Windows 7 Update appears to be compromised?

Anonymous
2015-09-30T11:04:55+00:00

These details of "Important" update, which I received this morning - 4:30 AM MT.  Copied to Notepad:

(appears to be a language pack?  4.3 MB)

______________________________________________________

gYxseNjwafVPfgsoHnzLblmmAxZUiOnGcchqEAEwjyxwjUIfpXfJQcdLapTmFaqHGCFsdvpLarmPJLOZYMEILGNIPwNOgEazuBVJcyVjBRL

Download size: 4.3 MB

You may need to restart your computer for this update to take effect.

Update type: Important

qQMphgyOoFUxFLfNprOUQpHS

More information: 

https://hckSLpGtvi.PguhWDz.fuVOl.gov

https://jNt.JFnFA.Jigf.xnzMQAFnZ.edu

Help and Support: 

https://IIKaR.ktBDARxd.plepVV.PGetGeG.lfIYQIHCN.mil

________________________________________________________________________

Did NOT install.  After my MSE definitions updated, I repeated Windows Update.  The above 'important' update did not reappear???

Did MS servers get compromised?

Thank you

Windows for home | Previous Windows versions | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

46 answers

Sort by: Most helpful
  1. Anonymous
    2015-09-30T18:34:46+00:00

    People can reasonably be concerned and mistrust their computers until they get a clear answer.

    Completely agree and they should. Something like this is extremely concerning. Especially with something that just doesn't look quite right. Something such as Windows Update getting compromised is highly concerning or any indication that it potentially could be.

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2015-09-30T18:27:42+00:00

    That's the flame malware I refer to that got on systems with usb flash drives.  It wasn't trivial at all to compromise the system and since then the manner in which they tricked the systems (a TS server that generated bogus Microsoft CA certs) has been removed and there's been a metric boatload of CA /root cert/ WU hardening done in the meantime so that the manner in which that attack occurred then can't be replicated now.

    https://social.technet.microsoft.com/Forums/office/en-US/18eeca65-21e1-42df-b882-8c1b099f1a7f/updates-needing-files-2-downloaded-133254-mb-of-133305-mb?forum=winserverwsus

    Note that thread.  See the same pattern of the funky server name - the rr1winwusfs04 referred to?  Back in August there was a similar issue where a  "test update for supersedence" was released.  Again my gut is still telling me this is not nefarious.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2015-09-30T18:26:30+00:00

    People can reasonably be concerned and mistrust their computers until they get a clear answer.

    Agreed.

    MS are obliged to say something.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2015-09-30T18:16:35+00:00

    Could you please do the following:

    Please zip-up the contents of the folder:

    C:\Windows\SoftwareDistribution

    And send the zip to secure@microsoft.com, referencing this thread so that Microsoft can triage what's going on here.

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2015-09-30T18:10:43+00:00

    Actually the way patches are digitally signed, and it has to match up with a Microsoft cert authority while one never says anything is impossible, one can't inject something into the update without first compromising the entire OS's cert checking process.  And in this case, an attacker would be REALLY stupid to go through all that trouble to compromise the cert checking process and then blow it on the actual attack sequence.

    This is true. Unfortunately, that system has indeed already been compromised at least once. http://www.wired.com/2012/06/flame-microsoft-certificate/ 

    People can reasonably be concerned and mistrust their computers until they get a clear answer.

    Was this answer helpful?

    0 comments No comments