System management patches that write to the registry write to wrong section on Win7x64 devices

I have entered a SR on this but just seeing if everyone else is running into
this on Win7x64 devices.
As an example if i try to deploy remediation of the 'System Management -
Disable Java Update for Java JRE (Disabled)' patch on a Win7x64 device I end
up with EnableJavaUpdate value in the wrong registry area.
HKLM\SOFTWARE\JavaSoft\Java Update\Policy\EnableJavaUpdate
I should say this would disable 64bit java update but not 32bit java update
but if you look in the patch management debug.log you see it is looking in
the Wow6432Node(32bit) key area for detection of this patch.
For this patch to be totally correct and disable updates for 64 and 32 bit
java both of the following values would need to be wrote.
HKLM\SOFTWARE\JavaSoft\Java Update\Policy\EnableJavaUpdate
HKLM\SOFTWARE\Wow6432Node\JavaSoft\Java Update\PolicyEnableJavaUpdate
This disconnect between where values are wrote to the registry and what is
being looked for by patch management seems to hold true for most of the
system management patches I have tried so far on 64bit machines.
Windows Event Application Log shows the following:
Log Name: Application
Source: WSH
Date: 4/19/2012 1:25:16 PM
Event ID: 4
Task Category: None
Level: Information
Keywords: Classic
User: N/A
Computer: JKoerner-LT.internal.reimelt.com
Description:
UPDATE SERVER DEPLOYMENT: Information
INSTALL COMMAND(Key1): RegWrite(HKLM\SOFTWARE\JavaSoft\Java
Update\Policy\EnableJavaUpdate,0,REG_DWORD)
Debug.log section relating to patch:
Opening file:
System Management - Disable Java Update for Java JRE (Disabled).pls
Importing
Filename : [System Management - Disable Java Update for Java JRE
(Disabled).pls]
OS Platform : [Microsoft Windows 7 Professional x64]
Library Build : [5.2.2][Jan 11 2012 17:10:20]
Finished Importing
Detecting
Looking In: [HKEY_LOCAL_MACHINE][SOFTWARE\Wow6432Node\JavaSoft\Java
Update\Policy]
Key NOT found
Finished Detecting
Another example:
Windows Event Application Log entries for the 'System Management - Disable
Adobe Updater for Shockwave Player 10 and 11 (Enabled)' patch
Log Name: Application
Source: WSH
Date: 4/19/2012 1:46:42 PM
Event ID: 4
Task Category: None
Level: Information
Keywords: Classic
User: N/A
Computer: JKoerner-LT.internal.reimelt.com
Description:
UPDATE SERVER DEPLOYMENT: Information
INSTALL COMMAND(Key1): RegWrite(HKLM\Software\Adobe\Shockwave
11\AutoUpdate\,n,REG_SZ)
Log Name: Application
Source: WSH
Date: 4/19/2012 1:46:42 PM
Event ID: 4
Task Category: None
Level: Information
Keywords: Classic
User: N/A
Computer: JKoerner-LT.internal.reimelt.com
Description:
UPDATE SERVER DEPLOYMENT: Information
INSTALL COMMAND(Key2): RegWrite(HKLM\Software\Macromedia\Shockwave
10\AutoUpdate\,n,REG_SZ)
Server - ZCM 11.2 on Win2008R2x64
Clients - ZCM 11.2 on Win7x64
Jim Koerner

To drag up a old thread and SR (gee it has been more than 7 months). Looks
like there is finally some work on this as I got a real preliminary test
file that seems to have fixed this issue but didn't get a timeframe on an
actual release and the SR is still open.
Jim Koerner
"Jim Koerner" wrote in message
news:ZExmr.10001$[email protected]. .
My SR just got pushed along to Lumension. The one thing I am concerned
about is the one example I gave 'System Management - Disable Java Update for
Java JRE (Disabled)' will be the only one fixed. There is a fundamental
flaw in how most of the System Management patches interact with 64-bit
machines. Looking at where registry entries get wrote and what is detected
from the scan I would say there were not even tested on 64bit machines. I
did note my concern in the SR.
Jim Koerner
"Shaun Pond" <[email protected]> wrote in message
news:[email protected]..
> Jim,
>
> no - tell them that I have seen this, it should speed things up for
> you...
>
> --
>
> Shaun Pond
>
>

Similar Messages

  • HT1923 I'm trying to re-install itunes on my laptop & I am getting a message that has stopped the re-install & it says: "Service 'Apple Mobile Device" (Apple Mobile Device) failed to start. Verify that you have sufficient privileges to start system servic

    I'm trying to re-install itunes on my laptop & I am getting a message that has stopped the re-install & it says: "Service 'Apple Mobile Device" (Apple Mobile Device) failed to start. Verify that you have sufficient privileges to start system services."  The diaglogue box gives me the options to abort, retry, or ignore; when I tried retry and ignore the re-install process stays stalled & the dialogue box comes back & I don't want to abort & start this all over to probably end up with the same issue; what does this mean & what do I do?

