Eye on Security: Windows Ransomware, DLL Hole, Malware, and More
- Dr. Roy Schestowitz
- 2010-09-03 06:46:58 UTC
- Modified: 2010-09-03 06:46:58 UTC
Summary: Menaces and unpleasant 'niceties' that only affect users of Windows this week
●
Russian cops cuff 10 ransomware Trojan suspects [
via]
PCs infected by the WinLock Trojan at the centre of the scam were rendered unusable because the malware disabled key Windows components. More embarrassingly pornographic images were displayed on compromised machines, IDG adds.
●
Polymorphic ransomware tops malware charts
Ransomware variant TotalSecurity is topping the malware charts, according to the latest threat report from security firm Fortinet.
August was the biggest comeback month since March for TotalSecurity, which locks out applications and data, and then demands a ransom to restore access.
●
Microsoft Releases 'Fix It' for DLL Hole
The DLL security vulnerability first grabbed headlines in August when a Slovenian security research firm pointed out that, under some circumstances, a malicious hacker could deploy a booby-trapped DLL file into a directory where Windows will load it, potentially granting the attacker control over the system. But it later surfaced that a U.S. security researcher had warned Microsoft about the DLL issue almost a year before, and had even published an academic paper on the threat last month.
●
Google Code hosting malware-spreading project
Google Code's project hosting feature has occasionally been used by malicious individuals for storing and spreading malware.
[...]
After this discovery was made public, Google removed the offending project. But this instance shows that the company must find a better way of detecting malware hosted on its sites.
●
University loses nearly 1 million dollars to malware
Thieves appear to have stolen the funds from University of Virginia after compromising a computer belonging to the University's Financial Controller. Malware intercepted the Online Banking Credentials for the University's Bank accounts and initiated a fraudulent wire transfer for $996,000 to a Bank in China.
●
25 percent of Windows malware now targets USB storage devices
In a survey of small businesses, PandaLabs discovered that 48 percent had been victims of malware in the past year. Of those businesses infected, 27 percent were able to verify that a compromised USB device was at the root of the issue.
●
New malware detects browser, shows fake malware warning page
While the malware is a pretty good attempt, it's not perfect. The goal is to get the user to download and install something, shelling out some cash in the process, which neither of the three browser vendors would ever recommend. The Firefox warning page, meanwhile, has an obvious typo ("Get me our of here"). In addition, it's suspicious that a webpage is going out of its way to tell you it is protecting your purchase. It's also not hard to check that the supposedly detected files do not actually exist on the user's computer. All of these missteps should raise red flags immediately; having said that, we've still not before seen this level of detail and effort from the bad guys.
●
Heartland pays another $5.4m for malware infection
The United States' fourth largest credit card payments processing company Heartland Payment Systems has agreed to pay a US$5 million ($5.4 million) settlement to its financial services customer Discover over a data breach caused by a malware infection.
Heartland processed card payments for Visa, Mastercard and other financial service providers to the tune of US$70 billion in 2009.
●
Rogue Win7 AV Copies the Microsoft Security Essentials Site
There are downsides to market success, and in the case of Microsoft Security Essentials is that attackers build malware designed to piggy-back ride the free security solution from Microsoft.
Recent Techrights' Posts
- Slopwatch: Linuxsecurity, WebProNews, and Google News Boosting Slopfarms as 'News'
- People who don't recognise the slopfarms and don't know which sites are fake would struggle to understand what's really going on
- Links 28/06/2025: Hardware/GPU Wars, GAFAM Throws Money (Borrowed Cash) at Hopeless Slop Pipe Dream
- Links for the day
- Gemini Links 28/06/2025: Shellshock and Network UPS Tools
- Links for the day
- Links 28/06/2025: The Age of Integrity and FreeBSD Foundation Added John Baldwin as Board Member
- Links for the day
- Fedora 44
- IBM now does to Fedora what it did to RHEL
- Microsoft Already Shaved Off Costs Anywhere It Could. It Was Not Enough.
- Office and Windows aren't "selling" (licences) like they used to
- Scheduled Maintenance Next Week
- Our community is alive and well
- BetaNews: We're Publishing LLM Slop About LLM Slop
- Beta version of a slopfarm?
- 3-Month Updates on Our Complaint to the Solicitors Regulation Authority (SRA)
- In short, the complaint remains open, updated, and is advancing
- IBM Red States Hat (Project 2025): Our "New Thing" Replaces This "Old Thing"
- The new replaces the old. That's how IBM frames it.
- Start X
- Just because something is old does not mean it is bad
- Slopwatch: Linuxsecurity, Google News Slopfarms, and Linux Journal (LJ)
- Today we take a quick look at 3 slopfarms
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Friday, June 27, 2025
- IRC logs for Friday, June 27, 2025
- Links 28/06/2025: "CC Signals" Virtue-Signals to Slop Ponzi Schemes, North Korea Aims for Tourism
- Links for the day
- Links 27/06/2025: International Tensions and Contentions Over Plagiarism Perfumed as "Hey Hi" and "Fair Use"
- Links for the day
- Gemini Links 27/06/2025: Poetry and Censorship by Social Control Media Centralisation
- Links for the day
- Links 27/06/2025: Journalists Under Fire and Microsoft Has Serious Slop Problems
- Links for the day
- X is Dying, But Not XServer/X11. Twitter X.com is Dying.
