Windows 7 Update appears to be compromised?

Anonymous
2015-09-30T11:04:55+00:00

These details of "Important" update, which I received this morning - 4:30 AM MT.  Copied to Notepad:

(appears to be a language pack?  4.3 MB)

______________________________________________________

gYxseNjwafVPfgsoHnzLblmmAxZUiOnGcchqEAEwjyxwjUIfpXfJQcdLapTmFaqHGCFsdvpLarmPJLOZYMEILGNIPwNOgEazuBVJcyVjBRL

Download size: 4.3 MB

You may need to restart your computer for this update to take effect.

Update type: Important

qQMphgyOoFUxFLfNprOUQpHS

More information: 

https://hckSLpGtvi.PguhWDz.fuVOl.gov

https://jNt.JFnFA.Jigf.xnzMQAFnZ.edu

Help and Support: 

https://IIKaR.ktBDARxd.plepVV.PGetGeG.lfIYQIHCN.mil

________________________________________________________________________

Did NOT install.  After my MSE definitions updated, I repeated Windows Update.  The above 'important' update did not reappear???

Did MS servers get compromised?

Thank you

Windows for home | Previous Windows versions | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

46 answers

Sort by: Most helpful
  1. Anonymous
    2015-09-30T19:36:15+00:00

    This is true. Unfortunately, that system has indeed already been compromised at least once. http://www.wired.com/2012/06/flame-microsoft-certificate/ 

    That's an inaccurate statement. Microsoft Update was not compromised; Flame used a man-in-the-middle attack and a bogus certificate.

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2015-09-30T19:11:37+00:00

    Fun Fact: SuperAntiSpyware is junk.  I worked for the company that makes the software (support.com) and they have a division that provides over the phone PC Support.  That department is not allowed to use SuperAntiSpyware..  Their main antimalware is MalwareBytes 1.75...  I wouldn't recommend using a product that the parent company doesn't even put faith into.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2015-09-30T18:59:59+00:00

    It didn't get compromised. 

    Don't panic: Microsoft mistakenly posted a 'test' Windows update patch | ZDNet:

    http://www.zdnet.com/article/microsoft-accidentally-issued-a-test-windows-update-patch/

    A Microsoft spokesperson confirmed Wednesday that it had "incorrectly published a test update" and is in the process of removing it.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2015-09-30T18:58:35+00:00

    Don't panic: Microsoft mistakenly posted a 'test' Windows update patch | ZDNet:

    http://www.zdnet.com/article/microsoft-accidentally-issued-a-test-windows-update-patch/

    A Microsoft spokesperson confirmed Wednesday that it had "incorrectly published a test update" and is in the process of removing it.

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2015-09-30T18:55:35+00:00

    Same here.  Looks to be exact same pieces as well.  On mine, last update I went through was 9/28 when everything was reported as "up to date", which had installed Definition Update for Windows Defender KB915597 (Definition 1.207.973.0)

    Today I saw two updates available - Definition Update for Windows Defender KB915597 (Definition 1.207.1296.0) and this Language Pack.  I disabled the language pack and marked it "hidden".

    I also ran SuperAntiSpyware and MalwareBytes anti-malware with databases updated this morning and they found nothing.  I'll run Windows Defender and FortiClient next.

    gYxseNjwafVPfgsoHnzLblmmAxZUiOnGcchqEAEwjyxwjUIfpXfJQcdLapTmFaqHGCFsdvpLarmPJLOZYMEILGNIPwNOgEazuBVJcyVjBRL

    Download size: 4.3 MB

    You may need to restart your computer for this update to take effect.

    Update type: Important

    qQMphgyOoFUxFLfNprOUQpHS

    More information: 

    https://hckSLpGtvi.PguhWDz.fuVOl.gov

    https://jNt.JFnFA.Jigf.xnzMQAFnZ.edu

    Help and Support: 

    https://IIKaR.ktBDARxd.plepVV.PGetGeG.lfIYQIHCN.mil

    Was this answer helpful?

    0 comments No comments