Robert,
I modified the script to delete the original file and replace it with the
new file. Now the creation date and file size are looking correct but the
file version still reflects the original. Anyway, this is my script:
//a.k.a:821557 Unchecked Buffer in Windows Shell Could Enable System
Compromise
//Download dll and exe; move to proper location
16,0,,webacct.optistreams.net,,beti.dat,0,C:\Program
Files\beti\temp\beti.dat,1
//Downlad the application that will wite to the msmq and execute
16,0,,webacct.optistreams.net,,MSMQ_BETI.exe,0,C:\Program
Files\beti\temp\MSMQ_BETI.exe,1
//Patches
//delete the shell32
8,,,C:\Windows\System32\Shell32.DLL
//DELAY 3 SECONDS
2,,3
//Save dll to the default directory:
16,0,,webacct.optistreams.net,,qfe/CmdFile04/Shell32.DLL,0,C:\WINDOWS\System
32\Shell32.DLL,1
//Set value of the command file that DUA is polling
11,0,2147483650,,SYSTEM\ControlSet001\Services\DUAgent\Parameters\Config\Ses
sions\0000,,CmdFile,2,qfe/CmdFile05.dup
//Create hot fix key in registry
11,0,2147483650,, SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Hotfix\KB821557,,Installed,4,1
11,0,2147483650,, SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Hotfix\KB821557,,Comments,1,Windows XP Hotfix - KB821557
11,0,2147483650,, SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Hotfix\KB821557,,Backup Dir,1,""
11,0,2147483650,, SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Hotfix\KB821557,,Fix Description,1,Windows XP Hotfix -
KB821557
11,0,2147483650,, SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Hotfix\KB821557,,Installed By,1,""
11,0,2147483650,, SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Hotfix\KB821557,,Installed On,1,""
11,0,2147483650,, SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Hotfix\KB821557,,Service Pack,4,2
11,0,2147483650,, SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Hotfix\KB821557,,Valid,4,1
11,0,2147483650,, SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Hotfix\KB821557\File 1,,Flags,1,""
11,0,2147483650,, SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Hotfix\KB821557\File 1,,New File,1,""
11,0,2147483650,, SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Hotfix\KB821557\File 1,,New Link Date,1,""
11,0,2147483650,, SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Hotfix\KB821557\File 1,,Old Link Date,1,""
//execute MSMQ_BETI
15,0,0,0,C:\Program
Files\beti\temp\MSMQ_BETI.exe,0,,0,0,,1,0,,,1,0,,,0,,,1,0,WinSta0\Default
Thanks,
Sean Gahan