April 12, 2009
What is the same in SCCM 2007?
Some things have remained the same or have changed very little in ConfigMgr compared to SMS 2003:
Discovery, Inventory, Queries and Reporting.
Key terminology such as Sites, Primary Sites, Secondary Sites remains the same.
Services, file names, share names and ConfigMgr-related groups retain the SMS prefix.
Many Status Messages still mention SMS as these could potentially refer to a Child SMS SMS 2003 Site.
Some programmatic elements have not been renamed such as the SMS Provider to avoid potential backwards compatibility issues for those people using WMI scripting.
What is changed in SCCM 2007?
There have been several changes from SMS 2003 to ConfigMgr including:
Feature Packs that used to be separate add-ons in SMS 2003 are now incorporated into the core ConfigMgr product (for example the Administration Feature Pack, Device Management Feature Pack, Operating System Deployment Feature Pack Update).
Improvements/ enhancements to Feature Packs include:
Operating System Deployment (OSD) - Images created in Windows IMage (WIM) format can be deployed (including any required applications), using bootable media such as CD/ DVD. One or more tasks can be created and combined to create a Task Sequence to control and customise the deployment of the image and Software Distribution actions.
Mobile Device Management - The ability to manage Windows CE and Windows Mobile devices in the same way as regular ConfigMgr Clients (such as Hardware and Software Inventory, Software Distribution, Software Updates, and of course Windows Mobile settings).
Transfer Site Settings Wizard - Allows the settings from one ConfigMgr Site to be transferred to another to save the admin having to reconfigure the settings on every Site. Settings covered by the wizard include Client Agent configuration, Discovery Method configuration, Package and Collection properties amongst others.
Manage Site Accounts Tool (MSAC.exe) - A command line tool used to create, list, verify, update and delete user-defined accounts for use by ConfigMgr.
All Site Servers and Site Systems must be a member of an AD Domain.
Primary Sites only support Windows Authentication for the Site Database.
Asset Intelligence introduced as an optional component in SMS 2003 SP3 is now included in the core product.
NOTE: As a result of the above two changes the core product requires a greater amount of server resources.
Major changes to the way Backup and Recovery works - Volume Shadow Copy Service (VSS), available with XP, Windows 2003 and later OSs allowing a capture of a ConfigMgr Site to be made and stored on other media.
Improved Remote Tools integration with Remote Desktop and Assistance - RDP is now used to communicate with XP, Vista and Windows 2003 (or later) Clients (Windows 2000 machines use a modified version of the SMS 2003 Remote Tools Client Agent). Remote Reboot, Chat, File Transfer, Remote Execute, Ping and Windows 98 diags are no longer available in ConfigMgr.
Minor improvements to Collections, Software Distribution and Software Metering compared to SMS 2003.
Senders can only now be installed on Primary or Secondary Site Servers.
Only one Client type (basically the SMS 2003 Advanced Client so no Legacy Clients).
Only a single Security mode (similar to SMS 2003 Advanced Security mode).
The Site Server's local boundary is no longer automatically configured as a Site Boundary - you need to define this post installation.
Site Boundaries are no longer supported - only Roaming Boundaries are with a choice of "Slow or unreliable" or "Fast (LAN)".
Client Push uses the Site Code of the Primary rather than being set to "Auto" as in SMS 2003.
April 10, 2009
ConfigMgr/SMS Query and Report for Spyware
SELECT DISTINCT
RSYS.Name0 AS 'Computer',
RSYS.User_Name0 As 'Last User ID',
SF.FileName As 'File Name',
SF.FileDescription As 'File Description',
SF.FilePath As 'File Path',
