Windows 10 Windows Update "Facilitator" KB4056254/KB4023057

terrym

Well-Known Member
#1
Abbreviations
W10 = Initial Release Windows 10 (v15xx
W10AU = Windows 10 Anniversary Update (v16xx
W10CU = Windows 10 Creators Update (v17xx
W10A8 = Windows 10 April 2018 Update (v18xx

WUP = Windows Update

Resources
AskWoody.com

########

Microsoft is at it again, trying to force-feed us the latest version of Windows. Updates KB4056254 + KB4023057 were re-released in June/July (2018) after first appearing in February. These two co-related updates are: Windows Update "Facilitator" and Update Assistant(V2). At the end of this post you will find a list of the files, services and scheduled tasks installed by the Feb updates -- I'm not sure of June/July details.

Together, these two updates are responsible for the annoying (and sometimes fatal) full-screen popup that interrupts what you are doing and tells you you MUST upgrade. By fatal I am referring to what happened in February when some users were FORCED to upgrade with no way to cancel.

February: these two updates, if installed, nagged the user to upgrade to W10CU v1709 and so should have appeared only if you were on v15xx, v16xx or v1703. Unfortunately, this invasive popup sometimes ignored the user's settings and started force installing! Microsoft soon after admitted this was 'human error' on their part.

June/July: I have no firsthand knowledge of this iteration because I have blocked both updates and plan to keep them blocked for the near future. My guess is their purpose is to force-feed us W10A8 v1803.

=> Why Have This "Facilitator"?

Here is Microsoft's stated purpose for the Facilitation Service:

"This update includes files and resources to address issues affecting background update processes in the Windows Update servicing stack. Maintaining Window Update service health and performance helps ensure that quality updates are installed seamlessly on your device and help to improve the reliability and security of devices running Windows 10."

I don't believe for a minute that it has anything to do with improving WUP; it's sole purpose is to nag you until you upgrade. FLASH: On 12 July 2018 AskWoody reported: KB 4023057 — an "update reliability" patch for older Win10 versions — has appeared again. Unless you want Microsoft to push you to a new version of Windows, you don’t need or want it — it only shuffles more telemetry data off to Microsoft.

=> How The "Facilitator" Works

It is important to note that once KB4056254 and KB4023057 are installed, they cannot be uninstalled.

The "Facilitator" is made up of three basic components


1. osrss Service

This System Service has the name "OS Remediation System Service". The service cannot be deleted, Disabled or even Stopped! It will always show Running, but does nothing if the UpdateAssistant Tasks are disabled.

2. UpdateAssistant

This is an executable which is invoked by the scheduled Tasks. By all accounts, this pops up the invasive window that tells you if you DON'T install the updates, life as you know it will end. To make things even worse, you can't do anything until this popup is dismissed. Hopefully, you will have a 'Skip' option which will do just that!

I believe UpdateAssistant can be uninstalled via Control Panel but will be re-installed by Microsoft. The only way to control it is by disabling the Tasks that invoke it.

3. UpdateAssistant Tasks

As of the February drop, there are four tasks that invoke UpdateAssistant at various times. All four Tasks (which are listed at the end of this post) must be !Disabled! Fortunately, so far Microsoft has not re-enabled these Tasks behind our backs. Let's hope this continues!

=> How to Avoid Installing These Updates

You probably installed these updates back in February. And, you got at least KB4056254 in June unless, if you're like me, you blocked them. In the off chance you haven't installed them, see my article:

How To REALLY Block Windows 10 Updates and Upgrades

If you have installed one or both of these updates, your only recourse is to disable the *four* Scheduled Tasks. Note: There were 4 tasks in the February drop; June/July may be different. Be sure and Disable any Task having a name starting with 'UpdateAssistant'.

############
Associated with these evil updates:

file=>C:\Windows\UpdateAssistant\UpdateAssistant.exe -access denied-
file=>C:\Windows\UpdateAssistantV2\UpdateAssistant.exe

service=>osrss "OS Remediation System Service"

Task Scheduler Library > Microsoft > Windows > Update Orchestrator
task=>UpdateAssistant
task=>UpdateAssistantAllUsersRun
task=>UpdateAssistantCalendarRun
task=>UpdateAssistantWakeupRun
 


Neemobeer

Windows Forum Team
Staff member
#2
Updates the most simple and free way to protect your device, your data and the rest of the Internet from malicious activity.
Poor patch management (Ex: disabling updates) is one of the top reasons for device compromise. Any security engineer will tell you this is probably one of the dumbest things you can do.
 


