4.7600.226
    2011-11-28	08:05:50:601	1408	d68	Setup	Update NOT required for C:\WINDOWS\system32\wuaucpl.cpl.mui: target version = 7.4.7600.226, required version = 7.4.7600.226
    2011-11-28	08:05:50:601	1408	d68	Setup	Update NOT required for C:\WINDOWS\system32\wuaueng.dll: target version = 7.4.7600.226, required version = 7.4.7600.226
    2011-11-28	08:05:50:632	1408	d68	Setup	Update NOT required for C:\WINDOWS\system32\wuaueng.dll.mui: target version = 7.4.7600.226, required version = 7.4.7600.226
    2011-11-28	08:05:50:632	1408	d68	Setup	Update NOT required for C:\WINDOWS\system32\wucltui.dll: target version = 7.4.7600.226, required version = 7.4.7600.226
    2011-11-28	08:05:50:648	1408	d68	Setup	Update NOT required for C:\WINDOWS\system32\wucltui.dll.mui: target version = 7.4.7600.226, required version = 7.4.7600.226
    2011-11-28	08:05:50:648	1408	d68	Setup	Update NOT required for C:\WINDOWS\system32\wups.dll: target version = 7.4.7600.226, required version = 7.4.7600.226
    2011-11-28	08:05:50:648	1408	d68	Setup	Update NOT required for C:\WINDOWS\system32\wups2.dll: target version = 7.4.7600.226, required version = 7.4.7600.226
    2011-11-28	08:05:50:664	1408	d68	Setup	Update NOT required for C:\WINDOWS\system32\wuweb.dll: target version = 7.4.7600.226, required version = 7.4.7600.226
    2011-11-28	08:05:50:664	1408	d68	Setup	  * IsUpdateRequired = No
    2011-11-28	08:05:56:812	1408	d68	PT	+++++++++++  PT: Synchronizing server updates  +++++++++++
    2011-11-28	08:05:56:812	1408	d68	PT	  + ServiceId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}, Server URL = http://10.0.0.25/ClientWebService/client.asmx
    2011-11-28	08:06:01:079	1408	d68	PT	+++++++++++  PT: Synchronizing extended update info  +++++++++++
    2011-11-28	08:06:01:079	1408	d68	PT	  + ServiceId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}, Server URL = http://10.0.0.25/ClientWebService/client.asmx
    2011-11-28	08:06:06:216	1408	d68	Agent	  * Found 0 updates and 58 categories in search; evaluated appl. rules of 1121 out of 2340 deployed entities
    2011-11-28	08:06:06:326	1408	d68	Agent	*********
    2011-11-28	08:06:06:326	1408	d68	Agent	**  END  **  Agent: Finding updates [CallerId = AutomaticUpdates]
    2011-11-28	08:06:06:326	1408	d68	Agent	*************
    2011-11-28	08:06:06:342	1408	9a0	AU	>>##  RESUMED  ## AU: Search for updates [CallId = {11FF2A2A-00CA-45AC-82C2-00B1BB14FD3D}]
    2011-11-28	08:06:06:342	1408	9a0	AU	  # 0 updates detected
    2011-11-28	08:06:06:358	1408	9a0	AU	#########
    2011-11-28	08:06:06:358	1408	9a0	AU	##  END  ##  AU: Search for updates [CallId = {11FF2A2A-00CA-45AC-82C2-00B1BB14FD3D}]
    2011-11-28	08:06:06:358	1408	9a0	AU	#############
    2011-11-28	08:06:06:358	1408	9a0	AU	Featured notifications is disabled.
    2011-11-28	08:06:06:358	1408	9a0	AU	AU setting next detection timeout to 2011-11-28 13:58:59
    2011-11-28	08:06:06:358	1408	9a0	AU	Setting AU scheduled install time to 2011-12-01 21:00:00
    2011-11-28	08:06:11:384	1408	d68	Report	REPORT EVENT: {DAAFB104-E11B-4075-B1E7-13007674083E}	2011-11-28 08:06:06:326-0500	1	147	101	{00000000-0000-0000-0000-000000000000}	0	0	AutomaticUpdates	Success	Software Synchronization	Windows Update Client successfully detected 0 updates.
    2011-11-28	08:06:11:384	1408	d68	Report	REPORT EVENT: {FA76F928-052C-40C4-9BB7-5B0B218C6E98}	2011-11-28 08:06:06:326-0500	1	156	101	{00000000-0000-0000-0000-000000000000}	0	0	AutomaticUpdates	Success	Pre-Deployment Check	Reporting client status.
    2011-11-28	08:13:51:257	1408	d68	Report	Uploading 3 events using cached cookie, reporting URL = http://10.0.0.25/ReportingWebService/ReportingWebService.asmx
    2011-11-28	08:13:51:571	1408	d68	Report	Reporter successfully uploaded 3 events.

    2. Got it, I had it in my head it only refreshed at certain intervals, but it does make sense as soon as you connect a machine to the network, it gets the latest GP.

    3. The Windows 7 machines are not built from single image, so some come directly from the manufacturer with W7 installed, others get it via an upgrade.  So there isn't a cookie cutter image going out that has a specific configuration in it.

    So let me know if the Windows XP log gives you any more ideas.  I'm going to try and investigate our group policies this morning.

    Monday, November 28, 2011 1:40 PM
  • Lawrence,

    As I've written before, I've tried showing displaying my proxy settings to confirm I wasn't using one.  As you can see below, it says Direct access.  This still produced the 127.0.0.1:80 entries in the WindowsUpdate.log though.

