Eye on Security: Windows Ransomware, DLL Hole, Malware, and More
- Dr. Roy Schestowitz
- 2010-09-03 06:46:58 UTC
- Modified: 2010-09-03 06:46:58 UTC
Summary: Menaces and unpleasant 'niceties' that only affect users of Windows this week
●
Russian cops cuff 10 ransomware Trojan suspects [
via]
PCs infected by the WinLock Trojan at the centre of the scam were rendered unusable because the malware disabled key Windows components. More embarrassingly pornographic images were displayed on compromised machines, IDG adds.
●
Polymorphic ransomware tops malware charts
Ransomware variant TotalSecurity is topping the malware charts, according to the latest threat report from security firm Fortinet.
August was the biggest comeback month since March for TotalSecurity, which locks out applications and data, and then demands a ransom to restore access.
●
Microsoft Releases 'Fix It' for DLL Hole
The DLL security vulnerability first grabbed headlines in August when a Slovenian security research firm pointed out that, under some circumstances, a malicious hacker could deploy a booby-trapped DLL file into a directory where Windows will load it, potentially granting the attacker control over the system. But it later surfaced that a U.S. security researcher had warned Microsoft about the DLL issue almost a year before, and had even published an academic paper on the threat last month.
●
Google Code hosting malware-spreading project
Google Code's project hosting feature has occasionally been used by malicious individuals for storing and spreading malware.
[...]
After this discovery was made public, Google removed the offending project. But this instance shows that the company must find a better way of detecting malware hosted on its sites.
●
University loses nearly 1 million dollars to malware
Thieves appear to have stolen the funds from University of Virginia after compromising a computer belonging to the University's Financial Controller. Malware intercepted the Online Banking Credentials for the University's Bank accounts and initiated a fraudulent wire transfer for $996,000 to a Bank in China.
●
25 percent of Windows malware now targets USB storage devices
In a survey of small businesses, PandaLabs discovered that 48 percent had been victims of malware in the past year. Of those businesses infected, 27 percent were able to verify that a compromised USB device was at the root of the issue.
●
New malware detects browser, shows fake malware warning page
While the malware is a pretty good attempt, it's not perfect. The goal is to get the user to download and install something, shelling out some cash in the process, which neither of the three browser vendors would ever recommend. The Firefox warning page, meanwhile, has an obvious typo ("Get me our of here"). In addition, it's suspicious that a webpage is going out of its way to tell you it is protecting your purchase. It's also not hard to check that the supposedly detected files do not actually exist on the user's computer. All of these missteps should raise red flags immediately; having said that, we've still not before seen this level of detail and effort from the bad guys.
●
Heartland pays another $5.4m for malware infection
The United States' fourth largest credit card payments processing company Heartland Payment Systems has agreed to pay a US$5 million ($5.4 million) settlement to its financial services customer Discover over a data breach caused by a malware infection.
Heartland processed card payments for Visa, Mastercard and other financial service providers to the tune of US$70 billion in 2009.
●
Rogue Win7 AV Copies the Microsoft Security Essentials Site
There are downsides to market success, and in the case of Microsoft Security Essentials is that attackers build malware designed to piggy-back ride the free security solution from Microsoft.
Recent Techrights' Posts
- Parties and Milestones Again
- we've begun putting up about 40 balloons
-
- Links 28/10/2025: Mass Layoffs at Amazon and Charter to Cut 1,200 Jobs
- Links for the day
- The Cocaine Patent Office - Part II: The Person Who Planted Paid-for Fake News for the European Patent Office (EPO) is a Cocaine User, Friend of António Campinos, Now on Record as Having Been Arrested
- Background: High-level manager at the European Patent Office caught in public with cocaine, arrested
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Monday, October 27, 2025
- IRC logs for Monday, October 27, 2025
- Google News Drowning in Slop (and Slopfarms That Hijack About Half the Results)
- Google News seems to be drowning in this stuff
- Gemini Links 28/10/2025: "How to Maximize Your Positive Impact" and ASCII Art and Artist Attribution
- Links for the day
- PETA and Activism
- Being staff or volunteer in PETA isn't easy
- Big Blue, Huge Debt
- debt will soar again
- Links 27/10/2025: Mass Surveillance Sold as "AI", People Reluctant to Lose Physical Media
- Links for the day
- Techrights' 19th Anniversary: Bronze
- Time to go back to preparing for this anniversary
- Our Latest European Patent Office (EPO) Series Will Last Several Weeks, Will Ask the EPO Management and the European Union (EU) Very Difficult Questions
- If nobody loses a job (or jobs) over this, then the EU basically became no better than Colombia or Nicaragua
- Slopwatch: LinuxSecurity, UbuntuPIT, Brian Fagioli, and Google News
- We focus on stories that are fake or LLM slop that disguises itself as "news" about Linux
- Links 27/10/2025: Wikipedia Vandalism, Bruce Perens Opens up on Childhood
- Links for the day
- This Site Could Not be Done by LLMs Even If It Wanted to (Because It's Not a Parrot of What Other Sites Say)
- LLMs have no knowledge or deep understanding
- Microsoft is Disloyal Towards Its Most Loyal Employees
- Against its most faithful enablers
- 19 Years, No Censorship
- No factual information is ever going to be removed, more so if it is in the public interest
- We Are Not a Conventional Site, That's Why They Hate (or Love) Us
- Throughout the week this week we'll be focusing on the EPO
- Following the Line of Cocaine All the Way to the Top
- Even a million denials and spin-doctoring won't distract from the core issue
- The Cocaine Patent Office - Part I: António Campinos Brought Corruption and Nepotism to the EPO, Then Came the Cocaine
- High-level manager at the European Patent Office (EPO) caught in public with cocaine, the Office has some answering to do
- Purchasing/Possessing Computers Isn't the Same as Controlling Computers
- Let's strive to put computers back under the control of their users, no matter who purchased these (usually the users)
- Gemini Links 27/10/2025: Alhena 5.4.3 and Fixing Bash
- Links for the day
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Sunday, October 26, 2025
- IRC logs for Sunday, October 26, 2025
- Thankfully We've Made Copies of More Interesting Data From statCounter
- If statCounter (the Web site or the 'webapp') vanished overnight, we'd still have something left of it
- More Silent Layoffs at IBM/Red Hat
- when the media counts such layoffs or presents tallies the numbers are very incomplete
- Links 26/10/2025: Microsoft Spies on Gamers, Open Transport Community Conference
- Links for the day
- Links 26/10/2025: LLM Slop / Plagiarism Programs Continue to Disappoint, CISA Layoffs Threaten Systems
- Links for the day
- Gemini Links 26/10/2025: Gemsync and Joining the Small Web
- Links for the day
- India.com a Click-baiting, SEO-Spamming, Slopfarming Heap
- They do this almost every day
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Saturday, October 25, 2025
- IRC logs for Saturday, October 25, 2025
- Without XBox Consoles, XBox is No More, It's Just a Brand (More Rumours of Microsoft Ending XBox, Then Laying Off Lots of Staff)
- All signs indicate that Microsoft wants to "exit" the XBox business (not brand), but it does not want to publicly admit this as it would alarm staff and shareholders