-
owdrtn
AskWoody Lounger[…] If your intention is to avoid the Meltdown/Spectre mitigation as a Group B patcher, you should stop updating with the December 2017 Security-only patches because after that even the Security-only patches have M/S mitigation.
@PKCano First things first.. I want to thank you for all the the guidances and experience you’ve been sharing with us on GroupB patching W7 & W81 for so long..I usually manage to figure things on my own with some search and reading, but this Spectre/Meltdown mitigation VS groupB patching got still get me confused … Particularly about the relevence of avoiding installation of Secu-Only patches as recommended on your previous (quoted) post..
As a GroupB patchers (with relatively old and S/M-vulnerable CPUs), I chose to also avoid the current S/M mitigations available…
However, I’m not sure to understand your recommandation to avoid installing any post-dec 2017 monthly Security-Only windows patches, just to avoid the Meltdown/Spectre’s mitigations they contains..
Here’s my point.. From my reading, all of the current S/M mitigations can be disabled from the windows registry entirely.. If that is true.. why skipping any post-Dec2017 monthly security-only patches, which most-likely not contains only Meltdown/Spectre mitigation, but probably many other security resolution not related to Meltdown/Spectre at all as well…
Installing those shouldn’t prevent anyone from removing S/M mitigations afterward..
If so, wouldn’t it be advised to continue installing all of the monthly Security-Only patches just as usual, and instead, neutralize/defuse/remove the patch(KB)-applied M/S mitigations afterward , using either the registry directly.. (or the fabulous Robert Gibson’s “InSpectre” tool, which does just the same.) I’ve tested it personally on a W7 host and a Debian VM Guest (using wine).. both successfully removed all mitigations. All it does is basically applying the Microsoft’s provided Registry manipulations programatically..That way, GroupB patchers can continue installing all and every Monthly Security-Only Patch as usual, while avoiding all of the undesired Meltdown/Spectre’s mitigations at OS-level (I do apply most Software-level mitigations too) (same for Hardware-Lvl.. ie: I did flash my ROM’s BIOS-UEFI firmware with my vendor-supplied M/S mitigation’s CPU-Microcode update)
Sorry for my english.. and the long post.. but I hope you get my point and provide me with some updated guidance/insight
TLDR:: Why not installing all of the monthly security-only patches as usual (including post-Dec2017), and defuse all of the mitigations afterward ?
thanks !
-
owdrtn
AskWoody LoungerApril 23, 2019 at 8:21 am in reply to: 1000003: Manually install the latest Microsoft root certs #838468@Rydan
However, i’m not sure to understand why not simply download the two cab file “authrootstl.cab” & “disallowedcertstl.cab” @
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab & http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cabThen just extract the two stl files from those and install both stl files using either:
the right-click context menu"Install CTL"
or certutil:certutil -addstore -f root authroot.stl disallowedcert.stl
?Also, how one would goes updating the “Trusted Publisher” & the “Intermediate CA” stores ? are those not relevent/applicable to update as well ?
-
owdrtn
AskWoody LoungerApril 23, 2019 at 5:22 am in reply to: 1000003: Manually install the latest Microsoft root certs #829250As rootsupd.exe was deprecated in favor of WU auto update and Enterprise CA…
You could get the trusted and untrusted sst files and import those.
(there are different options)Awesome find @Rydan.. works flawless, thanks !
Where have you found your way to the shell scripting of this ? I couldn’t find anything on that matter from the provided online docu.Thumbs up !!
-
owdrtn
AskWoody LoungerMore likely, a fairly long and adventurous one with many twists and turns of fortune have taught me to be cautious, but to avoid being scared of anything for too long.
Made my day..
1 user thanked author for this post.
-
owdrtn
AskWoody LoungerFebruary 19, 2019 at 10:12 pm in reply to: Comments on AKB 2000003: Ongoing list of "Group B" monthly updates for Win7 and 8.1 #329487Sorry in advance for such a blasphemic question, but really.. it’s still unclear to me whether or not GroupB are prescribed to integrate either of those two KB into their Gold Windows 7 x64 Installer Media Image:
- Service Pack 1 (KB976932)
- Enterprise Rollup Update (KB2775511)
- Convenience Rollup Update (KB3125574)
It does seems clear to me that SP1 is a sure go, but is it for GroupB, without any post-deploy “defusing” operations ?
