He's looking at the WSUS Console (Windows Server Update Services). It's a part of the Windows Server OS's
Windows 7 Update appears to be compromised?
These details of "Important" update, which I received this morning - 4:30 AM MT. Copied to Notepad:
(appears to be a language pack? 4.3 MB)
______________________________________________________
gYxseNjwafVPfgsoHnzLblmmAxZUiOnGcchqEAEwjyxwjUIfpXfJQcdLapTmFaqHGCFsdvpLarmPJLOZYMEILGNIPwNOgEazuBVJcyVjBRL
Download size: 4.3 MB
You may need to restart your computer for this update to take effect.
Update type: Important
qQMphgyOoFUxFLfNprOUQpHS
More information:
https://hckSLpGtvi.PguhWDz.fuVOl.gov
https://jNt.JFnFA.Jigf.xnzMQAFnZ.edu
Help and Support:
https://IIKaR.ktBDARxd.plepVV.PGetGeG.lfIYQIHCN.mil
________________________________________________________________________
Did NOT install. After my MSE definitions updated, I repeated Windows Update. The above 'important' update did not reappear???
Did MS servers get compromised?
Thank you
Windows for home | Previous Windows versions | Security and privacy
Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.
46 answers
Sort by: Most helpful
-
Anonymous
2015-09-30T17:23:36+00:00 -
Anonymous
2015-09-30T17:23:14+00:00 Its from a server running WSUS. Unless you're managing a large network with centralized patch deployment, you won't have anything like that.
-
Anonymous
2015-09-30T17:16:18+00:00 What software is the screenshot you posted from, please?
-
Anonymous
2015-09-30T17:10:56+00:00 If the update didn't install, it didn't install. The fact that it's listed in your update history doesn't mean that it's impacted your system.
If the update mechanism was compromised and attackers were able to inject content then you have no assurances of that. Depending on what vulnerabilities exist in the update mechanism, then simply injecting content into the update description could be enough to cause remote code execution.
That said, this looks more like a font / character encoding issue and isn't necessarily a sign of intrusion.
-
Anonymous
2015-09-30T17:05:49+00:00 If the update didn't install, it didn't install. The fact that it's listed in your update history doesn't mean that it's impacted your system. ByGodZombie, because I know you will want assurances, let's get a support case set up to properly investigate the root cause of your system crashing. I suspect it's not this update.
Please email me at sbradcpa-at-PacBell.net [change the -at- to @] or if that bounces (as sometimes PacBell does, email susan-at-sbslinks.com [also change the -at- to @] and I'll set up a support case to give your system a review.
To everyone else on this thread, I have an ask in on a listserve, I'll try to get official information back.