    C:\Windows\system32>netsh winhttp show proxy
    
    Current WinHTTP proxy settings:
    
        Direct access (no proxy server).
    As a test, I tried manually setting my proxy to that of my WSUS server.  I then tried to force my machine to find updates, and it actually did.  The WindowsUpdate.log has nothing about 127.0.0.1:80 from my latest attempt, and it looks normal.

    C:\Windows\system32>netsh winhttp set proxy 10.0.0.25:80
    
    Current WinHTTP proxy settings:
    
        Proxy Server(s) :  10.0.0.25:80
        Bypass List     :  (none)

    The question now is, why do I need to even do this?  Before when I displayed the proxy, it showed no proxy.  I even reset the proxy to which it showed no proxy, and still wouldn't work.  Now that I'm forcing it to use my WSUS server as a proxy, it works.

    I'm going to try installing my updates, resetting the proxy back to nothing, rebooting, and see if it will find updates after I reboot.

    Monday, November 28, 2011 3:03 PM
  • I got my updates, but resetting the proxy and rebooting does indeed bring me back to an 80072EFD when I try to find updates.
    Monday, November 28, 2011 3:33 PM
  • Lawrence,

    I was looking through the log file from when I manually added the proxy in netsh.  I previously said it has nothing about 127.0.0.1:80 in the log file, but I found that it does, just in different places.  The log file is too large to insert in this thread, but I have saved it to a txt file and stuck it in my dropbox public folder.  You can view the logfile here: http://dl.dropbox.com/u/6590381/manual_netsh_proxy_entry.txt

    Briefly, an example of 127.0.0.0.1:80 in this log file, is here:

    2011-11-28	09:55:53:762	1004	1e18	DnldMgr	BITS job {B62A11DC-B0A2-4334-A36E-6E282902C14D} using proxy = 10.0.0.25:80;127.0.0.1:80, bypass = <NULL>

    See how it tries to use 10.0.0.25 and 127.0.0.0.1.  Seems like that 127.0.0.1 is still buried some place in the settings, but it used the 10.0.0.25 I set manually as the primary so it worked.

    Thanks

     

    Monday, November 28, 2011 4:46 PM
  • Ok, so I disabled the group policy which provides the clients their settings for WSUS.  I did a gpupdate /force so that it went out.  I made sure my workstation got the updated policy (or lack thereof) with gpresult /r.  I went to force an update check, and it took a few minutes of searching, and then came back with a few available updates, all from the Microsoft update site, which is what I would expect.

    Next I went into my machine's local group policy (gpedit.msc) hoping I could force my workstation to connect to my WSUS server with minimal configuration, just basically specifying the intranet server.  I navigated to Computer Configuration -> Administrative Templates -> Windows Components -> Windows Updates, and edited the "Specify intranet Microsoft update service location".  I plugged in the IP of my WSUS server, enabled the policy, and then tried to force another update check.  This time it seemed to search indefinitely (I let it go about 15 minutes when it normally dies instantly), I checked the logs, and it was just looping over and over again with the 127.0.0.1-type entries.

    I decided to undo the changes I made to my local group policy, and re-enable the domain-wide WSUS group policy.  I was hoping maybe clearing the policies out might have helped, but it didn't.  It's back to giving 80072EFD errors when I try to force an update check.

    So far the only way I've gotten it to work using my WSUS server, is to use netsh to manually add that proxy with the IP to my WSUS server.  Then all is right in update-land, I just know that is a band-aid solution, and not addressing why it is I have to do that.

    Monday, November 28, 2011 8:21 PM
  • Since the last response on the thread, I’ve been able to get Windows 7 machines to detect their updates after running the command:

    netsh winhttp set proxy 10.0.0.25:80

    After I do this and check the log, the only reference to a 127.0.0.1 entry I see is in a line like this:

    2011-11-28          09:55:53:762       1004       1e18      DnldMgr              BITS job {B62A11DC-B0A2-4334-A36E-6E282902C14D} using proxy = 10.0.0.25:80;127.0.0.1:80, bypass = <NULL>

    Entire log here: http://dl.dropbox.com/u/6590381/manual_netsh_proxy_entry.txt

    It looks to me like the 127.0.0.1 becomes the secondary proxy after I manually input the IP of my WSUS server, and isn’t needed because it can now get to the WSUS (primary). 

    After I reset the WinHTTP proxy settings so that it reads “Direct access” and reboot, I can no longer access the WSUS, and 127.0.0.1 dominates the log again as the only proxy being used.  Do you have any guesses why resetting the WinHTTP proxy settings does not seem to have an effect on clearing out the localhost as the Windows Update client still tries to use 127.0.0.1 as its proxy?

    I’ve also tried experimenting by sticking my test machine in its own OU where I then proceeded to Block Inheritance on all GPO’s, so I could rule out one of them interfering.  I get the same results.

    Lastly, if I can’t end up getting this fixed, would setting the proxy manually on the Windows 7 machines and leaving it like that create any problems?  It didn’t seem to on the machines I tested on (could still access internet, network servers, etc).

    Thanks again for your help on this and I’d like to thank you in advance for any additional tips or insights you’d be able to provide me on this that might point me in the right direction.

