During the recent Welchia/Nachi attack I rolled out the hotfixes and in some cases Windows 2000 SP4 through the login script.

I first tested whether the user had admin rights, and if so installed the required patches.

If the user did not have admin rights, I used TcqRunAs to build an encrypted package that contained the password to the service account that installed the patches on the system.

Similarly, when it came time to run the virus removal tools (that required admin rights to run) I used the same process.

[ 04. September 2003, 13:56: Message edited by: Chris S. ]