SF.FileSize As 'File Size',
SF.FileVersion As 'File Version'
FROM
V_R_SYSTEM RSYS
INNER JOIN V_GS_SoftwareFile SF
ON RSYS.ResourceID = SF.ResourceID
AND ( SF.FileDescription like '%doom%' OR /* DOOM Game */
SF.FileDescription like '%GNUTE%' OR /* MP3 Resources */
SF.FileDescription like '%l0pht%'OR /* Password cracker */
SF.FileDescription like 'Lime%' OR /* Peer-to-Peer file sharing */
SF.FileDescription like '%nuke%' OR /* DOOM Game */
SF.FileDescription like '%orafice%' OR /* Keystroke mapper */
SF.FileDescription like '%sniff%' OR /* Network sniffer */
SF.FileDescription like '%unreal%' OR /* Games */
SF.FileName like '%as-101%' OR
SF.FileName like '%babylon%' OR
SF.FileName like '%bearshare%' OR
SF.FileName like '%bindery%' OR
/* SF.FileName like '%bindin%' OR */
SF.FileName like '%bo2k%' OR
SF.FileName like '%chknull%' OR
SF.FileName like '%Cracker%' OR /* Password cracker */
SF.FileName like '%Craserv%' OR
SF.FileName like '%doom%' OR /* DOOM game */
SF.FileName like '%EbatesMoeMoney%' OR /* Spyware */
SF.FileName like '%expolit%' OR
SF.FileName like 'gator%' OR /* Gator Spyware/Adware */
SF.FileName like '%getadmin%' OR
SF.FileName like '%gnucleus%' OR
SF.FileName like '%GNUTE%' OR /* MP3 Resources */
SF.FileName like '%GROK%' OR
SF.FileName like '%hack%' OR /* Password cracker */
SF.FileName like '%hotbar%' OR /* IE Toolbar - Spyware/Adware */
SF.FileName like '%kazaa%' OR /* Peer-to-Peer file sharing */
SF.FileName like 'keygen%'OR /* Password cracker */
SF.FileName like '%l0phtcrack%' OR /* Password cracker */
SF.FileName like '%lc252install%' OR /* Password cracker */
SF.FileName like '%LIME%' OR /* Peer-to-Peer file sharing */
SF.FileName like '%morpheus%' OR
SF.FileName like '%Napster%' OR /* Peer-to-Peer file sharing - MP3 Resources */
SF.FileName like '%nbsvr%' OR
SF.FileName like '%nbtscan%' OR
SF.FileName like '%ndssnoop%' OR
SF.FileName like '%netbusr%' OR
SF.FileName like '%nmapNT%' OR
SF.FileName like '%nuke%' OR /* DOOM Game */
SF.FileName like '%nwpcrack%' OR
SF.FileName like '%orafice%' OR /* Keaystroke mapper */
SF.FileName like '%otglove%' OR
SF.FileName like '%precisiontime%' OR
SF.FileName like '%pwdump%' OR /* Password cracker */
SF.FileName like '%quake%' OR /* DOOM game */
SF.FileName like '%Retina%' OR
SF.FileName like '%RFPoison%' OR
SF.FileName like '%smbdie%' OR
SF.FileName like '%smurf%' OR
SF.FileName like '%unreal%' OR
SF.FileName like '%XUPITER%' OR
SF.FileName like 'POPSRV%' OR
SF.FileName IN ('_DLL.exe', /* Troj_Bagle.AC Trojan */
'ARR.exe', /* Dial-up Hijacker - high cost toll number */
'asart.exe', /* ? */
'av.exe', /* W32.Alphx.Word.A Virus */
'BackWeb.exe', /* Spyware - BackWeb Technologies */
'Bargains.exe', /* BargainBuddy - Adware/Spyware */
'BELT.exe', /* Spyware - SearchV.com */
'Bling.exe', /* W32.SDBot-OH.Worm */
'BLSS.exe', /* Spyware - CBlaster Trojan */
'Bootconf.exe', /* Sypware - Homepage Hijacker */
'BonziBdy.exe', /* Spyware */
'botzor.exe', /* W32.ZOTOB.Worm */
'BPC.exe', /* Spyware - Grokster */
'Bundle.exe', /* Adware.SAHAgent */
'businessbg0002.exe', /* Spyware - ? */
'cmesys.exe', /* Adware.W32.Claria */
'crafty.exe', /* ? */
'CFD.exe', /* Spyware - Motive Cleint Foudation */
'csm.exe', /* W32.ZOTOB.B Worm */
'Datemanager.exe', /* Pop-Ups via Gator */
'DIVX.exe', /* MASTAK Virus or NALDEM Trojan */
'DPPS2.exe', /* Don't Panic! Pop-up blocker - Spyware */
'DSSagent.exe', /* Adware - Broderbund - Spyware? */
'eanthology.exe', /* eAcceleration Software Station - Spyware? */
'EditSRV.exe', /* Spyware - Email_Update.exe */
'email_Update.exe', /* StopSign Email Scanner - eAcceleration Software - Spyware? */
'EMSW.exe', /* Spyware - Alset Inc. */
'Gator.exe', /* Adware.W32.Claria */
'gmt.exe', /* Adware.W32.Claria */
'haha.exe', /* Myet Trojan */
'Hbinst.exe', /* Spyware - HotBar */
'HBSRV.exe', /* Spyware - HotBar */
'Hotbar.exe', /* Spyware - HotBar */
'HXDL.exe', /* HXDL Spyware - Gator */
