Subscribe to Windows IT Pro

 

Get Newsletters

  • Get the Latest News
  • Product Updates
  • Helpful Tricks
  • Productivity Tips

Subscribe Now!

November 06, 2009 12:00 AM

Get Updates on Microsoft Updates

Windows IT Pro
InstantDoc ID #102913
Rating: (5)
Downloads
102913.zip

I created a script, WinUpdateCheck.vbs, that you can use to generate a report that details the number of Microsoft updates installed and the date of the most recently installed update for every Windows XP machine on your network. This information can be very useful in identifying machines that have been compromised with malware that prevents the installation of Microsoft updates (e.g., Conficker worm). It also provides a simple way to monitor Microsoft update installations throughout your network.

Here are the steps to get WinUpdateCheck.vbs working in your environment:

  1. Download WinUpdateCheck.vbs by clicking the Download the Code Here button.
  2. Create a text file that lists the name of every Windows XP host on your network. Each host name should be on a separate line.
  3. In the code that Listing 1 shows, modify the PCLIST constant to reflect the directory path and name of the text file created in step 2.
  4. Modify the PATH constant to reflect the directory location of where you want the results to be logged.

Listing 1: Code to Modify in WinUpdateCheck.vbs



WinUpdateCheck.vbs logs the results in a comma-separated value (CSV) file named Update-Log.csv. (If you run the script more than once, the subsequent runs' results are appended to the existing CSV file.) At the end, the script attempts to open the CSV file in Microsoft Excel. If you don't have Excel installed on the machine from which you're running the script, the results will still be logged in the CSV file. The file just won't open at the end of the script's run.

Note that WinUpdateCheck.vbs assumes the machines being inspected have Windows installed in the C:\Windows directory. If your machines have Windows installed in a different location, you'll need to change \$c\Windows to the appropriate directory in the script's UpdateLog subroutine.

WinUpdateCheck.vbs takes roughly 10 minutes per 100 machines to run, so if you have 500 machines it will take about 50 minutes to complete. (It might be slower or faster, depending on your network infrastructure.)

Related Content:

ARTICLE TOOLS

Comments
  • JIM
    3 years ago
    Dec 10, 2009

    You can improve the reliability of the script by replacing:
    "\\c$\\Windows"
    with:
    "\\admin$"
    in the second line of the "CheckUpdates" subroutine.

    The Admin$ hidden share is created by Windows (NT 4.0 and newer) during installation and always points to the Windows installation directory, so it will be valid even if Windows is installed in a directory other than C:\\Windows. It will also be valid on a Windows 2000 computer where the default installation directory is C:\\WinNT.

  • Ian
    3 years ago
    Dec 02, 2009

    Hi

    I ran the script and the csv was created - all PC's came back as "OFF LINE", including my own PC.

    This was run as domain account that has admin privileges on all the machines.

    Any ideas?

    cheers

    Ian

  • Duncan
    3 years ago
    Dec 01, 2009

    The code has a bug on the following line:
    Set objFolder = objFSO.GetFolder("\\\\" & strComputer & "\\c$\\Windows")
    This assumes that windows has been installed into c:\\windows (not the case where I'm currently working) - it should instead use the %systemroot% environment variable.

  • Ed
    3 years ago
    Dec 01, 2009

    Hmmm. If your company uses WSUS [or some of the equivalents], it keeps track of updates that have and have not been installed [and I don't think a worm can trick it]. So this script is unnecessary - unless you want a second opinion.

You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

White Papers

Get your Windows 7 deployment off to the right start by implementing PC lockdown. A locked-down environment is easier and cheaper to support since users are less likely to make unnecessary changes to the core system configuration - read more here!

Essential Guides

Is your iSCSI "lossy"? The reality is that most off-the-shelf Ethernet hardware deployed for iSCSI can lose packets, resulting in slow performance or application downtime. Learn how to assess your current iSCSI infrastructure and engineer an advanced iSCSI SAN infrastructure.

Web Seminars

What's the best way to keep your network safe from malware? In this web seminar, security expert Greg Shields suggests an alternative method to the traditional blacklisting approach that is common with anti-virus and anti-malware solutions.

eLearning Series

We bring the experts direct to you to share their real-world perspective and expertise. During each event, three sessions stream in real time, so you can learn, ask questions, and get solutions.
Upcoming event: Getting the Most with Exchange 2010 with Paul Robichaux

Subscribe to Windows IT Pro!

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.