Labels

Showing posts with label WSUS. Show all posts
Showing posts with label WSUS. Show all posts

Wednesday, December 28, 2011

Batch script to extract updates from WSUS content folder

This script will extract/copy particular updates from WSUS content folder. WSUS stores updates in \WSUSContent folder using SHA1 hash for file names and this script will attempt to decrypt SHA1 hash for file names by querying  WSUS SQL/MSDE database and then exports those updates as well.

Command line switches to run the script

SYNTAX:   WSUSExtract.cmd <-f:search_string> [-l:lang] [-t:target]

-f:search_string   - Part of update KB to search for.

-l:lang      - Update language. If omitted, all languages will be processed.

-t:target  - Target folder to copy updates to. If omitted, script assumes 'View Only' mode.

Examples

The command below will Copy downloaded English updates corresponding 896358 KB article to 'c:\temp' folder

WSUSExtract.cmd -f:896358 -l:enu -t:c:\temp

The command below will output/display/View all downloaded updates corresponding to 896358 KB article:

WSUSExtract.cmd  -f:896358

Copy the code below in a text file and name it as 'WSUSExtract.cmd'.

::======== start of script ========

::  Batch script to 'extract' particular updates from WSUS content folder.
:: 
::  The problem with content folder is that WSUS stores updates using SHA1 hash for
::  file names so it is difficult to determine what file belongs to what
::  update. The script determines a human-readable name of update file byquerying 
::  WSUS SQL/MSDE database.
:: 
::  ====================================================================
::  SYNTAX:   WSUSExtract.cmd <-f:search_string> [-l:lang] [-t:target]
:: 
::  -f:search_string - Part of update KB to search for.
:: 
::  -l:lang    - Update language. If omitted, all languages will be processed.
:: 
::  -t:target  - Target folder to copy updates to. If omitted, script assumes 'View Only' mode.
:: 
::  EXAMPLES:
::  Copy downloaded english updates corresponding 896358 KB article to 'c:\temp'folder:
::      WSUSExtract.cmd -f:896358 -l:enu -t:c:\temp
:: 
::  View all downloaded updates corresponding to 896358 KB article:
::      WSUSExtract.cmd  -f:896358
::  ====================================================================
:: 

::*************************************************************************
:: Name:           WSUSExtract.cmd
::
:: Purpose:        Finds and copies particular update(s) from WSUS content folder.
::
:: Syntax:         WSUSExtract.cmd <-f:search_string> [-l:language] [-t:target_folder]
::
:: Version:        1.1
:: Technology:     NT Batch
::
:: Requirements:   Windows 2000+
::                 REG.EXE (in case of Windows 2000, install Support Tools or download REG.EXE from
::
http://www.dynawell.com/reskit/microsoft/win2000/reg.zip)
::                 OSQL.EXE Utility (included in MSDE)
::
:: Authors:        Alexander Suhovey
::
:: History:        08/07/2005 - Database server address is now determined from registry
::                 08/05/2005 - First release.
::*************************************************************************
@echo off
setlocal ENABLEEXTENSIONS ENABLEDELAYEDEXPANSION
Echo.

::========= OS Check ============
if not "%OS%" == "Windows_NT" goto BADOS
if "%APPDATA%" == "" goto BADOS

::====== Parse command line =====
If "%1"=="" GOTO USAGE
If "%1"=="/?" GOTO USAGE
If "%1"=="-?" GOTO USAGE
:PARSE
set arg=%1
shift /1
If not defined arg GOTO NEXT
If "%arg:~0,3%"=="-f:" (set fstr=%arg:~3%&GOTO PARSE)
If "%arg:~0,3%"=="-l:" (set lang=%arg:~3%&GOTO PARSE)
If "%arg:~0,3%"=="-t:" (set target=%arg:~3%&GOTO PARSE)
Echo ERROR: Unknown argument: %arg%
GOTO USAGE
:NEXT
If defined target (
    set target=%target:"=%\
    If not exist "%target%" echo ERROR: Cannot find target folder: "%target%" & goto :eof
) Else (
    set viewonly=1
    Echo Target folder not defined. Assuming View Only mode.
    echo.
)