'HXIUL.exe', /* Adware - HelpExpress - Alset Inc. */
'IDHost.exe', /* Topicks Spyware */
'IEDll.exe', /* Homepage Hijacker */
'IEDriver.exe', /* Peer-To-Peer File Sharing */
'INFUS.exe', /* Dial-up Hijacker - high cost toll number */
'InfWin.exe', /* MSView Parasite */
'INTDEL.exe', /* Adware - Pop-ups */
'ISTSVC.exe', /* Spyware - Integrated Search Technologies */
'KeenValue.exe', /* Spyware - Gator */
'loader.exe', /* Backdoor.Prorat Virus */
'lol.exe', /* W32.HLLW.Rackus Virus */
'Lspmonitor.exe', /* Spyware - StopSign */
'mapisvc32.exe', /* KX Virus */
'MD.exe', /* System MD Virus */
'MDie.exe', /* Backdoor.Win32.Rbot.Gen Virus */
'MemoryMeter.exe', /* Grokster Peer-To-Peer File Sharing Suite */
'MFIN32.exe', /* Adware - MyFreeInternet Update */
'MMod.exe', /* Adware.W32.EarnBundleWare */
'MOStat.exe', /* Spyware - Wurld Media */
'mousebm.exe', /* W32.ESBot Virus */
'mousemm.exe', /* W32.ESBot.A Virus */
'MSBB.exe', /* Adware.W32.BargainBuddy - 180Solutions */
'MSCache.exe', /* Spyware - Integrated Search Technologies */
'MSCMan.exe', /* Spyware - Odysseus Marketing */
'msdefr.exe', /* Spybot Worm */
'MSMACROPROTXZ.exe', /* Spybot Worm */
'MSMGT.exe', /* Spyware - Total Velocity */
'MSSVR.exe', /* Spyware - 2020DownLoader - 2020 Internet Search Toolbar */
'MSUpdater.exe', /* TrojanDownLoader.Win32.WinShow Trojan */
'MWSOEMON.exe', /* MyWebSearch Toolbar */
'mwsvm.exe', /* Adware - Adw.ScanPortAL.A */
'Nail.exe', /* Trojan.Win32.Stervis.B Trojan */
'nb32ext2.exe', /* MyDoom.BV worm */
'nbmanager.exe', /* Spyware - eAnthology */
'netbutler.exe', /* ? */
'onsrvr.exe', /* Spyware - OnWebMedia */
'PC32.exe', /* Mastak Virus */
'per.exe', /* Worm.ZOTOB.C Virus */
'PGMonitr.exe', /* Adware.W32.DelFin */
'PowerScan.exe', /* Adware.W32.PowerScan */
'PRMVR.exe', /* Spyware - Adtomi.com */
'pnpsrv.exe', /* W32.SDBOT.Worm Virus */
'Precisiontime.exe', /* Adware.W32.ClariaPrecision */
'PrizeSurfer.exe',/* Spyware - PrizeSurfer */
'Prmt.exe', /* Spyware - OpiStat */
'RAY.exe', /* Homepage Hijacker */
'RB32.exe', /* Adware.W32.RapicBlaster */
'RCSync.exe', /* Spyware - PrizeSurfer */
'Run32DLL.exe', /* Key Recorder - Screen Capture - PAL PC Spy */
'SAHAgent.exe', /* Adware.W32.CyDoor - CyDoor Desktop Media */
'savenow.exe', /* Coupons - WhenU.com */
'SBHC.exe', /* IE Plugin - GIGATech Software */
'ShowBehind.exe', /* Adware - MicroSmarts Enterprise */
'SLMSS.exe', /* Spyware - 2nd Thourgh by CPM Media */
'SRNG.exe', /* Spyware - Search Hijacker */
'STCLoader.exe', /* Spyware - 2nd Thourgh by CPM Media */
'SUSP.exe', /* Spyware - ABetterInternet */
'SVCINIT.exe', /* Backdoor.Sinit Trojan */
'svnlitup32.exe', /* Worm.RBOT.CBJ */
'syscpy.exe', /* Backdoor.Hogle Trojan */
'Systesm32.exe', /* Spyware - Bling.exe */
'thefourthcoming.exe', /* ? */
'Trickler.exe', /* Spyware - Gator GAIN (Gator Advertising and Info Network) */
'TSADBot.exe', /* Adware */
'TVMD.exe', /* Spyware */
'TVTMD.exe', /* Spyware */
'UCMWESKU.exe', /* ? */
'Updates32.exe', /* Spyware - Bling.exe */
'uptodate.exe', /* Adware - BrowserPal */
'veloz.exe', /* StopSign Email Scanner - eAcceleration Software */
'velozsys.exe', /* StopSign Email Scanner - eAcceleration Software */
'Weather.exe', /* Adware */
'webcel.exe', /* eAcceleration Software - Spyware - ? */
'WebDev.exe', /* ? */
'Win32US.exe', /* Dial-up Hijacker - high cost toll number */
'WinActive.exe', /* Homepage Hijacker */
'windrg32.exe', /* W32.ZOTOB.D Worm */
'WinMain.exe', /* Trojan.KonDeli */
'WinNet.exe', /* Adware/Spyware - CommonName I.E. Search */
'winpnp.exe', /* W32.SDBOT.Worm */
'WinServN.exe', /* Adware.W32.PurityScan - ClickSpring LLC */
'WinStart.exe', /* Homepage Hijacker - iGetNet */
'WinStart001.exe', /* Adware */
'wintbp.exe', /* W32.ZOTOB.E Worm */
'wintbpx.exe', /* W32.BOZORI.Worm.B */
'WNAD.exe', /* Spyware - TwistedHumor.com */
'wpa.exe', /* ESBOT Worm */
'ygpmrgsb.exe', /* ? */
'zeus.exe', /* Zeus:Master of Olympus game */