terrym

Well-Known Member
#3
Updates the most simple and free way to protect your device, your data and the rest of the Internet from malicious activity.
Poor patch management (Ex: disabling updates) is one of the top reasons for device compromise. Any security engineer will tell you this is probably one of the dumbest things you can do.
NO IT IS NOT DUMB! It is smart to block worthless updates that are not updates, in this case "updates" that want to force you to upgrade when you don't want to. If not me, listen to AskWoody:

On 12 July 2018 AskWoody reported: KB 4023057 — an "update reliability" patch for older Win10 versions — has appeared again. Unless you want Microsoft to push you to a new version of Windows, you don’t need or want it — it only shuffles more telemetry data off to Microsoft.
 


Neemobeer

Windows Forum Team
Staff member
#4
Askwoody which uses a expired cert for their website. Lets trust our security to a site that can't even update their certs..
1531882398381.png
 


Neemobeer

Windows Forum Team
Staff member
#5
Newer Windows 10 builds are pushed because Microsoft stops supporting older builds and then you suffer from the same problems
 


Last edited:

terrym

Well-Known Member
#7
 


Neemobeer

Windows Forum Team
Staff member
#8
Windows deprecates old builds, so you will no longer get security updates so it does directly affect security patching.
 


Mike

Windows Forum Admin
Staff member
Premium Supporter
#9
####
I'LL SAY IT AGAIN AS SOME ARE NOT LISTENING
KB4056254 and KB4023057 are **NOT** Security Patches


THEIR PURPOSE IS TO FORCE YOU TO UPGRADE TO THE LATEST VERSION OF WINDOWS. HAS NOTHING TO DO WITH SECURITY.
Microsoft is moving away from "Delta Updates" (cumulative updates) to "Express Updates" that use differential updates, depending on the build/file versions, to mitigate the problem of the cumulative updates getting bigger and bigger over time. There is a great article about this here. Patching Windows Update components can be considered a security update if it facilitates the delivery of future updates that mitigate serious threats. These threats are not just published by Microsoft, but other major corporations and governmental institutions like US-CERT.

If your concern is forced obsolescence, by design, being built into Windows, that has been going on for years. They overdid it with nag screens to upgrade to Windows versions, people complained, and they released optional patches to prevent the upgrade. But ultimately, they do have a time table to phase out updates for earlier versions of Windows. In particular, they are phasing out security updates for prior versions of Windows 10 because these are older builds of the same operating system, which I would estimate, require a very careful and arduous process of maintaining security updates compatible with every single build.

I would suggest re-evaluating why you are so fearful of future updates, especially if they streamline the update process or do not directly have an impact on you financially. If the updates are being distributed for free, and increase the stability of the Windows kernel and its various components, I don't see a problem. I'd also advise against blocking updates for most users, as you are only opening up your machine to potential security risks in the future.
 


terrym

Well-Known Member
#10
People are way misinterpreting what I am saying in this post.

@Mike says: "I would suggest re-evaluating why you are so fearful of future updates ...". I don't know how many times I have to say this: I am not fearful of updates and I apply all Cumulative Updates when safe to do so. In other words, I am generally at the latest Build# within a month of its release.

I am however fearful of two things

1. buggy updates (security or otherwise) that break Windows

Microsoft has recently confirmed that this month’s (July 2018) update rollout includes a botched patch that breaks .NET Framework and apps, and Windows 10 devices are affected as well.

=> for example Cumulative Update KB4345420 for Fall Creators Update (version 1709)

2. updates that are **NOT** security updates

KB4056254/KB4023057 (Windows Update "Facilitator" and Update Asst V2) are **NOT** Security Updates; their sole purpose is to force you to upgrade Windows. NO ONE has any reason to install them. Unfortunately most people will. If you don't want to be hounded, Disable the Scheduled Tasks detailed in this post.
 


stueycaster

Millennium Celebration Award Winner
Premium Supporter
#11
The only one misinterpreting anything here is you @terrym. Microsoft is not an evil entity. Windows is the most widely used operating system on Earth. Therefore they receive a constant barrage of threats from evil entities that are trying to rip people off. Keeping the O/S updated to the latest version is the first line of defense against them.

@Neemobeer , @Mike and Microsoft are far more trustworthy than AskWoody.com.
 


This website is not affiliated, owned, or endorsed by Microsoft Corporation. It is a member of the Microsoft Partner Program.
Top