Eye on Security: Windows Ransomware, DLL Hole, Malware, and More
- Dr. Roy Schestowitz
- 2010-09-03 06:46:58 UTC
- Modified: 2010-09-03 06:46:58 UTC
Summary: Menaces and unpleasant 'niceties' that only affect users of Windows this week
●
Russian cops cuff 10 ransomware Trojan suspects [
via]
PCs infected by the WinLock Trojan at the centre of the scam were rendered unusable because the malware disabled key Windows components. More embarrassingly pornographic images were displayed on compromised machines, IDG adds.
●
Polymorphic ransomware tops malware charts
Ransomware variant TotalSecurity is topping the malware charts, according to the latest threat report from security firm Fortinet.
August was the biggest comeback month since March for TotalSecurity, which locks out applications and data, and then demands a ransom to restore access.
●
Microsoft Releases 'Fix It' for DLL Hole
The DLL security vulnerability first grabbed headlines in August when a Slovenian security research firm pointed out that, under some circumstances, a malicious hacker could deploy a booby-trapped DLL file into a directory where Windows will load it, potentially granting the attacker control over the system. But it later surfaced that a U.S. security researcher had warned Microsoft about the DLL issue almost a year before, and had even published an academic paper on the threat last month.
●
Google Code hosting malware-spreading project
Google Code's project hosting feature has occasionally been used by malicious individuals for storing and spreading malware.
[...]
After this discovery was made public, Google removed the offending project. But this instance shows that the company must find a better way of detecting malware hosted on its sites.
●
University loses nearly 1 million dollars to malware
Thieves appear to have stolen the funds from University of Virginia after compromising a computer belonging to the University's Financial Controller. Malware intercepted the Online Banking Credentials for the University's Bank accounts and initiated a fraudulent wire transfer for $996,000 to a Bank in China.
●
25 percent of Windows malware now targets USB storage devices
In a survey of small businesses, PandaLabs discovered that 48 percent had been victims of malware in the past year. Of those businesses infected, 27 percent were able to verify that a compromised USB device was at the root of the issue.
●
New malware detects browser, shows fake malware warning page
While the malware is a pretty good attempt, it's not perfect. The goal is to get the user to download and install something, shelling out some cash in the process, which neither of the three browser vendors would ever recommend. The Firefox warning page, meanwhile, has an obvious typo ("Get me our of here"). In addition, it's suspicious that a webpage is going out of its way to tell you it is protecting your purchase. It's also not hard to check that the supposedly detected files do not actually exist on the user's computer. All of these missteps should raise red flags immediately; having said that, we've still not before seen this level of detail and effort from the bad guys.
●
Heartland pays another $5.4m for malware infection
The United States' fourth largest credit card payments processing company Heartland Payment Systems has agreed to pay a US$5 million ($5.4 million) settlement to its financial services customer Discover over a data breach caused by a malware infection.
Heartland processed card payments for Visa, Mastercard and other financial service providers to the tune of US$70 billion in 2009.
●
Rogue Win7 AV Copies the Microsoft Security Essentials Site
There are downsides to market success, and in the case of Microsoft Security Essentials is that attackers build malware designed to piggy-back ride the free security solution from Microsoft.
Recent Techrights' Posts
- In New Letter Sent to Chair and Heads of Delegation of the Administrative Council of the European Patent Organisation the Staff Union Explains How to End European Patent Office Strikes
- If Campinos continues to behave as he does right now, the Council can show him the door
- Microsoft Debt Rose Almost $50 Billion Since We Moved to Debian
- GAFAM has a new name for debt
- European Patent Office Management Mocked for Trying to 'Bribe' Staff With a Little Food
- The Office is having a crisis; a little breakfast treat won't solve it
- The Corporate Media Intentionally Overlooks How Google's Debt Trebles in Just Over a Year
- We'll soon see how much more money Microsoft has borrowed
- (Trigger Warning) Jeremy Bicha & Debian-Edu, TecKids, Ubuntu incest scandal at DebConf25
- Reprinted with permission from Daniel Pocock
-
- Microsoft "Buyout" Offer is Less Than One Year's Salary
- So our assumption about this was correct
- The Corrupt Lecture the Non-Corrupt - Part X - European Patent Office Managers Have Crossed Red Lines, According to Themselves
- The girlfriend of the President of the European Patent Office (EPO) is trying to muzzle EPO critics
- Techrights is Still Growing, Attacking Techrights Does Not Weaken the Community
- Bullying us for 2+ years does not result in fear, it results in us feeling more emboldened and motivated
- SLAPP Censorship - Part 63 Out of 200: Graveley as a Stripped-Down Version of Garrett in the Particulars of Claim (5RB Barrister Could Do This in One Minute)
- Lazily and sloppily, it looks like the barrister took Garrett's claims and tweaked them a little (shortened) for Graveley
- Lots of People Leave IBM, Today IBM Has About 1,000 Workers Fewer Than Yesterday
- Confluent "last day" for 800+ people
- Been a Very Busy Week
- Next week, as we have no upgrades to prepare for, we should be able to publish at the usual pace of 20+ pages per day
- Links 01/05/2026: Poems and Continuous Privacy Policy
- Links for the day
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Thursday, April 30, 2026
- IRC logs for Thursday, April 30, 2026
- Google News Sloppy Again
- Today was disappointing
- SLAPP Censorship - Part 62 Out of 200: Garrett and Graveley Issue Astounding Copy-Paste Masterpiece Asserting Publicly-Accessible Embarrassing Facts Must Remain Hidden
- Are Garrett and Graveley twins separated at birth but joined by GNOME and Microsoft?