    Go to Control Panel > Add or Remove Programs (Win XP) or Programs and Features (later)
    Remove all of these items in the following order:
    iTunes
    Apple Software Update
    Apple Mobile Device Support (if this won't uninstall move on to the next item)
    Bonjour
    Apple Application Support
    Reboot, download iTunes, then reinstall, either using an account with administrative rights, or right-clicking the downloaded installer and selecting Run as Administrator.
    The uninstall and reinstall process will preserve your iTunes library and settings, but ideally you would back up the library and your other important personal documents and data on a regular basis. See this user tip for a suggested technique.
    Please note:
    Some users may need to follow all the steps in whichever of the following support documents applies to their system. These include some additional manual file and folder deletions not mentioned above.
    HT1925: Removing and Reinstalling iTunes for Windows XP
    HT1923: Removing and reinstalling iTunes for Windows Vista, Windows 7, or Windows 8
    tt2

  • HT1926 I'm trying to re-install itunes on my laptop & I am getting a message that has stopped the re-install & it says: "Service 'Apple Mobile Device" (Apple Mobile Device) failed to start. Verify that you have sufficient privileges to start system servic

    I'm trying to re-install itunes on my laptop & I am getting a message that has stopped the re-install & it says: "Service 'Apple Mobile Device" (Apple Mobile Device) failed to start. Verify that you have sufficient privileges to start system services." ?

    Go to Control Panel > Add or Remove Programs (Win XP) or Programs and Features (later)
    Remove all of these items in the following order:
    iTunes
    Apple Software Update
    Apple Mobile Device Support (if this won't uninstall move on to the next item)
    Bonjour
    Apple Application Support
    Reboot, download iTunes, then reinstall, either using an account with administrative rights, or right-clicking the downloaded installer and selecting Run as Administrator.
    The uninstall and reinstall process will preserve your iTunes library and settings, but ideally you would back up the library and your other important personal documents and data on a regular basis. See this user tip for a suggested technique.
    Please note:
    Some users may need to follow all the steps in whichever of the following support documents applies to their system. These include some additional manual file and folder deletions not mentioned above.
    HT1925: Removing and Reinstalling iTunes for Windows XP
    HT1923: Removing and reinstalling iTunes for Windows Vista, Windows 7, or Windows 8
    tt2

  • After updating, as requested, each time I select iPhoto, the system is requesting that I download the iPhoto upgrade.  I have downloaded this several times.  However, I continue to receive this message.  Please help me resolve this issue.

    After updating, as requested, each time I select iPhoto, the system is requesting that I download the iPhoto upgrade.  I have downloaded this several times.  However, I continue to receive this message.  Please help me resolve this issue.

    Can you give us the exact error message you get?

  • I have the curve but was never able to open the download manager disc that came with the phone. i have a mac computer. i do not have the internet on my phone. i would like to backup my phone book. thankyou, joan

    i have the curve but was never able to open the download manager disc that came with the phone. i have a mac computer. i do not have the internet on my phone. i would like to backup my phone book. thankyou, joan

    Unfortunately I lost my life and am trying to rebuild.  Isn't the technical era great.
    Backup, backup, backup
    As a minimum, use 3-2-1 (or even more)
    3 copies of your data (original copy counts as 1)
    2 different backup utilities/storage formats (protects from bugs in the software)
    1 copy off-site (protects against theft, fire, and natural disaster)
    More backup copies are even better.
    Backup disks are cheap compared to the lost of personal data that does not exist anywhere else.

  • GPO to push HKCU regkeys to users that do not have permissions to write to the registry?

    We run a 2008r2 domain and mostly Win7 clients, but some are still XP.  I need to apply some application settings in an admin template(user), and also need to push a regkey to HkeyCurrentUser for those users.  I would like to use GPP for the
    regkey, if possible, but the end-users do not have permissions to edit the registry on their computers.  Is this something that would have to be scripted? or can I do this through group policy?
    I was thinking that the computer side of Group Policy ran under the System account, but that user side ran under the user's security context?  This is probably an easy one, but any ideas would be appreciated.
    Thanks,
    Dan
    Dan Heim

