(imported topic written by boostaz191)
I am trying to get a grip on my pending restart operations. However We run groupwise which incorrectly uses the “PendingFileRenameOperations” of key “HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager” so to counter act this I have set the following.
setting “_BESClient_ActionManager_PendingRestartExclusions”=“Text%2ehtm%3bMime%2e822%3bGWViewer%3b” on “Mon, 20 Aug 2007 16:40:05 +0000” for client
However this has not corrected the problem. I Have systems which report back as pending restart. I have created the following analysis to help me identifiy which restart are valid.
Properties
Triggered by BES
Period Every Report
(
exists key “HKEY_LOCAL_MACHINE\SOFTWARE\BigFix\EnterpriseClient\BESPendingRestart” of it
AND
exists value “BESPendingRestart” of key “HKEY_LOCAL_MACHINE\SOFTWARE\BigFix\EnterpriseClient\BESPendingRestart” of it
)
of registry
OR
(
exists key “HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce” of it
AND
exists value “BESPendingRestart” of key “HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce” of it
)
of registry
(exists key “HKEY_LOCAL_MACHINE\SOFTWARE\BigFix\EnterpriseClient\BESPendingRestart” of it AND exists value “BESPendingRestart” of key “HKEY_LOCAL_MACHINE\SOFTWARE\BigFix\EnterpriseClient\BESPendingRestart” of it) of registry OR (exists key “HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce” of it AND exists value “BESPendingRestart” of key “HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce” of it) of registry
Not Triggered by BES
Period Every Report
pending restart
pending restart
Triggerd By MS
Period Every Report
exists value “PendingFileRenameOperations” of key “HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager” of registry
exists value “PendingFileRenameOperations” of key “HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager” of registry
Invalid restart
Period Every Report
value “PendingFileRenameOperations” of key “HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager” of registry as string contains “.htm”
value “PendingFileRenameOperations” of key “HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager” of registry as string contains “.htm”
Value of Pending Restart
Period Every Report
value “PendingFileRenameOperations” of key “HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager” of registry as string
value “PendingFileRenameOperations” of key “HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager” of registry as string
Here is an example of the results:
XXXXX True True True True ??\C:\DOCUME~1\XXXXX\LOCALS~1\Temp\Text.htm%00%00??\C:\DOCUME~1\XXXXX\LOCALS~1\Temp\Lessons Learned 080507.doc%00%00??\C:\WINNT\system32\SETB10.tmp%00!??\C:\WINNT\system32\ntdsa.dll%00??\C:\WINNT\system32\SETB11.tmp%00!??\C:\WINNT\system32\sp3res.dll%00??\C:\WINNT\system32\DllCache\SETB12.tmp%00!??\C:\WINNT\system32\DllCache\sp3res.dll%00??\C:\WINNT\system32\DllCache\SETB13.tmp%00!??\C:\WINNT\system32\DllCache\ntdsa.dll%00??\C:\WINNT\system32_000006_.tmp.dll%00%00??\C:\WINNT\system32\SET24DC.tmp%00!??\C:\WINNT\system32\GDI32.DLL%00??\C:\WINNT\system32\DllCache\SET24DD.tmp%00!??\C:\WINNT\system32\DllCache\GDI32.DLL%00%00
XXXXX True True True True
XXXXX False True True True
XXXXX True True True True ??\C:\DOCUME~1\XXXXX\LOCALS~1\Temp\Text.htm%00%00??\C:\DOCUME~1\XXXXX\LOCALS~1\Temp\TEXT.htm%00%00??\C:\DOCUME~1\XXXXX\LOCALS~1\Temp\Text.htm%00%00??\C:\DOCUME~1\XXXXX\LOCALS~1\Temp\Mime.822%00%00??\C:\WINDOWS\System32\spool\drivers\W32X86\3\temp\mdi31.tmp%00%00??\C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\New\mdiui.dll%00??\C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mdiui.dll%00??\C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\New\mdiui.dll%00??\C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mdiui.dll%00??\C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\New\mdiui.dll%00??\C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mdiui.dll%00??\C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\New\mdiui.dll%00??\C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mdiui.dll%00??\C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\New\mdiui.dll%00??\C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mdiui.dll%00??\C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\New\mdiui.dll%00??\C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\mdiui.dll%00%00
XXXXX False True True True ??\C:\DOCUME~1\XXXXX\LOCALS~1\Temp\ROI Lessons Learned 8-17-07.doc%00%00??\C:\DOCUME~1\XXXXX\LOCALS~1\Temp\Mime.822%00%00??\C:\DOCUME~1\XXXXX\LOCALS~1\Temp\Text.htm%00%00??\C:\DOCUME~1\XXXXX\LOCALS~1\Temp\GWViewer\EmpReferralApp 07.doc%00%00??\C:\DOCUME~1\XXXXX\LOCALS~1\Temp\Mime.822%00%00??\C:\DOCUME~1\XXXXX\LOCALS~1\Temp\Text.htm%00%00%00
XXXXX True True True True
COMPUTER AND USER NAMES HAVE BEEN REMOVED TO PROCTECT INDIGENT.