automatic updates for Windows: =virus danger?

Microsoft sends updates to Windows users. Till now, I never paid much attention to them, and let them install automatically,trusting Bill Gates to keep me from harm.

Now, I’ve changed my settings to notify me first and ask permission before proceeding with a download.**

As a result, I periodically get little messages that ask me to click yes and allow the download. But these messages remind me of those messages in spam and phishing emails that I never click on. (I’m no techie geek,but I know the old rule not to click on links that re-route me to a site I dont know.)

So my question is: is it possible (or likely) for a virus writer to send me a message that looks just like a valid update from Microsoft, and then install itself (as a virus) on my computer?

Also: the update messages don’t arrive as emails, so how do they get to me?
Can anyone other than Microsoft send them to me?

I use Windows XP Home Edition, Service Pack 2

**the reason: I don’t want the new IE7 browser to install itself and screw up my old habits. Installing IE7 is automatic and apparently cannot be blocked by ordinary methods (i.e selecting the “ask me first” option) , so I downloaded a program from this site that is supposed to be able to block the IE7 installation.

The main question I can’t answer as I can very well see some virus writer hijacking the Microsoft update process to install his own little creations.

As regards not installing IE7, you can go to the Windows Update site and set it to not install IE7 on your machine.

can you be more specific?
I couldn’t find anything at the Update site about not installing IE7.

OOPS–I just found the link:
http://www.microsoft.com/downloads/details.aspx?FamilyID=4516A6F7-5D44-482B-9DBD-869B4A90159C&displaylang=en

But the link I gave in my OP apparently uses the same info in a more friendly way.

I don’t know anything about the program you installed, but when the balloon popped up to tell you that you had some items to be downloaded and you saw IE7 all you had to do was uncheck it and tell it not to remind you again.