    • Proposed as answer by jlmcjrsyt Monday, December 5, 2011 11:18 AM
    • Unproposed as answer by jlmcjrsyt Monday, December 5, 2011 11:18 AM
    Tuesday, November 29, 2011 4:03 PM
  • Not sure if this will help, but I was having a similar issue, and what I found as the root cause is potentially an extremely ugly hack...

    While researching the error, I was running a network monitor and found that although I have no proxy server in the domain, it was, like in your case setting the proxy to localhost. WPAD was searching for a wpad server, and finding none in the network, starts reaching out... Someone has put up a server and somehow managed to get domains without a TLD into dns (it appears to be hosted at a rackspace farm in Dallas)... for example your domain is example.com... they have put in a server that answers to wpad.example, with a wpad.dat file that points back to localhost, effectively highjacking anything that uses winhttp, although without help in the middle the net result is to prevent windows update and other functions that use winhttp as their primary protocol.

    To fix this, I simply added an example forwarding zone to my domain dns... Not the ideal solution, but as a workaround it solved several issues I was seeing on the clients network... next step, go back and fix all the crap left behind by my predecessor that would have prevented this in the first place...

    Hope this helps and is looked into further.

    John


    • Edited by jlmcjrsyt Monday, December 5, 2011 4:53 PM
    • Marked as answer by RockAdmin Friday, December 9, 2011 3:03 PM
    Monday, December 5, 2011 11:35 AM
  • Not sure if this will help, but I was having a similar issue, and what I found as the root cause is potentially an extremely ugly hack...

    While researching the error, I was running a network monitor and found that although I have no proxy server in the domain, it was, like in your case setting the proxy to localhost. WPAD was searching for a wpad server, and finding none in the network, starts reaching out... Someone has put up a server and somehow managed to get domains without a TLD into dns (it appears to be hosted at a rackspace farm in Dallas)... for example your domain is example.com... they have put in a server that answers to wpad.example, with a wpad.dat file that points back to localhost, effectively highjacking anything that uses winhttp, although without help in the middle the net result is to prevent windows update and other functions that use winhttp as their primary protocol.

    To fix this, I simply added an example forwarding zone to my domain dns... Not the ideal solution, but as a workaround it solved several issues I was seeing on the clients network... next step, go back and fix all the crap left behind by my predesessor that would have prevented this in the first place...

    Hope this helps and is looked into further.

    John

    John,

    Thanks so much for your reply.  I think you've hit the nail on the head.  I did an nslookup of wpad.domain and this is what I get:

    Now if I run a tracert to these IP's, guess where I am taken?  A rackspace farm in Dallas...

    I will try your suggestion of adding a forwarding zone.  After I do that, I'll get back to you.  I am curious though how something like this can happen, and what I can do to stop it in the future?

    Thanks a lot for your help so far!

    Monday, December 5, 2011 2:51 PM
  • WPAD was searching for a wpad server, and finding none in the network, starts reaching out...

    While it's unfortunate that somebody has put such a service on the public Internet, it also begs pointing out that an organization that does not use WPAD, probably should DISABLE that functionality on their client systems.

    Turning off WPAD detection seems to me to be a much more appropriate solution than hacking invalid forwarding zones into DNS.


    Lawrence Garvin, M.S., MCITP:EA, MCDBA, MCSA
    Principal/CTO, Onsite Technology Solutions, Houston, Texas
    Microsoft MVP - Software Distribution (2005-2011)
    My MVP Profile: http://mvp.support.microsoft.com/profile/Lawrence.Garvin
    My Blog: http://onsitechsolutions.spaces.live.com

    Monday, December 5, 2011 5:02 PM
    Moderator
  • Hi......I wanted to reply to your posts because I spent at least 6 hours yesterday trying to figure out a solution to this problem.  I was experiencing the EXACT same issues that you posted in this forum....exactly.  Your posts were very helpful towards finding a solution.  Basically, I just disabled the "WinHTTP Web Proxy Auto-Discovery Service", and all was well.  I think that is a much easier solution than messing with your DNS, as long as you don't use the WPAD service.  Lawrence's comment below and this page put me on the right track.......

    http://social.technet.microsoft.com/Forums/en-US/winserverPN/thread/291bfa80-7bac-4184-bbf1-6525f4eba8bb

    Thanks again.

    • Edited by TPGWorks Tuesday, December 6, 2011 4:31 PM
    Tuesday, December 6, 2011 4:10 PM
  • This one is driving me crazy, as I have looked through many other forums.  I'm having the same issue as RockAdmin down to some screwy IE happenings (clicked links not loading, turning off protected mode got them working), but I had no proxy entry in windowsupdate.log and no strange entries in DNS.  No Windows 7 client will contact WSUS successfully.  All other (XP, server 2003 R2) clients do.  Did you shutdown winhttp on the server or client computers?  Shutting the service down on client did not work for me. A portion of my windowsupdate.log can be seen below:

    2012-02-07 14:40:54:727 1232 1d38 AU Triggering AU detection through DetectNow API
    2012-02-07 14:40:54:727 1232 1d38 AU Triggering Online detection (interactive)
    2012-02-07 14:40:54:727 1232 15d0 AU #############
    2012-02-07 14:40:54:727 1232 15d0 AU ## START ##  AU: Search for updates
    2012-02-07 14:40:54:727 1232 15d0 AU #########
    2012-02-07 14:40:54:742 1232 15d0 AU <<## SUBMITTED ## AU: Search for updates [CallId = {F37EEE0C-A977-4C7C-9675-3036F2400385}]
    2012-02-07 14:40:54:742 1232 16c8 Agent *************
    2012-02-07 14:40:54:742 1232 16c8 Agent ** START **  Agent: Finding updates [CallerId = AutomaticUpdates]
    2012-02-07 14:40:54:742 1232 16c8 Agent *********
    2012-02-07 14:40:54:742 1232 16c8 Agent  * Online = Yes; Ignore download priority = No
    2012-02-07 14:40:54:742 1232 16c8 Agent  * Criteria = "IsInstalled=0 and DeploymentAction='Installation' or IsPresent=1 and DeploymentAction='Uninstallation' or IsInstalled=1 and DeploymentAction='Installation' and RebootRequired=1 or IsInstalled=0 and DeploymentAction='Uninstallation' and RebootRequired=1"
    2012-02-07 14:40:54:742 1232 16c8 Agent  * ServiceID = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7} Managed
    2012-02-07 14:40:54:742 1232 16c8 Agent  * Search Scope = {Machine}
    2012-02-07 14:40:54:773 1232 16c8 Setup Checking for agent SelfUpdate
    2012-02-07 14:40:54:773 1232 16c8 Setup Client version: Core: 7.5.7601.17514  Aux: 7.5.7601.17514
    2012-02-07 14:40:54:773 1232 16c8 Misc Validating signature for C:\Windows\SoftwareDistribution\SelfUpdate\wuident.cab:
    2012-02-07 14:40:54:773 1232 16c8 Misc Microsoft signed: Yes
    2012-02-07 14:40:54:789 1232 16c8 Misc Validating signature for C:\Windows\SoftwareDistribution\SelfUpdate\wuident.cab:
    2012-02-07 14:40:54:805 1232 16c8 Misc Microsoft signed: Yes
    2012-02-07 14:40:54:805 1232 16c8 Misc Validating signature for C:\Windows\SoftwareDistribution\SelfUpdate\wsus3setup.cab:
    2012-02-07 14:40:54:805 1232 16c8 Misc Microsoft signed: Yes
    2012-02-07 14:40:54:820 1232 16c8 Misc Validating signature for C:\Windows\SoftwareDistribution\SelfUpdate\wsus3setup.cab:
    2012-02-07 14:40:54:836 1232 16c8 Misc Microsoft signed: Yes
    2012-02-07 14:40:54:851 1232 16c8 Setup Determining whether a new setup handler needs to be downloaded
    2012-02-07 14:40:54:851 1232 16c8 Setup SelfUpdate handler is not found.  It will be downloaded
    2012-02-07 14:40:54:851 1232 16c8 Setup Evaluating applicability of setup package "WUClient-SelfUpdate-ActiveX~31bf3856ad364e35~x86~~7.4.7600.226"
    2012-02-07 14:40:54:867 1232 16c8 Setup Setup package "WUClient-SelfUpdate-ActiveX~31bf3856ad364e35~x86~~7.4.7600.226" is not applicable
    2012-02-07 14:40:54:867 1232 16c8 Setup Evaluating applicability of setup package "WUClient-SelfUpdate-Aux-TopLevel~31bf3856ad364e35~x86~~7.4.7600.226"
    2012-02-07 14:40:54:883 1232 16c8 Setup Setup package "WUClient-SelfUpdate-Aux-TopLevel~31bf3856ad364e35~x86~~7.4.7600.226" is not applicable
    2012-02-07 14:40:54:883 1232 16c8 Setup Evaluating applicability of setup package "WUClient-SelfUpdate-Core-TopLevel~31bf3856ad364e35~x86~~7.4.7600.226"
    2012-02-07 14:40:54:898 1232 16c8 Setup Setup package "WUClient-SelfUpdate-Core-TopLevel~31bf3856ad364e35~x86~~7.4.7600.226" is not applicable
    2012-02-07 14:40:54:898 1232 16c8 Setup SelfUpdate check completed.  SelfUpdate is NOT required.
    2012-02-07 14:40:55:709 1232 16c8 PT +++++++++++  PT: Synchronizing server updates  +++++++++++
    2012-02-07 14:40:55:709 1232 16c8 PT  + ServiceId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}, Server URL = http://PAXR-UTIL1:8530/ClientWebService/client.asmx
    2012-02-07 14:40:55:725 1232 16c8 PT WARNING: Cached cookie has expired or new PID is available
    2012-02-07 14:40:55:725 1232 16c8 PT Initializing simple targeting cookie, clientId = 0ab3be6c-113c-4191-934d-ec9029effc3a, target group = , DNS name = pax-hatchj.ampierce.com
    2012-02-07 14:40:55:725 1232 16c8 PT  Server URL = http://PAXR-UTIL1:8530/SimpleAuthWebService/SimpleAuth.asmx
    2012-02-07 14:40:55:756 1232 16c8 PT WARNING: GetAuthorizationCookie failure, error = 0x80244019, soap client error = 10, soap error code = 0, HTTP status code = 404
    2012-02-07 14:40:55:756 1232 16c8 PT WARNING: Failed to initialize Simple Targeting Cookie: 0x80244019
    2012-02-07 14:40:55:756 1232 16c8 PT WARNING: PopulateAuthCookies failed: 0x80244019
    2012-02-07 14:40:55:756 1232 16c8 PT WARNING: RefreshCookie failed: 0x80244019
    2012-02-07 14:40:55:756 1232 16c8 PT WARNING: RefreshPTState failed: 0x80244019
    2012-02-07 14:40:55:756 1232 16c8 PT WARNING: Sync of Updates: 0x80244019
    2012-02-07 14:40:55:756 1232 16c8 PT WARNING: SyncServerUpdatesInternal failed: 0x80244019
    2012-02-07 14:40:55:756 1232 16c8 Agent  * WARNING: Failed to synchronize, error = 0x80244019
    2012-02-07 14:40:55:756 1232 16c8 Agent  * WARNING: Exit code = 0x80244019
    2012-02-07 14:40:55:756 1232 16c8 Agent *********
    2012-02-07 14:40:55:756 1232 16c8 Agent **  END  **  Agent: Finding updates [CallerId = AutomaticUpdates]
    2012-02-07 14:40:55:756 1232 16c8 Agent *************
    2012-02-07 14:40:55:756 1232 16c8 Agent WARNING: WU client failed Searching for update with error 0x80244019
    2012-02-07 14:40:55:772 1232 1e64 AU >>##  RESUMED  ## AU: Search for updates [CallId = {F37EEE0C-A977-4C7C-9675-3036F2400385}]
    2012-02-07 14:40:55:772 1232 1e64 AU  # WARNING: Search callback failed, result = 0x80244019
    2012-02-07 14:40:55:772 1232 1e64 AU  # WARNING: Failed to find updates with error code 80244019
    2012-02-07 14:40:55:772 1232 1e64 AU #########
