Sign in
Stuff n Things
Content from a CSS Security Engineer usually covering FCS and Incident Response
Translate This Page
Translate this page
Powered by
Microsoft® Translator
Options
Email Blog Author
RSS for posts
Atom
RSS for comments
OK
Search Blogs
Tags
FCS
FCS ADM
FCS Client
FCS Database
FCS Definitions
FCS Policy
Forefront Client Security
Incident Response
SCE
Scheduled Scans
System Center Essentials
WSUS
Archive
Archives
April 2010
(1)
March 2010
(1)
January 2010
(1)
December 2009
(2)
October 2009
(1)
July 2009
(1)
May 2009
(2)
April 2009
(1)
March 2009
(2)
February 2009
(2)
January 2009
(4)
November 2008
(2)
October 2008
(3)
September 2008
(1)
August 2008
(2)
TechNet Blogs
>
Stuff n Things
Posts
Subscribe via RSS
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
Stuff n Things
Another WSUS Cleanup Script
Posted
over 3 years ago
by
Kurt Falde
0
Comments
Just noticed this as I was looking for a solution for a different WSUS problem and thought I would share this here as well. http://gallery.technet.microsoft.com/ScriptCenter/en-us/90ca6976-d441-4a10-89b0-30a7103d55db Apparently a “Thomas Schlacter...
Stuff n Things
Some thoughts on Adobe Reader and malware
Posted
over 3 years ago
by
Kurt Falde
0
Comments
Not sure if anyone saw this bit of news recently where a report put out by ScanSafe indicates that PDF’s accounted for 80% of exploits in the 4th quarter of 2009 . I support both FCS our antivirus product and I also do Incident Response work. ...
Stuff n Things
Some more logparser & eventcomb stuff for IR work
Posted
over 3 years ago
by
Kurt Falde
0
Comments
Counting and sorting by unique text in the strings section: As a follow on to a previous article http://blogs.technet.com/kfalde/archive/2009/01/28/using-logparser-eventcomb-to-find-malware.aspx I found some other useful queries that I figured I would...
Stuff n Things
Determining the cause of FCS client performance issues
Posted
over 4 years ago
by
Kurt Falde
2
Comments
Realistically this process should work for other AV clients as well but I’m doing it in the context of the one I support. Although it isn’t extremely common we do run into scenarios where customer has issues with the FCS client taking up large amounts...
Stuff n Things
Logparsing FCS to find files that were infected
Posted
over 4 years ago
by
Kurt Falde
0
Comments
Working an interesting case at the moment where we have multiple files across servers that were infected and we are needing to generate a list of all the files that were infected on each server. So the first thing to realize is that the 1006 and 3004...
Stuff n Things
Rare off-topic post :)
Posted
over 4 years ago
by
Kurt Falde
0
Comments
It is currently MS’s giving campaign where we promote philanthropicness :). A coworker sent this out to our internal blogger alias along with some others from this site that various MS MVP’s and internal employees worth with asking if we could post...
Stuff n Things
Dealing with malware that creates .exe’s on file shares
Posted
over 4 years ago
by
Kurt Falde
5
Comments
So lately we keep seeing variants of malware that modifies content on file servers in an environment in hopes of spreading to other users. My guess is that it is just using mapped drive letters thinking they are USB keys but the effects is the same...
Stuff n Things
How to go green with FCS
Posted
over 4 years ago
by
Kurt Falde
0
Comments
I’m not a treehugger but I can definitely see the $$ with power savings. Having said that I had a customer recently that wanted his computers to wake up from sleep in order to do their scheduled scans for FCS. At first I was like nope not possible we...
Stuff n Things
Some Interesting FCS SQL Queries
Posted
over 4 years ago
by
Kurt Falde
4
Comments
With a recent case I have an issue where the client count of managed computers in MOM admin console was quite different then that in the FCS console so I was trying to find out exactly which computers were not in FCS so I could troubleshoot some of those...
Stuff n Things
Update Views for FCS in WSUS
Posted
over 4 years ago
by
Kurt Falde
0
Comments
Nothing profound with this post just detailing out a step I typically recommend to most of our new customers with regards to making life easier when viewing updates in WSUS. In order to make your life easier viewing FCS inside of WSUS I typically...
Stuff n Things
Cheap real time monitoring for Conficker clients
Posted
over 4 years ago
by
Kurt Falde
0
Comments
I already did one post about using eventcomb/logparser to look for clients but found a better way to do it on a case last night which I wanted to share. The first thing you need is to enable netlogon debug logging on all of your DC’s save the following...
