Re: Security Update Q811493

From: Jupiter Jones [MVP] (jones_jupiter_at_hotnomail.com)
Date: 06/26/03


Date: Wed, 25 Jun 2003 17:28:18 -0600


You have a few options:
1. do without this patch, for most home users the patch is not an
issue:
http://support.microsoft.com/default.aspx?scid=kb;en-us;811493
Under "Symptoms"
"For an attack to be successful, an attacker would have to be able to
log on interactively to the system, either at the console or through a
terminal session. Also, a successful attack would require the
introduction of code to exploit this vulnerability"
This basically means the person needs to be at the keyboard.

2. Run system File checker to check for corrupted system files:
Start/Run
Type "cmd" ENTER
Type "sfc /scannow" ENTER
Have Windows XP CD available

-- 
Jupiter Jones  [MVP]
An easier way to read newsgroup messages:
http://www.microsoft.com/windowsxp/pro/using/newsgroups/setup.asp
Please respond to newsgroup only for everyone's benefit.
"ccuurrllyy" <ccuurrllyy@rogers.com> wrote in message
news:00e701c33a06$16e1fdf0$a001280a@phx.gbl...
> hello
> I have tried what you said earlier and came with the same
> results. The part with the windows update log is in here
> again but it looks like its all good to me. if you have
> anymore ideas let me know.
> thanks ccuurrllyy
>
> "2003-06-23 21:14:26  01:14:26   Success   IUCTL
> Starting
> 2003-06-23 21:14:28  01:14:28   Success   IUCTL
> Downloaded iuident.cab from
> http://windowsupdate.microsoft.com/v4/ to C:\Program
> Files\WindowsUpdate\V4
> 2003-06-23 21:14:29  01:14:29   Success   IUCTL
> Current iuengine.dll version: 5.4.3630.2550
> 2003-06-23 21:14:29  01:14:29   Success   IUCTL
> Current iuctl.dll version: 5.4.3630.2550
> 2003-06-23 21:14:29  01:14:29   Success   IUENGINE
> Starting
> 2003-06-23 21:14:29  01:14:29   Success   IUCTL
> Windows Update Web Site has a valid address:
> http://v4.windowsupdate.microsoft.com/en/default.asp
> 2003-06-23 21:14:29  01:14:29   Success   IUENGINE
> Determining machine configuration
> 2003-06-23 21:14:29  01:14:29   Success   IUENGINE
> Determining machine configuration
> 2003-06-23 21:15:02  01:15:02   Success   IUENGINE
> Shutting down
> 2003-06-23 21:15:19  01:15:19   Success   IUCTL
> Downloaded iuident.cab from
> http://windowsupdate.microsoft.com/v4/ to C:\Program
> Files\WindowsUpdate\V4
> 2003-06-23 21:15:19  01:15:19   Success   IUCTL
> Current iuengine.dll version: 5.4.3630.2550
> 2003-06-23 21:15:19  01:15:19   Success   IUCTL
> Current iuctl.dll version: 5.4.3630.2550
> 2003-06-23 21:15:19  01:15:19   Success   IUENGINE
> Starting
> 2003-06-23 21:15:19  01:15:19   Success   IUCTL
> Windows Update Web Site has a valid address:
> http://v4.windowsupdate.microsoft.com/en/default.asp
> 2003-06-23 21:15:19  01:15:19   Success   IUENGINE
> Determining machine configuration
> 2003-06-23 21:15:19  01:15:19   Success   IUENGINE
> Determining machine configuration
> 2003-06-23 21:19:01  01:19:01   Success   IUENGINE
> Shutting down
> 2003-06-23 21:24:12  01:24:12   Success   IUCTL
> Starting
> 2003-06-23 21:24:17  01:24:17   Success   IUCTL
> Downloaded iuident.cab from
> http://windowsupdate.microsoft.com/v4/ to C:\Program
> Files\WindowsUpdate\V4
> 2003-06-23 21:24:17  01:24:17   Success   IUCTL
> Current iuengine.dll version: 5.4.3630.2550
> 2003-06-23 21:24:17  01:24:17   Success   IUCTL
> Current iuctl.dll version: 5.4.3630.2550
> 2003-06-23 21:24:17  01:24:17   Success   IUENGINE
> Starting
> 2003-06-23 21:24:17  01:24:17   Success   IUCTL
> Windows Update Web Site has a valid address:
> http://v4.windowsupdate.microsoft.com/en/default.asp
> 2003-06-23 21:24:17  01:24:17   Success   IUENGINE
> Determining machine configuration
> 2003-06-23 21:24:18  01:24:18   Success   IUENGINE
> Determining machine configuration
> 2003-06-23 21:24:26  01:24:26   Success   IUENGINE