    2012-02-07 14:40:55:772 1232 1e64 AU ##  END  ##  AU: Search for updates [CallId = {F37EEE0C-A977-4C7C-9675-3036F2400385}]
    2012-02-07 14:40:55:772 1232 1e64 AU #############
    2012-02-07 14:40:55:772 1232 1e64 AU Successfully wrote event for AU health state:0
    2012-02-07 14:40:55:772 1232 1e64 AU AU setting next detection timeout to 2012-02-08 00:40:55
    2012-02-07 14:40:55:772 1232 1e64 AU Setting AU scheduled install time to 2012-02-08 08:00:00
    2012-02-07 14:40:55:772 1232 1e64 AU Successfully wrote event for AU health state:0
    2012-02-07 14:40:55:772 1232 1e64 AU Successfully wrote event for AU health state:0
    2012-02-07 14:41:00:764 1232 16c8 Report REPORT EVENT: {803C5273-46B5-489B-BEF1-2E9C4A0D22B7} 2012-02-07 14:40:55:756-0500 1 148 101 {00000000-0000-0000-0000-000000000000} 0 80244019 AutomaticUpdates Failure Software Synchronization Windows Update Client failed to detect with error 0x80244019.
    2012-02-07 14:41:00:764 1232 16c8 Report CWERReporter::HandleEvents - WER report upload completed with status 0x8
    2012-02-07 14:41:00:764 1232 16c8 Report WER Report sent: 7.5.7601.17514 0x80244019 00000000-0000-0000-0000-000000000000 Scan 101 Managed
    2012-02-07 14:41:00:764 1232 16c8 Report CWERReporter finishing event handling. (00000000)
    2012-02-07 14:45:23:488 1232 16c8 PT WARNING: Cached cookie has expired or new PID is available
    2012-02-07 14:45:23:488 1232 16c8 PT Initializing simple targeting cookie, clientId = 0ab3be6c-113c-4191-934d-ec9029effc3a, target group = , DNS name = pax-hatchj.ampierce.com
    2012-02-07 14:45:23:488 1232 16c8 PT  Server URL = http://PAXR-UTIL1:8530/SimpleAuthWebService/SimpleAuth.asmx
    2012-02-07 14:45:23:516 1232 16c8 PT WARNING: GetAuthorizationCookie failure, error = 0x80244019, soap client error = 10, soap error code = 0, HTTP status code = 404
    2012-02-07 14:45:23:516 1232 16c8 PT WARNING: Failed to initialize Simple Targeting Cookie: 0x80244019
    2012-02-07 14:45:23:516 1232 16c8 PT WARNING: PopulateAuthCookies failed: 0x80244019
    2012-02-07 14:45:23:516 1232 16c8 PT WARNING: RefreshCookie failed: 0x80244019
    2012-02-07 14:45:23:517 1232 16c8 PT WARNING: RefreshPTState failed: 0x80244019
    2012-02-07 14:45:23:517 1232 16c8 PT WARNING: PTError: 0x80244019
    2012-02-07 14:45:23:517 1232 16c8 Report WARNING: Reporter failed to upload events with hr = 80244019.
    2012-02-07 15:09:31:569 1232 1e50 PT WARNING: Cached cookie has expired or new PID is available
    2012-02-07 15:09:31:569 1232 1e50 PT Initializing simple targeting cookie, clientId = 0ab3be6c-113c-4191-934d-ec9029effc3a, target group = , DNS name = pax-hatchj.ampierce.com
    2012-02-07 15:09:31:569 1232 1e50 PT  Server URL = http://PAXR-UTIL1:8530/SimpleAuthWebService/SimpleAuth.asmx
    2012-02-07 15:09:31:601 1232 1e50 PT WARNING: GetAuthorizationCookie failure, error = 0x80244019, soap client error = 10, soap error code = 0, HTTP status code = 404
    2012-02-07 15:09:31:601 1232 1e50 PT WARNING: Failed to initialize Simple Targeting Cookie: 0x80244019
    2012-02-07 15:09:31:601 1232 1e50 PT WARNING: PopulateAuthCookies failed: 0x80244019
    2012-02-07 15:09:31:601 1232 1e50 PT WARNING: RefreshCookie failed: 0x80244019
    2012-02-07 15:09:31:601 1232 1e50 PT WARNING: RefreshPTState failed: 0x80244019
    2012-02-07 15:09:31:601 1232 1e50 PT WARNING: PTError: 0x80244019
    2012-02-07 15:09:31:601 1232 1e50 Report WARNING: Reporter failed to upload events with hr = 80244019.
    2012-02-07 15:34:54:695 1232 a54 PT WARNING: Cached cookie has expired or new PID is available
    2012-02-07 15:34:54:696 1232 a54 PT Initializing simple targeting cookie, clientId = 0ab3be6c-113c-4191-934d-ec9029effc3a, target group = , DNS name = pax-hatchj.ampierce.com
    2012-02-07 15:34:54:696 1232 a54 PT  Server URL = http://PAXR-UTIL1:8530/SimpleAuthWebService/SimpleAuth.asmx
    2012-02-07 15:34:55:249 1232 a54 PT WARNING: GetAuthorizationCookie failure, error = 0x80244019, soap client error = 10, soap error code = 0, HTTP status code = 404
    2012-02-07 15:34:55:249 1232 a54 PT WARNING: Failed to initialize Simple Targeting Cookie: 0x80244019
    2012-02-07 15:34:55:249 1232 a54 PT WARNING: PopulateAuthCookies failed: 0x80244019
    2012-02-07 15:34:55:249 1232 a54 PT WARNING: RefreshCookie failed: 0x80244019
    2012-02-07 15:34:55:249 1232 a54 PT WARNING: RefreshPTState failed: 0x80244019
    2012-02-07 15:34:55:249 1232 a54 PT WARNING: PTError: 0x80244019
    2012-02-07 15:34:55:249 1232 a54 Report WARNING: Reporter failed to upload events with hr = 80244019.
    2012-02-07 15:49:33:330 1232 a54 PT WARNING: Cached cookie has expired or new PID is available
    2012-02-07 15:49:33:330 1232 a54 PT Initializing simple targeting cookie, clientId = 0ab3be6c-113c-4191-934d-ec9029effc3a, target group = , DNS name = pax-hatchj.ampierce.com
    2012-02-07 15:49:33:330 1232 a54 PT  Server URL = http://PAXR-UTIL1:8530/SimpleAuthWebService/SimpleAuth.asmx
    2012-02-07 15:49:33:358 1232 a54 PT WARNING: GetAuthorizationCookie failure, error = 0x80244019, soap client error = 10, soap error code = 0, HTTP status code = 404
    2012-02-07 15:49:33:358 1232 a54 PT WARNING: Failed to initialize Simple Targeting Cookie: 0x80244019
    2012-02-07 15:49:33:358 1232 a54 PT WARNING: PopulateAuthCookies failed: 0x80244019
    2012-02-07 15:49:33:358 1232 a54 PT WARNING: RefreshCookie failed: 0x80244019
    2012-02-07 15:49:33:358 1232 a54 PT WARNING: RefreshPTState failed: 0x80244019
    2012-02-07 15:49:33:358 1232 a54 PT WARNING: PTError: 0x80244019
    2012-02-07 15:49:33:358 1232 a54 Report WARNING: Reporter failed to upload events with hr = 80244019.



