Eye on Security: Windows Ransomware, DLL Hole, Malware, and More
- Dr. Roy Schestowitz
- 2010-09-03 06:46:58 UTC
- Modified: 2010-09-03 06:46:58 UTC
Summary: Menaces and unpleasant 'niceties' that only affect users of Windows this week
●
Russian cops cuff 10 ransomware Trojan suspects [
via]
PCs infected by the WinLock Trojan at the centre of the scam were rendered unusable because the malware disabled key Windows components. More embarrassingly pornographic images were displayed on compromised machines, IDG adds.
●
Polymorphic ransomware tops malware charts
Ransomware variant TotalSecurity is topping the malware charts, according to the latest threat report from security firm Fortinet.
August was the biggest comeback month since March for TotalSecurity, which locks out applications and data, and then demands a ransom to restore access.
●
Microsoft Releases 'Fix It' for DLL Hole
The DLL security vulnerability first grabbed headlines in August when a Slovenian security research firm pointed out that, under some circumstances, a malicious hacker could deploy a booby-trapped DLL file into a directory where Windows will load it, potentially granting the attacker control over the system. But it later surfaced that a U.S. security researcher had warned Microsoft about the DLL issue almost a year before, and had even published an academic paper on the threat last month.
●
Google Code hosting malware-spreading project
Google Code's project hosting feature has occasionally been used by malicious individuals for storing and spreading malware.
[...]
After this discovery was made public, Google removed the offending project. But this instance shows that the company must find a better way of detecting malware hosted on its sites.
●
University loses nearly 1 million dollars to malware
Thieves appear to have stolen the funds from University of Virginia after compromising a computer belonging to the University's Financial Controller. Malware intercepted the Online Banking Credentials for the University's Bank accounts and initiated a fraudulent wire transfer for $996,000 to a Bank in China.
●
25 percent of Windows malware now targets USB storage devices
In a survey of small businesses, PandaLabs discovered that 48 percent had been victims of malware in the past year. Of those businesses infected, 27 percent were able to verify that a compromised USB device was at the root of the issue.
●
New malware detects browser, shows fake malware warning page
While the malware is a pretty good attempt, it's not perfect. The goal is to get the user to download and install something, shelling out some cash in the process, which neither of the three browser vendors would ever recommend. The Firefox warning page, meanwhile, has an obvious typo ("Get me our of here"). In addition, it's suspicious that a webpage is going out of its way to tell you it is protecting your purchase. It's also not hard to check that the supposedly detected files do not actually exist on the user's computer. All of these missteps should raise red flags immediately; having said that, we've still not before seen this level of detail and effort from the bad guys.
●
Heartland pays another $5.4m for malware infection
The United States' fourth largest credit card payments processing company Heartland Payment Systems has agreed to pay a US$5 million ($5.4 million) settlement to its financial services customer Discover over a data breach caused by a malware infection.
Heartland processed card payments for Visa, Mastercard and other financial service providers to the tune of US$70 billion in 2009.
●
Rogue Win7 AV Copies the Microsoft Security Essentials Site
There are downsides to market success, and in the case of Microsoft Security Essentials is that attackers build malware designed to piggy-back ride the free security solution from Microsoft.
Recent Techrights' Posts
- "A single witness shall not rise up against a person regarding any wrongdoing or any sin that he commits; on the testimony of two or three witnesses a matter shall be confirmed." (Deuteronomy 19-21)
- The spouse of Garrett repeatedly points out that Garrett can barely code or can only do so very poorly
- Rust People Sabotage Stability for the Sake of a Falsely-Promised 'Security'
- Set aside severe performance issues, poor handling of "edge cases", general bugs, lack of compatibility, and even crashes
- Huge Strike at the European Patent Office (EPO) This Coming Friday (May 1st)
- International Worker’s day
-
- Links 26/04/2026: Korean Inflation, GLP-1 Drugs Linked to Cognitive Impairment, Lithuania's Public Broadcaster LRT Besieged
- Links for the day
- Hopefully Smooth Sailing in OS Upgrade
- There are some contingencies at hand
- Links 25/04/2026: "Horrible Economics of AI Are Starting to Come Crashing Down", More Restrictions Placed on Social Control Media
- Links for the day
- Getting Aggressive Suggestive of Loss - Part IV - Shutting Down My Existence
- Would anyone out there tolerate such messages sent from burner accounts?
- Gemini Links 26/04/2026: Gemini Movie Database (or GeminiMDB) and Star Trek III
- Links for the day
- Weeks Before Linux Removed Over 100,000 Lines of Code Due to Slop 'Bug Reports' Microsoft Paid 'Linux' Foundation to Advance Slop in the Name of 'Security'
- What can possible go wrong? Both for security and for stability.
- Tracking Ages of People
- To stay "safe" tell us your age
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Saturday, April 25, 2026
- IRC logs for Saturday, April 25, 2026
- SLAPP Censorship - Part 57 Out of 200: 5RB and Brett Wilson LLP Made the Garrett and Graveley Particulars of Claims a Lot Like Photocopies!
