Eye on Security: Windows Ransomware, DLL Hole, Malware, and More
- Dr. Roy Schestowitz
- 2010-09-03 06:46:58 UTC
- Modified: 2010-09-03 06:46:58 UTC
Summary: Menaces and unpleasant 'niceties' that only affect users of Windows this week
●
Russian cops cuff 10 ransomware Trojan suspects [
via]
PCs infected by the WinLock Trojan at the centre of the scam were rendered unusable because the malware disabled key Windows components. More embarrassingly pornographic images were displayed on compromised machines, IDG adds.
●
Polymorphic ransomware tops malware charts
Ransomware variant TotalSecurity is topping the malware charts, according to the latest threat report from security firm Fortinet.
August was the biggest comeback month since March for TotalSecurity, which locks out applications and data, and then demands a ransom to restore access.
●
Microsoft Releases 'Fix It' for DLL Hole
The DLL security vulnerability first grabbed headlines in August when a Slovenian security research firm pointed out that, under some circumstances, a malicious hacker could deploy a booby-trapped DLL file into a directory where Windows will load it, potentially granting the attacker control over the system. But it later surfaced that a U.S. security researcher had warned Microsoft about the DLL issue almost a year before, and had even published an academic paper on the threat last month.
●
Google Code hosting malware-spreading project
Google Code's project hosting feature has occasionally been used by malicious individuals for storing and spreading malware.
[...]
After this discovery was made public, Google removed the offending project. But this instance shows that the company must find a better way of detecting malware hosted on its sites.
●
University loses nearly 1 million dollars to malware
Thieves appear to have stolen the funds from University of Virginia after compromising a computer belonging to the University's Financial Controller. Malware intercepted the Online Banking Credentials for the University's Bank accounts and initiated a fraudulent wire transfer for $996,000 to a Bank in China.
●
25 percent of Windows malware now targets USB storage devices
In a survey of small businesses, PandaLabs discovered that 48 percent had been victims of malware in the past year. Of those businesses infected, 27 percent were able to verify that a compromised USB device was at the root of the issue.
●
New malware detects browser, shows fake malware warning page
While the malware is a pretty good attempt, it's not perfect. The goal is to get the user to download and install something, shelling out some cash in the process, which neither of the three browser vendors would ever recommend. The Firefox warning page, meanwhile, has an obvious typo ("Get me our of here"). In addition, it's suspicious that a webpage is going out of its way to tell you it is protecting your purchase. It's also not hard to check that the supposedly detected files do not actually exist on the user's computer. All of these missteps should raise red flags immediately; having said that, we've still not before seen this level of detail and effort from the bad guys.
●
Heartland pays another $5.4m for malware infection
The United States' fourth largest credit card payments processing company Heartland Payment Systems has agreed to pay a US$5 million ($5.4 million) settlement to its financial services customer Discover over a data breach caused by a malware infection.
Heartland processed card payments for Visa, Mastercard and other financial service providers to the tune of US$70 billion in 2009.
●
Rogue Win7 AV Copies the Microsoft Security Essentials Site
There are downsides to market success, and in the case of Microsoft Security Essentials is that attackers build malware designed to piggy-back ride the free security solution from Microsoft.
Recent Techrights' Posts
- Georgia Institute of Technology (Georgia Tech) Formally Announces Upcoming Richard Stallman Talk
- Room 100, Scheller College of Business
- The four freedoms and GNU/Linux naming controversy, by Akira Urushibata
- Social control media owned and run by 'broligarchs' keeps attacking RMS for insisting on names that include GNU
- Open Source Initiative (OSI) Not Doing Its Job, Instead It's Promoting Microsoft Ponzi Schemes
- it participates in Microsoft's Ponzi scheme, which helps Microsoft distract from or excuse the mass layoffs
- The Register MS: Installing Free Software on Your Device is 'Sideloading'
- This is a form of propaganda
- Mozilla's Assisted Suicide, Assisted by GNOME
- Firefox is meant to get better all the time, but instead it gets worse
- Frankly Getting Sick of Slop About "AI" (Slop)
- Calling everything out there "AI" serves nobody and nothing but the Ponzi scheme
-
- Gemini Links 08/01/2026: Potentiometer Calculator, Power Outages, Why You Should Abandon Discord for IRC (e.g. Ergo), and Formatting Gopher Posts
- Links for the day
- Links 08/01/2026: More Software Patents Squashed, White House Repeats Misinformation From the Kremlin
- Links for the day
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Wednesday, January 07, 2026
- IRC logs for Wednesday, January 07, 2026
- The Free Software Foundation (FSF) Looking to Add Associate Members
- "Celebrate '26 by helping us reach our New Year's goal before Jan. 16: join as an associate member today. You will help the FSF remain strong and independent to empower technology users everywhere. Join us today and help us reach our goal of 100 new associate members!"
