republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Problem with Automatic Update since Tuesday
Search Topic:
Uniqs:
7461
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Security Software Updates - 15 May 2007 »
« Trojan could be infecting computers through Microsoft update  
page: 1 · 2 · 3 · 4
AuthorAll Replies

OZO
Premium
join:2003-01-17

reply to slashman
Re: Problem with Automatic Update since Tuesday

After installing new two packages and several reboots running "Custom" check took 3:30 min, wich is better than previous 17 min.

What I did:
1. Uninstall v2 of 927891, reboot.
2. Install v3 of 927891, reboot.
3. Install UpdateAgent v3.0, reboot.
4. Check and install latest updates, reboot.

It's better now. Thank you rdhw See Profile for the links and advice to re-install 927891 fix.

It may be the best that can be done for now, who knows. Real improvement may bring only a new SP3 package though. In this case we will not need to check / download / install more then hundred(!) latest updates (since SP2).

When it will finally come to us, bringing to the end this obvious absurd of downloading so many hotfixes separately?
--
Keep it simple, it'll become complex by itself...


La Luna
Surviving Ashraful
Premium
join:2001-07-12
Warwick, NY
clubs:
I don't have v2 of KB927891 installed, I've got none. Is that an issue?


HA Nut
Premium
join:2004-05-13
USA
Not IMO. Just means you had not yet tried to patch this bug. Makes sense since you had not been suffering from it...

OZO
Premium
join:2003-01-17
reply to La Luna
927891 fixes 916089, which in turn fixes 100% CPU utilization problem. So, I think it's be logical to install 927891 v3 now.
--
Keep it simple, it'll become complex by itself...


La Luna
Surviving Ashraful
Premium
join:2001-07-12
Warwick, NY
clubs:
·Optimum Online
·Vonage

reply to HA Nut
said by HA Nut See Profile :

Not IMO. Just means you had not yet tried to patch this bug. Makes sense since you had not been suffering from it...
Okey dokey, thanks.

I guess I'll install that first as OZO See Profile did. I could have sworn I read to do it in the opposite order somewhere but maybe I'm not remembering right, I read a lot of stuff about this.
--
~~"As long as America is an infidel enemy, terrorizing it is a duty." Sayed Imam Abdul-Aziz el-Sheriff~~



La Luna
Surviving Ashraful
Premium
join:2001-07-12
Warwick, NY
clubs:
reply to slashman
YAY!! It seems to have worked!! Took about 2 1/2 minutes, but no freezes or anything.

gworkman7

join:2005-10-18
Vail, AZ
·PHONE POWER
·magicjack.com
·Qwest.net
·Broadvox Direct

reply to slashman
So now what to do? All KBs talk about 2003 Server and XP. I have 2000 Server and I have the issue. I utilized the switch from "Microsoft Update" to "Windows Update" and my server is now performing as expected. I called Microsoft and was told I needed to provide a credit card so they can charge me $245 to speak to somebody.

So my options are no updates and eventually I'll get hit with some worm or updates and my server won't run. You'd think this company has enough money that they don't need to charge it's customers to fix issues they cause in the first place. I could understand being charged if this were my lack of ability to manage a server, but c'mon...


yeti34
RC Onroad racin

join:2001-04-12
Salt Lake City, UT

reply to slashman
This really sucks and I wish I had seen this thread before I went out and got a new HD. I thought I just had a HD going out on me and figured I just needed to replace it. I can't return it for it is used since that is what I am runnning off of now. I will try to get this update and hopee it solves the issue. I have to reread to find out what I need, for I just skimmed over everything and thought I needed to post. I did not notice it on my other PC's for I have not had them on in awhile. I love this site for info but only wished I had seen it sooner. Live and learn I guess.


HA Nut
Premium
join:2004-05-13
USA


1 edit
reply to gworkman7
said by gworkman7 See Profile :

So now what to do? All KBs talk about 2003 Server and XP. I have 2000 Server and I have the issue. I utilized the switch from "Microsoft Update" to "Windows Update" and my server is now performing as expected. I called Microsoft and was told I needed to provide a credit card so they can charge me $245 to speak to somebody.

So my options are no updates and eventually I'll get hit with some worm or updates and my server won't run. You'd think this company has enough money that they don't need to charge it's customers to fix issues they cause in the first place. I could understand being charged if this were my lack of ability to manage a server, but c'mon...
No question that MS does not want to support it's older OS's. No profit in it. (The only thing they gain would be happy customers. ) But short of going to another completely different OS, most of us will have no choice but to upgrade.

I'm a PC person and don't know much about servers. At this point in time, MS will still let PC owners get updates manually by using the TechNet site. »www.microsoft.com/technet/securi···may.mspx Is this an avenue you could take advantage of?