-
owdrtn
AskWoody LoungerMay 22, 2017 at 4:09 pm in reply to: (Closed) Comments on AKB 2000003: Ongoing list of "Group B" monthly updates for Win7 and 8.1 #117721please read my post entierely.. this is not persistent
-
owdrtn
AskWoody LoungerMay 22, 2017 at 3:26 pm in reply to: (Closed) Comments on AKB 2000003: Ongoing list of "Group B" monthly updates for Win7 and 8.1 #117704The instructions to put it back can be found at this Microsoft website […]
Thanks for sharing.
that script create a new service however.
The registry modif provided on bottom-most of the article is only persistant on WUA version 7.0.6000 and earlier. Are you aware of any registry workaround to it persistant on later version as well ? -
owdrtn
AskWoody LoungerMay 21, 2017 at 11:13 pm in reply to: 2000007: Turning off the worst Windows 7 and 8.1 snooping #117382Turn off Windows Defender Cloud-based Protection and Automatic sample submission in Settings > Update & security > Windows Defender.
Don’t see any such thing on Win7 ? Could this apply only to later OS ?
1 user thanked author for this post.
-
owdrtn
AskWoody LoungerDownload KB3020369, KB3138612, KB3177467 and KB3172605
[…]*confused* Ain’t 30220369 superseded by 3177467 as reported in MS Catalog (shown below).. To add to the confusion, the SP2 KB article still mention 3020369 as the prerequisite..
-
owdrtn
AskWoody LoungerMay 21, 2017 at 8:20 pm in reply to: 3125574 – Convenience Rollup (aka SP2) … Still No-Go? (&GroupB) #117356Thanks for the reply PK,
There’s so much FUD/confusion surrounding this kb.. But considering it could saves me from installing ~123 individual KBs It definitely worth figuring out..
The general consensus here was it was for Enterprise use, no the general public.
It’s applicable for Ultimate as well.
Also, maybe as a reminder, or some trigger to further discussion, don’t you remember @Gonetoplaid’s post from earlier in May, which was a list including all of the individual KBs included within SP2(3125574).
Among those were:- 5 are known/believed to contains telemetry: (KB3118401, KB3080149, KB3075249, KB3068708, & KB2999226).
- 5 are known/believed to cause/potentially cause issues: KB3102429, KB3133977, KB3080079, KB3006137, KB2970228
-
owdrtn
AskWoody LoungerMay 21, 2017 at 5:20 pm in reply to: 3125574 – Convenience Rollup (aka SP2) … Still No-Go? (&GroupB) #117300Some answer would be so appreciated..
I’ve lost track of the actual current recommendation on that infamous KB …OS: Win7x64 Ultimate
Servicing stragegy: Group-B-hydrid (installed October 2016 RU), and maybe SP2, if I can get some insight of you guys..Thanks
-
owdrtn
AskWoody LoungerMay 15, 2017 at 11:19 pm in reply to: (Closed) Comments on AKB 2000003: Ongoing list of "Group B" monthly updates for Win7 and 8.1 #115578 -
owdrtn
AskWoody LoungerMay 15, 2017 at 11:04 pm in reply to: (Closed) Comments on AKB 2000003: Ongoing list of "Group B" monthly updates for Win7 and 8.1 #115572I was referring to the Catalog. I guess we can’t rely on it anymore just as WU..
How have you found out about KB4012212, KB4015546 & KB4019263 to supersede 3212642 ? -
owdrtn
AskWoody LoungerAs a single-user consumer (in contrast to some corporate/sysadmin-context), I’ve never really gave an try at MS’s WSUS. It’s only recently, that I moved from using the basic idiot-proof (now “trouble-sure”) WU, to some mixed use of the Catalog (MUC) & their Bulletins .