    • Edited by jmhhatch Tuesday, February 7, 2012 9:22 PM
    Tuesday, February 7, 2012 8:56 PM
  • I'm having the same issue as RockAdmin
    I can't comment on your other "wierd" isuses, since you did not post any actual details about them, but this is a plain old HTTP 404 error -- probably due to a misconfigured URL in the GPO.

    2012-02-07 15:49:33:3301232 a54PT  Server URL = http://PAXR-UTIL1:8530/SimpleAuthWebService/SimpleAuth.asmx

    2012-02-07 15:49:33:3581232 a54PT WARNING: GetAuthorizationCookie failure, error = 0x80244019, soap client error = 10, soap error code = 0, HTTP status code = 404

    It would appear that the WSUS server is not at http://paxr-util1:8530 -- either the port number is incorrect, or this client is resolving paxr-util1 to a different web server.

    Lawrence Garvin, M.S., MCITP:EA, MCDBA, MCSA
    Principal/CTO, Onsite Technology Solutions, Houston, Texas
    Microsoft MVP - Software Distribution (2005-2012)
    My MVP Profile: http://mvp.support.microsoft.com/profile/Lawrence.Garvin

    Friday, February 10, 2012 2:51 PM
    Moderator
  • I'm having the same issue as RockAdmin
    I can't comment on your other "wierd" isuses, since you did not post any actual details about them, but this is a plain old HTTP 404 error -- probably due to a misconfigured URL in the GPO.

    2012-02-07 15:49:33:3301232a54PT  Server URL = http://PAXR-UTIL1:8530/SimpleAuthWebService/SimpleAuth.asmx

    2012-02-07 15:49:33:3581232a54PT WARNING: GetAuthorizationCookie failure, error = 0x80244019, soap client error = 10, soap error code = 0, HTTP status code = 404

    It would appear that the WSUS server is not at http://paxr-util1:8530 -- either the port number is incorrect, or this client is resolving paxr-util1 to a different web server.