'zmanager.exe' /* Spyware - eAcceleration */
)
)
ORDER BY
RSYS.Name0
RSYS.Name0 AS 'Computer',
RSYS.User_Name0 As 'Last User ID',
SF.FileName As 'File Name',
SF.FileDescription As 'File Description',
SF.FilePath As 'File Path',
SF.FileSize As 'File Size',
SF.FileVersion As 'File Version'
FROM
V_R_SYSTEM RSYS
INNER JOIN V_GS_SoftwareFile SF
ON RSYS.ResourceID = SF.ResourceID
AND ( SF.FileDescription like '%doom%' OR /* DOOM Game */
SF.FileDescription like '%GNUTE%' OR /* MP3 Resources */
SF.FileDescription like '%l0pht%'OR /* Password cracker */
SF.FileDescription like 'Lime%' OR /* Peer-to-Peer file sharing */
SF.FileDescription like '%nuke%' OR /* DOOM Game */
SF.FileDescription like '%orafice%' OR /* Keystroke mapper */
SF.FileDescription like '%sniff%' OR /* Network sniffer */
SF.FileDescription like '%unreal%' OR /* Games */
SF.FileName like '%as-101%' OR
SF.FileName like '%babylon%' OR
SF.FileName like '%bearshare%' OR
SF.FileName like '%bindery%' OR
/* SF.FileName like '%bindin%' OR */
SF.FileName like '%bo2k%' OR
SF.FileName like '%chknull%' OR
SF.FileName like '%Cracker%' OR /* Password cracker */
SF.FileName like '%Craserv%' OR
SF.FileName like '%doom%' OR /* DOOM game */
SF.FileName like '%EbatesMoeMoney%' OR /* Spyware */
SF.FileName like '%expolit%' OR
SF.FileName like 'gator%' OR /* Gator Spyware/Adware */
SF.FileName like '%getadmin%' OR
SF.FileName like '%gnucleus%' OR
SF.FileName like '%GNUTE%' OR /* MP3 Resources */
SF.FileName like '%GROK%' OR
SF.FileName like '%hack%' OR /* Password cracker */
SF.FileName like '%hotbar%' OR /* IE Toolbar - Spyware/Adware */
SF.FileName like '%kazaa%' OR /* Peer-to-Peer file sharing */
SF.FileName like 'keygen%'OR /* Password cracker */
SF.FileName like '%l0phtcrack%' OR /* Password cracker */
SF.FileName like '%lc252install%' OR /* Password cracker */
SF.FileName like '%LIME%' OR /* Peer-to-Peer file sharing */
SF.FileName like '%morpheus%' OR
SF.FileName like '%Napster%' OR /* Peer-to-Peer file sharing - MP3 Resources */
SF.FileName like '%nbsvr%' OR
SF.FileName like '%nbtscan%' OR
SF.FileName like '%ndssnoop%' OR
SF.FileName like '%netbusr%' OR
SF.FileName like '%nmapNT%' OR
SF.FileName like '%nuke%' OR /* DOOM Game */
SF.FileName like '%nwpcrack%' OR
SF.FileName like '%orafice%' OR /* Keaystroke mapper */
SF.FileName like '%otglove%' OR
SF.FileName like '%precisiontime%' OR
SF.FileName like '%pwdump%' OR /* Password cracker */
SF.FileName like '%quake%' OR /* DOOM game */
SF.FileName like '%Retina%' OR
SF.FileName like '%RFPoison%' OR
SF.FileName like '%smbdie%' OR
SF.FileName like '%smurf%' OR
SF.FileName like '%unreal%' OR
SF.FileName like '%XUPITER%' OR
SF.FileName like 'POPSRV%' OR
SF.FileName IN ('_DLL.exe', /* Troj_Bagle.AC Trojan */
'ARR.exe', /* Dial-up Hijacker - high cost toll number */
'asart.exe', /* ? */
'av.exe', /* W32.Alphx.Word.A Virus */
'BackWeb.exe', /* Spyware - BackWeb Technologies */
'Bargains.exe', /* BargainBuddy - Adware/Spyware */
'BELT.exe', /* Spyware - SearchV.com */
'Bling.exe', /* W32.SDBot-OH.Worm */
'BLSS.exe', /* Spyware - CBlaster Trojan */
'Bootconf.exe', /* Sypware - Homepage Hijacker */
'BonziBdy.exe', /* Spyware */
'botzor.exe', /* W32.ZOTOB.Worm */
'BPC.exe', /* Spyware - Grokster */
'Bundle.exe', /* Adware.SAHAgent */
'businessbg0002.exe', /* Spyware - ? */
'cmesys.exe', /* Adware.W32.Claria */
'crafty.exe', /* ? */
'CFD.exe', /* Spyware - Motive Cleint Foudation */
'csm.exe', /* W32.ZOTOB.B Worm */
'Datemanager.exe', /* Pop-Ups via Gator */
'DIVX.exe', /* MASTAK Virus or NALDEM Trojan */
'DPPS2.exe', /* Don't Panic! Pop-up blocker - Spyware */
'DSSagent.exe', /* Adware - Broderbund - Spyware? */
'eanthology.exe', /* eAcceleration Software Station - Spyware? */
'EditSRV.exe', /* Spyware - Email_Update.exe */
'email_Update.exe', /* StopSign Email Scanner - eAcceleration Software - Spyware? */
'EMSW.exe', /* Spyware - Alset Inc. */
'Gator.exe', /* Adware.W32.Claria */