> Querying software update catalog from
> https://v4.windowsupdate.microsoft.com/getmanifest.asp
> 2003-06-23 21:24:26  01:24:26   Success   IUENGINE
> Querying software update catalog from
> https://v4.windowsupdate.microsoft.com/getmanifest.asp
> 2003-06-23 21:24:27  01:24:27   Success   IUENGINE
> Querying software update catalog from
> https://v4.windowsupdate.microsoft.com/getmanifest.asp
> 2003-06-23 21:24:30  01:24:30   Success   IUENGINE
> Querying software update catalog from
> https://v4.windowsupdate.microsoft.com/getmanifest.asp
> 2003-06-23 21:24:31  01:24:31   Success   IUENGINE
> Determining machine configuration
> 2003-06-23 21:24:32  01:24:32   Success   IUENGINE
> Querying software update catalog from
> https://v4.windowsupdate.microsoft.com/consumerdrivers/get
> manifest.asp
> 2003-06-23 21:25:10  01:25:10   Success   IUENGINE
> Querying software update catalog from
> https://v4.windowsupdate.microsoft.com/getmanifest.asp
> 2003-06-23 21:25:16  01:25:16   Success   IUENGINE
> Asynchronous Download started
> 2003-06-23 21:25:16  01:25:16   Success   IUENGINE
> Download destination root folder is: D:\WUTemp
> 2003-06-23 21:25:17  01:25:17   Success   IUENGINE
> Downloaded file
> http://download.windowsupdate.com/msdownload/update/v3-
> 19990518/cabpool/Q811493_WXP_SP2_x86_ENU_1d41442ff6ba32e97
> 51dd62228f10a4.exe
> 2003-06-23 21:25:17  01:25:17   Success   IUENGINE
> Local path
> D:\WUTemp\com_microsoft.811493_XP_5951_Rec\Q811493_WXP_SP2
> _x86_ENU.exe
> 2003-06-23 21:25:17  01:25:17   Success   IUENGINE
> See iuhist.xml for details: Download finished
> 2003-06-23 21:25:17  01:25:17   Success   IUENGINE
> Asynchronous Install started
> 2003-06-23 21:25:17  01:25:17   Success   IUENGINE
> Asynchronous Install completed startup
> 2003-06-23 21:25:21  01:25:21   Success   IUENGINE
> Installing SOFTWARE item from publisher com_microsoft
> 2003-06-23 21:25:21  01:25:21   Success   IUENGINE
> Installer Command Type: EXE
> 2003-06-23 21:27:10  01:27:10   Success   IUENGINE
> See iuhist.xml for details: Install finished
> 2003-06-23 22:36:16  02:36:16   Success   IUCTL
> Starting
> 2003-06-23 22:36:17  02:36:17   Success   IUCTL
> Downloaded iuident.cab from
> http://windowsupdate.microsoft.com/v4/ to C:\Program
> Files\WindowsUpdate\V4
> 2003-06-23 22:36:19  02:36:19   Success   IUCTL
> Current iuengine.dll version: 5.4.3630.2550
> 2003-06-23 22:36:19  02:36:19   Success   IUCTL
> Current iuctl.dll version: 5.4.3630.2550
> 2003-06-23 22:36:19  02:36:19   Success   IUENGINE
> Starting
> 2003-06-23 22:36:20  02:36:20   Success   IUCTL
> Windows Update Web Site has a valid address:
> http://v4.windowsupdate.microsoft.com/en/default.asp
> 2003-06-23 22:36:20  02:36:20   Success   IUENGINE
> Determining machine configuration
> 2003-06-23 22:36:21  02:36:21   Success   IUENGINE
> Determining machine configuration
> 2003-06-23 22:36:29  02:36:29   Success   IUENGINE
> Querying software update catalog from
> https://v4.windowsupdate.microsoft.com/getmanifest.asp
> 2003-06-23 22:36:29  02:36:29   Success   IUENGINE
> Querying software update catalog from
> https://v4.windowsupdate.microsoft.com/getmanifest.asp
> 2003-06-23 22:36:30  02:36:30   Success   IUENGINE
> Querying software update catalog from
> https://v4.windowsupdate.microsoft.com/getmanifest.asp
> 2003-06-23 22:36:32  02:36:32   Success   IUENGINE
> Querying software update catalog from
> https://v4.windowsupdate.microsoft.com/getmanifest.asp
> 2003-06-23 22:36:34  02:36:34   Success   IUENGINE
> Determining machine configuration
> 2003-06-23 22:36:36  02:36:36   Success   IUENGINE
> Querying software update catalog from
> https://v4.windowsupdate.microsoft.com/consumerdrivers/get
> manifest.asp
> 2003-06-23 22:39:18  02:39:18   Success   IUENGINE
> Shutting down"
>
>
> >-----Original Message-----
> >That seems to show nothing but Success.
