Solved

How to use Wireshark to monitor XP bootup Applying computer settings

Posted on 2008-10-06
10
1,166 Views
Last Modified: 2011-10-19
In the past few weeks I've noticed that our computers all hang on applying computer settings for 1-2 minutes.  I've checked all the DNS issues in other posts but still not finding anything wrong there.  I've seen a few people recommend to use Wireshark to see what is happening during the 'applying computer settings'.  However, I can't find any documentation on how to setup Wireshark to run during this period.  The only thing I see is the live capture where I have to start it manually.  Any help would be appreciated.  Thanks!
0
Comment
Question by:ryanmgreen
  • 5
  • 4
10 Comments
 
LVL 59

Expert Comment

by:Darius Ghassem
ID: 22651618
I'm not very experienced with WireShark but maybe I can help with the other issue. Do you have any GPOs running? Make sure your clients only point to internal DNS servers. Are you getting any errors in the Event logs on the clients and server? Can you give me a quick overview of your network setup?
0
 
LVL 6

Expert Comment

by:marce_lito
ID: 22653526
>However, I can't find any documentation on how to setup Wireshark to run during this period

I don't know if that's even possible... but you could get a small hub (or a switch capable of replicating traffic on a port) and capture the traffic on another machine...

the setup would be something like this:
net---[hub]---[problem computer]
            |
[functional computer running wireshark]

then again, i don't know if wireshark is the tool for diagnosing that kind of problem...
0
 

Author Comment

by:ryanmgreen
ID: 22661223
Dariusg-We do have GPOs running and am starting to think that may be causing the issue-although nothing was changed recently.  We have one for domain computers and one for laptop computers.  Seems that the laptop computers are the only ones have the lag on applying computer settings.  Possibly because of the firewall disable entry being in both policies.  Maybe it is conflicting there?  I turned on verbose logging and attached the file.  You'll notice there's almost a 2 minute delay in this area:
USERENV(470.3f4) 12:27:34:897 PolicyChangedThread: Calling UpdateUser with 1.
USERENV(470.3f4) 12:27:35:022 PolicyChangedThread: Broadcast message for 1.
USERENV(40c.410) 12:27:35:116 LibMain: Process Name:  C:\WINDOWS\System32\alg.exe
USERENV(470.3f4) 12:27:35:789 PolicyChangedThread: Leaving
USERENV(2f8.298) 12:27:41:827 LibMain: Process Name:  C:\WINDOWS\system32\wbem\wmiprvse.exe
USERENV(ba0.ba4) 12:28:36:095 LibMain: Process Name:  C:\WINDOWS\system32\userinit.exe
USERENV(470.e58) 12:30:44:796 IsSyncForegroundPolicyRefresh: Synchronous, Reason: policy set to SYNC
USERENV(470.474) 12:30:46:360 LoadUserProfile: Yes, we can impersonate the user. Running as self

We don't do anything with WMI and I'm not sure why the userinit.exe would take so long.  Any ideas?
startup.txt
0
 
LVL 59

Expert Comment

by:Darius Ghassem
ID: 22661320
userinit.exe usually runs the scripts listed in the GPO. See if this link helps out.

http://www.experts-exchange.com/OS/Microsoft_Operating_Systems/Server/Remote_Desktop-Terminal_Services/Q_23683948.html
0
 

Author Comment

by:ryanmgreen
ID: 22661568
I have uphclean installed on all our laptops here.  So that doesn't appear to be helping.  

Also, I can't disable autocert enrollment as we do use that for email encryption and I believe that needs to be running in order for our local CA to work properly.  
0
Find Ransomware Secrets With All-Source Analysis

Ransomware has become a major concern for organizations; its prevalence has grown due to past successes achieved by threat actors. While each ransomware variant is different, we’ve seen some common tactics and trends used among the authors of the malware.

 
LVL 59

Expert Comment

by:Darius Ghassem
ID: 22661617
There is more then one post on EE and google talking about the autoenrollment fixing the issue.
0
 

Author Comment

by:ryanmgreen
ID: 22661923
Ok well I'll look into it.  Any idea if disabling Autoenrollment would mess with the Exchange encryption from our CA?  I've been googling that but not having any luck.
0
 
LVL 59

Expert Comment

by:Darius Ghassem
ID: 22662474
Honestly I would think it might but I'm not for sure. You can always test.
0
 

Author Comment

by:ryanmgreen
ID: 22689056
It does cause problems with encryption and it didn't fix the issue either.  We have a computer policy and a laptop policy.  In the computer policy the domain profile has the firewall disabled.  In the laptop Policy the firewall is disabled on the standard profile, for some in-house wireless issues.  Removing this laptop policy fixes the issue so I guess that is the problem.  Maybe just trying to read from two different policies is slowing it down.
0
 
LVL 59

Accepted Solution

by:
Darius Ghassem earned 500 total points
ID: 22689092
Most likely a conflict.
0

Featured Post

IT, Stop Being Called Into Every Meeting

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

Join & Write a Comment

Can I legally transfer my OEM version of Windows to another PC?  (AKA - Can I put a new systemboard in my OEM PC?) Few of us are both IT and legal experts but we all have our own views of Microsoft's licensing rules and how they apply.  There are…
I've always wanted to allow a user to have a printer no matter where they login. The steps below will show you how to achieve just that. In this Article I'll show how to deploy printers automatically with group policy and then using security fil…
Access reports are powerful and flexible. Learn how to create a query and then a grouped report using the wizard. Modify the report design after the wizard is done to make it look better. There will be another video to explain how to put the final p…
Polish reports in Access so they look terrific. Take yourself to another level. Equations, Back Color, Alternate Back Color. Write easy VBA Code. Tighten space to use less pages. Launch report from a menu, considering criteria only when it is filled…

705 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now