Making Windows think KB836528 has been run
#1
Posted 15 December 2004 - 12:02 AM
Has anybody figured out a way to trick WindowsUpdate???
#2
Posted 15 December 2004 - 12:16 AM
#3
Posted 15 December 2004 - 12:21 AM
#5
Posted 16 December 2004 - 10:36 PM
#6
Posted 17 December 2004 - 12:11 AM
i simply hid it away in WU ...
ur steps fools WU to think it's been executed or installed ...
what if you dump the doomcln.log file? does WU look for the exe or log (string search)??
#7
Posted 17 December 2004 - 01:55 AM
#8
Posted 17 December 2004 - 06:00 AM
#9
Posted 17 December 2004 - 08:42 PM
#10
Posted 18 December 2004 - 10:05 PM
- download the KB836528 update (for english language)
- decompress the DoomCln-KB836528-v4-ENU.exe file. (english file)
- on the decompressed folder, rename the uncompressed doomcln.exe to blastcln.exe
- compress the blastcln.exe file to blastcln.ex_ to the source i386 folder.
#11
Posted 18 December 2004 - 10:23 PM
#12
Posted 19 December 2004 - 12:02 AM
Microsoft MyDoom removal tool (build 1.227) started on Sun Dec 19 12:52:12 2004 Checking 23 processes. Checking startup registry keys for current user. Checking keys for 1 other users Insufficient memory - 0 bytes needed Can't query value for `Startup`, datasize=148, err=00000002 Deleted registry key 80000002:Software\Microsoft\Windows\CurrentVersion\Shell Checking known MyDoom filenames. Microsoft MyDoom removal tool stopped on Sun Dec 19 12:52:12 2004
wonder if i did something different.
i just repacked the doomcln.exe file with the makecab...
#13
Posted 19 December 2004 - 12:29 AM
i tried decompressing the blastcln.ex_ file i just integrated onto the source with the one i re-downloaded from the web... thinking there was just an integrity problem with the files that were burned... i found no differences using the FC /B command.
however, when i tried re-compressing the downloaded file to a cab via makecab and did a file comparison... i saw some differences... grrr... im confused now...
00000036: 02 93 00000038: 5C 2A 00000039: 73 61
#14
Posted 19 December 2004 - 12:59 AM
Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemovalTools] "MydoomTool"="OK"i wonder if this in combination of adding a dummy log file (%windir%\doomcln.log) on the debug folder is enough to trick WU into thinking the doomcln.exe has been executed.
sorry for the succeeding questions...
i just happened to look at the %windir%\setuperr.log file... and i saw these... (snippets only)
Error: Setup had problems registering the following OLE control DLL: C:\WINDOWS\system32\blastcln.exe Contact your system administrator, who may provide assistance in diagnosing this problem. *** Error: Setup detected that the system file named [c:\windows\system32\blastcln.exe] is not signed properly by Microsoft. This file could not be restored to the correct Microsoft version. Use the SFC utility to verify the integrity of the file. ***
#16
Posted 01 January 2005 - 08:13 PM
#17
Posted 01 January 2005 - 08:16 PM
*edited*
once again answering my own questions, and providing more theories, cmdlines.txt runs with 12min left, anyone remember when this error happens? and Ryan, you said you had this 100% working, what did you do exactly, can you give us all steps?
#18
Posted 01 January 2005 - 10:45 PM
I'm going to try and have it fixed for the next release.
In the mean time, you can trick WindowsUpdate by adding the "MydoomTool" entry and removing the Shell key as described here
#19
Posted 02 January 2005 - 12:51 AM
*edit*
just incase someone made the same mistake heres the file, i took it off a cd that had only sp2 integrated....
Attached File(s)
-
blastcln.ex_ (33.17K)
Number of downloads: 6
#20
Posted 02 January 2005 - 12:43 PM



Help


Back to top








