Re: lsass.exe worm

From: David H. Lipman (DLipman~nospam~_at_Verizon.Net)
Date: 10/19/04


Date: Mon, 18 Oct 2004 22:10:34 -0400

Lanwench.

I distribute all patches and HotFixes that are corp. requirements via our Login Script which
is based upon the kixtart script Interpreter.

Many OS patches use the syantax; PATCH.EXE -z -n -q

This allows installations that, are quiet (no screens), rquires no reboot and requires no
user intervention.

In the situation where there were *multiple* GDI DLL fixes for the JPEG vulnerability, the
above was not the case. In those cases all the patches wre self extracting ZIP files. I
used WinZIP to extract the contents of the EXE. The patches were based around OHOTFIX.EXE
and I put that command in the script uses its switch parameters.

Since *all* my LAN users must login to the Domain, and run the Login Script, they all get
the updates. If needed, i can reboot the platform useing the Kix command; shutdown()

Dave

"Lanwench [MVP - Exchange]" <lanwench@heybuddy.donotsendme.unsolicitedmail.atyahoo.com>
wrote in message news:uQq9P5XtEHA.3872@TK2MSFTNGP15.phx.gbl...
| Selarom De Janerio wrote:
| > we got affected by this today on our 2000 workstations.
| > is there an automated way to push down the updates for this?
| >
| > regards -
|
| Not without SUS or something similar.
| Standard boilerplate follows:
|
| You've been infected by the Sasser worm or variant. This means you didn't
| apply Windows Updates (at least not very recently - patch for this came out
| April 13 2004) and don't have a firewall enabled....
|
| For WinXP: If you can't stop your computer from restarting:
|
| As soon as your computer reboots and Windows loads, click Start, then Run.
| In the box, type the following:
|
| shutdown -a (then click OK)
|
| [for Win2k, shutdown.exe is part of the resource kit and the correct syntax
| is
| shutdown /a]
|
| Then see http://www.microsoft.com/security/incident/sasser.asp and
| http://www.microsoft.com/technet/security/bulletin/MS04-011.mspx
|
| McAfee's Stinger tool to remove Sasser: http://vil.nai.com/vil/stinger/
|
| MS removal tool for Windows 2000 SP2 and up, or Windows XP:
| http://support.microsoft.com/default.aspx?scid=kb;EN-US;841720
|
| Enable your XP firewall (or get a third party one if not on XP or even if
| so - www.zonealarm.com has a free one) - if you're on a network, you need a
| good perimeter firewall anyway. Run Windows Update regularly to
| keep your OS patched to the gills. You also need good antivirus software and
| need to keep it updated regularly. As mentioned, the patch for this exploit
| was released April 13th...but there are plenty you do need. Perhaps want to
| enable the autoupdate feature of Windows Update and subscribe to the
| security bulletin announcements at www.microsoft.com/security.
|
|



Relevant Pages

  • Re: IE patches killed internet connection
    ... IE to download/install from Windows Update manually, so don't even try using Firefox. ... Later, Auto Update reoffered the security update, but I was ... Microsoft.com to try to download manually, but I have to use Firefox to ... install all patches offered except for SP2. ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • Re: KB 905915 and KB 910437 automatic update, USB failures, Delayed Write Error for external USB 2.0
    ... The second is a Windows Update to fix broken Windows Update. ... >those two checkboxes on and the two patches installed got me nowhere, ... >unchecked the two checkboxes in the XP firewall and tried copying, ... mileage irrespective of what the patch is supposed to do. ...
    (microsoft.public.windowsxp.general)
  • Re: Windows Update <=> Microsoft Security Bulletin
    ... We aim to release the patches for 'manual' installation to the Micrsoft ... download center (the MSxx-xxx patches Olaf talks about) at exactly the same ... time as the same patches get released to Windows Update. ... > available sooner via the msxx-xxx routes, ...
    (microsoft.public.security)
  • RE: Help with XP Hotfixes and Patches
    ... Help with XP Hotfixes and Patches ... > After installing I immediately went to Windows Update to try and grab ... > I have run the Microsoft Baseline Security Analyzer thru several times ...
    (Focus-Microsoft)
  • Re: Deploy patches with login script?
    ... GFI LANguard Network Security Scanner can push patches to ... > My boss has just asked if it is possible for me to modify our login script ... > mostly XP machines and right now our login script is Kix (but I would ...
    (microsoft.public.windows.server.scripting)