Update.Microsoft.com.Fixme

CompuNerd

New member
Local time
12:06 PM
Messages
1
Hello, I have been dealing with this issue for several days now ever since Microsoft removed XP support from their list of supported product and I wanted to see if anyone knows what it means. First of all, the details of my setup. I have a Firewall which is protecting my AD domain network. This is a closed network with no servers on the other side of the firewall and no DMZ. It all started last week when I began to see an alert for DNS queries in the firewall logs. I thought I might have been the victim of a DNS attack, so I analyzed the packets. What surprised me is what I found in the packets and the main reason I even considered posting here. It seems it is coming from Windows Update. Of course they are Win 7 boxes since I am posting here. The outgoing query had this as a hex dump: "*.......update.microsoft.* *com.nsatc.net......!....* The incoming responses from the ISP's DNS server were slightly different: "*.......update.microsoft.* *com.nsatc.net......!....* *...o...admin.!.fixme.exa* *mple.com.SE....*0.....6.*" Does anyone have any idea what the "fixme" means inside of the hex dump? It looks to be the cause of the alerts as the "example.com" inside of the packet registers as an attack signature. Something is obviously wrong, but I am not sure where to start looking. Should I contact my ISP or do I need to do something to the configuration of automatic updates for the workstations? All searches on the internet for anything even remotely resembling this have turned up empty. Again, this all started after Microsoft changed their updates to no longer support XP. I would really appreciate any insight I can get here since it is about to drive me insane. Thanks
 

My Computer

Computer type
PC/Desktop
OS
win 7 pro 32 bit

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custome Built
OS
Microsoft Windows 7 Ultimate 64-bit 7601 Multiprocessor Free Service Pack 1
CPU
Intel(R) Core(TM) i7 CPU 950 @ 3.07GHz
Motherboard
ASUSTeK Computer INC. SABERTOOTH X58 (LGA1366)
Memory
16.0GB Dual-Channel DDR3 @ 534MHz (8-8-8-20)
Graphics Card(s)
1023MB NVIDIA GeForce GTX 650 (EVGA)
Sound Card
(1) NVIDIA High Definition Audio (2) High Definition Audio
Monitor(s) Displays
HP W2072a LED Backlit
Screen Resolution
1920x1080@60Hz
Hard Drives
(1) SAMSUNG MMCRE28G5MXP-0VB SCSI Disk Device
(2) ST1000DM 003-1CH162 SCSI Disk Device
(3) WDC WD10EURX-73FH1Y0 SCSI Disk Device
PSU
XION XON-1000P14F
Cooling
Fans
Antivirus
Windows Security Essentials
Browser
Mozilla Firefox
Other Info
BIOS Version/Date
American Megatrends Inc. 1402, 8/9/2012
SMBIOS Version 2.5
Back
Top