HA Nut
Premium
join:2004-05-13
USA

reply to La Luna
said by La Luna See Profile :

YAY!! It seems to have worked!! Took about 2 1/2 minutes, but no freezes or anything.
Glad to hear it! Both you and OZO have given me the hope it will work on the PCs I need to fix.


La Luna
Surviving Ashraful
Premium
join:2001-07-12
Warwick, NY
clubs:
·Optimum Online
·Vonage

reply to gworkman7
said by gworkman7 See Profile :

So now what to do? All KBs talk about 2003 Server and XP. I have 2000 Server and I have the issue. I utilized the switch from "Microsoft Update" to "Windows Update" and my server is now performing as expected. I called Microsoft and was told I needed to provide a credit card so they can charge me $245 to speak to somebody.

So my options are no updates and eventually I'll get hit with some worm or updates and my server won't run. You'd think this company has enough money that they don't need to charge it's customers to fix issues they cause in the first place. I could understand being charged if this were my lack of ability to manage a server, but c'mon...
IMHO, you should just leave it as is, using Windows Update. A little less convenient, but better than being burned with some nasty.

If this fix didn't work for me, that's what I was going to do.
--
~~"As long as America is an infidel enemy, terrorizing it is a duty." Sayed Imam Abdul-Aziz el-Sheriff~~


gworkman7

join:2005-10-18
Vail, AZ
·PHONE POWER
·magicjack.com
·Qwest.net
·Broadvox Direct

That is my plan for now..Win Updates only. It is working. I'm not concerned about the Office updates. The only product used on the server is Excel and the only spreadsheets/macros run on it are created by me. I'm sure M$ needs to sell more upgrades, but some people work for companies who are satisfied with what already does the job for them.

Thanks for the suggestions.


nu2this
NOT
Premium
join:2005-04-07
Hallandale, FL

reply to slashman
one way to fix this issue, since most people have to update to use Vista... take it a step further and update to a mac... then you don't have to worry about these issues...

and... you can also run windows on a mac...
--
Why are you so surprised to see sinners in church? Are you shocked to see sick people in a hospital too?


jstone00

join:2004-06-19
Fortuna, CA
reply to slashman
I, too, was having the problem described in the first post in this thread. The fixes described in previous posts worked for me, and I've now successfully updated my machines. Thank you!


Annmarie
Premium,Mod
join:2000-11-11
Ronkonkoma, NY
clubs:
·Optimum Online

Host:
Electronics
reply to slashman
This same issue came up at work on my husband's laptop - ground to a halt and took forever to get anything to run. After many hard reboots I was able to view the process in Task Manager and discovered svchost hitting the CPU at almost 100%.

I told my husband he had a virus (because he is very negligent at keeping his computer clean and secure) and will most likely get fired.

Did a bit of Googling and found the solution laluna posted about.

After a few questions - honey how long has the update icon been in your systray? Oh a week now? Um - that is bad.

I am so embarrassed - I never even searched here before I Googled. I should have known better that you guys were all over it. I did learn a lot about different services and processes and was able to carefully remove or disable several from starting on his machine.

I told him the virus has been cleaned and he better be more careful in the future.


antiphishing
Phishing Scam Terminator
Premium
join:2004-06-09
Wilkes Barre, PA

reply to slashman
Download backdoor found in Windows Update

No protection currently available for Bits flaw
Matt Chapman, vnunet.com 11 May 2007
ADVERTISEMENT
Click Here!

A security firm has warned that parts of Windows designed to download official patches and updates are being used to download malicious files.

Elia Florio, security response engineer at Symantec, said on a company blog that the Background Intelligent Transfer Service (Bits) in Windows had been used to download files to PCs infected with a Trojan.

"Using Bits to download malicious files is a clever trick because it bypasses local firewalls, as the download is performed by Windows itself and does not require suspicious actions for process injection," she said.

Florio also warned that there is currently no way to stop files being downloaded using this attack.

"At the moment there is no immediate workaround against this type of attack as it is not easy to check what Bits should download and not download," she said.

"Probably the Bits interface should be designed to be accessible only with a higher level of privilege, or the download jobs created with Bits should be restricted to only trusted URLs."

The Downloader Trojan that uses this attack was emailed out in spam messages in Germany at the end of March 2007.