'gmt.exe', /* Adware.W32.Claria */
'haha.exe', /* Myet Trojan */
'Hbinst.exe', /* Spyware - HotBar */
'HBSRV.exe', /* Spyware - HotBar */
'Hotbar.exe', /* Spyware - HotBar */
'HXDL.exe', /* HXDL Spyware - Gator */
'HXIUL.exe', /* Adware - HelpExpress - Alset Inc. */
'IDHost.exe', /* Topicks Spyware */
'IEDll.exe', /* Homepage Hijacker */
'IEDriver.exe', /* Peer-To-Peer File Sharing */
'INFUS.exe', /* Dial-up Hijacker - high cost toll number */
'InfWin.exe', /* MSView Parasite */
'INTDEL.exe', /* Adware - Pop-ups */
'ISTSVC.exe', /* Spyware - Integrated Search Technologies */
'KeenValue.exe', /* Spyware - Gator */
'loader.exe', /* Backdoor.Prorat Virus */
'lol.exe', /* W32.HLLW.Rackus Virus */
'Lspmonitor.exe', /* Spyware - StopSign */
'mapisvc32.exe', /* KX Virus */
'MD.exe', /* System MD Virus */
'MDie.exe', /* Backdoor.Win32.Rbot.Gen Virus */
'MemoryMeter.exe', /* Grokster Peer-To-Peer File Sharing Suite */
'MFIN32.exe', /* Adware - MyFreeInternet Update */
'MMod.exe', /* Adware.W32.EarnBundleWare */
'MOStat.exe', /* Spyware - Wurld Media */
'mousebm.exe', /* W32.ESBot Virus */
'mousemm.exe', /* W32.ESBot.A Virus */
'MSBB.exe', /* Adware.W32.BargainBuddy - 180Solutions */
'MSCache.exe', /* Spyware - Integrated Search Technologies */
'MSCMan.exe', /* Spyware - Odysseus Marketing */
'msdefr.exe', /* Spybot Worm */
'MSMACROPROTXZ.exe', /* Spybot Worm */
'MSMGT.exe', /* Spyware - Total Velocity */
'MSSVR.exe', /* Spyware - 2020DownLoader - 2020 Internet Search Toolbar */
'MSUpdater.exe', /* TrojanDownLoader.Win32.WinShow Trojan */
'MWSOEMON.exe', /* MyWebSearch Toolbar */
'mwsvm.exe', /* Adware - Adw.ScanPortAL.A */
'Nail.exe', /* Trojan.Win32.Stervis.B Trojan */
'nb32ext2.exe', /* MyDoom.BV worm */
'nbmanager.exe', /* Spyware - eAnthology */
'netbutler.exe', /* ? */
'onsrvr.exe', /* Spyware - OnWebMedia */
'PC32.exe', /* Mastak Virus */
'per.exe', /* Worm.ZOTOB.C Virus */
'PGMonitr.exe', /* Adware.W32.DelFin */
'PowerScan.exe', /* Adware.W32.PowerScan */
'PRMVR.exe', /* Spyware - Adtomi.com */
'pnpsrv.exe', /* W32.SDBOT.Worm Virus */
'Precisiontime.exe', /* Adware.W32.ClariaPrecision */
'PrizeSurfer.exe',/* Spyware - PrizeSurfer */
'Prmt.exe', /* Spyware - OpiStat */
'RAY.exe', /* Homepage Hijacker */
'RB32.exe', /* Adware.W32.RapicBlaster */
'RCSync.exe', /* Spyware - PrizeSurfer */
'Run32DLL.exe', /* Key Recorder - Screen Capture - PAL PC Spy */
'SAHAgent.exe', /* Adware.W32.CyDoor - CyDoor Desktop Media */
'savenow.exe', /* Coupons - WhenU.com */
'SBHC.exe', /* IE Plugin - GIGATech Software */
'ShowBehind.exe', /* Adware - MicroSmarts Enterprise */
'SLMSS.exe', /* Spyware - 2nd Thourgh by CPM Media */
'SRNG.exe', /* Spyware - Search Hijacker */
'STCLoader.exe', /* Spyware - 2nd Thourgh by CPM Media */
'SUSP.exe', /* Spyware - ABetterInternet */
'SVCINIT.exe', /* Backdoor.Sinit Trojan */
'svnlitup32.exe', /* Worm.RBOT.CBJ */
'syscpy.exe', /* Backdoor.Hogle Trojan */
'Systesm32.exe', /* Spyware - Bling.exe */
'thefourthcoming.exe', /* ? */
'Trickler.exe', /* Spyware - Gator GAIN (Gator Advertising and Info Network) */
'TSADBot.exe', /* Adware */
'TVMD.exe', /* Spyware */
'TVTMD.exe', /* Spyware */
'UCMWESKU.exe', /* ? */
'Updates32.exe', /* Spyware - Bling.exe */
'uptodate.exe', /* Adware - BrowserPal */
'veloz.exe', /* StopSign Email Scanner - eAcceleration Software */
'velozsys.exe', /* StopSign Email Scanner - eAcceleration Software */
'Weather.exe', /* Adware */
'webcel.exe', /* eAcceleration Software - Spyware - ? */
'WebDev.exe', /* ? */
'Win32US.exe', /* Dial-up Hijacker - high cost toll number */
'WinActive.exe', /* Homepage Hijacker */
'windrg32.exe', /* W32.ZOTOB.D Worm */
'WinMain.exe', /* Trojan.KonDeli */
'WinNet.exe', /* Adware/Spyware - CommonName I.E. Search */
'winpnp.exe', /* W32.SDBOT.Worm */
'WinServN.exe', /* Adware.W32.PurityScan - ClickSpring LLC */
'WinStart.exe', /* Homepage Hijacker - iGetNet */
