Is Windows File Protection enabled by default?
Windows File Protection scanning is not enabled by default. If you have not run SFC.EXE, and Windows File Protection is not invoked by a group policy, Windows File Protection will not scan your system, the hashes on protected system files will not be compared with those in the catalog, and there is essentially no danger of newly installed (security or other) hotfixes being replaced with older versions.