- They seem very much irritated that I speak about this
- Links 25/04/2026: Nokia Wins Embargo in Kangaroo Court Where Judges Are Salaried Nokia Staff (UPC), Allison Pearson Defamation Case (UK) Succeeds, Smokey Robinson and "Puff Daddy" (US) Fail
- Links for the day
- Gemini Links 25/04/2026: Weekly Echoes, Gemtext Tables, and Using Offpunk
- Links for the day
- Corporate Media Did Not Specify What Microsoft Means by "Buyouts" (Layoffs), It May Be Hardly Different From Severance
- Time will tell, but investigative journalism hardly exists anymore, so we won't hold our breath
- The Corrupt Lecture the Non-Corrupt - Part V - "Diversity" and "Inclusion" at EPO Means Sleeping With Sister of "Cocaine Communication Manager" and Making Them Millionaires
- Remember that top applicants or key stakeholders of the EPO are already complaining about a lack of quality
- Links 25/04/2026: Fake GAFAM Valuations (Gripping the Market Based on False Accounting), "Evidence Isn't Just for Research", and "Putin Defends Mobile Internet Outages"
- Links for the day
- Dr. Andy Farnell on Why Calling Slop or Chaff "Hey Hi" (AI) Harm Us All, Except for "Ten or Twenty Rich Industrialists"
- "words to avoid"
- Internet Trolls Likely Trying to Distract From the Demise of IBM, Problems With Red Hat
- there seems to be trolling online aimed at suppressing discussion
- Debian Upgrade Coming Up (Soon)
- Yesterday we contacted the datacentre staff about it
- Getting Aggressive Suggestive of Loss - Part III - Threats From Burner Accounts Formally Treated as a Crime
- Countries that cannot preserve freedom from self-censorship are countries where free press ultimately cannot prevail
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Friday, April 24, 2026
- IRC logs for Friday, April 24, 2026
- Gemini Links 25/04/2026: 3.4k+ Capsules, Microsoft Layoffs, Call for Nuclear Disarmament, "Internet is Sad and Lonely"
- Links for the day
- Links 24/04/2026: Zelenskyy Says Ukraine's War Position "Most Stable", Samsung Workers on Strike Due to Pay
- Links for the day
- Recent Happenings at IBM Reaffirm Rumours About the CEO; He Might be Resigning (or Pushed Out) Soon
- If the rumours are true (no, we did not check those tax records for ourselves), it's not unthinkable that IBM is already doing what Apple did months ago
- Gemini Links 24/04/2026: Public Reticulum Gateway Node, Smol Computers, and Old E-mail
- Links for the day
- Links 24/04/2026: Intel Abandoning Computer Freedom (Even Further), Iran Reports That American Software and Hardware Remotely Sabotaged/Hijacked During War
- Links for the day
- 24/7 Wall St. Editor-In-Chief and CEO Calls IBM Is "America’s Worst Big Tech Company", Talent is Leaving, Supposedly Strategic Units Culled
- 21 hours ago by Douglas A. McIntyre
- The Great Wonders of Slop "Efficiency"
- Thankfully nothing was lost in the transmission and lots of work (datacentre emissions) got "done"
- IBM's Debt Increased Over $5 Billion in 3 Months While IBM Laid Off Many in Europe, US, Confluent, HashiCorp, and Red Hat
- An increase of $5,000,000,000+ in debt in just 3 months!
- IBMers Expect Another Giant Wave of Layoffs, Talk (and Sing) About the PIPs
- The media won't be covering the key facts
- Drama at the European Patent Office (EPO) This Week
- We'll be covering the EPO quite a lot this weekend and next week
- As We Predicted, Francophonie Countries in the EU and Outside the EU Dumping Microsoft for National Security Reasons
- We expected Belgium or some other Francophonie place to do so next
- Even to Microsoft Insiders It Seems Like XBox Has Already Died or Surrendered to the Japanese Companies
- Now the Microsoft layoffs are evident for people to see
- EPO Cocainegate Escalates - Part VI - The Strikes Go On and On (Major Strike Today)
- We'll be covering this later today in relation to what the Office dubs "ethics"
- Absolutely Terrible Journalism About Microsoft Layoffs This Week
- 7 hours ago by Leila Sheridan
- SLAPP Censorship - Part 56 Out of 200: 5RB and Brett Wilson LLP's Copy-Paste Machination for Garrett and Graveley
- Here is another straightforward example of their junior barrister overusing copy-paste on his Mac
- Getting Aggressive Suggestive of Loss - Part II - Lawyers Are Not "Hired Guns" (and Should Never Act Like Ones)
- The matter is being investigated
- Nadella is Killing Microsoft. Slop Kills It Even Faster.
- A decade from now we'll look back at slop like we look back at skateboards
- Huge Microsoft Layoffs Coming Shortly (With Financial Report)
- There will be lots of slop layoffs. Be ready. It's a bubble.
- Gemini Links 24/04/2026: Data Breaches and Unofficial Gemini Protocol Specification Archive
- Links for the day
- Microsoft Offers About 10,000 of Its Senior American (Read: Expensive) Workers to be Laid Off
- How many slopfarms and media parrots play along?
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Thursday, April 23, 2026
- IRC logs for Thursday, April 23, 2026