    Lawrence Garvin, M.S., MCITP:EA, MCDBA, MCSA
    Principal/CTO, Onsite Technology Solutions, Houston, Texas
    Microsoft MVP - Software Distribution (2005-2012)
    My MVP Profile: http://mvp.support.microsoft.com/profile/Lawrence.Garvin


    Friday, February 10, 2012 2:51 PM
    Moderator
  • Thanks for your input Lawrence, but as you can see from the two logs I posted at http://social.technet.microsoft.com/Forums/en-US/winserverwsus/thread/34ea3d30-d419-47df-98b0-caf56065c115/#583c78a6-9130-4da4-8f28-546e22ce76a7 .   The XP clients are clearly using the WSUS in that location.  The Windows 7 clients are not.  Since they are all in the same OU with the same GPO applied where else could I look for differences in how these two different machines obtain WSUS connectivity?

    PS- I did an nslookup with the FQDN of the WSUS and it did resolve correctly on the Windows 7 client.

    Friday, February 17, 2012 1:09 PM
  • Thanks for your input Lawrence, but as you can see from the two logs I posted at http://social.technet.microsoft.com/Forums/en-US/winserverwsus/thread/34ea3d30-d419-47df-98b0-caf56065c115/#583c78a6-9130-4da4-8f28-546e22ce76a7 .   The XP clients are clearly using the WSUS in that location.  The Windows 7 clients are not.  Since they are all in the same OU with the same GPO applied where else could I look for differences in how these two different machines obtain WSUS connectivity?

    PS- I did an nslookup with the FQDN of the WSUS and it did resolve correctly on the Windows 7 client.

    Then review the IIS logs for the connections coming from the Windows 7 clients and determine exactly why IIS is returning an HTTP 404 error, specifically identify the SUBCODE of that HTTP 404 error.

    These are the subcodes of HTTP 404 errors relevant to the WSUS server:

    404    Resource not found

    • Content file is missing from filesystem

    404.1 Web site does not exist or is inaccessible on specified port

    • Port suffix of configured URL does not match the installation port.

    404.2 Web service extension lockdown policy prevents request

    • IIS Web Service Extensions are misconfigured (e.g. ASP.NET v1.1 is enabled instead of ASP.NET v2.0)

    404.3 MIME map policy prevents request

    • MIME mappings for website are not correct for EXE or CAB files

    Practically speaking, only the first two options could possibly exist in this scenario. The third and fourth options are server-side and would impact all clients. Fundamentally the question here is: Are there log entries for the Win7 clients. If there are no log entries, then those Win7 clients are talking to the wrong webserver. If there are entries, then believe what you read -- either the resource they're looking for isn't on the server -- or something is blocking their access to that webserver. A relevant question is whether you can browse to these resources from IE on one of those Win7 systems:

    http://paxr-util/iuident.cab

    http://paxr-util/selfupdate/iuident.cab

    http://paxr-util:8530/iuident.cab

    http://paxr-util:8530/selfupdate/iuident.cab

    http://paxr-util:8530/simpleauthwebservice/simpleauth.asmx

    The first four links should generate a File Open/Save dialog. The fifth link should generate a webservices method listing page.

    Also a possible culprit here -- make sure that the Win7 machines are appending the CORRECT domain suffix to the 'paxr-util' hostname, and that the WSUS server does not have host headers enabled on the WSUS Administration v-root.


    Lawrence Garvin, M.S., MCITP:EA, MCDBA, MCSA
    Principal/CTO, Onsite Technology Solutions, Houston, Texas
    Microsoft MVP - Software Distribution (2005-2012)
    My MVP Profile: http://mvp.support.microsoft.com/profile/Lawrence.Garvin

    Friday, February 17, 2012 11:10 PM
    Moderator
  • A relevant question is whether you can browse to these resources from IE on one of those Win7 systems:

    http://paxr-util/iuident.cab

    http://paxr-util/selfupdate/iuident.cab

    http://paxr-util:8530/iuident.cab

    http://paxr-util:8530/selfupdate/iuident.cab

    http://paxr-util:8530/simpleauthwebservice/simpleauth.asmx

    The first four links should generate a File Open/Save dialog. The fifth link should generate a webservices method listing page.

    Yes I can browse to all those sites from the Windows7 clients. The last does return a website page with hyperlinks to click on.

    Then review the IIS logs for the connections coming from the Windows 7 clients and determine exactly why IIS is returning an HTTP 404 error, specifically identify the SUBCODE of that HTTP 404 error.

    I have reviewed the IIS logs and it looks as though it is returning 200 0 0 and 401 1 0. Please see below log excerpt.

