Discussion:
confiker virus attack
(too old to reply)
irsh19
2009-09-07 22:43:26 UTC
Permalink
Hi Folks,

I need some urgent HELP from you ALL, my client is facing confike
virus attack, they dnt hav any patch managenemt system,n there are man
remote client machines which are windows 2000,windows xp and window
2003 and these machines dont have the KB958644 installed... I need hel
in installing this KB958644 on all the client m/c remotely using Admi
credentials hidden also i need to install couple of .exe files als
with this MS patch using any script or vbs file with GP start up,afte
instaling the above files we also need the log files for the clients t
be generated in a network share location.

can anyone help me with this type of script which can be run through G
startup???

thnx in advanc

--
irsh1
-----------------------------------------------------------------------
irsh19's Profile: http://forums.techarena.in/members/123384.ht
View this thread: http://forums.techarena.in/server-scripting/1243292.ht

http://forums.techarena.i
Richard Mueller [MVP]
2009-09-08 03:34:41 UTC
Permalink
Post by irsh19
Hi Folks,
I need some urgent HELP from you ALL, my client is facing confiker
virus attack, they dnt hav any patch managenemt system,n there are many
remote client machines which are windows 2000,windows xp and windows
2003 and these machines dont have the KB958644 installed... I need help
in installing this KB958644 on all the client m/c remotely using Admin
credentials hidden also i need to install couple of .exe files also
with this MS patch using any script or vbs file with GP start up,after
instaling the above files we also need the log files for the clients to
be generated in a network share location.
can anyone help me with this type of script which can be run through GP
startup???
thnx in advance
--
irsh19
------------------------------------------------------------------------
irsh19's Profile: http://forums.techarena.in/members/123384.htm
View this thread: http://forums.techarena.in/server-scripting/1243292.htm
http://forums.techarena.in
I have a VBScript program that can deploy and run any executable (if it runs
silently with no user intervention) remotely to all computers in a group in
bulk. The program is linked here:

http://www.rlmueller.net/Deploy.htm

The program writes a detailed log file. You can create a domain group and
make all affected computers members of the group. The advantage here is that
you know when the program runs, you know it runs just once, you know the
remote client computers run the program locally, the program is deleted from
the client after it runs, and the patch runs with your credentials (no need
to hard code credentials. You should be a member of Domain Admins, which by
default will be a member of the local Administrators group of all computers
joined to the domain (or you need to be a member of another group that is a
member of all local Administrator groups). No one needs to be logged into
each computer, but the computers need to be on and connected to the network.
The log will indicate which computers were not available, so you can repeat
the process until all are fixed (modifying the group membership so only
computers that need the deployment remain as members). There appears to be a
different executable for kb 958644 for each OS, so you will need a domain
group for each.
--
Richard Mueller
MVP Directory Services
Hilltop Lab - http://www.rlmueller.net
--
irsh19
2009-09-08 07:31:50 UTC
Permalink
Thnx for the script Richard,

however here we have different version of OS (2000 and XP) with coupl
of different languages (EN-US, JP, AR) so this script will find th
version n language, also let me knw what changes should i make to th
script so tht it can work for me (eg: the patch location, credential
and all other things in the script), I am really new to this scripting
can you please walk through with this....

thnx
irs

--
irsh1
-----------------------------------------------------------------------
irsh19's Profile: http://forums.techarena.in/members/123384.ht
View this thread: http://forums.techarena.in/server-scripting/1243292.ht

http://forums.techarena.i
David H. Lipman
2009-09-08 10:46:12 UTC
Permalink
From: "Richard Mueller [MVP]" <rlmueller-***@ameritech.nospam.net>



| I have a VBScript program that can deploy and run any executable (if it runs
| silently with no user intervention) remotely to all computers in a group in
| bulk. The program is linked here:

| http://www.rlmueller.net/Deploy.htm

| The program writes a detailed log file. You can create a domain group and
| make all affected computers members of the group. The advantage here is that
| you know when the program runs, you know it runs just once, you know the
| remote client computers run the program locally, the program is deleted from
| the client after it runs, and the patch runs with your credentials (no need
| to hard code credentials. You should be a member of Domain Admins, which by
| default will be a member of the local Administrators group of all computers
| joined to the domain (or you need to be a member of another group that is a
| member of all local Administrator groups). No one needs to be logged into
| each computer, but the computers need to be on and connected to the network.
| The log will indicate which computers were not available, so you can repeat
| the process until all are fixed (modifying the group membership so only
| computers that need the deployment remain as members). There appears to be a
| different executable for kb 958644 for each OS, so you will need a domain
| group for each.

| --
| Richard Mueller
| MVP Directory Services
| Hilltop Lab - http://www.rlmueller.net
| --


The horses are already out of the barn and it is bandaid approach to compound fracture.

Sure KB958644 might get pushed but the platforms still won't be information assirance
compliant and the underlying problems that led to a mass infection will still exist.
--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp
Jens Hastrup
2009-09-09 20:42:22 UTC
Permalink
Post by irsh19
Hi Folks,
I need some urgent HELP from you ALL, my client is facing confiker
virus attack, they dnt hav any patch managenemt system,n there are many
remote client machines which are windows 2000,windows xp and windows
2003 and these machines dont have the KB958644 installed... I need help
in installing this KB958644 on all the client m/c remotely using Admin
credentials hidden also i need to install couple of .exe files also
with this MS patch using any script or vbs file with GP start up,after
instaling the above files we also need the log files for the clients to
be generated in a network share location.
can anyone help me with this type of script which can be run through GP
startup???
thnx in advance
--
irsh19
------------------------------------------------------------------------
irsh19's Profile: http://forums.techarena.in/members/123384.htm
View this thread: http://forums.techarena.in/server-scripting/1243292.htm
http://forums.techarena.in
Hi,

You might want to have a look here
http://support.microsoft.com/default.aspx?scid=kb;en-us;824687
and here as well http://vil.nai.com/vil/averttools.aspx

Its a pain not being fully patched these days :-

Jens

Loading...