'WinStart001.exe', /* Adware */
'wintbp.exe', /* W32.ZOTOB.E Worm */
'wintbpx.exe', /* W32.BOZORI.Worm.B */
'WNAD.exe', /* Spyware - TwistedHumor.com */
'wpa.exe', /* ESBOT Worm */
'ygpmrgsb.exe', /* ? */
'zeus.exe', /* Zeus:Master of Olympus game */
'zmanager.exe' /* Spyware - eAcceleration */
)
)
ORDER BY
RSYS.Name0
April 9, 2009
Understanding Software Updates in SCCM 2007
Configmgr 2007 comes with a totally new way of deploying software updates. The new method offers some great advantages over the old one(s) available in Sms 2003. It didn't take me too long to see the benefits the new architecture brings, but it did take me quite some effort in understanding how I could create a working operational process to maximize these benefits, it actually took a fellow mvp (Thanks Pannu) and Wally to set things straight in my head (Thanks Wally). This 2 -series post will try to give you some insight in how the Configmgr 2007 solution stacks up with the sms 2003 implementation. The second portion will explain the objects involved and will guide you through a potential implementation of Software updates in Sccm 2007.
Let's start by briefly explaining how the sms 2003 infrastructure operates, followed by the currently known issues. Later in this post we'll review what the Sccm 2007 architecture looks like, and how this new architecture deals with the known issues of the past.
In sms 2003 the backend infrastructure relied on software distribution packages and advertisements to initiate the sofware catalog download, the software update scan and patch installation processes. The scan process itself, using the final scan engine itmu, was based on the Windows automatic update agent. The scan engines prior to that were sms specific engines like the software update inventory scan tool, the office update inventory scan tool or the extended software update inventory tool. Clients have always reported their software update compliance state based on hardware inventory regardless of the scan engine used.
One of the downsides of the sms 2003 infrastructure was the fact that multiple scan engines were necessary, which complicated the software update management quite a bit. And no matter what engine you used, all engines first downloaded the catalog locally and cached it in a specific folder prior to starting the scan. This caching of the catalog files didn't always work flawlessly resulting in clients scanning with an old catalog which obviously didn't report the expected information. Another issue was the fact that the reporting process relied on hardware inventory to do its reporting, this resulted in a slower and not very flexible reporting process.
Now let's look at how this all works in sccm 2007. Sofware updates now integrates/relies on a Wsus 3.0 server. The Wsus server is used to download the catalog and to serve as the "scan point" for the Configmgr2007 clients. This eliminates the problem that the sms 2003 engines had with caching the catalog, because the clients now scan directly from a wsus server. Another benefit of this integration is the increased content that can be deployed. The sms 2003 engines only supported security updates whereas wsus 3.0 supports a wide variety of updates ranging from security updates over critical updates, feature pack, service packs, drivers and more. All these benefits come at a fairly low cost, yes you now need to install a wsus server but all management of this wsus server is done from the Sccm 2007 admin console. (This is why you need to install the wsus admin console on the site server if you want to use a remote wsus server).
Another major change afaic is that clients now report their software update compliance state based on state messages. This allows for faster more flexible and more detailed status reporting from the clients to flow up to the server.
The above view is presented by Kim oppalfenss (My one of the favourite SMS Expert).
