Re: Pathes Not Applying

From: Ben Sudbury (bsudbury_at_hotmail.com)
Date: 10/25/04


Date: Mon, 25 Oct 2004 16:13:49 +1000

Interesting!

Looking at the first patch.

Microsoft Security Bulletin MS04-035
Vulnerability in SMTP Could Allow Remote Code Execution (885881)
http://www.microsoft.com/technet/security/bulletin/ms04-035.mspx

I find that there is nothing particularly strange in the log file.

However, when I look for the smtpsvc.dll file that should have been replaced
I find the old version in windows\system32\inetsrv\ and another copy in
Windows\Lastgood and Windows\LastGood.Tmp but the new version is sitting in
C:\WINDOWS\LastGood\$hf_mig$\KB885881\RTMQFE and
C:\WINDOWS\LastGood.Tmp\$hf_mig$\KB885881\RTMQFE .

I saw a reference to this $hf_mig$ folder in the log for this patch but I
assumed that it was a variable and not intended to be a used as a literal.

Maybe it has not been successful in replacing the file after the reboot?

Regards,

Ben.

"Bigbruva" <Richardh@dontusethis.ws> wrote in message
news:uO8GPrFuEHA.376@TK2MSFTNGP09.phx.gbl...
> Ben, Torgeir has provided some good troubleshooting advice, please try
this
> out and let us know how it works out for you
>
> BB
>
> "Torgeir Bakken (MVP)" <Torgeir.Bakken-spam@hydro.com> wrote in message
> news:enOyedCuEHA.2956@TK2MSFTNGP12.phx.gbl...
> > Ben Sudbury wrote:
> >
> >> Hi BB,
> >>
> >> I am using the Windows Update Web site or the Automatic updates
> >> facility without using SUS or SMS.
> > Hi
> >
> > You could look at the updates log files to see if you can find any
> > clues, they are placed in the Windows folder and are named KBxxxxxx.log
> > where xxxxxx is the KB number of the update.
> >
> > Please download and install the updates manually (use download links
> > in the links below) and see what happens then.
> >
> > Also, the bulletins below will tell you how to manually check if the
> > update is applied or not, look under "Security General Information
> > --> Update Information". Note that if the update asks for an reboot,
> > you need to reboot first.
> >
> >
> > Microsoft Security Bulletin MS04-035
> > Vulnerability in SMTP Could Allow Remote Code Execution (885881)
> > http://www.microsoft.com/technet/security/bulletin/ms04-035.mspx
> >
> >
> > Microsoft Security Bulletin MS04-037
> > Vulnerability in Windows Shell Could Allow Remote Code Execution
(841356)
> > http://www.microsoft.com/technet/security/bulletin/ms04-037.mspx
> >
> > Microsoft Security Bulletin MS04-032
> > Security Update for Microsoft Windows (840987)
> > http://www.microsoft.com/technet/security/bulletin/ms04-032.mspx
> >
> > Microsoft Security Bulletin MS04-030
> > Vulnerability in WebDAV XML Message Handler Could Lead to a Denial
> > of Service (824151)
> > http://www.microsoft.com/technet/security/bulletin/ms04-030.mspx
> >
> > --
> > torgeir, Microsoft MVP Scripting and WMI, Porsgrunn Norway
> > Administration scripting examples and an ONLINE version of
> > the 1328 page Scripting Guide:
> > http://www.microsoft.com/technet/scriptcenter/default.mspx
>
>



Relevant Pages


Quantcast