    2012-02-18 16:13:55 W3SVC1666638324 192.168.111.220 POST /ApiRemoting30/WebService.asmx - 8530 - 192.168.111.220 Mozilla/4.0+(compatible;+MSIE+6.0;+MS+Web+Services+Client+Protocol+2.0.50727.3625) 401 1 0 2012-02-18 16:13:55 W3SVC1666638324 192.168.111.220 POST /ApiRemoting30/WebService.asmx - 8530 DOMAINNAME\joseph.hatch 192.168.111.220 Mozilla/4.0+(compatible;+MSIE+6.0;+MS+Web+Services+Client+Protocol+2.0.50727.3625) 200 0 0 2012-02-18 16:13:55 W3SVC1666638324 192.168.111.220 POST /ApiRemoting30/WebService.asmx - 8530 - 192.168.111.220 Mozilla/4.0+(compatible;+MSIE+6.0;+MS+Web+Services+Client+Protocol+2.0.50727.3625) 401 1 0 2012-02-18 16:13:55 W3SVC1666638324 192.168.111.220 POST /ApiRemoting30/WebService.asmx - 8530 DOMAINNAME\joseph.hatch 192.168.111.220 Mozilla/4.0+(compatible;+MSIE+6.0;+MS+Web+Services+Client+Protocol+2.0.50727.3625) 200 0 0 2012-02-18 16:13:55 W3SVC1666638324 192.168.111.220 POST /ApiRemoting30/WebService.asmx - 8530 - 192.168.111.220 Mozilla/4.0+(compatible;+MSIE+6.0;+MS+Web+Services+Client+Protocol+2.0.50727.3625) 401 1 0 2012-02-18 16:13:55 W3SVC1666638324 192.168.111.220 POST /ApiRemoting30/WebService.asmx - 8530 DOMAINNAME\joseph.hatch 192.168.111.220 Mozilla/4.0+(compatible;+MSIE+6.0;+MS+Web+Services+Client+Protocol+2.0.50727.3625) 200 0 0 2012-02-18 16:13:55 W3SVC1666638324 192.168.111.220 POST /ApiRemoting30/WebService.asmx - 8530 - 192.168.111.220 Mozilla/4.0+(compatible;+MSIE+6.0;+MS+Web+Services+Client+Protocol+2.0.50727.3625) 401 1 0 2012-02-18 16:13:55 W3SVC1666638324 192.168.111.220 POST /ApiRemoting30/WebService.asmx - 8530 DOMAINNAME\joseph.hatch 192.168.111.220 Mozilla/4.0+(compatible;+MSIE+6.0;+MS+Web+Services+Client+Protocol+2.0.50727.3625) 200 0 0 2012-02-18 16:18:39 W3SVC1666638324 192.168.111.220 GET /selfupdate/iuident.cab - 8530 - 192.168.111.220 - 200 0 0 2012-02-18 16:18:39 W3SVC1666638324 192.168.111.220 POST /reportingwebservice/reportingwebservice.asmx - 8530 - 192.168.111.220 Mozilla/4.0+(compatible;+MSIE+6.0;+MS+Web+Services+Client+Protocol+2.0.50727.3625) 200 0 0 2012-02-18 16:18:39 W3SVC1666638324 192.168.111.220 POST /ApiRemoting30/WebService.asmx - 8530 - 192.168.111.220 Mozilla/4.0+(compatible;+MSIE+6.0;+MS+Web+Services+Client+Protocol+2.0.50727.3625) 401 1 0 2012-02-18 16:18:39 W3SVC1666638324 192.168.111.220 POST /ApiRemoting30/WebService.asmx - 8530 DOMAINNAME\PAXR-UTIL1$ 192.168.111.220 Mozilla/4.0+(compatible;+MSIE+6.0;+MS+Web+Services+Client+Protocol+2.0.50727.3625) 200 0 0 2012-02-18 16:18:39 W3SVC1666638324 192.168.111.220 POST /ServerSyncWebService/serversyncwebservice.asmx - 8530 - 192.168.111.220 Mozilla/4.0+(compatible;+MSIE+6.0;+MS+Web+Services+Client+Protocol+2.0.50727.3625) 200 0 0 2012-02-18 16:18:39 W3SVC1666638324 192.168.111.220 POST /ClientWebService/Client.asmx - 8530 - 192.168.111.220 Mozilla/4.0+(compatible;+MSIE+6.0;+MS+Web+Services+Client+Protocol+2.0.50727.3625) 200 0 0 2012-02-18 16:18:39 W3SVC1666638324 192.168.111.220 POST /SimpleAuthWebService/SimpleAuth.asmx - 8530 - 192.168.111.220 Mozilla/4.0+(compatible;+MSIE+6.0;+MS+Web+Services+Client+Protocol+2.0.50727.3625) 200 0 0 2012-02-18 16:18:39 W3SVC1666638324 192.168.111.220 POST /DssAuthWebService/DssAuthWebService.asmx - 8530 - 192.168.111.220 Mozilla/4.0+(compatible;+MSIE+6.0;+MS+Web+Services+Client+Protocol+2.0.50727.3625)


    • Edited by jmhhatch Saturday, February 18, 2012 4:57 PM
    Saturday, February 18, 2012 4:55 PM
  • I have reviewed the IIS logs and it looks as though it is returning 200 0 0 and 401 1 0.

    Actually, those are NORMAL messages, and represent the process of connecting a remote console session.

    There are no HTTP 404 errors in the above IIS log snippet, and I have a suspicion that none of those entries are coming from the machine named pax-hatchj, so, in accordance with my response in the other thread on this same topic, it surely looks like these Windows 7 systems are getting an IP Address for a different web server from DNS, and that webserver does not have WSUS installed. Or, perhaps you have not properly configured the WinHTTP proxy configurations on these Win7 systems, and the HTTP 404 is coming back (erroneously, unfortunately) from a proxy server. (A proxy server should only return '403' and '407' errors.)


    Lawrence Garvin, M.S., MCITP:EA, MCDBA, MCSA
    Principal/CTO, Onsite Technology Solutions, Houston, Texas
    Microsoft MVP - Software Distribution (2005-2012)
    My MVP Profile: http://mvp.support.microsoft.com/profile/Lawrence.Garvin

    Saturday, February 18, 2012 10:18 PM
    Moderator