For persistent cases, use a tool like or Sysinternals WinObj to inspect the \KernelObjects\ namespace for a stale WindowsUpdateTraceLog event handle. No public tool directly deletes these; a reboot is the cleanest solution.

: A process tries to initiate a logging session already in use by another process or a previous session that wasn't properly closed.

net stop wuauserv net stop bits net stop dosvc

: An existing trace session is already using the name WindowsUpdateTraceLog.