Bonum Certa Men Certa

Eye on Security: Windows Ransomware, DLL Hole, Malware, and More

Tips cup



Summary: Menaces and unpleasant 'niceties' that only affect users of Windows this week

Russian cops cuff 10 ransomware Trojan suspects [via]

PCs infected by the WinLock Trojan at the centre of the scam were rendered unusable because the malware disabled key Windows components. More embarrassingly pornographic images were displayed on compromised machines, IDG adds.


Polymorphic ransomware tops malware charts

Ransomware variant TotalSecurity is topping the malware charts, according to the latest threat report from security firm Fortinet.

August was the biggest comeback month since March for TotalSecurity, which locks out applications and data, and then demands a ransom to restore access.


Microsoft Releases 'Fix It' for DLL Hole



The DLL security vulnerability first grabbed headlines in August when a Slovenian security research firm pointed out that, under some circumstances, a malicious hacker could deploy a booby-trapped DLL file into a directory where Windows will load it, potentially granting the attacker control over the system. But it later surfaced that a U.S. security researcher had warned Microsoft about the DLL issue almost a year before, and had even published an academic paper on the threat last month.


Google Code hosting malware-spreading project

Google Code's project hosting feature has occasionally been used by malicious individuals for storing and spreading malware.

[...]

After this discovery was made public, Google removed the offending project. But this instance shows that the company must find a better way of detecting malware hosted on its sites.


University loses nearly 1 million dollars to malware

Thieves appear to have stolen the funds from University of Virginia after compromising a computer belonging to the University's Financial Controller. Malware intercepted the Online Banking Credentials for the University's Bank accounts and initiated a fraudulent wire transfer for $996,000 to a Bank in China.


25 percent of Windows malware now targets USB storage devices

In a survey of small businesses, PandaLabs discovered that 48 percent had been victims of malware in the past year. Of those businesses infected, 27 percent were able to verify that a compromised USB device was at the root of the issue.


New malware detects browser, shows fake malware warning page

While the malware is a pretty good attempt, it's not perfect. The goal is to get the user to download and install something, shelling out some cash in the process, which neither of the three browser vendors would ever recommend. The Firefox warning page, meanwhile, has an obvious typo ("Get me our of here"). In addition, it's suspicious that a webpage is going out of its way to tell you it is protecting your purchase. It's also not hard to check that the supposedly detected files do not actually exist on the user's computer. All of these missteps should raise red flags immediately; having said that, we've still not before seen this level of detail and effort from the bad guys.


Heartland pays another $5.4m for malware infection



The United States' fourth largest credit card payments processing company Heartland Payment Systems has agreed to pay a US$5 million ($5.4 million) settlement to its financial services customer Discover over a data breach caused by a malware infection.

Heartland processed card payments for Visa, Mastercard and other financial service providers to the tune of US$70 billion in 2009.


Rogue Win7 AV Copies the Microsoft Security Essentials Site

There are downsides to market success, and in the case of Microsoft Security Essentials is that attackers build malware designed to piggy-back ride the free security solution from Microsoft.

Recent Techrights' Posts

This New Determination on a Case Echoes the Modus Operandi of Microsoft's Serial Strangler vs Techrights (Its Online Decision/Judgment Says Truth and Public Interest Defend the Publisher)
Noel Anthony Clarke hopefully has enough money left to pay his victims, which include the publishers
 