::== Find WSUS content folder ===
::=== and SQL server address  ===
set regkey="HKLM\SOFTWARE\Microsoft\Update Services\Server\Setup"
for /f "tokens=2* delims= " %%i in ('reg query %regkey% /v ContentDir ^| find "ContentDir"') do set source=%%j
If not defined source Echo ERROR: Cannot find WSUS content folder in registry. Check if WSUS is installed. & goto :eof
set source=%source%\WsusContent
for /f "tokens=2* delims= " %%i in ('reg query %regkey% /v SqlServerName ^| find "SqlServerName"') do set server=%%j
If not defined server Echo ERROR: Cannot find WSUS database server in registry. Check if WSUS is installed. & goto :eof
set osqlcommand=osql.exe -w 500 -h-1 -E -d SUSDB -S %server%

::====== Test SQL database ======
::========= connection ==========
for /f "delims=" %%i in ('%osqlcommand% -Q') do (
    Echo ERROR: Cannot connect to WSUS SQL server '%server%'
    goto :eof
)

::=== Format osql.exe query =====
set query=select FileDigest,FileName from tbFile
If defined fstr set query=%query% where FileName like '%%%fstr%%%'
If defined lang (
    If defined fstr (set query=!query! and) Else (set query=!query! where)
    set query=!query! FileName like '%%%lang%%%'
)

::======== Main section =========
set num1=0
set num2=0
echo ========================================
for /f "tokens=1,2" %%i in ('%osqlcommand% -Q "%query%" ^| find /v "rows affected"') do (
    set /a num1+=1
    set dstfile=%%j
    set srcfile=%%i
    set srcfilepath="%source%\!srcfile:~-2!\!srcfile:~2!.!dstfile:~-3!"
    set dstfilepath="%target%%%j"
    If exist !srcfilepath! (
        set /a num2+=1
        If defined viewonly (
            echo !dstfile!
        ) Else (
            If exist !dstfilepath! set dstfilepath="%target%%%~nj(Copy !random!)%%~xj"
            set /p foo="Copying !dstfile! ... "<nul
            copy !srcfilepath! !dstfilepath! >nul 2>&1
            If errorlevel 1 (echo FAILED.) Else (echo Done.)
        )
    )
)
echo ========================================
echo Updates found in content folder    : %num2%
echo Total matching updates in database : %num1%
goto :eof

::========= Echo syntax =========
:USAGE
echo.
Echo %~nx0
Echo Finds and copies particular update(s) from WSUS content folder.
Echo Renames updates to human-readable format using information
Echo obtained from local WSUS SQL database.
Echo.
Echo SYNTAX:   %~nx0 ^<-f:search_string^> [-l:lang] [-t:target]
Echo.
Echo -f:search_string - Part of update name to search for.
Echo                    Naming format for OS updates: OS-KBNUMBER-HW-LANG.EXT
Echo                    OS       - Operating system (eg 'WindowsXP')
Echo                    KBNUMBER - MSKB number (e.g 'KB896358')
Echo                    HW       - Hardware technology ('x86', 'ia64' etc)
Echo                    LANG     - OS language (see -l switch below)
Echo                    EXT      - Extention ('exe', 'cab' etc)
Echo -l:lang          - Update language. If omitted, all languages will
Echo                    be processes. Examples are:
Echo                    rus - russian
Echo                    enu - english
Echo                    fra - french
Echo                    deu - deutch
Echo -t:target        - Target folder to copy updates to.
Echo                    If omitted, script assumes 'View Only' mode.
Echo                    Do not use trailing slash.
Echo.
Echo EXAMPLES:
Echo.
Echo Copy downloaded english updates corresponding
Echo to 896358 KB article to 'c:\temp' folder:
Echo.
Echo     %~nx0 -f:896358 -l:enu -t:c:\temp
Echo.
Echo View all downloaded updates corresponding to 896358 KB article:
Echo.
Echo     %~nx0 -f:896358
Echo.
goto :eof

::===== If Bad OS detected ======
:BADOS
echo.
echo ERROR: This script needs Windows 2000 or better.
goto :eof