Let's start by briefly explaining how the sms 2003 infrastructure operates, followed by the currently known issues. Later in this post we'll review what the Sccm 2007 architecture looks like, and how this new architecture deals with the known issues of the past.
In sms 2003 the backend infrastructure relied on software distribution packages and advertisements to initiate the sofware catalog download, the software update scan and patch installation processes. The scan process itself, using the final scan engine itmu, was based on the Windows automatic update agent. The scan engines prior to that were sms specific engines like the software update inventory scan tool, the office update inventory scan tool or the extended software update inventory tool. Clients have always reported their software update compliance state based on hardware inventory regardless of the scan engine used.
One of the downsides of the sms 2003 infrastructure was the fact that multiple scan engines were necessary, which complicated the software update management quite a bit. And no matter what engine you used, all engines first downloaded the catalog locally and cached it in a specific folder prior to starting the scan. This caching of the catalog files didn't always work flawlessly resulting in clients scanning with an old catalog which obviously didn't report the expected information. Another issue was the fact that the reporting process relied on hardware inventory to do its reporting, this resulted in a slower and not very flexible reporting process.
Now let's look at how this all works in sccm 2007. Sofware updates now integrates/relies on a Wsus 3.0 server. The Wsus server is used to download the catalog and to serve as the "scan point" for the Configmgr2007 clients. This eliminates the problem that the sms 2003 engines had with caching the catalog, because the clients now scan directly from a wsus server. Another benefit of this integration is the increased content that can be deployed. The sms 2003 engines only supported security updates whereas wsus 3.0 supports a wide variety of updates ranging from security updates over critical updates, feature pack, service packs, drivers and more. All these benefits come at a fairly low cost, yes you now need to install a wsus server but all management of this wsus server is done from the Sccm 2007 admin console. (This is why you need to install the wsus admin console on the site server if you want to use a remote wsus server).
Another major change afaic is that clients now report their software update compliance state based on state messages. This allows for faster more flexible and more detailed status reporting from the clients to flow up to the server.
The above view is presented by Kim oppalfenss (My one of the favourite SMS Expert).
Sccm 2007 client agent deployment using Software updates
Sccm 2007 has a new client deployment method called Software update point based client installation. The idea behind Software update point based client installation is to publish the Sccm 2007 client as a critical update, and hence its name is installed from the Software update point. Most of you will probably now that Software Update management in Sccm 2007 integrates with Wsus 3.0 Sccm 2007 relies on Wsus to synchronize the catalog and to scan clients, but that's food for another post.
Why?
Why does sccm 2007 require a new installation method? What was wrong with the previous installation methods we had in sms 2003? To be honest, not much, but they all had their drawbacks. Let's just have a look at each of the installation methods and their drawbacks before we continue and see what Software update point based installation has in store for us.
Manual installation: This installation method lacks automation and requires the end-user to be a local administrator on the machine which is obviously a big NONO security wise.
Login script installation: Lacks from the same security issue as manual installation and is by consequence a NOGO.
Software Distribution based installation: Good installation method but this is often a chicken or egg kinda problem, you already need to have a software distribution mechanism out there for this to work.
Client Push Installation (Wizard): Great installation method but it has some requirements that could prove to be problematic in a real secure environment. It requires remote local admin privileges which is usually fine. But it also requires remote registry and access to the admin$ share. A secure environment should have file and print sharing disabled on desktops or laptops, or at the very least have them blocked by a personal firewall.
GPO based installation: Nice installation method with very modest requirements on the machine to be installed, but it suffers from its own drawbacks. The main problem with GPO based installation is that it is end-user driven. GPO's software installation only happens at logon or after a restart. Both events normally only happen after the end-user gave their user name and password or powered on the machine. If you have pesky users that just close their laptop lid in the evening and open it back up the next morning then your out of luck with gpo's. With todays more stable os's like Windows XP and Windows Vista It could take a pretty long time before the machine actually needs to be rebooted on the lan.
Software update based client installation: Superb installation method that mixes the benefits of GPO based installation with those of software distribution based installation. In other words it has pretty low requirements on the target machine, even lower as software distribution based installation as it does not require a software distribution solution in place and doesn't require the target machine to be in active directory. (You'll need a different way than adm templates to set the registry keys though). On top of that it offers a Schedule based installation which eliminates the end-user initiated drawback of gpo's. By the way if you install a newer version of the SCCM 2007 beta or install a Service pack after RTM you will be able to update your publication so that you can use this method to easily upgrade your existed install base to the new version.
How?
How do you get this to work? Remarkably easy actually.
STEP 1 Configure the Windows Update agent GPO:
Open a GPO
Go to Computer configuration\Windows Components\Windows Update
Configure the Configure automatic updates option, Set it to auto download and shedule the install
Choose your own schedule
Configure the Specify intranet microsoft update service location
Configure both options with the value http://Wsusserver
STEP 2 Import the SCCM-2007 adm template:
Download the adm template to configure SCCM 2007 client installation command line parameters http://www.blogcastrepository.com/files/folders/documents/entry15469.aspx
Open a GPO
In Computer Configuration Right-click on Administrative templates
Browse to the SCCM-2007 and add the template.