> >Look again, there should be some with errors.
> >
> >Try these also:
> >****Sections changed 22 June 2003****
> >POST BACK WITH THE EXACT INFORMATION FROM STEP 16 if all
> else fails.
> >
> >1.  Reboot computer then try updates one at a time if
> issue involved
> >multiple updates.
> >
> >2.  Check Date/Time
> >
> >3.  Disable firewall
> >
> >4.  Disable antivirus
> >
> >5.  (Windows XP):
> >Reboot computer.
> >http://support.microsoft.com/?scid=kb;en-us;326815
> >Don't forget steps 6-9 catroot2 file.
> >Do this whether SP1 is the issue or not.
> >
> >Another way to do #5:
> >Reboot, login to an Administrator account.
> >Double click My Computer.
> >Double click C drive.
> >Double click Windows file.
> >Double click System32 file.
> >Right click catroot2, click rename, type "catroot2old"
> >ENTER
> >Reboot
> >
> >6.  (Windows XP)
> >Go to Control Panel.
> >Click Windows Update on the left panel
> >
> >7.  Go to Internet Options in the Control Panel:
> >Delete Cookies
> >Delete Files (check box "Delete all offline content")
> >Clear History
> >
> >8.  If you use AOL, minimize AOL and open Internet
> Explorer and try
> >Windows Update
> >
> >9.  Set a language in Internet Explorer:
> >To check the language setting in Internet Explorer:
> >(1.) Click "Tools" and then select "Internet Options".
> >(2.) Click "Languages".button
> >(3.) Make sure at least one language is listed in
> the "Language
> >Options" dialog box.
> >
> >10.  Disable the options "Automatically detect settings"
> and "Use
> >automatic configuration script."
> >To do this:
> >(1.) Open Internet Explorer.
> >(2.) Click "Tools," and then click "Internet Options."
> >(3.) Click "Connections," and then click "LAN Settings."
> >(4.) Make sure the check boxes for "Automatically detect
> settings" and
> >"Use automatic configuration script" are not selected.
> >
> >11.  Open Internet Explorer
> >Click Tools
> >Click Internet Options
> >Click Security tab.
> >Click Default
> >Click OK and follow prompts.
> >
> >12.  Upgrade to Internet Explorer Service Pack 1 if not
> already
> >installed:
> >http://www.microsoft.com/windows/ie/downloads/critical/ie
> 6sp1/default.asp
> >
> >13.  Start/Run
> >Type "msconfig" ENTER
> >Click Start-up tab and make a note of what is checked
> and unchecked.
> >Go back to General tab.
> >Select Selective Start-up (unless already selected).
> >Uncheck "Load Start-up group items".
> >Click OK, follow prompts and reboot.
> >Try windows Update again.
> >When done, go back to MSCONFIG.
> >Recheck Start-up tab items and place to normal Start-up
> if that was
> >original configuration.
> >Click OK and follow prompts.
> >
> >14.  Change the URL from "http..." to "https...".
> >
> >15.  http://support.microsoft.com/default.aspx?
> scid=kb;en-us;q193385
> >
> >16.  Check the Windows Update Log in
> the "C:\Windows\Windows
> >Update.log" for the exact error message.
> >See if something here fits
> >http://v4.windowsupdate.microsoft.com/troubleshoot/
> >
> >-- 
> >Jupiter Jones  [MVP]
> >An easier way to read newsgroup messages:
> >http://www.microsoft.com/windowsxp/pro/using/newsgroups/s
> etup.asp
> >Please respond to newsgroup only for everyone's benefit.
> >
> >
> >"ccuurrllyy" <ccuurrllyy@rogers.com> wrote in message
> >news:03be01c33944$669b9ee0$a601280a@phx.gbl...