::======== End of script ========

Friday, December 16, 2011

Windows Update Deployment on Workgroup PC through Domain WSUS Server

Follow the Following Steps

1. Enter the Below Code into text file and save as (.reg) file.

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate]

"WUServer"="http://ocean:8530"

"WUStatusServer"="http://ocean:8530"

"TargetGroupEnabled"=dword:00000001

"TargetGroup"="MUM"

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU]

"NoAutoUpdate"=dword:00000000

"AUOptions"=dword:00000003

"ScheduledInstallDay"=dword:00000000

"ScheduledInstallTime"=dword:0000000e

"UseWUServer"=dword:00000001

"RescheduleWaitTime"=dword:00000014

"DetectionFrequencyEnabled"=dword:00000001

"DetectionFrequency"=dword:0000000c

"NoAutoRebootWithLoggedOnUsers"=dword:00000001

2. Run this REG file on Client system.

3. Set Client PC Date and Time as per WSUS server.

4. Restart the Windows Update service on Client PC or Restart the system.

Configure Automatic Updates by Using Group Policy

When you configure the Group Policy settings for WSUS, use a Group Policy object (GPO) linked to an Active Directory container appropriate for your environment. Microsoft does not recommend editing the Default Domain or Default Domain Controller GPOs to add WSUS settings.
In a simple environment, link the GPO with the WSUS settings to the domain. In more complex environment, you might have multiple GPOs linked to several organizational units (OUs), which enables you to have different WSUS policy settings applied to different types of computers.
After you set up a client computer, it will take a few minutes before it appears on the Computers page in the WSUS console. For client computers configured with an Active Directory-based GPO, it will take about 20 minutes after Group Policy refreshes (that is, applies any new settings to the client computer). By default, Group Policy refreshes in the background every 90 minutes, with a random offset of 0 to 30 minutes. If you want to refresh Group Policy sooner, you can go to a command prompt on the client computer and type: gpupdate /force.
clip_image001Note
On client computers running Windows 2000, you can type the following at a command prompt: secedit /refreshpolicy machine_policy enforce.
The following is a list of the Group Policy options available for configuring WSUS-related items in the environment.
clip_image001[1]Note
In Windows 2000, Group Policy Object Editor is known as Group Policy Editor. Although the name changed, it is the same tool for editing Group Policy objects. It is also commonly referred to as gpedit.

Load the WSUS Administrative Template

Before you can set any Group Policy options for WSUS, you must ensure that the latest administrative template has been loaded on the computer used to administer Group Policy. The administrative template with WSUS settings is named Wuau.adm. Although there are additional Group Policy settings related to the Windows Update Web site, all the new Group Policy settings for WSUS are contained within the Wuau.adm file.
If the computer you are using to configure Group Policy has the latest version of Wuau.adm, you do not need to load the file to configure settings. The new version of Wuau.adm is available on Windows XP with Service Pack 2. Administrative templates files are stored by default in the %windir%\Inf directory.
clip_image002Important
You can find the correct version of Wuau.adm on any computer having the WSUS-compatible Automatic Updates installed. You can use the old version of Wuau.adm to initially point Automatic Updates to the WSUS server in order to self-update. After the Automatic Updates self-updates, the new Wuau.adm file appears in the %windir%\Inf folder.
If the computer you are using to configure Group Policy does not have the latest version of Wuau.adm, you must first load it by using the following procedure.
To add the WSUS Administrative Template
  1. In Group Policy Object Editor, click either of the Administrative Templates nodes.
  2. On the Action menu, click Add/Remove Templates.
  3. Click Add.
  4. In the Policy Templates dialog box, select Wuau.adm, and then click Open.
  5. In the Add/Remove Templates dialog box, click Close.