- Only Google is Still Spreading Lots of Slopfarms' Fake News and Plagiarism About Linux
- 2 days' worth of Google News spewing crap out about "Linux"
- Links 07/01/2026: Europe's 'Binding Commitments' on Ukraine's Security, "Venezuelan Leaders Project Independence"
- Links for the day
- Gemini Links 07/01/2026: Smart Toaster and Social Control Media Fatigue
- Links for the day
- Projection Tactics - Part II: Causing "Serious Harm" to Many People (Even Animals)
- Narcissists and sociopaths are like that
- Even Microsofters Now Speak About Microsoft Reportedly Planning to Sack 10% of Its Staff (as Early as This Month, or 2 Weeks From Now) as Real Income Falls
- Microsoft buying from Microsoft isn't real income, it is accounting fraud
- Crans-Montana, Le Constellation: journalists, victims' families, ProtonMail users at risk, police raids
- Reprinted with permission from Daniel Pocock
- GNU/Linux Reaches All-Time High in Tanzania
- This month (and year) GNU/Linux is measured at an all-time high there, based on the data that statCounter can see
- Links 07/01/2026: Microsoft ChatGPT Killing People and Microsoft "Github monopoly is destroying the open source ecosystem"
- Links for the day
- Mass Layoffs in Microsoft's XBox Soon, Just Like We've Said for Months
- IBM and Microsoft are heading in a similar trajectory and are hiding how bad things are using similar tactics
- Now It's a Mainstream Media (MSM) Story: Microsoft Layoffs Coming, They'll be Vast (and They Blame "AI", As Usual!)
- the books were cooked (accounting fraud) to hide what really went on
- Stick to the Science, the Facts, the Observable Reality
- Science is at the heart of this site
- Africa's Search Market Has Been Unfavourable to Microsoft
- In Africa, as we've just noticed, Bing is moving down, even more sharply this year
- Slideshare is Slop
- Be sure fools will rewrite history online
- Gemini Links 07/01/2026: Looking at 2026, Linux Anti-Minimalism, Diode Function Generators, and Inkscape
- Links for the day
- Projection Tactics - Part I: What is "Serious Harm"? Or Whose?
- the most serious harm was done to us
- Links 07/01/2026: More Signs XBox the Console is Dead/Dying, Convicted Felon Repeats Threats of Greenland Annexation
- Links for the day
- EPO People Power - Part XXVII - Science- and Principles-First Journalism About Issues That Matter
- journalism became so shallow that nowadays it can be replaced by bots
- Media Gaslighting Dooms the Media
- this "AI" gaslighting is done because publishers get paid to do so
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Tuesday, January 06, 2026
- IRC logs for Tuesday, January 06, 2026
- Gemini Links 06/01/2026: Collective Responsibility, Pico2DVI, and TV Detox
- Links for the day
- Microsoft Loves Freedom, Democracy... and Linux? No, Microsoft Laying Off Because "Microsoft Loves Linux" Was Failed Posturing, Its Former Staff Moves to GNU/Linux
- "What are the running totals for IBM and Microsoft layoffs?"
- GNU/Linux at 4% "Market Share" (Even According to Steam Survey)
- Another milestone
- Links 06/01/2026: Neglect of the Elderly, Abandonment of International Laws
- Links for the day
- Links 06/01/2026: More Reports Point to Mass Layoffs at Microsoft (Later This Month), Greenland/Denmark Cautions the Dictator Who Illegally Invaded Venezuela
- Links for the day
- Internet Policy/Net Reality: You Must Never Ever Rely on Google (no "S.E.O." Either)
- Stack Overflow is dying
- Ahead of Mass Layoffs Microsoft Tries to Rebrand or Redefine XBox (Because the XBox is Tentatively Dead)
- 2026 will be the last year of XBox in all likelihood
- Richard Stallman (RMS) Announces His Georgia Talk 2.5 Weeks in Advance
- A lot earlier than usual
- Dr. Andy Farnell on Technology That Harms People (and Lack of Regulation Which is Needed to Address This Problem)
- Dr. Farnell's article is long but well worth reading
- GNU/Linux Rising to 5% in Cameroon and It's Hardly the Exception
- "AI" is just a smokescreen as losses pile up
- Rumours: Microsoft to Lay Off 12,500-25,000 Workers Soon (Tentatively Wednesday, 15 Days From Now)
- "Layoffs are coming third full week of Jan. Likely 21st but these things can move around a bit based on last minute developments."
- EPO People Power - Part XXVI - European Media Has Become Part of the Problem
- it is as clear as daylight that Cocainegate is real
- IBM 2026 "Organizational Change/s" Means Layoffs Resume Soon, Some Claim "Forever Layoffs."
- It's about "narrative control"
- Microsoft Layoffs in January 2026
- Get ready
- Google Still Boosting Slopfarms
- Slopfarms will probably all perish as soon as Google News quits sending them visitors
- Links 06/01/2026: Cryptocurrency Scam Emails and Greenland's Fear of Getting 'Venezuelad'
- Links for the day
- Links 06/01/2026: DIY Projects and Inertial Music
- Links for the day
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Monday, January 05, 2026
- IRC logs for Monday, January 05, 2026