Tried everything - unable to complete update ox80072efd

G

Guest

I have tried everthing from all the support pages, including the process
shown below by Bill Sanderson MVP, but I apparently don't have a winlogon.log
file. Would be really grateful for some help. Thanks.
 
B

Bill Sanderson MVP

This error often indicates a machine restricted by policy settings from
reaching Microsoft's servers. Is this a work machine, on a managed network?
 
G

Guest

No, this is my own machine, connecting via adsl from home. It is set up for
a work network, however. Could this be a problem?
 
G

Guest

One other thing: I downloaded the latest signatures, ran the exe file and
restarted, but defender still says it has not been updated. Really confusing
 
B

Bill Sanderson MVP

This sounds very fixable--but I'm short on time now--will get back to you.

I think it'd be good to have you do an attempted update (help, about, check
for updates)--then open the windowsupdate log file in notepad, and cut and
paste just the last part related to this update into a reply here:

start, run, notepad %windir%\windowsupdate.log
<enter>

--
 
G

Guest

Here are the last few lines, if you want more I have saved the report.

2006-05-25 17:35:46 3980 bdc COMAPI -- END -- COMAPI: Search [ClientId =
Windows Defender]
2006-05-25 17:35:46 3980 bdc COMAPI -------------
2006-05-25 17:35:46 3980 c8c COMAPI WARNING: Operation failed due to earlier
error, hr=80072EFD
2006-05-25 17:35:46 3980 c8c COMAPI FATAL: Unable to complete asynchronous
search. (hr=80072EFD)
2006-05-25 17:35:51 1016 d4 Report REPORT EVENT:
{51EC3FD6-26B4-4D1A-B132-830ABD99D69F} 2006-05-25
17:35:45+0200 1 148 101 {00000000-0000-0000-0000-000000000000} 0 80072efd Windows
Defender Failure Software Synchronization Error: Agent failed detecting with
reason: 0x80072efd

Thanks for your help
 
B

Bill Sanderson MVP

I'm particularly interested in the beginning---where it trys to get in touch
with the server--there should be a line including the string "server url".
Some lines on either side of that would probably be useful.

--

Carter said:
Here are the last few lines, if you want more I have saved the report.

2006-05-25 17:35:46 3980 bdc COMAPI -- END -- COMAPI: Search [ClientId
=
Windows Defender]
2006-05-25 17:35:46 3980 bdc COMAPI -------------
2006-05-25 17:35:46 3980 c8c COMAPI WARNING: Operation failed due to
earlier
error, hr=80072EFD
2006-05-25 17:35:46 3980 c8c COMAPI FATAL: Unable to complete asynchronous
search. (hr=80072EFD)
2006-05-25 17:35:51 1016 d4 Report REPORT EVENT:
{51EC3FD6-26B4-4D1A-B132-830ABD99D69F} 2006-05-25
17:35:45+0200 1 148 101 {00000000-0000-0000-0000-000000000000} 0 80072efd
Windows
Defender Failure Software Synchronization Error: Agent failed detecting
with
reason: 0x80072efd

Thanks for your help

Bill Sanderson MVP said:
This sounds very fixable--but I'm short on time now--will get back to
you.

I think it'd be good to have you do an attempted update (help, about,
check
for updates)--then open the windowsupdate log file in notepad, and cut
and
paste just the last part related to this update into a reply here:

start, run, notepad %windir%\windowsupdate.log
<enter>
 
G

Guest

Here's the text from start to finish (I think) of the update

2006-05-25 17:33:59 3980 dac COMAPI -------------
2006-05-25 17:33:59 3980 dac COMAPI -- START -- COMAPI: Search [ClientId =
Windows Defender]
2006-05-25 17:33:59 3980 dac COMAPI ---------
2006-05-25 17:33:59 3980 dac COMAPI - Online = Yes; Ignore download
priority = No
2006-05-25 17:33:59 3980 dac COMAPI - Criteria = "(IsInstalled = 0 and
IsHidden = 0 and CategoryIDs contains '0a487050-8b0f-4f81-b401-be4ceacd61cd')
or (IsInstalled = 0 and IsHidden = 0 and CategoryIDs contains
'8c3fcc84-7410-4a95-8b89-a166a0190486')"
2006-05-25 17:33:59 3980 dac COMAPI - ServiceID =
{00000000-0000-0000-0000-000000000000}
2006-05-25 17:33:59 3980 dac COMAPI <<-- SUBMITTED -- COMAPI: Search
[ClientId = Windows Defender]
2006-05-25 17:33:59 1016 d4 Agent *************
2006-05-25 17:33:59 1016 d4 Agent ** START ** Agent: Finding updates
[CallerId = Windows Defender]
2006-05-25 17:33:59 1016 d4 Agent *********
2006-05-25 17:34:00 1016 d4 PT +++++++++++ PT: Synchronizing server
updates +++++++++++
2006-05-25 17:34:00 1016 d4 PT + ServiceId =
{3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}, Server URL =
http://10.0.1.200/ClientWebService/client.asmx
2006-05-25 17:34:01 1016 d4 PT Initializing simple targeting cookie,
clientId = 96145f8e-eba9-4168-9265-3306ab534a07, target group = Pupil
Laptops, DNS name = lt-carterc.bishops.org.za
2006-05-25 17:34:01 1016 d4 PT Server URL =
http://10.0.1.200/SimpleAuthWebService/SimpleAuth.asmx
2006-05-25 17:34:22 1016 d4 Misc WARNING: Send failed with hr = 80072efd.
2006-05-25 17:34:22 1016 d4 Misc WARNING: SendRequest failed with hr =
80072efd. Proxy List used: <(null)> Bypass List used : <(null)> Auth Schemes
used : <>
2006-05-25 17:34:22 1016 d4 PT + Last proxy send request failed with hr =
0x80072EFD, HTTP status code = 0
2006-05-25 17:34:22 1016 d4 PT + Caller provided credentials = No
2006-05-25 17:34:22 1016 d4 PT + Impersonate flags = 0
2006-05-25 17:34:22 1016 d4 PT + Possible authorization schemes used =
2006-05-25 17:34:22 1016 d4 PT WARNING: GetAuthorizationCookie failure,
error = 0x80072EFD, soap client error = 5, soap error code = 0, HTTP status
code = 200
2006-05-25 17:34:42 1016 d4 Misc WARNING: Send failed with hr = 80072efd.
2006-05-25 17:34:42 1016 d4 Misc WARNING: SendRequest failed with hr =
80072efd. Proxy List used: <(null)> Bypass List used : <(null)> Auth Schemes
used : <>
2006-05-25 17:34:42 1016 d4 Misc WARNING: WinHttp: SendRequestUsingProxy
failed for <http://10.0.1.200/clientwebservice/WusServerVersion.xml>. error
0x80072efd
2006-05-25 17:34:42 1016 d4 Misc WARNING: WinHttp:
SendRequestToServerForFileInformation MakeRequest failed. error 0x80072efd
2006-05-25 17:34:42 1016 d4 Misc WARNING: WinHttp:
SendRequestToServerForFileInformation failed with 0x80072efd
2006-05-25 17:34:42 1016 d4 Misc WARNING: WinHttp: ShouldFileBeDownloaded
failed with 0x80072efd
2006-05-25 17:35:04 1016 d4 Misc WARNING: Send failed with hr = 80072efd.
2006-05-25 17:35:04 1016 d4 Misc WARNING: SendRequest failed with hr =
80072efd. Proxy List used: <(null)> Bypass List used : <(null)> Auth Schemes
used : <>
2006-05-25 17:35:04 1016 d4 Misc WARNING: WinHttp: SendRequestUsingProxy
failed for <http://10.0.1.200/clientwebservice/WusServerVersion.xml>. error
0x80072efd
2006-05-25 17:35:04 1016 d4 Misc WARNING: WinHttp:
SendRequestToServerForFileInformation MakeRequest failed. error 0x80072efd
2006-05-25 17:35:04 1016 d4 Misc WARNING: WinHttp:
SendRequestToServerForFileInformation failed with 0x80072efd
2006-05-25 17:35:04 1016 d4 Misc WARNING: WinHttp: ShouldFileBeDownloaded
failed with 0x80072efd
2006-05-25 17:35:25 1016 d4 Misc WARNING: Send failed with hr = 80072efd.
2006-05-25 17:35:25 1016 d4 Misc WARNING: SendRequest failed with hr =
80072efd. Proxy List used: <(null)> Bypass List used : <(null)> Auth Schemes
used : <>
2006-05-25 17:35:25 1016 d4 Misc WARNING: WinHttp: SendRequestUsingProxy
failed for <http://10.0.1.200/clientwebservice/WusServerVersion.xml>. error
0x80072efd
2006-05-25 17:35:25 1016 d4 Misc WARNING: WinHttp:
SendRequestToServerForFileInformation MakeRequest failed. error 0x80072efd
2006-05-25 17:35:25 1016 d4 Misc WARNING: WinHttp:
SendRequestToServerForFileInformation failed with 0x80072efd
2006-05-25 17:35:25 1016 d4 Misc WARNING: WinHttp: ShouldFileBeDownloaded
failed with 0x80072efd
2006-05-25 17:35:45 1016 d4 Misc WARNING: Send failed with hr = 80072efd.
2006-05-25 17:35:45 1016 d4 Misc WARNING: SendRequest failed with hr =
80072efd. Proxy List used: <(null)> Bypass List used : <(null)> Auth Schemes
used : <>
2006-05-25 17:35:45 1016 d4 Misc WARNING: WinHttp: SendRequestUsingProxy
failed for <http://10.0.1.200/clientwebservice/WusServerVersion.xml>. error
0x80072efd
2006-05-25 17:35:45 1016 d4 Misc WARNING: WinHttp:
SendRequestToServerForFileInformation MakeRequest failed. error 0x80072efd
2006-05-25 17:35:45 1016 d4 Misc WARNING: WinHttp:
SendRequestToServerForFileInformation failed with 0x80072efd
2006-05-25 17:35:45 1016 d4 Misc WARNING: WinHttp: ShouldFileBeDownloaded
failed with 0x80072efd
2006-05-25 17:35:45 1016 d4 PT WARNING: Sync of Updates: 0x80072efd
2006-05-25 17:35:45 1016 d4 Agent * WARNING: Failed to synchronize, error
= 0x80072EFD
2006-05-25 17:35:46 1016 d4 Agent * WARNING: Exit code = 0x80072EFD
2006-05-25 17:35:46 1016 d4 Agent *********
2006-05-25 17:35:46 1016 d4 Agent ** END ** Agent: Finding updates
[CallerId = Windows Defender]
2006-05-25 17:35:46 1016 d4 Agent *************
2006-05-25 17:35:46 1016 d4 Agent WARNING: WU client failed Searching for
update with error 0x80072efd
2006-05-25 17:35:46 3980 bdc COMAPI >>-- RESUMED -- COMAPI: Search
[ClientId = Windows Defender]
2006-05-25 17:35:46 3980 bdc COMAPI - Updates found = 0
2006-05-25 17:35:46 3980 bdc COMAPI - WARNING: Exit code = 0x00000000,
Result code = 0x80072EFD
2006-05-25 17:35:46 3980 bdc COMAPI ---------
2006-05-25 17:35:46 3980 bdc COMAPI -- END -- COMAPI: Search [ClientId =
Windows Defender]
2006-05-25 17:35:46 3980 bdc COMAPI -------------
2006-05-25 17:35:46 3980 c8c COMAPI WARNING: Operation failed due to earlier
error, hr=80072EFD
2006-05-25 17:35:46 3980 c8c COMAPI FATAL: Unable to complete asynchronous
search. (hr=80072EFD)
2006-05-25 17:35:51 1016 d4 Report REPORT EVENT:
{51EC3FD6-26B4-4D1A-B132-830ABD99D69F} 2006-05-25 17:35:45+0200