Configure Automatic Updates

The settings for this policy enable you to configure how Automatic Updates works. You must specify that Automatic Updates download updates from the WSUS server rather than from Windows Update.
To configure the behavior of Automatic Updates
  1. In Group Policy Object Editor, expand Computer Configuration, expand Administrative Templates, expand Windows Components, and then click Windows Update.
  2. In the details pane, click Configure Automatic Updates.
  3. Click Enabled and select one of the following options:
    • Notify for download and notify for install. This option notifies a logged-on administrative user prior to the download and prior to the installation of the updates.
    • Auto download and notify for install. This option automatically begins downloading updates and then notifies a logged-on administrative user prior to installing the updates.
    • Auto download and schedule the install. If Automatic Updates is configured to perform a scheduled installation, you must also set the day and time for the recurring scheduled installation.
    • Allow local admin to choose setting. With this option, the local administrators are allowed to use Automatic Updates in Control Panel to select a configuration option of their choice. For example, they can choose their own scheduled installation time. Local administrators are not allowed to disable Automatic Updates.
  4. Click OK.

Specify Intranet Microsoft Update Service Location

The settings for this policy enable you to configure a WSUS server that Automatic Updates will contact for updates. You must enable this policy in order for Automatic Updates to download updates from the WSUS server.
Enter the WSUS server HTTP(S) URL twice, so that the server specified for updates is also used for reporting client events. For example, type http(s)://servername in both boxes. Both URLs are required.
To redirect Automatic Updates to a WSUS server
  1. In Group Policy Object Editor, expand Computer Configuration, expand Administrative Templates, expand Windows Components, and then click Windows Update.
  2. In the details pane, click Specify Intranet Microsoft update service location.
  3. Click Enabled and type the HTTP(S) URL of the same WSUS server in the Set the intranet update service for detecting updates box and in the Set the intranet statistics server box. For example, type http(s)://servername in both boxes.
  4. Click OK.

Enable Client-side Targeting

This policy enables client computers to self-populate computer groups that exist on the WSUS server.
If the status is set to Enabled, the specified computer group information is sent to WSUS, which uses it to determine which updates should be deployed to this computer. This setting is only capable of indicating to the WSUS server which group the client computer should use. You must actually create the group on the WSUS server.
If the status is set to Disabled or Not Configured, no computer group information will be sent to WSUS.
To enable client-side targeting
  1. In Group Policy Object Editor, expand Computer Configuration, expand Administrative Templates, expand Windows Components, and then click Windows Update.
  2. In the details pane, click Enable client-side targeting.
  3. Click Enabled and type the name of the computer group in the box.
  4. Click OK.

Reschedule Automatic Update Scheduled Installations

This policy specifies the amount of time for Automatic Updates to wait, following system startup, before proceeding with a scheduled installation that was missed previously.
If the status is set to Enabled, a scheduled installation that did not take place earlier will occur the specified number of minutes after the computer is next started.
If the status is set to Disabled, a missed scheduled installation will occur with the next scheduled installation.
If the status is set to Not Configured, a missed scheduled installation will occur one minute after the computer is next started.
This policy applies only when Automatic Updates is configured to perform scheduled installations of updates. If the Configure Automatic Updates policy is disabled, this policy has no effect.
To reschedule Automatic Update scheduled installation
  1. In Group Policy Object Editor, expand Computer Configuration, expand Administrative Templates, expand Windows Components, and then click Windows Update.
  2. In the details pane, click Reschedule Automatic Update scheduled installations, click Enable, and type a value in minutes.
  3. Click OK.

No Auto-restart for Scheduled Automatic Update Installation Options

This policy specifies that to complete a scheduled installation, Automatic Updates will wait for the computer to be restarted by any user who is logged on, instead of causing the computer to restart automatically.
If the status is set to Enabled, Automatic Updates will not restart a computer automatically during a scheduled installation if a user is logged on to the computer. Instead, Automatic Updates will notify the user to restart the computer in order to complete the installation.
Be aware that Automatic Updates will not be able to detect future updates until the restart occurs.
If the status is set to Disabled or Not Configured, Automatic Updates will notify the user that the computer will automatically restart in 5 minutes to complete the installation.
This policy applies only when Automatic Updates is configured to perform scheduled installations of updates. If the Configure Automatic Updates policy is disabled, this policy has no effect.
To inhibit auto-restart for scheduled Automatic Update installation options
  1. In Group Policy Object Editor, expand Computer Configuration, expand Administrative Templates, expand Windows Components, and then click Windows Update.
  2. In the details pane, click No auto-restart for scheduled Automatic Update installation options, and set the option.
  3. Click OK.