Florio said that it was worth mentioning that the Bits download method is already well-documented in the underground and was posted as an "anti-firewall loader" example on a Russian forum at the end of 2006.
»www.vnunet.com/vnunet/news/21897···-windows
--

Specializing in "takes downs" of phishing and advance fee scams
Send your Phishing/Advance fee scams to: phish@antihotmail.com
»/profile/1021645

tlking98

join:2001-02-27
Fishers, IN

reply to slashman
This is what I used to fix the issue with svchost going to 100% when running automatic updates. I found it after searching on groups.google.com.
===========================================================
The following assumes you're
on Windows XP but will probably work OK for Win2k as well. If you're
confident about what you're doing, then try the
following first - only if it doesn't work, then there's another level of
stuff that can be done following:

1. Stop and Disable Automatic Updates, Background Intelligent Transfer
Service and the Cryptographic Service.
2. Rename the folder %SystemRoot%\SoftwareDistribution to
%SystemRoot%\OldSoftwareDistribution
3. Open Notepad and create a file containing the following:

REGSVR32 WUAPI.DLL
REGSVR32 WUAUENG.DLL
REGSVR32 WUAUENG1.DLL
REGSVR32 ATL.DLL
REGSVR32 WUCLTUI.DLL
REGSVR32 WUPS.DLL
REGSVR32 WUPS2.DLL
REGSVR32 WUWEB.DLL

Save this file as 'Wudll.cmd' (without the quotes) to any convenient
location then exit Notepad and double click on the file you just saved. You
should get a 'Sucess' mesage for each of the .dll's listed above.

4. Now Re-enable to Automatic status and then Start each of the services
you stopped before - Automatic Updates, Background Intelligent Transfer
Service and the Cryptographic Service.

5. Now Reboot. Now Reboot Again. (Yes, twice.)

See if that solves it - give it a couple of days. If so, then you can
delete 'OldSoftwareDistribution'.


La Luna
Surviving Ashraful
Premium
join:2001-07-12
Warwick, NY
clubs:
·Optimum Online
·Vonage


1 edit
reply to antiphishing
said by antiphishing See Profile :

Download backdoor found in Windows Update.....
Not sure what this has to do with the issues being discussed in this thread, but the trojan has to already be on the machine for it to be able to use BITS to download more malware.

»Trojan could be infecting computers through Microsoft update
--
~~"As long as America is an infidel enemy, terrorizing it is a duty." Sayed Imam Abdul-Aziz el-Sheriff~~



Name Game
Premium
join:2002-07-07
North Myrtle Beach, SC


1 edit
reply to slashman
Fix for Microsoft Automatic Updates not working
Users report continued problems with Microsoft patch, even after downloading and running new hotfix

»www.infoworld.com/article/07/05/···g_1.html

»www.computerworld.com/action/art···c=kc_top

--
Gladiator Security Forum »www.gladiator-antivirus.com/
Missing Kids
»www.missingkids.com/


La Luna
Surviving Ashraful
Premium
join:2001-07-12
Warwick, NY
clubs:
·Optimum Online
·Vonage

said by Name Game See Profile :

Fix for Microsoft Automatic Updates not working
Users report continued problems with Microsoft patch, even after downloading and running new hotfix

»www.infoworld.com/article/07/05/···g_1.html

»www.computerworld.com/action/art···c=kc_top

Well, I mentioned here in one of my other posts that people were reporting that the "fix" didn't work for them, which is why I was reluctant to try it. I didn't want to further muck things up by applying a hotfix that might then have to be uninstalled somewhere down the line to try something else. The more "fixes* that don't work that you apply for a problem, the more likely that something else is going to blow down the line eventually.

The people who tried it here gave me the confidence to give it a go, and luckily, it worked for me. I suppose it's also possible that *some* (not all) people who say it didn't work did something wrong in the way they applied the hotfix.
--
~~"As long as America is an infidel enemy, terrorizing it is a duty." Sayed Imam Abdul-Aziz el-Sheriff~~

Forums » Up and Running » Security » SecuritySecurity Software Updates - 15 May 2007 »
« Trojan could be infecting computers through Microsoft update  
page: 1 · 2 · 3 · 4


Thursday, 03-Dec 09:47:56 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [162] Comcast Releasing Promised Usage Meter
· [104] Avast Antivirus Has Gone Mad
· [101] Graduate Student Unveils Sprint's GPS Sharing With Feds
· [80] Latest Consumer Reports Survey Not Kind To AT&T
· [70] Baltimore To Ban Lazy Cable Installs
· [63] Broadband Killed The Game Console
· [55] Rogers Unveils The ISP Dream Model
· [47] ACTA: Global Three Strikes
· [41] Rural Carriers Quickly Embracing Fiber
· [41] Cable Industry's 'Adoption Plus': Altruism Or PR Stunt?
Most people now reading
· False positive in Avast! or is it real? [Security]
· [TWC] Audio/Video outage in Brooklyn [Time Warner Cable TV/Voice]
· [Rant] Disrespect of PTO [Rants, Raves, and Praise]
· Quality/longevity of 15A 120V receptacles [Home Repair & Improvement]
· Working in a Stairwell and Surrounding High Walls [Home Repair & Improvement]
· Options if ACTA is ratified [TekSavvy]
· Equal speeds ruling [Canadian Broadband]
· outdoor to indoor conduit power run [Home Repair & Improvement]
· ICC Strats??? [World of Warcraft]
· Many Sites Unreachable [Rogers]