Microsoft's Windows "Market Share" Overestimated
Microsoft's income sources are shrinking
We Shall See...
My wife and I are hardly the first victims of Brett Wilson LLP
Going Offline
There was life before the Net
The Register MS Has Apparently Shut Down Its Office
It is basically a fake address on the face of it
There Are Also Expectations of IBM Layoffs Very Soon With "Narrative Control."
Some of them mention Red Hat and how IBM failed to achieve anything substantial with that acquisition
After at Least Two Rounds of Mass Layoffs in August Microsoft Said to Have "September Layoff Confirmed - Performance Based"
Those "M5 level meetings" sound plausible
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, August 25, 2025
IRC logs for Monday, August 25, 2025
Slopwatch: Slopfarms All Over Google News and Real News Sites Pushed Out of Visibility
Google News is dying (as a tool of value)
Gemini Links 25/08/2025: Numeric-only VM and Alhena 5.3.0
Links for the day
Links 25/08/2025: ‘Panama Playlists’ and Live Nation/Ticketmaster Suit Aims at Class Action
Links for the day
Gemini Links 25/08/2025: Empathy Towards Autistic People and Old Gadgets
Links for the day
Links 25/08/2025: Datacentres Versus Water Supplies and "The IPv6 Divide"
Links for the day
Links 25/08/2025: Data Breaches, Politics, and Financial Strain
Links for the day
GNU/Linux Distros Ought to Replace Firefox (and Firefox ESR) With Something Like LibreWolf
Perhaps it's come to replace Firefox
Father of Julian Assange Said the US Government Was Trying to Bankrupt WikiLeaks, Now the Assange Family Promotes Fake Currencies
Using the name for bad purposes?
Bailing Out GAFAM, Giving Taxpayers' Money to Failing Companies, and Trying to Outlaw Lawsuits Against Them
What would the late Lincoln have said?
Software Freedom Conservancy (SFC) Inc. Lost 2 Million Dollars Last Year and Its Chief Took a Salary Increase of Almost $6,000
Another year or two like this... and the SFC will be bankrupt [...] Hallmark of mismanagement
The "New Techrights" Turns Two Very Soon
Accomplishing something each year is what's important, not merely "finishing" another year
Gulf Nations Leave Microsoft Behind
How much lower will Microsoft stoop in an effort to raise money from oil-rich lenders?
How to Combat IRC Trolls (in Our Experience)
Today I want to share my experience (or knowledge) of how to deal with IRC trolls
The Register MS Needs to Stop Participating in the "Hey Hi" (AI) Hype, But It Gets Paid to Participate in This Hype
the publisher (The Register MS) wants to have it both ways
Gemini Links 24/08/2025: Living With Your Parents, Zürich Zoo, and Macondo
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, August 24, 2025
IRC logs for Sunday, August 24, 2025
Gemini Links 24/08/2025: Signal on OpenBSD and Keyboard Layouts Compared
Links for the day
Men Who Abuse Women Should Never Spend Over 3 Years of the UK High Court's Time
This demonstrates that we need a reform in the UK
Links 24/08/2025: Microsoft Settles Data Breach Lawsuits and Climate Change Causes Heatwaves, Water Shortages
Links for the day
CachyOS is Rising Fast, But Slopfarms Are 'Googlebombing' It
CachyOS receives more media attention
No Reason for Red Hat Relief Yet (Layoff Rumours)
the execution could be stalled, delayed, or scheduled for some time after people come back from holiday
GNU/Linux 6%, Windows 60% in Venezuela, Suggests statCounter
The cash cows are dying
Mass Layoffs Continue at Microsoft This Month (Remaining Workers See Conditions That Deteriorate)
So far this month (one week remaining) we saw at least two waves of layoffs at Microsoft
How SPAM E-mails With Windows-Centric Files Get Twisted as Linux Threats, Then Slopfarms Spread the Word
Fear, Uncertainty, Doubt/Fear-mongering/Dramatisation
Links 24/08/2025: Heatwaves Threaten Workers, Maldives Versus Press freedom
Links for the day
Gemini Links 24/08/2025: Digital Cameras and Printers
Links for the day
Links 24/08/2025: GAFAM Lie About Pollution and Slop's Carbon Footprint, The Guardian Says Slop ("Hey Hi") is a Bubble That Will Send Stock Markets Into a Freefall
Links for the day
80% of the Sponsored (Fake) Articles in The Register MS Are Promotions of Ponzi Schemes (Unethical Money), the Rest is Banned Chinese Business
Is that an ethical way to make money? No.
The UEFI Restricted Boot 'Time Bomb' is About to Go Off in a Few Weeks
Garrett was the first person to face sanctions (like muting) in our IRC channels because of his abuse; worse yet, he hijacked other people's names and then locked them out of their own accounts
Should Currys PCWorld Start Voiding Warranties of Users of Vista 11?
If a person's laptop has a mechanical issue, should this person replace GNU/Linux with Vista 11 for the repair shop? Only to damage the SSD?
Newer is Not Always Better, and It's Possible That 'Peak' is the Past
People creating their own platforms means progress, whereas centralisation (like moving from blogs to social control media) is the opposite of progress
LLM Hype is Sowing Destruction: It Contributes to DDoS Attacks and Makes the Web Less Accessible (JavaScript "R U Human?" Tests)
If it was googlebot, it would be possible to argue that you'd at least then get referral traffic from Google Search. With LLMs, all you get is plagiarised.
Links 24/08/2025: New York Times Talks About Hey Hi (AI) Bubble
Links for the day
Gemini Links 24/08/2025: Upgrading Debian and Mobile-indifferent Design
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, August 23, 2025
IRC logs for Saturday, August 23, 2025