Automatic Update Detection Frequency

This policy specifies the hours that Windows will use to determine how long to wait before checking for available updates. The exact wait time is determined by using the hours specified here, minus 0 to 20 percent of the hours specified. For example, if this policy is used to specify a 20-hour detection frequency, then all WSUS clients to which this policy is applied will check for updates anywhere between 16 and 20 hours.
If the status is set to Enabled, Automatic Updates will check for available updates at the specified interval.
If the status is set to Disabled or Not Configured, Automatic Updates will check for available updates at the default interval of 22 hours.
To set Automatic Update detection frequency
  1. In Group Policy Object Editor, expand Computer Configuration, expand Administrative Templates, expand Windows Components, and then click Windows Update.
  2. In the details pane, click Automatic Update detection frequency, and set the option.
  3. Click OK.

Allow Automatic Update Immediate Installation

This policy specifies whether Automatic Updates should automatically install certain updates that neither interrupt Windows services nor restart Windows.
If the status is set to Enabled, Automatic Updates will immediately install these updates after they have been downloaded and are ready to install.
If the status is set to Disabled, such updates will not be installed immediately.
To allow Automatic Update immediate installation
  1. In Group Policy Object Editor, expand Computer Configuration, expand Administrative Templates, expand Windows Components, and then click Windows Update.
  2. In the details pane, click Allow Automatic Update immediate installation, and set the option.
  3. Click OK.

Delay Restart for Scheduled Installations

This policy specifies the amount of time for Automatic Updates to wait before proceeding with a scheduled restart.
If the status is set to Enabled, a scheduled restart will occur the specified number of minutes after the installation is finished.
If the status is set to Disabled or Not Configured, the default wait time is five minutes.
To delay restart for scheduled installations
  1. In Group Policy Object Editor, expand Computer Configuration, expand Administrative Templates, expand Windows Components, and then click Windows Update.
  2. In the details pane, click Delay restart for scheduled installations, and set the option.
  3. Click OK.

Re-prompt for Restart with Scheduled Installations

This policy specifies the amount of time for Automatic Updates to wait before prompting the user again for a scheduled restart.
If the status is set to Enabled, a scheduled restart will occur the specified number of minutes after the previous prompt for restart was postponed.
If the status is set to Disabled or Not Configured, the default interval is 10 minutes.
To re-prompt for restart with scheduled installations
  1. In Group Policy Object Editor, expand Computer Configuration, expand Administrative Templates, expand Windows Components, and then click Windows Update.
  2. In the details pane, click Re-prompt for restart with scheduled installations, and set the option.
  3. Click OK.

Allow Non-administrators to Receive Update Notifications

This policy specifies whether logged-on non-administrative users will receive update notifications based on the configuration settings for Automatic Updates. If Automatic Updates is configured, by policy or locally, to notify the user either before downloading or only before installation, these notifications will be offered to any non-administrator who logs onto the computer.
If the status is set to Enabled, Automatic Updates will include non-administrators when determining which logged-on user should receive notification.
If the status is set to Disabled or Not Configured, Automatic Updates will notify only logged-on administrators.
To allow non-administrators to receive update notifications
  1. In Group Policy Object Editor, expand Computer Configuration, expand Administrative Templates, expand Windows Components, and then click Windows Update.
  2. In the details pane, click Allow non-administrators to receive update notifications, and set the option.
  3. Click OK.
clip_image001[2]Note
This policy setting does not allow non-administrative Terminal Services users to restart the remote computer where they are logged in. This is because, by default, non-administrative Terminal Services users do not have computer restart privileges.

Remove Links and Access to Windows Update

If this setting is enabled, Automatic Updates receives updates from the WSUS server. Users who have this policy set cannot get updates from a Windows Update Web site that you have not approved. If this policy is not enabled, the Windows Update icon remains on the Start menu for local administrators to visit the Windows Update Web site. Local administrative users can use it to install unapproved software from the public Windows Update Web site. This happens even if you have specified that Automatic Updates must get approved updates from your WSUS server.
To remove links and access to Windows Update
  1. In Group Policy Object Editor, expand User Configuration, expand Administrative Templates, and then click Start Menu and Taskbar.
  2. In the details pane, click Remove links and access to Windows Update, and set the option.
  3. Click OK.