Let me know if you need anything more
Thanks

Bill Sanderson MVP said:
I'm particularly interested in the beginning---where it trys to get in touch
with the server--there should be a line including the string "server url".
Some lines on either side of that would probably be useful.

--

Carter said:
Here are the last few lines, if you want more I have saved the report.

2006-05-25 17:35:46 3980 bdc COMAPI -- END -- COMAPI: Search [ClientId
=
Windows Defender]
2006-05-25 17:35:46 3980 bdc COMAPI -------------
2006-05-25 17:35:46 3980 c8c COMAPI WARNING: Operation failed due to
earlier
error, hr=80072EFD
2006-05-25 17:35:46 3980 c8c COMAPI FATAL: Unable to complete asynchronous
search. (hr=80072EFD)
2006-05-25 17:35:51 1016 d4 Report REPORT EVENT:
{51EC3FD6-26B4-4D1A-B132-830ABD99D69F} 2006-05-25
17:35:45+0200 1 148 101 {00000000-0000-0000-0000-000000000000} 0 80072efd
Windows
Defender Failure Software Synchronization Error: Agent failed detecting
with
reason: 0x80072efd

Thanks for your help

Bill Sanderson MVP said:
This sounds very fixable--but I'm short on time now--will get back to
you.

I think it'd be good to have you do an attempted update (help, about,
check
for updates)--then open the windowsupdate log file in notepad, and cut
and
paste just the last part related to this update into a reply here:

start, run, notepad %windir%\windowsupdate.log
<enter>

--

One other thing: I downloaded the latest signatures, ran the exe file
and
restarted, but defender still says it has not been updated. Really
confusing

:

No, this is my own machine, connecting via adsl from home. It is set
up
for
a work network, however. Could this be a problem?

:

This error often indicates a machine restricted by policy settings
from
reaching Microsoft's servers. Is this a work machine, on a managed
network?

