Google Answers Logo
View Question
 
Q: Win 2000 HotFix #811493 Is Updating Every Day ( Answered 5 out of 5 stars,   2 Comments )
Question  
Subject: Win 2000 HotFix #811493 Is Updating Every Day
Category: Computers > Operating Systems
Asked by: janaugcpa-ga
List Price: $10.00
Posted: 24 Feb 2004 20:37 PST
Expires: 25 Mar 2004 20:37 PST
Question ID: 310529
Windows Update is telling me to download and install Security Update
811493 every day.  So far I have done so.  When I go online with Win
Update my history shows many successful installations of 811493. 
Add/Remove Programs lists it once and calls it Windows 2000 Hotfix
(SP4)Q811493.  I am running Win 2000 Pro 5.0.2195 SP 3.

Here's the question: Can I solve this by installing SP4? and should I
uninstall Hotfix Q811493 first or leave it?  I am a tax accountant and
absolutely can not afford to screw up my computer at this time.  Am I
safer doing nothing until April 16 and if so, do I continue updating
811493 or ignore it for two months?

Other info: I have a 2-year old Athlon XP system.  I'm on a shared DSL
network which is behind a hardware router but the network is otherwise
invisible both ways so my computer operates as  standalone unit.  I
have Norton AV 2002 and update automatically (which is every day,
lately).

Thanks for any advice.
Answer  
Subject: Re: Win 2000 HotFix #811493 Is Updating Every Day
Answered By: denco-ga on 25 Feb 2004 11:25 PST
Rated:5 out of 5 stars
 
Howdy janaugcpa-ga,

Having been plagued with the same problem, I feel the following
will help you quite a bit.

First, as this is a critical time for you, do nothing.  As the
Microsoft web page that goes into detail on the 811493 update
points out, there are only very specific conditions where this
vulnerability can be exploited.
http://support.microsoft.com/default.aspx?scid=kb;EN-US;811493

"For an attack to be successful, an attacker would have to be able
to log on interactively to the system, either at the console or
through a terminal session. Also, a successful attack would require
the introduction of code to exploit this vulnerability.
...
- A successful attack requires the ability to log on interactively to
the target computer, either directly at the console or through a
terminal session.
- Properly secured servers are at little risk from this vulnerability.
Standard best practices resources recommend that you only allow
trusted administrators to log on to these kinds of systems
interactively. Without these privileges, an attacker could not
exploit the vulnerability."

To translate the above into English, someone would have to be in
front of the computer and using it, and then run a specific program
that would use the exploit.  They also could be running a terminal
session on your machine to do the above, but it doesn't sound like
you have your computer set up so someone could log on to your
computer from a remote (outside your office) location.  You should
be more afraid of a person breaking in and stealing your computer
than someone using this exploit.

So, you have now gone until May or June, not having done anything
about this (that means not doing the 811493 "update" on a daily
basis as well) and are ready to try to fix it.

First, remove the original patch.  This Microsoft web page shows
how to do it for Windows XP, but it is same process for you.
http://support.microsoft.com/default.aspx?scid=kb;en-us;819634

"To remove the original 811493 security update:
In Control Panel, double-click Add or Remove Programs.
Click Change or Remove Programs.
Click Windows [2000 Hotfix (SP4)] Q811493 ... and then click Remove.
Click Next, and then click Finish to restart your computer."

Next, you will want to install the Windows 2000 Service Pack 4 (SP4).
which also contains the 811493 fix.  The Microsoft page on "How to
Obtain the Latest Windows 2000 Service Pack" details this.
http://support.microsoft.com/default.aspx?scid=kb;EN-US;260910

"Windows 2000 fixes are distributed in service packs. Service packs
keep the product current. Service packs include updates, system
administration tools, drivers, and additional components."

On that page, there is a link to the "List of Bugs That Are Fixed
in Windows 2000 Service Pack 4" which includes the Q811493 hotfix.
http://support.microsoft.com/default.aspx?scid=kb;EN-US;327194

"811493 MS03-013: Buffer Overrun in Windows Kernel Message Handling"

You can download SP4 at no cost through the Microsoft "Windows 2000
Service Pack 4" web page.
http://www.microsoft.com/windows2000/downloads/servicepacks/sp4/default.asp

"Windows 2000 Service Pack 4 (SP4) provides the latest updates to
the Windows 2000 operating systems. These updates are a collection
of fixes in the following areas: security, application compatibility,
operating system reliability, and setup."

Hopefully, after that, you will not be notified that you should install
the 811493 fix.  On my XP system, doing a "Cumulative Patch" (which is
sort of the same thing you will be doing by applying SP4) did the trick.

If you need clarification, feel free to ask.


Search Strategy:  Personal experience of 6 months of being notified that
I should install Q811493.  Also went to the Microsoft web site and did
various queries on the 811493 hotfix.
http://www.microsoft.com

Looking Forward, denco-ga - Google Answers Researcher
janaugcpa-ga rated this answer:5 out of 5 stars and gave an additional tip of: $10.00
Perfect answer - each component of my question was answered thoroughly
and understandably, with technical backup and useful links, my
concerns were addressed, and I have a clear plan of action.

Comments  
Subject: Re: Win 2000 HotFix #811493 Is Updating Every Day
From: hummer-ga on 25 Feb 2004 05:24 PST
 
Hi janaugcpa,

You aren't alone, but theirs seems to have been solved by running Win Update:

811493: Security Update (Windows 2000) installs over & over again:
http://www.derkeiler.com/Newsgroups/microsoft.public.win2000.security/2003-06/0980.html

hummer
Subject: Re: Win 2000 HotFix #811493 Is Updating Every Day
From: denco-ga on 25 Feb 2004 13:40 PST
 
Howdy janaugcpa-ga,

Much thanks for the 5 star rating, kind comments and a most generous tip!

My pleasure, denco-ga - Google Answers Researcher

Important Disclaimer: Answers and comments provided on Google Answers are general information, and are not intended to substitute for informed professional medical, psychiatric, psychological, tax, legal, investment, accounting, or other professional advice. Google does not endorse, and expressly disclaims liability for any product, manufacturer, distributor, service or service provider mentioned or any opinion expressed in answers or comments. Please read carefully the Google Answers Terms of Service.

If you feel that you have found inappropriate content, please let us know by emailing us at answers-support@google.com with the question ID listed above. Thank you.
Search Google Answers for
Google Answers  


Google Home - Answers FAQ - Terms of Service - Privacy Policy