Batch script to extract updates from WSUS content folder

This script will extract/copy particular updates from WSUS content folder. WSUS stores updates in \WSUSContent folder using SHA1 hash for file names and this script will attempt to decrypt SHA1 hash for file names by querying  WSUS SQL/MSDE database and then exports those updates as well.

Command line switches to run the script

SYNTAX:   WSUSExtract.cmd <-f:search_string> [-l:lang] [-t:target]

-f:search_string   - Part of update KB to search for.

-l:lang      - Update language. If omitted, all languages will be processed.

-t:target  - Target folder to copy updates to. If omitted, script assumes 'View Only' mode.

Examples

The command below will Copy downloaded English updates corresponding 896358 KB article to 'c:\temp' folder

WSUSExtract.cmd -f:896358 -l:enu -t:c:\temp

The command below will output/display/View all downloaded updates corresponding to 896358 KB article:

WSUSExtract.cmd  -f:896358

Copy the code below in a text file and name it as 'WSUSExtract.cmd'.

::======== start of script ========

::  Batch script to 'extract' particular updates from WSUS content folder.
:: 
::  The problem with content folder is that WSUS stores updates using SHA1 hash for
::  file names so it is difficult to determine what file belongs to what
::  update. The script determines a human-readable name of update file byquerying 
::  WSUS SQL/MSDE database.
:: 
::  ====================================================================
::  SYNTAX:   WSUSExtract.cmd <-f:search_string> [-l:lang] [-t:target]
:: 
::  -f:search_string - Part of update KB to search for.
:: 
::  -l:lang    - Update language. If omitted, all languages will be processed.
:: 
::  -t:target  - Target folder to copy updates to. If omitted, script assumes 'View Only' mode.
:: 
::  EXAMPLES:
::  Copy downloaded english updates corresponding 896358 KB article to 'c:\temp'folder:
::      WSUSExtract.cmd -f:896358 -l:enu -t:c:\temp
:: 
::  View all downloaded updates corresponding to 896358 KB article:
::      WSUSExtract.cmd  -f:896358
::  ====================================================================
:: 

::*************************************************************************
:: Name:           WSUSExtract.cmd
::
:: Purpose:        Finds and copies particular update(s) from WSUS content folder.
::
:: Syntax:         WSUSExtract.cmd <-f:search_string> [-l:language] [-t:target_folder]
::
:: Version:        1.1
:: Technology:     NT Batch
::
:: Requirements:   Windows 2000+
::                 REG.EXE (in case of Windows 2000, install Support Tools or download REG.EXE from
:: http://www.dynawell.com/reskit/microsoft/win2000/reg.zip)
::                 OSQL.EXE Utility (included in MSDE)
::
:: Authors:        Alexander Suhovey
::
:: History:        08/07/2005 - Database server address is now determined from registry
::                 08/05/2005 - First release.
::*************************************************************************
@echo off
setlocal ENABLEEXTENSIONS ENABLEDELAYEDEXPANSION
Echo.

::========= OS Check ============
if not "%OS%" == "Windows_NT" goto BADOS
if "%APPDATA%" == "" goto BADOS

::====== Parse command line =====
If "%1"=="" GOTO USAGE
If "%1"=="/?" GOTO USAGE
If "%1"=="-?" GOTO USAGE
:PARSE
set arg=%1
shift /1
If not defined arg GOTO NEXT
If "%arg:~0,3%"=="-f:" (set fstr=%arg:~3%&GOTO PARSE)
If "%arg:~0,3%"=="-l:" (set lang=%arg:~3%&GOTO PARSE)
If "%arg:~0,3%"=="-t:" (set target=%arg:~3%&GOTO PARSE)
Echo ERROR: Unknown argument: %arg%
GOTO USAGE
:NEXT
If defined target (
    set target=%target:"=%\
    If not exist "%target%" echo ERROR: Cannot find target folder: "%target%" & goto :eof
) Else (
    set viewonly=1
    Echo Target folder not defined. Assuming View Only mode.
    echo.
)