--

I have tried everthing from all the support pages, including the
process
shown below by Bill Sanderson MVP, but I apparently don't have a
winlogon.log
file. Would be really grateful for some help. Thanks.
 
B

Bill Sanderson MVP

OK - it's trying to connect to a WSUS (I think...) server at 10.0.xxx--which
is a non-routable private IP subnet.

So-- Autoupdate on your machine is locked into connecting to the corporate
WSUS server, which can't be reached from your home (unless you connect via
VPN?)--and which probably isn't carrying Defender definitions anyway.
 
G

Guest

Okay, that makes sense, I think I changed my registry at one point for
automatic updates to go through the server. If this is causing the problem,
how can I undo it? Because I'd rather update from home anyway, especially if
Defender can't update through that server.
 
B

Bill Sanderson MVP

Reverse the registry change. At some point, I found the instructions for
doing that (the change to manually install WSUS) and posted it twice in
these groups. However, I haven't been able to find either the original
source or those posts, looking for them yesterday.

--
 
G

Guest

If you are able to find anything, please just let me know. Not urgent but it
would be great if you could help me fix the problem. Thanks for your help so
far.
 
B

Bill Sanderson MVP

I still can't find that stuff-I posted it twice. However, here's an
equivalent from another user in your position.

[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\WindowsUpdate]

I have no such key on my non-domain-joined system which has never been
connected to WSUS or SUS.

The other user did this:

"and found that two string values called "WUServer" and "WUStatusServer" are
both pointing to the National University of Singapore's server. Since these
are settings for custom update server, it can be removed. I removed them and
rebooted my machine."

However, since I don't have that key at all, I'd recommend saving the key by
exporting it to a .reg file, and then simply deleting it.



--
 
G

Guest

Forgive my possible ignorance, but how do I get to that
location?([HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\WindowsUpdate])

Bill Sanderson MVP said:
I still can't find that stuff-I posted it twice. However, here's an
equivalent from another user in your position.

[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\WindowsUpdate]

I have no such key on my non-domain-joined system which has never been
connected to WSUS or SUS.

The other user did this:

"and found that two string values called "WUServer" and "WUStatusServer" are
both pointing to the National University of Singapore's server. Since these
are settings for custom update server, it can be removed. I removed them and
rebooted my machine."

However, since I don't have that key at all, I'd recommend saving the key by
exporting it to a .reg file, and then simply deleting it.



--

Bill Sanderson MVP said:
Reverse the registry change. At some point, I found the instructions for
doing that (the change to manually install WSUS) and posted it twice in
these groups. However, I haven't been able to find either the original
source or those posts, looking for them yesterday.
 
G

Guest

Don't worry, I figured it out, deleted a few entries that looked suspicious.
Everything seems fine, when I run defender's update it tells me there are no
new updates (this is because I manually installed the latest defenitions) One
thing that still worries me, however, is when I open windows update through
the control panel, everything is greyed out. Dunno if there's something I
missed or if thats normal?
 
B

Bill Sanderson MVP

Sorry about that:

With some caution--

Ah--excellent--Microsoft has a KB article that lays it all out nicely:

http://support.microsoft.com/kb/322756/

--

Carter said:
Forgive my possible ignorance, but how do I get to that
location?([HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\WindowsUpdate])

Bill Sanderson MVP said:
I still can't find that stuff-I posted it twice. However, here's an
equivalent from another user in your position.

[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\WindowsUpdate]

I have no such key on my non-domain-joined system which has never been
connected to WSUS or SUS.

The other user did this:

"and found that two string values called "WUServer" and "WUStatusServer"
are
both pointing to the National University of Singapore's server. Since
these
are settings for custom update server, it can be removed. I removed them
and
rebooted my machine."

However, since I don't have that key at all, I'd recommend saving the key
by
exporting it to a .reg file, and then simply deleting it.



--

Bill Sanderson MVP said:
Reverse the registry change. At some point, I found the instructions
for
doing that (the change to manually install WSUS) and posted it twice in
these groups. However, I haven't been able to find either the original
source or those posts, looking for them yesterday.

--

Okay, that makes sense, I think I changed my registry at one point for
automatic updates to go through the server. If this is causing the
problem,
how can I undo it? Because I'd rather update from home anyway,
especially if
Defender can't update through that server.

:

OK - it's trying to connect to a WSUS (I think...) server at
10.0.xxx--which
is a non-routable private IP subnet.

So-- Autoupdate on your machine is locked into connecting to the
corporate
WSUS server, which can't be reached from your home (unless you
connect
via
VPN?)--and which probably isn't carrying Defender definitions anyway.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top