4 Replies Latest reply on Sep 10, 2015 8:22 PM by forands

    Shavlik scan MS15-031 show missing, because wrong file Service Branch detection (GDR vs LDR) ???

    Rookie

      Hi all.

       

      I am a Shavlik user, and Scan show MS15-031 Missing, while I can prove it is correctly installed, inside windows "Add Remove Program" control Panel / installed hotfix view.  After few search on Microsoft Web site, and Shavlik Forum .  I found that it can happen the XML Shavlik Meta data, could contain error. about MS file version  GDR versus LDR.

      Link 1) GDR & LDR : The Next Generation - if (ms) blog++; - Site Home - TechNet Blogs

      Link 2) Several incorrect detections due to GDR vs LDR version issues

       

       

      I think, this is exactly what is happening to many of our scan's results. and where confusion a lot of people and cause side effect : generate lot of LOST TIME.

       

      Who can help to validate why Shavlik scan, show missing : see bellow some evidence of my Case :

       

      1) Shavlik reason of detection : File version is less than expected. [C:\Windows\SYSTEM32\DRIVERS\KSECDD.SYS 6.0.6002.18643 < 6.0.6002.23592]

      2) Microsoft web site, statement f GDR LDR  =

      **************************************************************************************************

      https://support.microsoft.com/en-us/kb/3046049

      Windows Vista and Windows Server 2008 file information
      •The files that apply to a specific product, milestone (SPn), and service branch (LDR, GDR) can be identified by examining the file version numbers as shown in the following table:

      Version,                    Product,                                                                       Milestone,       Service branch

      6.0.6002.18xxx         Windows Vista SP2 and Windows Server 2008          SP2                 GDR
      6.0.6002.23xxx         Windows Vista SP2 and Windows Server 2008          SP2                 LDR

      **************************************************************************************************

      .

      Then why is Shavlik scan is trying to compare 6.0.6002.23xxxx   with  6.0.6002.18xxxx ?????  there hot in the same server branch. so far, this seem abnormal to me.

       

      any idea ?

       

      best regard's