::== Find WSUS content folder ===
::=== and SQL server address  ===
set regkey="HKLM\SOFTWARE\Microsoft\Update Services\Server\Setup"
for /f "tokens=2* delims= " %%i in ('reg query %regkey% /v ContentDir ^| find "ContentDir"') do set source=%%j
If not defined source Echo ERROR: Cannot find WSUS content folder in registry. Check if WSUS is installed. & goto :eof
set source=%source%\WsusContent
for /f "tokens=2* delims= " %%i in ('reg query %regkey% /v SqlServerName ^| find "SqlServerName"') do set server=%%j
If not defined server Echo ERROR: Cannot find WSUS database server in registry. Check if WSUS is installed. & goto :eof
set osqlcommand=osql.exe -w 500 -h-1 -E -d SUSDB -S %server%

::====== Test SQL database ======
::========= connection ==========
for /f "delims=" %%i in ('%osqlcommand% -Q') do (
    Echo ERROR: Cannot connect to WSUS SQL server '%server%'
    goto :eof
)

::=== Format osql.exe query =====
set query=select FileDigest,FileName from tbFile
If defined fstr set query=%query% where FileName like '%%%fstr%%%'
If defined lang (
    If defined fstr (set query=!query! and) Else (set query=!query! where)
    set query=!query! FileName like '%%%lang%%%'
)

::======== Main section =========
set num1=0
set num2=0
echo ========================================
for /f "tokens=1,2" %%i in ('%osqlcommand% -Q "%query%" ^| find /v "rows affected"') do (
    set /a num1+=1
    set dstfile=%%j
    set srcfile=%%i
    set srcfilepath="%source%\!srcfile:~-2!\!srcfile:~2!.!dstfile:~-3!"
    set dstfilepath="%target%%%j"
    If exist !srcfilepath! (
        set /a num2+=1
        If defined viewonly (
            echo !dstfile!
        ) Else (
            If exist !dstfilepath! set dstfilepath="%target%%%~nj(Copy !random!)%%~xj"
            set /p foo="Copying !dstfile! ... "<nul
            copy !srcfilepath! !dstfilepath! >nul 2>&1
            If errorlevel 1 (echo FAILED.) Else (echo Done.)
        )
    )
)
echo ========================================
echo Updates found in content folder    : %num2%
echo Total matching updates in database : %num1%
goto :eof

::========= Echo syntax =========
:USAGE
echo.
Echo %~nx0
Echo Finds and copies particular update(s) from WSUS content folder.
Echo Renames updates to human-readable format using information
Echo obtained from local WSUS SQL database.
Echo.
Echo SYNTAX:   %~nx0 ^<-f:search_string^> [-l:lang] [-t:target]
Echo.
Echo -f:search_string - Part of update name to search for.
Echo                    Naming format for OS updates: OS-KBNUMBER-HW-LANG.EXT
Echo                    OS       - Operating system (eg 'WindowsXP')
Echo                    KBNUMBER - MSKB number (e.g 'KB896358')
Echo                    HW       - Hardware technology ('x86', 'ia64' etc)
Echo                    LANG     - OS language (see -l switch below)
Echo                    EXT      - Extention ('exe', 'cab' etc)
Echo -l:lang          - Update language. If omitted, all languages will
Echo                    be processes. Examples are:
Echo                    rus - russian
Echo                    enu - english
Echo                    fra - french
Echo                    deu - deutch
Echo -t:target        - Target folder to copy updates to.
Echo                    If omitted, script assumes 'View Only' mode.
Echo                    Do not use trailing slash.
Echo.
Echo EXAMPLES:
Echo.
Echo Copy downloaded english updates corresponding
Echo to 896358 KB article to 'c:\temp' folder:
Echo.
Echo     %~nx0 -f:896358 -l:enu -t:c:\temp
Echo.
Echo View all downloaded updates corresponding to 896358 KB article:
Echo.
Echo     %~nx0 -f:896358
Echo.
goto :eof

::===== If Bad OS detected ======
:BADOS
echo.
echo ERROR: This script needs Windows 2000 or better.
goto :eof

::======== End of script ========