    Even though users are not admins, some parts of the registry are open for editing. The easiest way to determine if thats the case, is to actually try changing the value when you're logged on to a client as non-admin.
    Note that according to: http://support.microsoft.com/kb/2252421, a possibility would also be to change the value as following (that can sometimes help when using both policies and GPP's)
    How to deploy the junk email list trigger to the non-policy location in the registry
    You can also configure the junk email list trigger in the following non-policy location in the registry:
    Key: HKEY_CURRENT_USER\Software\Microsoft\Office\1x.0\Outlook\Options\Mail
    DWORD: JunkMailImportLists
    Value: 1
    Note The 1x.0 placeholder represents your version of Outlook (11.0 = Outlook 2003, 12.0 = Outlook 2007, 14.0 = Outlook 2010, and 15.0 = Outlook 2013)."
    Microsoft Certified Trainer
    MCSE: Desktop, Server, Private Cloud, Messaging
    Blog: http://365lab.net

  • A Financial Management App that works for the UK??

    I've been running a MacBook Pro for some five years and have also used a Parallels partition to run some legacy Windows programs such as Quicken Deluxe 2000!
    I am now determined to dump the Parallels partition and now need a money management app that runs under Yosemite and is suitable for a UK user - we cannot (easily) buy the US/Canada Quicken software anymore - so I need a package that will run UK£ and can handle multiple accounts but I do not need any stock market look up capability etc.
    Yours hopefully,
                   george                   

    I ran Quicken Deluxe 2002 for years and now I use Quicken 2007 for Mac, since it is now compatible with Snow Leopard through Yosemite.
    You can obtain it for $15 using the Intuit online chat function, and I assume they will sell and ship to the UK.  Try it:
    Use the chat feature for Quicken for Mac: Quicken 2007 for Lion: Shopping and Buying: Buying Quicken on this page:
    https://quicken.custhelp.com/app/contact/plvl1/win
    Since you are using Quicken Deluxe 2000 you first need to convert the data files while still running in Tiger/Leopard/Snow Leopard:
    Download Quicken 2006 (PPC) from Intuit:
    https://quicken.intuit.com/support/help/patching/quicken-2006-manual-updates--ma c-/GEN82200.html
    Open your data file in Quicken 2006 (PPC) and it will automatically convert it to Quicken 2005/6/7 data file. 
    NOTE: I know this procedure worked for my Quicken Deluxe 2002 data files, I have not personally tried it on a Quicken Deluxe 2000 data file.

  • My iPhone 5c screen is lifting at the corner and the store says it's my fault even though my phone is in an otter box and is in immaculate condition. The manager insinuated that I bent the frame to get a new phone!

    My screen is lifting in the corner and the phone is in an otter box and in immaculate condition. Took it in and the manager told me that it's my fault and insinuated that I bent the frame on purpose to get a new phone! I just want my phone fixed. I don't want to pay 300 for another phone when they have already fixed the screen once as it wasn't working.

    So call AppleCare and ask to be transferred to customer service and talk to them.

  • Want the "System.out.println()" that is within the java stored procedure works?

    hello
    i write a java stored procedure,and put a line as "System.out.println(...)" within the procedure,after publish it,i can test it within the sqlplus by invoke following command:
    SQL>set serveroutput on;
    SQL>call dbms_java.set_output(....);
    but when i test it within the jdeveloper9.0.3,it can't be print,why?
    thank you!

    You can try this:
    DBMS_OUTPUT.enable(100000);
    DBMS_JAVA.set_output(100000);
    HTH,
    Robert

  • Writing to the registry

    How can you write to the registry in java, and then retrieve those keys (for an installer)?

    J++, microsoft's old tool, had a way to do this.
    Standard java may not support this type of thing as
    it is not platform independent.I'd suggest that you'd check out the Preferences class's behaviour on a Windows system and then make another assumption...

  • Installing IPCC on a non Cisco Hardware: The registry

    Hi All;
    If I need to install the IPCCE on a non Cisco harware (HP or IBM server), I heared that there is a registry file need to be run that will modify the registry to allow the IPCCE software to be installed on the hardware.
    Can anyone advise for this file?
    Any help?
    Regards
    Bilal

    VMWare allows you to create a virtual Linux box abstracted from the underlying host and you can then insert the CUCM installation DVD and it will install. The host can be running a range of operating systems - I have used Windows XP, Windows 2003 Server and VMWare's own operating system on an ESX server.
    The installer knows it's a VMWare abstraction and does not do the normal hardware checks. The process could not be any easier.
    There are many blogs out there with movies that guide you through the process of installing. Try this URL and watch the video.
    http://www.blindhog.net/how-to-install-call-manager-6x-in-vmware/
    Since I just helped a colleague install CUCM 7.x on an ESX 3.5 server today and I found this simple guide to the post-install steps, with a movie you can watch, I'll provide the URL.
    http://www.brainbump.net/2008/12/getting-cisco-unified-communications-manager-70-up-and-running-using-vmware/
    Regards,
    Geoff

  • Systems Management recommendation?

