Windows Update Agent 7.6.7600.320

Anonymous
2014-08-01T05:20:34+00:00

Although I have my computer set to notify me when there are updates before I install them, my computer automatically updated

Windows Update Agent 7.6.7600.320. Do I need this update and why did it load into my computer before I selected. I have searched for some explanation as to what this program is but am unable to find anything. WHAT IS IT?

Windows for home | Other | Windows update

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

84 answers

Sort by: Most helpful
  1. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

  2. Anonymous
    2014-08-04T05:40:46+00:00

    Dragon32:

    Your response was right on the money. I experienced the exact same issue under similar conditions with the same results.

    I assume you are using CIS (Comodo Internet Security) which altered me: 1) WuSetupV.exe was attempting to modify windowsupdate.log and 2) WUsetupV.exe was attempting to modify the following registry key: HKLM\software\Microsoft\SystemCertificates\root

    I denied the changes. I quickly ran into information about the Flame virus while researching this matter. Other info I found:

    Virustotal.com reports the file as being safe.

    The SHA1 checksum of WuSetupV.exe on my drive is: 2E3BEBEB8C62EC4035BBD115434C5ACCED99E46C

    WuSetupV.exe is located at C:\Windows\SoftwareDistribution\SelfUpdate\Handler

    The file is signed despite complaints by CIS that it "could not be recognized". That signature involves a certificate associated with the file that is radically different from the one involved with the original Flame virus in 2012 (which is now in everyone's untrusted certificate store: see certmgr.msc on your own computer)

    I went so far as to download and install ALL of the MS-provided root certificates from this link to ensure integrity of my catalog:

    http://catalog.update.microsoft.com/v7/site/Install.aspx?q=root%20certificate%20update&referringpage=Search.aspx

    I agree with the other posters on this forum: if this update is legitimate, MS should post notification of such updates in a central location before they occur so that InfoSec/IT teams can prepare-- otherwise, such security alerts will cause much wasted time in the post-Snowden age of heightened awareness. Or am I missing out on that "central location"?

    PS - I didn't allow the installation of this update, and I can still successfully manually query MS servers for updates using the existing "Windows Update" control panel function on my Windows 7 x64 installation.

    UPDATE TO POST:

    If you don't want to trust the WuSetupV.exe file which attempts to update Windows Update, then you can download the "Windows Update" update package and install it yourself (for Windows 7 and Server 2008). I did and it worked:

    http://blogs.technet.com/b/configmgrteam/archive/2014/07/14/how-to-install-the-windows-update-agent-on-client-computers.aspx

    In hindsight, it appears that my encounter with WuSetupV.exe had about a 99.9% change of being legitimate given the evidence. But, given the security alert coupled with the transmission method and the fact that Flame used the same transmission method (from an unwitting user's point of view), this gave me a bit of a startle until it could get sorted out.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2014-08-03T22:28:33+00:00

    I also have my PC set to notify me when updates are ready to install and for me to choose when to install them and this update ignored this setting.  My third party firewall caught it and gave me a big red warning.  It said a file it didn't recognize was trying to update a log and the registry.  The updates it was trying to make to the registry were root certificate settings and certification revocation list settings!

    I temporarily blocked it and set about researching it.  After 28 hours of frustration, scanning my computer with anti-virus and anti-malware software and researching everything, I could only conclude that one of the following two possibilities was most likely.  Either:

    1.  The update was a real Microsoft update and Microsoft was installing it automatically and ignoring my settings for Windows updates... and the Microsoft file doing it had never been seen (and was therefore not trusted via crowd/cloud sourcing) by a major third-party firewall vendor.

    OR

    2.  There are some indications it might be a new variant of the Flame / Flamer / sKyWIper virus / cyberwarfare weapon.  That's the most complex sophisticated malware ever discovered, believed to have been co-developed by the CIA, NSA, British intelligence, and the Israeli military.  It hijacks the Microsoft Windows update service masquerading with Microsoft certificates and gains full access to everything on your computer - your files, microphone, webcam, keystrokes, etc., and anything on your network and any bluetooth devices that come into range.  Hmm-mm-mm... I'll bet that would modify the root certificate and CRL settings in the registry too.

    Surely Microsoft wouldn't completely ignore my update settings, right?  But if it was a Microsoft update, surely a major PC firewall vendor would have seen the file before, right?

    But Flame / Flamer / sKyWIper is a targeted weapon, mostly used against government officials and 'people of interest' in the Mideast and eastern Europe.  I'm just a guy on a computer in the American Midwest.  What could I have done to become a target of powerful intelligence agencies?  Did they not like some Facebook post?

    Eventually I gave in and allowed the update to install for two reasons:  1)  The Windows update service would no longer search for updates ever again unless I installed it, and 2) there is no way I could be sure that security software would detect a new variant of Flame but in a post-Snowden world it seems likely these intelligence agencies already have total access to just about everything.  :-(

    After allowing the install to run, I was able to get additional info that brought me to this thread.  I really hope this is a legitimate Microsoft update.  But if so, I think it was pretty irresponsible for Microsoft to ignore update settings and cause such a security concern.  Even an announcement to major technical sites would have allowed people to find reassurances that the update was safe.  I wound up taking a day off work and wasting 28 hours of my time trying to satisfy myself (unsuccessfully!) that it isn't a virus.  Not cool.  And I'm still not really sure.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2014-08-03T18:54:08+00:00

    I've read that some PCs after getting the WUA 7.6.7600.320 have had problems searching for, downloading and installing any further windows updates(that probably includes MSE)   I think Microsoft issued a patch or a fix. Sorry I don't have the link for it.

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2014-08-03T13:00:15+00:00

    I am seeing that since this update that MSE Security Essentials is failing to update with 'connection' failed during the 'install' phase.  Download seems to be doing something, but won't install.

    After the update I did see 2 updates to MSE 1.179.1743.0 & 1.179.1889.0

    From 1.179.1986.0 on they are all failing with Network connection failed.

    I've rebooted the router/modem and restarted the PC and also saw the registry update 65 of 65 complete, but MSE is still failing to Update.

    Was this answer helpful?

    0 comments No comments