Go to Computer configuration\Windows Components\SCCM 2007\Software Update point client installation
Configure the command line with the parameters you want.
STEP 3 Publish the SCCM 2007 client (As documented in the SCCM 2007 help file)
To publish the Configuration Manager 2007 client to the WSUS server:
In the Configuration Manager console, navigate to System Center Configuration Manager / Site Database / Site Management / – / Site Settings / Client Installation Methods.
Right-click Software Update Point Client Installation, and click Properties.
To enable client installation, select the Enable Software Update Point Client Installation check box.
If the client software on the Configuration Manager 2007 site server is newer than that stored on the software update point, the Upgrade Client Package Version dialog box will open. You should click Yes in this dialog box to publish the most recent version of the client software to he software update point.
To finish configuring the software update point client installation, click OK.
Why?
Why does sccm 2007 require a new installation method? What was wrong with the previous installation methods we had in sms 2003? To be honest, not much, but they all had their drawbacks. Let's just have a look at each of the installation methods and their drawbacks before we continue and see what Software update point based installation has in store for us.
Manual installation: This installation method lacks automation and requires the end-user to be a local administrator on the machine which is obviously a big NONO security wise.
Login script installation: Lacks from the same security issue as manual installation and is by consequence a NOGO.
Software Distribution based installation: Good installation method but this is often a chicken or egg kinda problem, you already need to have a software distribution mechanism out there for this to work.
Client Push Installation (Wizard): Great installation method but it has some requirements that could prove to be problematic in a real secure environment. It requires remote local admin privileges which is usually fine. But it also requires remote registry and access to the admin$ share. A secure environment should have file and print sharing disabled on desktops or laptops, or at the very least have them blocked by a personal firewall.
GPO based installation: Nice installation method with very modest requirements on the machine to be installed, but it suffers from its own drawbacks. The main problem with GPO based installation is that it is end-user driven. GPO's software installation only happens at logon or after a restart. Both events normally only happen after the end-user gave their user name and password or powered on the machine. If you have pesky users that just close their laptop lid in the evening and open it back up the next morning then your out of luck with gpo's. With todays more stable os's like Windows XP and Windows Vista It could take a pretty long time before the machine actually needs to be rebooted on the lan.
Software update based client installation: Superb installation method that mixes the benefits of GPO based installation with those of software distribution based installation. In other words it has pretty low requirements on the target machine, even lower as software distribution based installation as it does not require a software distribution solution in place and doesn't require the target machine to be in active directory. (You'll need a different way than adm templates to set the registry keys though). On top of that it offers a Schedule based installation which eliminates the end-user initiated drawback of gpo's. By the way if you install a newer version of the SCCM 2007 beta or install a Service pack after RTM you will be able to update your publication so that you can use this method to easily upgrade your existed install base to the new version.
How?
How do you get this to work? Remarkably easy actually.
STEP 1 Configure the Windows Update agent GPO:
Open a GPO
Go to Computer configuration\Windows Components\Windows Update
Configure the Configure automatic updates option, Set it to auto download and shedule the install
Choose your own schedule
Configure the Specify intranet microsoft update service location
Configure both options with the value http://Wsusserver
STEP 2 Import the SCCM-2007 adm template:
Download the adm template to configure SCCM 2007 client installation command line parameters http://www.blogcastrepository.com/files/folders/documents/entry15469.aspx
Open a GPO
In Computer Configuration Right-click on Administrative templates
Browse to the SCCM-2007 and add the template.
Go to Computer configuration\Windows Components\SCCM 2007\Software Update point client installation
Configure the command line with the parameters you want.
STEP 3 Publish the SCCM 2007 client (As documented in the SCCM 2007 help file)
To publish the Configuration Manager 2007 client to the WSUS server:
In the Configuration Manager console, navigate to System Center Configuration Manager / Site Database / Site Management /
Right-click Software Update Point Client Installation, and click Properties.
To enable client installation, select the Enable Software Update Point Client Installation check box.
If the client software on the Configuration Manager 2007 site server is newer than that stored on the software update point, the Upgrade Client Package Version dialog box will open. You should click Yes in this dialog box to publish the most recent version of the client software to he software update point.
To finish configuring the software update point client installation, click OK.
http verification .sms_aut () failed with status code 503, service unavailable
If MPControl.log file throwing error “http verification .sms_aut () failed with status code 503, service unavailable” then check for your IIS application pool. SMS management point pool and CCM server framework pool might have stopped.
For resolution please check site server’s for Netlogon service is stopped or not.
Starting of Netlogon service solved our problem.
For resolution please check site server’s for Netlogon service is stopped or not.
Starting of Netlogon service solved our problem.
Subscribe to:
Posts (Atom)