    Hi everyone,I have to imagine this topic has been discussed at length here, but my Google Fu seems to be rather weak, as I haven't found anything that really addresses this question for me. I'm on month #3 in my first non-hotel IT job and I'm looking to help the company out by implementing a systems management solution that takes care of a number of challenges we're encountering.
    In a nutshell, we are a SaaS shop with Windows, Linux, and Mac systems. Servers are mostly Windows-based, all virtualized (VMware 5.5), with two data centers and four branch offices around the country. We currently use Kaseya for remote desktop (and want to get rid of it), WSUS for Windows patches, Puppet (from what I've heard) for Linux patches, and don't have anything for Mac. We have some sort of hardware device for vulnerability scanning, and don't have a...
    This topic first appeared in the Spiceworks Community

    Cisco today released a security advisorythat details a security vulnerability that has been discovered in its Unified Communications Domain Manager (Unified CDM) software that "exposes the platform to hacking by remote attackers."The security hole,according to CIO, is due to "default privileged account with a static password [in Cisco'sUnified CDM software]." The software enables automation and administration of Cisco's Unified Communications Manager, Jabber applications, Unity Connections, and phone and software clients. It is widely used by organizations.CIO reports that the privileged account in Unified CDM is present from installation "and cannot be changed or removed without affecting the system's functionality." Cisco has released several patches that, at present, are the only solution to the vulnerability. Cisco has given it its...

  • What part of the registry is related to SAPI?

    system mechanic pro is incompatible with windows 8.1 64bit. Means programs like adobe reader and foxit reader and Babylon can not use windows TTS engine.
    This is because registry changes, because I'd undo the registry will solve the problem.
    Systems mechanical and Windows are both updated.
    Can you tell me what part of the change in the registry is causing this problem?
    I want to make a
    backup of that part of the registry
    ,and I'll
    fix my other windows that I
    can not undo the registry edited.

    Hi,
    I think this issue can be caused that if the older version of system mechanic is not compatible well with Windows 8.
    http://www.microsoft.com/en-us/windows/compatibility/CompatCenter/ProductViewerWithDefaultFilters?TempOsid=Windows%208.1&Locale=en-us&Architecture=X64&TextSearch=System%2BMechanic&Type=Both&CurrentPage=0&TotalPages=1&ShowCriteria=0&SortCriteria=Relevance&Compatibility=Unknown&LastRequested=14
    As following article, version 12 is released to improve the performance in Windows 8.1:
    System Mechanic Version 12 Now Available, Includes Enhancements for Windows 8.1
    http://www.maximumpc.com/system_mechanic_version_12_now_available_includes_enhancements_windows_81
    Note: this third part website is not on behalf of Microsoft.
    Thanks for your understanding.
    Kate Li
    TechNet Community Support

  • USP (menu) - How to configure System management?

    right now my System Management section has:
    Root Terminal (totally not useful)
    Control Center (not that useful either)
    Lock Screen (don't need it)
    I want to add things like Quit, Logout, Shutdown, Install software...
    How do I do that? I know there are people using it

    I don't see creation is indicated in the log. It attempted to created it then is says "System Management could not be created". It's one of those interesting things really. Why even try creating it? Interesting... ConfigMgr servers should not have access(create)
    to "System" container at all.
    It is clearly defined here as how to create it 
    http://technet.microsoft.com/en-us/library/bb633169.aspx. Use AD Users and computers, it's simpler
    Click Start, click Run, and then enter
    dsa.msc to open the Active Directory Users and Computers administrative tool.
    Click View, and then click Advanced Features.
    Expand the System container.
    Right-click System Management, and then click Properties.
    In the System Management Properties dialog box, click the
    Security tab.
    Click Add to add the site server computer account and grant the account
    Full Control permissions.
    Click Advanced, select the site server’s computer account, and then click
    Edit.
    In the Apply onto list, select This object and all child objects.
    Click OK.

  • Is possible to connect as system/manager automatically???

    Hi,
    I have any problems
    I have a package with two procedures (MT_PROC and SEN_MAIL) the first call to second.
    The first run in system/manager and in myuser/password, while the second run just in system/manager.
    Is possibile run the package in myuser/password and after connect to system/manager automatically inside the package????
    thanks
    Raffaele

    Ideally if you create a public synonym for the package and grant the 'execute' previlege to the user then it should work fine.

Maybe you are looking for