Stuff n Things
WSUS FCS Definitions
Posted
over 4 years ago
by
Kurt Falde
4
Comments
This is a follow up post to my previous FCS definitions post. The first one focused on the mpam-fe files and what is contained that you can find on the security portal at www.microsoft.com/security/portal . This one instead focuses on what...
Stuff n Things
Blocking and finding Conficker and Downadup systems
Posted
over 4 years ago
by
Kurt Falde
0
Comments
EDIT 4/27/09: THIS NO LONGER WORKS WITH NEW VARIANTS OF CONFICKER HOWEVER THE CONCEPT IS STILL SOUND IF YOU ARE LOOKING FOR SYSTEMS THAT ARE QUERYING FOR SPECIFIC DNS NAMES. I’ve already created one post on finding malware systems using eventcomb...
Stuff n Things
Understanding FCS Definitions
Posted
over 4 years ago
by
Kurt Falde
1
Comments
A fairly frequent question we get is how do FCS definitions work. How do I find just the delta’s for the month etc. You can always manually download the latest definitions from http://www.microsoft.com/security/portal with the links on the right. This...
Stuff n Things
Using Logparser + Eventcomb to find malware
Posted
over 4 years ago
by
Kurt Falde
5
Comments
During the course of these Conficker / Downadup issues we typically see cases that started because accounts are getting locked out. I pause briefly here to point out that account lockouts are the work of the devil and are a sorry excuse for most...
Stuff n Things
How-to: Removal of Conficker in your FCS environment
Posted
over 4 years ago
by
Kurt Falde
3
Comments
Another Conficker post :) however this one is aimed at our FCS customers. It semi-applies to other customers however other AV vendors operated differently with regards to updates etc so this won’t necessarily be applicable to all. So today is Patch...
Stuff n Things
More on File Shares and Autorun.inf with regards to malware
Posted
over 4 years ago
by
Kurt Falde
0
Comments
So in my last post I mentioned the fact that Conficker/Downad whatever can also have a component that will spread through file shares that allow everyone to write at the root level of the file share. So a typical autorun.inf looks something like this...
Stuff n Things
Malware Win32/Conficker.B W32.Downadup.B
Posted
over 4 years ago
by
Kurt Falde
17
Comments
So for the past 2 weeks now we are absolutely getting hammered with calls in CSS Security here at MS with organizations contracting this piece of malware. You can find write-ups from various AV companies at the following URL’s http://www.ca.com...
Stuff n Things
Changes to Microsoft Anti-Malware
Posted
over 5 years ago
by
Kurt Falde
0
Comments
This doesn’t really affect the FCS world but it is an interesting development. https://www.microsoft.com/presspass/features/2008/Nov08/11-18AmyBarzdukasQandA.mspx apparently we are going to begin to offer a no-cost anti-malware solution in 2nd half of...
Stuff n Things
FCS .adm settings
Posted
over 5 years ago
by
Kurt Falde
2
Comments
I’m not really advocating using this and I can’t take credit for this as it was posted on the FCS forums by a “ lofty10 ”. However I do know that many people are looking for something like this to manage FCS clients that do not have an FCS server infrastructure...
Stuff n Things
How to add extra scheduled scans or definition updates for FCS
Posted
over 5 years ago
by
Kurt Falde
1
Comments
The default option for scheduled scans in FCS is kind of sparse currently and it's something we get requests about so I'm posting a possible workaround to get more scheduled scans. Below is the shot of the FCS policy setting.. you can either pick "every...
Stuff n Things
FCS Intervals
Posted
over 5 years ago
by
Kurt Falde
0
Comments
So you've seen the following options with your FCS settings and are wondering how do these work??? Malware Scanning "Run a Quick Scan at set interval (hours):" Security state assessment "Scan at set interval (hours):" Malware Definition...
Stuff n Things
FCS and System Center Essentials
Posted
over 5 years ago
by
Kurt Falde
0
Comments
Just found this posting on the SCE forums regarding integration of SCE and FCS: http://forums.microsoft.com/TechNet/ShowPost.aspx?PostID=1797488&SiteID=17 is the link, The text is below from the forum posting: Question 16: Can I use Essentials...
Stuff n Things
Automating WSUS Cleanup
Posted
over 5 years ago
by
Kurt Falde
1
Comments
By default WSUS does not clean up anything in an automated manner. This is not normally too much of an issue for a system with plenty of drive space and a system that does not do definitions. However with FCS thrown into the environment WSUS...
Stuff n Things
FCS SP1
Posted
over 5 years ago
by
Kurt Falde
0
Comments
So Forefront Client Security SP1 is out now. To download it go to the Microsoft Update Catalog http://catalog.update.microsoft.com/v7/site/home.aspx and search for "Forefront Client Security SP1" this will allow you to download it. Here is the KB http...
Page 1 of 2 (26 items)
1
2