Windows 7 Update appears to be compromised?

Anonymous
2015-09-30T11:04:55+00:00

These details of "Important" update, which I received this morning - 4:30 AM MT.  Copied to Notepad:

(appears to be a language pack?  4.3 MB)

______________________________________________________

gYxseNjwafVPfgsoHnzLblmmAxZUiOnGcchqEAEwjyxwjUIfpXfJQcdLapTmFaqHGCFsdvpLarmPJLOZYMEILGNIPwNOgEazuBVJcyVjBRL

Download size: 4.3 MB

You may need to restart your computer for this update to take effect.

Update type: Important

qQMphgyOoFUxFLfNprOUQpHS

More information: 

https://hckSLpGtvi.PguhWDz.fuVOl.gov

https://jNt.JFnFA.Jigf.xnzMQAFnZ.edu

Help and Support: 

https://IIKaR.ktBDARxd.plepVV.PGetGeG.lfIYQIHCN.mil

________________________________________________________________________

Did NOT install.  After my MSE definitions updated, I repeated Windows Update.  The above 'important' update did not reappear???

Did MS servers get compromised?

Thank you

Windows for home | Previous Windows versions | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

46 answers

Sort by: Newest
  1. Anonymous
    2015-09-30T19:42:12+00:00

    Technically, if you wanted to insert malicious software into an update that is signed, one way do it might be to find a nonsense piece of text that - when hashed - appears to match an existing hash from other contents.

    That's the reason MD5 is useless now - you can pad almost any data to make it have almost any MD5 that you like if you spend enough time.

    But, I have to admit, it sounds more like corruption, junk, internal testing, a mistake, etc. than anything else.  But WE cannot be sure.  Only MS can provide that answer.  It wouldn't be unusual for a false-Microsoft-cert to be signed by some high-up certificate authority "for testing" which leaks out and allows someone to generate a valid, signed update with whatever they wanted in it.

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2015-09-30T19:36:15+00:00

    This is true. Unfortunately, that system has indeed already been compromised at least once. http://www.wired.com/2012/06/flame-microsoft-certificate/ 

    That's an inaccurate statement. Microsoft Update was not compromised; Flame used a man-in-the-middle attack and a bogus certificate.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2015-09-30T19:11:37+00:00

    Fun Fact: SuperAntiSpyware is junk.  I worked for the company that makes the software (support.com) and they have a division that provides over the phone PC Support.  That department is not allowed to use SuperAntiSpyware..  Their main antimalware is MalwareBytes 1.75...  I wouldn't recommend using a product that the parent company doesn't even put faith into.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2015-09-30T18:59:59+00:00

    It didn't get compromised. 

    Don't panic: Microsoft mistakenly posted a 'test' Windows update patch | ZDNet:

    http://www.zdnet.com/article/microsoft-accidentally-issued-a-test-windows-update-patch/

    A Microsoft spokesperson confirmed Wednesday that it had "incorrectly published a test update" and is in the process of removing it.

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2015-09-30T18:58:35+00:00

    Don't panic: Microsoft mistakenly posted a 'test' Windows update patch | ZDNet:

    http://www.zdnet.com/article/microsoft-accidentally-issued-a-test-windows-update-patch/

    A Microsoft spokesperson confirmed Wednesday that it had "incorrectly published a test update" and is in the process of removing it.

    Was this answer helpful?

    0 comments No comments