Running an sfc /scannow
on a Windows Server 2019 Standard server, at about 76% it failed with the following message.
Windows Resource Protection could not perform the requested operation.
Edit
Looking through %Windir%\Windows\Logs\CBS.log
I see the following:
2023-08-17 15:34:41, Error CSI 00004fa8 (F) c0000011 [Error,Facility=(system),Code=17 (0x0011)] #38088700# from Windows::Rtl::SystemImplementation::DirectFileSystemProvider::SysReadFile(h = cd4 ('\Device\HarddiskVolume2\Windows\WinSxS\amd64_windows-defender-management-powershell_31bf3856ad364e35_10.0.17763.831_none_5892c02f26f780e5\MSFT_MpComputerStatus.cdxml'), evt = 0, apcr = NULL, apcc = NULL, iosb = @0x45dec7c050, data = {l:0 b:}, byteoffset = (null), key = (null)) [gle=0xd0000011] 2023-08-17 15:34:41, Error CSI 00004fa9@2023/8/17:19:34:41.397 (F) onecore\base\wcp\sil\ntsystem.cpp(3610): Error c0000011 [Error,Facility=(system),Code=17 (0x0011)] originated in function Windows::Rtl::SystemImplementation::DirectFileSystemProvider::SysReadFile expression: (null) [gle=0x80004005] 2023-08-17 15:34:41, Info CBS Could not get active session for current session file logging [HRESULT = 0x80004003 - E_POINTER] 2023-08-17 15:34:41, Info CBS Could not get file name for current session file logging [HRESULT = 0x80004003 - E_POINTER] 2023-08-17 15:34:41, Info CBS Added C:\Windows\Logs\CBS\CBS.log to WER report.
Event Viewer details three events:
Fault bucket 1793356441015391089, type 5 Event Name: WindowsWcpOtherFailure3 Response: Not available Cab Id: 0 Problem signature: P1: 10.0.17763.4640:3 P2: wcp\sil\ntsystem.cpp P3: Windows::Rtl::SystemImplementation::DirectFileSystemProvider::SysReadFile P4: 3610 P5: c0000011 P6: 0x435f651d P7: P8: P9: P10: Attached files: \\?\C:\Windows\Logs\CBS\CBS.log \\?\C:\Windows\Logs\CBS\CbsPersist_20230817123621.log \\?\C:\Windows\Logs\CBS\CbsPersist_20230816233716.log \\?\C:\Windows\Logs\CBS\CbsPersist_20230815183505.log \\?\C:\Windows\Logs\CBS\CbsPersist_20230814052711.log \\?\C:\Windows\Logs\CBS\CbsPersist_20230812022642.cab \\?\C:\Windows\servicing\Sessions\Sessions.xml \\?\C:\Windows\WinSxs\poqexec.log \\?\C:\Windows\Logs\Cbs\FilterList.log \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WERB67.tmp.WERInternalMetadata.xml \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WERBA6.tmp.xml \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WERC42.tmp.csv \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WERC62.tmp.txt \\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WERC92.tmp.mdmp \\?\C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_10.0.17763.4640__7ecf3189d0be67147e71f883985df1bed431e6e_00000000_cab_17b40ef1\memory.hdmp \\?\C:\Windows\Temp\WEREF4.tmp.WERDataCollectionStatus.txt These files may be available here: \\?\C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_10.0.17763.4640__7ecf3189d0be67147e71f883985df1bed431e6e_00000000_10e8155a Analysis symbol: Rechecking for solution: 0 Report Id: b33a6f7e-74bf-456a-a60e-9af2f5c88c59 Report Status: 268435456 Hashed bucket: 8f95577d69101277c8e3482e76619371 Cab Guid: 0