Microsoft fixes troublesome patch

Analysis
Mar 2, 20104 mins

The patch that didn't mix with the Alureon rootkit now detects it.

Microsoft has re-released a troublesome Patch Tuesday update that was, in part, causing XP machines to crash. As of today, MS10-015 will be once again pushed out to Windows users through Automatic Update. The patch was originally blamed for the BSODs that occured after some users installed it, but investigations by Microsoft and other security researchers found that crashes occured only when the machines were infected by the Alureon rootkit. The rootkit is also known by a other of names — including TDSS, Tidserv and TDL3.

Readers of this blog were not entirely ready to let Microsoft off the hook. They noted on the previous post that Microsoft could publish checksums on all system32 drivers and *sys files, so that IT security pros could validate that machines are clean before they installed the critical patch.

Another somewhat humorous note to this patch story is that the rootkit makers beat Microsoft to the punch. A mere week after the discovery, they altered their rootkit to be compatible with the patch. Apparently, they didn’t want their botnets to dwindle and their rootkit to continue its mission undisturbed.

But in all fairness, Microsoft is being proactive. The company added detection logic to this specific bulletin that searches for indications of the Alureon rootkit. If abnormal conditions are found — such as modified operating system files that look like they’ve been generated by the Alureon rootkit — the patch will not proceed. Instead, it will fail and users will get an error message. In such a case, Microsoft encourages those users to contact customer support and promises it “will work with impacted customers to resolve each issue.”

Moreover, IT professionals can run the MpSysChk.exe scanning tool to determine if a computer may be incompatible with MS10-015 — and the tool is said to alert you to any conditions that might indicate the OS was compromised and rootkit installed.  If the tool says the patch is compatible, Microsoft Knowledge Base Article 980966 offers more information about deploying the update in a enterprise environment.

Moreover, Microsoft promises that it is ” working to develop an automated solution to detect and remove Alureon rootkit from affected systems. We anticipate that tools for both consumers and enterprise customers will be available in a few weeks.”

Microsoft offers the following help.

  • Additional support for customers installing Microsoft security updates is available at: https://consumersecuritysupport.microsoft.com.
  • Those in the United States can contact Customer Service and Support at no charge using the PC Safety hotline: 1-866-727-2338 (PCSAFETY).
  • Those outside the United States can find local contact numbers at https://support.microsoft.com/international.
  • Customers who suspect they may have malware on a computer should consult their antivirus vendor.

MS10-015 fixed a pair of 17-year-old kernel bugs in 32-bit versions of Windows. The holes became public a few weeks ago when a Google engineer published proof-of-concept attack code, reports Computerworld.

Although Microsoft had stopped the patch from automatically downloading onto consumers machines until today, it did not immediately removed it from enterprise auto-patching systems.

Like this post? Check out these others.

Plus, visit the Microsoft Subnet web site for more news, blogs, podcasts. Subscribe to all Microsoft Subnet bloggers. Sign up for the bi-weekly Microsoft newsletter. (Click on News/Microsoft News Alert.) All Microsoft Subnet bloggers on Twitter Julie Bort on Twitter

Follow

Follow