- Links 30/04/2026: Barrage of Lawsuits Against Slop, Microsoft's Stock Crashes
- Links for the day
- Microsoft Says Mass Layoffs Are Coming and Puts a Price on Them
- Microsoft will shrink
- Upgrade Successful
- we had a downtime of only 1-2 minutes overall (for two reboots)
- Links 30/04/2026: Slop Industry Cannot Keep Up With Bills, "The World Is Getting Too Hot to Feed Itself"
- Links for the day
- Then Come the DDoS Attacks
- Is someone trying to 'kill' Techrights?
- The Corrupt Lecture the Non-Corrupt - Part X - Deliberately Violate European Patent Convention (EPC), Tolerate Cocaine Use in Management, Hide That From Staff and Stakeholders
- The "Alicante Mafia" (as staff calls it) is a disgrace to Europe
- The Register MS Running Spam Pieces for Huawei, a Banned Company
- Money does not excuse bad behaviour
- Apparently Last Day for Nearly 1,000 Confluent Workers IBM Laid Off Last Month
- IBM is a dying company pretending to be strong because of its age
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Wednesday, April 29, 2026
- IRC logs for Wednesday, April 29, 2026
- Gemini Links 30/04/2026: Outdoor Time, Old Computers, and Joining Geminispace
- Links for the day
- In Past 6 Months IBM Lost About 100 Billion Dollars in 'Value' While Debt Ballooned to 70 Billion Dollars
- Welcome to a universe of fake finances and phony accounting based on fictional assets with made-up 'worth'
- Dr. Andy Farnell on Weaponising Morality Against Technofascism and Slop
- It's longer than a "tweet", so social control media addicts are likely mentally unfit to read it
- Six Months
- Techrights will be around (and active) for a very long time to come
- If We Move Everything to Devuan...
- IRC, Git, Apache and so on
- Why We Publish "The Corrupt Lecture the Non-Corrupt"
- We intend to report the facts, fearlessly, until real and lasting solutions are reached
- SLAPP Censorship - Part 61 Out of 200: Garrett and Graveley Must Understand That Reporting Women's Issues in the United States of America (“the US”) is Not Impermissible
- when you cover Microsoft corruption and have real effect
- Weeks After Mass Layoffs of Red Hat Engineers We Learn of European "Buyouts" and Layoffs at IBM
- At Microsoft, they tell us there are merely "buyouts", but they don't tell us what happens if you say "no!"
- OS Upgrade Tentatively Scheduled for Tomorrow
- We have some contingencies in case the upgrade goes wrong
- Campinos is a Lame Duck President This Year at the European Patent Office (EPO)
- The strikes are not ending. If anything, they intensify further.
- Links 29/04/2026: LLM Chatbot Usage Goes Down Sharply (as Do Stocks Associated With Them), Microsoft's Circular Financing Accounting Fraud at Risk
- Links for the day
- Gemini Links 29/04/2026: Returning to an Exodus and Farewell APU
- Links for the day
- Slop Has a Long Way to Go Before It Gets Basic Facts Right
- Please do not rely on slop for anything
- The Corrupt Lecture the Non-Corrupt - Part IX - European Patents That Are Illegal (But Serve Non-European Monopolists in Exchange for 'Quick Cash')
- People who shamelessly violate the European Patent Convention (EPC) have the audacity to lecture workers on "ethics"
- Canonical is Selling You, Ubuntu is a Data-Collecting Platform
- Canonical is looking for money in the wrong places
- Links 29/04/2026: "Snowden Affair 13 Years Later" and "Landmark Data Center Pause"
- Links for the day
- Seems Like Only Techrights Covered IBM Laying Off About 33% of Confluent Staff
- How can such a large round of layoffs evade today's media?
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Tuesday, April 28, 2026
- IRC logs for Tuesday, April 28, 2026
- Gemini Links 29/04/2026: Bad Diet, New Middle Ages, and Temperature Model
- Links for the day