📜 ⬆️ ⬇️

Samsung software can intentionally disable Windows Update

This is what Patrick Barker discovered during an investigation into the Samsung laptop incident.
As Patrick writes in his blog, he was approached by a Samsung laptop user through the Sysnative forum, who had a strange problem with the work of Windows Update services. In the course of researching the system for viruses, a specialist who, by the way, is Microsoft MVP , revealed an executable file responsible for disabling the update service. To his surprise, it turned out to be a file with an unambiguous name Disable_Windowsupdate.exe and a digital signature from Samsung, which is stored in the C: \ ProgramData \ Samsung folder.



During the investigation, Barker discovered that the Samsung SW Update update system had downloaded and launched this file for execution. He, in turn, made changes to the registry, tightly disabling the Windows Update service.


')
When contacting Samsung technical support, he was reluctant to, but confirmed that their software can really disable receiving official Windows updates:
TP employee : Hello, thank you for contacting Samsung technical support. How can I help you?
Barker : Hello, I have a question regarding your software update, SW Update.
TP employee : Please ask a question.
TP employee : I will be happy to help you.
Barker : Thank you! Here is my question: why does this program actively monitor the registry and intentionally disable the Windows Update Center, forcibly disabling it?
Employee TP : SW Update Tool helps automatically detect hardware on a laptop and installs drivers for them. This tool does not directly affect the registry of your laptop or Windows updates.
Barker : I'm afraid you're wrong. The update system downloads the exe file named "Disable_Windowsupdate.exe"
Barker : When SW Update is installed, Windows Update turns off. If it is turned on initially or set up manually, then Windows Update will be re-disabled after reboot.
Barker : If your SW Update is removed, then after the restart Windows Update still remains disabled.
TP employee : Thank you for waiting. I will come back to you in a minute.
Barker : Of course.
TP Officer : When you turn on Windows Update, it will install standard drivers for all laptop hardware that may not work. For example, if your laptop has USB 3.0, the ports may not work after installing regular updates. Therefore, to prevent this from happening, our tool will prevent the Windows update.

The hash of the Disable_Windowsupdate.exe file is:
x86 MD5 - 3727acd09814c0d5ce8fd3d6be705254
x64 MD5 - d0a3a1c266845ef1e2cdf65c226facae
x86 SHA-256 - 61da7461e8a60a20e9d2b595edff89a0898c8f2d47d2be847c8a7ceff0fc4bd4
x64 SHA-256 - 7b9547acf8b3792b48fe5a02f7d5f3e0dfba8e57055d60f479bb8adfed99871c

UPD
The register has managed to get a rather strange comment from Samsung:
It is not true that we are blocking the update of the Windows 8.1 operating system on our computers. As part of our commitment to satisfying user needs, we give them a choice, in case they want to update Windows software.
We take product safety very seriously and urge all Samsung customers to contact us directly at 1-800-SAMSUNG with questions or concerns.

UPD2
According to several news articles, Samsung has made another statement:
Samsung is committed to security and we still value our partnership with Microsoft. Within a few days, we will release a patch through our update system to return to the recommended Windows automatic update settings.

Source: https://habr.com/ru/post/261085/


All Articles