- People or businesses or government officials (and departments) that still rely on Social Control Media are playing Russian Roulette with their future online
- Wayland is About Less Choice, About Removing Choices, It's Not About Freedom
- IBM insists that it cares about "diversity"
- Keeping Things Accessible
- Gemini Protocol seems to be growing
- Escaping Colonialism (or 'Hegemony') Requires Abandoning GAFAM, Microsoft in Particular
- Europe is already in the process of abandoning Microsoft
- Microsoft Will Shut Down More Studios This Week, Its Media Operatives Will Tell Lies About the Magnitude of the Shutdowns and Layoffs (They Always Do)
- Many people who get counted as "workforce" are "temps" or similar
- Not Much Better Than LLM Slop: Linux Foundation-Funded 'News' Site Writes Linux Foundation 'News', Composed by Linux Foundation Operative, Quoting Linux Foundation Staff
- ...they get paid (sponsored) to produce this spam. Then they call it "journalism".
- What Linux Foundation 'Research' is: Paid Marketing
- What is Linux Foundation 'Research'?
- Annual Southern California Linux Expo (SCALE 22x) 'Bought' by Microsoft and Microsoft Exceeded Sponsorship Limits by Giving Double the Maximum Permitted Amount
- When people get bribed they tend to forget how to utter a simple word: "No."
- No, IBM Does Not Care About People With Disabilities
- "Aktion T4" did not seem to bother Watson
- Microsoft's Financial Problems Mean Shutdowns, Not Just Mass Layoffs
- If the original rumour is true, then expect almost 30,000 Microsoft workers to be let go this year
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Thursday, June 26, 2025
- IRC logs for Thursday, June 26, 2025
- The Netherlands: GNU/Linux Measured at All-Time High
- Are any Dutch cities going to announce dumping Microsoft?
- Gemini Links 27/06/2025: "Interstitial Existence" and Autocorrect
- Links for the day
- EPO Examiners Point Out to the Heads of Delegations in the Administrative Council of the EPO That the "AI Policy" of the Office is Illegal
- "the Central Staff Committee (CSC) asks the Administrative Council to exert its supervisory role and instruct EPO management to enter into genuine dialogue with the staff representation on the AI Policy, to revise the “Leverage AI” target of 90% AI-automated classification in the SP2028 and to put in place the measures supported by staff in the resolution."
- Technical People Need Technical Lawyers
- Technical Litigants in Person (LIPs) have many real and concrete advantages
- 10,000+ Articles in About 20 Months (and How We Got Here)
- More bloat does not beget efficiency and "bells and whistles" tend to have a hidden cost
- French Cities Dumping Microsoft Because They Recognise Software Freedom, Open Standards, GNU/Linux Autonomy
- We hope that more French cities - maybe Paris - will follow Lyon.
- Links 26/06/2025: Illegal Kangaroo Court (UPC) Failing Scandinavia, K-Pop Agencies Abuse People
- Links for the day
- Gemini Links 26/06/2025: AuraGem Twitch Proxy is Back and UI Sluggishness
- Links for the day
- LWN is a Voice of GAFAM (Through Linux Foundation, Their Front Group or Occupying Force Inside Linux)
- remember who the chief editor works for and who sponsors many of the articles
- Links 26/06/2025: Noise Pollution Considered High in Europe, Mass Layoffs Next Week in Microsoft Confirmed, Very Large in Scale and Scope
- Links for the day
- The 'Case' of the Serial Strangler From Microsoft is a Lot of Copypasta (Maybe Also LLM Slop) From the Matthew Garrett 'Case'
- 5RB deserves to know and the matter shall be properly reported in due course (when the time is right)
- EPO Squeezing the Staff - Part II - Office Breaks Rules, Ignores Courts, Defies Justice
- False promises everywhere
- No, I Don't Want Your Latest XYZ, ThankYouVeryMuch...
- Wayland is finally ready?
- China Keeps Breaking Into Microsoft Systems, So for True Sovereignty, Nations Wary of China Need to Dump Microsoft
- Looking at data from Taiwan (not China) and Maharlika (not Philippines, the king is dead and Spain is out), there are encouraging signs
- Linux Journal Wants Ads on Its LLM Slop or Ads as 'Articles'
- it's basically another BetaNews
- How to Kill a Monopoly
- in 10 simple steps
- IBM - Like Microsoft - is a Dying Company and Perishing Brand ("AI" is a Lie and Decoy)
- "Arvind is cutting costs (layoffs, PIPs, forced RTO, etc...) like crazy. IBM offices are closing all over the place in the US."
- "Code of Conduct" Invoked When Fedora and Red Hat Users (Since the 1990s) Don't Want to Use Wayland
- That is IBM "DEI"
- Mozambique: GNU/Linux Rose From 0.5% Last Year to 3% This Year
- what (or how) statCounter is measuring
- Microsoft Layoffs Next Week: About 10% to be Laid Off in Microsoft Gaming (2 Days Before Independence Day), About 20%+ of XBox Staff
- Microsoft is rapidly collapsing
- Next Month Marks 11 Years Since Our In-Depth EPO Coverage
- The same is happening to Microsoft right now
- Free Software Foundation (FSF) Campaigns Against Vista 11, Adds 4 New Associate Members Per Day
- If more people understood the underlying principles, more of them would flock to Free software overnight
- Canonical Seems to Have Culled Some Sources of LLM Slop From Planet Ubuntu
- It's like "junk food", it's not information
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Wednesday, June 25, 2025
- IRC logs for Wednesday, June 25, 2025
- On "Weak Claims"
- For the record, they sent me unjustified threats, repeatedly tried injunctions (censorship)
- EPO Squeezing the Staff - Part I - Burnout and Family Health
- more exceptional circumstances
- This Month's Mail (MX) Server Survey Shows Microsoft at 0.20% "Market Share"
- We need to remind people that desktops and laptops decline (in proportion to other client devices) and at the "back end" GNU/Linux is already dominant and has long been dominant
- Links 26/06/2025: Filespooler Guide and Learning to Code
- Links for the day