But the more I hear about WSUS (along with other similar “more Corporate-Targeted Windows update management solutions), the more I feel like I should step-in, or at the very least give those a try.
But having not much experience with servers (yet open to), I’d be tempted to try the unofficial offline version WSUS Offline first.
I’d love to know your insight on this ? Sounds more like a fair “GO” or “NO-GO” to you guys ?Everyone’s opinion are much appreciated, just try to back your claim with some source when possible.
-
owdrtn
AskWoody LoungerMay 13, 2017 at 12:37 pm in reply to: (Closed) Comments on AKB 2000003: Ongoing list of "Group B" monthly updates for Win7 and 8.1 #114858ON-GOING
Culprit might be my limited english here, i’ll have a look at the distinction of the “ongoing” word vs “up-to-date” . Thanks for specifying.
Just want to point out however, that I didn’t refer to the catalog’s availability of those KB listed here, but their relevence in regards to their “supersedence” & “B-Group” properties …
![]() |
Patch reliability is unclear, but widespread attacks make patching prudent. Go ahead and patch, but watch out for potential problems. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Sycophancy in GPT-4o: What happened
by
Alex5723
4 hours, 36 minutes ago -
How can I install Skype on Windows 7?
by
Help
3 hours, 18 minutes ago -
Logitech MK850 Keyboard issues
by
Rush2112
2 hours, 9 minutes ago -
We live in a simulation
by
Alex5723
18 hours, 43 minutes ago -
Netplwiz not working
by
RetiredGeek
5 hours, 18 minutes ago -
Windows 11 24H2 is broadly available
by
Alex5723
1 day, 7 hours ago -
Microsoft is killing Authenticator
by
Alex5723
14 hours, 41 minutes ago -
Downloads folder location
by
CWBillow
1 day, 13 hours ago -
Remove a User from Login screen
by
CWBillow
9 hours, 13 minutes ago -
TikTok fined €530 million for sending European user data to China
by
Nibbled To Death By Ducks
1 day, 4 hours ago -
Microsoft Speech Recognition Service Error Code 1002
by
stanhutchings
1 day, 4 hours ago -
Is it a bug or is it expected?
by
Susan Bradley
1 day, 9 hours ago -
Image for Windows TBwinRE image not enough space on target location
by
bobolink
1 day, 3 hours ago -
Start menu jump lists for some apps might not work as expected on Windows 10
by
Susan Bradley
3 hours, 22 minutes ago -
Malicious Go Modules disk-wiping malware
by
Alex5723
1 day, 17 hours ago -
Multiple Partitions?
by
CWBillow
1 day, 18 hours ago -
World Passkey Day 2025
by
Alex5723
2 days, 11 hours ago -
Add serial device in Windows 11
by
Theodore Dawson
3 days, 2 hours ago -
Windows 11 users reportedly losing data due forced BitLocker encryption
by
Alex5723
1 day, 3 hours ago -
Cached credentials is not a new bug
by
Susan Bradley
3 days, 7 hours ago -
Win11 24H4 Slow!
by
Bob Bible
3 days, 7 hours ago -
Microsoft hiking XBox prices starting today due to Trump’s tariffs
by
Alex5723
3 days, 4 hours ago -
Asus adds “movement sensor” to their Graphics cards
by
n0ads
3 days, 9 hours ago -
‘Minority Report’ coming to NYC
by
Alex5723
3 days, 6 hours ago -
Apple notifies new victims of spyware attacks across the world
by
Alex5723
3 days, 18 hours ago -
Tracking content block list GONE in Firefox 138
by
Bob99
3 days, 17 hours ago -
How do I migrate Password Managers
by
Rush2112
3 days, 1 hour ago -
Orb : how fast is my Internet connection
by
Alex5723
3 days, 3 hours ago -
Solid color background slows Windows 7 login
by
Alex5723
4 days, 6 hours ago -
Windows 11, version 24H2 might not download via Windows Server Updates Services
by
Alex5723
4 days, 4 hours ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.