Windows 7 Update appears to be compromised?

Anonymous
2015-09-30T11:04:55+00:00

These details of "Important" update, which I received this morning - 4:30 AM MT.  Copied to Notepad:

(appears to be a language pack?  4.3 MB)

______________________________________________________

gYxseNjwafVPfgsoHnzLblmmAxZUiOnGcchqEAEwjyxwjUIfpXfJQcdLapTmFaqHGCFsdvpLarmPJLOZYMEILGNIPwNOgEazuBVJcyVjBRL

Download size: 4.3 MB

You may need to restart your computer for this update to take effect.

Update type: Important

qQMphgyOoFUxFLfNprOUQpHS

More information: 

https://hckSLpGtvi.PguhWDz.fuVOl.gov

https://jNt.JFnFA.Jigf.xnzMQAFnZ.edu

Help and Support: 

https://IIKaR.ktBDARxd.plepVV.PGetGeG.lfIYQIHCN.mil

________________________________________________________________________

Did NOT install.  After my MSE definitions updated, I repeated Windows Update.  The above 'important' update did not reappear???

Did MS servers get compromised?

Thank you

Windows for home | Previous Windows versions | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

46 answers

Sort by: Newest
  1. Anonymous
    2015-09-30T18:55:35+00:00

    Same here.  Looks to be exact same pieces as well.  On mine, last update I went through was 9/28 when everything was reported as "up to date", which had installed Definition Update for Windows Defender KB915597 (Definition 1.207.973.0)

    Today I saw two updates available - Definition Update for Windows Defender KB915597 (Definition 1.207.1296.0) and this Language Pack.  I disabled the language pack and marked it "hidden".

    I also ran SuperAntiSpyware and MalwareBytes anti-malware with databases updated this morning and they found nothing.  I'll run Windows Defender and FortiClient next.

    gYxseNjwafVPfgsoHnzLblmmAxZUiOnGcchqEAEwjyxwjUIfpXfJQcdLapTmFaqHGCFsdvpLarmPJLOZYMEILGNIPwNOgEazuBVJcyVjBRL

    Download size: 4.3 MB

    You may need to restart your computer for this update to take effect.

    Update type: Important

    qQMphgyOoFUxFLfNprOUQpHS

    More information: 

    https://hckSLpGtvi.PguhWDz.fuVOl.gov

    https://jNt.JFnFA.Jigf.xnzMQAFnZ.edu

    Help and Support: 

    https://IIKaR.ktBDARxd.plepVV.PGetGeG.lfIYQIHCN.mil

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2015-09-30T18:34:46+00:00

    People can reasonably be concerned and mistrust their computers until they get a clear answer.

    Completely agree and they should. Something like this is extremely concerning. Especially with something that just doesn't look quite right. Something such as Windows Update getting compromised is highly concerning or any indication that it potentially could be.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2015-09-30T18:27:42+00:00

    That's the flame malware I refer to that got on systems with usb flash drives.  It wasn't trivial at all to compromise the system and since then the manner in which they tricked the systems (a TS server that generated bogus Microsoft CA certs) has been removed and there's been a metric boatload of CA /root cert/ WU hardening done in the meantime so that the manner in which that attack occurred then can't be replicated now.

    https://social.technet.microsoft.com/Forums/office/en-US/18eeca65-21e1-42df-b882-8c1b099f1a7f/updates-needing-files-2-downloaded-133254-mb-of-133305-mb?forum=winserverwsus

    Note that thread.  See the same pattern of the funky server name - the rr1winwusfs04 referred to?  Back in August there was a similar issue where a  "test update for supersedence" was released.  Again my gut is still telling me this is not nefarious.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2015-09-30T18:26:30+00:00

    People can reasonably be concerned and mistrust their computers until they get a clear answer.

    Agreed.

    MS are obliged to say something.

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2015-09-30T18:16:35+00:00

    Could you please do the following:

    Please zip-up the contents of the folder:

    C:\Windows\SoftwareDistribution

    And send the zip to secure@microsoft.com, referencing this thread so that Microsoft can triage what's going on here.

    Was this answer helpful?

    0 comments No comments