> >> I have done all that you asked to do and here is the
> part
> >> in the windows update log "2003-06-20 00:42:17
> >> 04:42:17   Success   IUCTL          Starting
> >> 2003-06-20 00:42:19  04:42:19   Success   IUCTL
> >> Downloaded iuident.cab from
> >> http://windowsupdate.microsoft.com/v4/ to C:\Program
> >> Files\WindowsUpdate\V4
> >> 2003-06-20 00:42:20  04:42:20   Success   IUCTL
> >> Current iuengine.dll version: 5.4.3630.2550
> >> 2003-06-20 00:42:20  04:42:20   Success   IUCTL
> >> Current iuctl.dll version: 5.4.3630.2550
> >> 2003-06-20 00:42:20  04:42:20   Success   IUENGINE
> >> Starting
> >> 2003-06-20 00:42:20  04:42:20   Success   IUCTL
> >> Windows Update Web Site has a valid address:
> >> http://v4.windowsupdate.microsoft.com/en/default.asp
> >> 2003-06-20 00:42:20  04:42:20   Success   IUENGINE
> >> Determining machine configuration
> >> 2003-06-20 00:42:21  04:42:21   Success   IUENGINE
> >> Determining machine configuration
> >> 2003-06-20 00:42:26  04:42:26   Success   IUENGINE
> >> Querying software update catalog from
> >> https://v4.windowsupdate.microsoft.com/getmanifest.asp
> >> 2003-06-20 00:42:27  04:42:27   Success   IUENGINE
> >> Querying software update catalog from
> >> https://v4.windowsupdate.microsoft.com/getmanifest.asp
> >> 2003-06-20 00:42:28  04:42:28   Success   IUENGINE
> >> Querying software update catalog from
> >> https://v4.windowsupdate.microsoft.com/getmanifest.asp
> >> 2003-06-20 00:42:30  04:42:30   Success   IUENGINE
> >> Querying software update catalog from
> >> https://v4.windowsupdate.microsoft.com/getmanifest.asp
> >> 2003-06-20 00:42:32  04:42:32   Success   IUENGINE
> >> Determining machine configuration
> >> 2003-06-20 00:42:33  04:42:33   Success   IUENGINE
> >> Querying software update catalog from
> >>
> https://v4.windowsupdate.microsoft.com/consumerdrivers/get
> >> manifest.asp
> >> 2003-06-20 00:42:42  04:42:42   Success   IUENGINE
> >> Querying software update catalog from
> >> https://v4.windowsupdate.microsoft.com/getmanifest.asp
> >> 2003-06-20 00:42:46  04:42:46   Success   IUENGINE
> >> Asynchronous Download started
> >> 2003-06-20 00:42:46  04:42:46   Success   IUENGINE
> >> Download destination root folder is: D:\WUTemp
> >> 2003-06-20 00:43:08  04:43:08   Success   IUENGINE
> >> Downloaded file
> >> http://download.windowsupdate.com/msdownload/update/v3-
> >>
> 19990518/cabpool/Q811493_WXP_SP2_x86_ENU_1d41442ff6ba32e97
> >> 51dd62228f10a4.exe
> >> 2003-06-20 00:43:08  04:43:08   Success   IUENGINE
> >> Local path
> >>
> D:\WUTemp\com_microsoft.811493_XP_5951_Rec\Q811493_WXP_SP2
> >> _x86_ENU.exe
> >> 2003-06-20 00:43:09  04:43:09   Success   IUENGINE
> >> See iuhist.xml for details: Download finished
> >> 2003-06-20 00:43:09  04:43:09   Success   IUENGINE
> >> Asynchronous Install started
> >> 2003-06-20 00:43:09  04:43:09   Success   IUENGINE
> >> Asynchronous Install completed startup
> >> 2003-06-20 00:43:16  04:43:16   Success   IUENGINE
> >> Installing SOFTWARE item from publisher com_microsoft
> >> 2003-06-20 00:43:16  04:43:16   Success   IUENGINE
> >> Installer Command Type: EXE
> >> 2003-06-20 00:45:07  04:45:07   Success   IUENGINE
> >> See iuhist.xml for details: Install finished"
> >> Hope This help you help me
> >> thanks
> >>
> >> >-----Original Message-----
> >> >Reboot, disable all unnecessary applications
> especially
> >> antivirus
> >> >applications.
> >> >After it is installed, what does the
> C;|Windows\Windows
> >> Update.log
> >> >show?
> >> >
> >> >-- 
> >> >Jupiter Jones  [MVP]
> >> >An easier way to read newsgroup messages:
> >>
> >http://www.microsoft.com/windowsxp/pro/using/newsgroups/s
> >> etup.asp
> >> >Please respond to newsgroup only for everyone's
> benefit.
> >
> >
> >.
> >