Eye on Security: Windows Ransomware, DLL Hole, Malware, and More
- Dr. Roy Schestowitz
- 2010-09-03 06:46:58 UTC
- Modified: 2010-09-03 06:46:58 UTC
Summary: Menaces and unpleasant 'niceties' that only affect users of Windows this week
●
Russian cops cuff 10 ransomware Trojan suspects [
via]
PCs infected by the WinLock Trojan at the centre of the scam were rendered unusable because the malware disabled key Windows components. More embarrassingly pornographic images were displayed on compromised machines, IDG adds.
●
Polymorphic ransomware tops malware charts
Ransomware variant TotalSecurity is topping the malware charts, according to the latest threat report from security firm Fortinet.
August was the biggest comeback month since March for TotalSecurity, which locks out applications and data, and then demands a ransom to restore access.
●
Microsoft Releases 'Fix It' for DLL Hole
The DLL security vulnerability first grabbed headlines in August when a Slovenian security research firm pointed out that, under some circumstances, a malicious hacker could deploy a booby-trapped DLL file into a directory where Windows will load it, potentially granting the attacker control over the system. But it later surfaced that a U.S. security researcher had warned Microsoft about the DLL issue almost a year before, and had even published an academic paper on the threat last month.
●
Google Code hosting malware-spreading project
Google Code's project hosting feature has occasionally been used by malicious individuals for storing and spreading malware.
[...]
After this discovery was made public, Google removed the offending project. But this instance shows that the company must find a better way of detecting malware hosted on its sites.
●
University loses nearly 1 million dollars to malware
Thieves appear to have stolen the funds from University of Virginia after compromising a computer belonging to the University's Financial Controller. Malware intercepted the Online Banking Credentials for the University's Bank accounts and initiated a fraudulent wire transfer for $996,000 to a Bank in China.
●
25 percent of Windows malware now targets USB storage devices
In a survey of small businesses, PandaLabs discovered that 48 percent had been victims of malware in the past year. Of those businesses infected, 27 percent were able to verify that a compromised USB device was at the root of the issue.
●
New malware detects browser, shows fake malware warning page
While the malware is a pretty good attempt, it's not perfect. The goal is to get the user to download and install something, shelling out some cash in the process, which neither of the three browser vendors would ever recommend. The Firefox warning page, meanwhile, has an obvious typo ("Get me our of here"). In addition, it's suspicious that a webpage is going out of its way to tell you it is protecting your purchase. It's also not hard to check that the supposedly detected files do not actually exist on the user's computer. All of these missteps should raise red flags immediately; having said that, we've still not before seen this level of detail and effort from the bad guys.
●
Heartland pays another $5.4m for malware infection
The United States' fourth largest credit card payments processing company Heartland Payment Systems has agreed to pay a US$5 million ($5.4 million) settlement to its financial services customer Discover over a data breach caused by a malware infection.
Heartland processed card payments for Visa, Mastercard and other financial service providers to the tune of US$70 billion in 2009.
●
Rogue Win7 AV Copies the Microsoft Security Essentials Site
There are downsides to market success, and in the case of Microsoft Security Essentials is that attackers build malware designed to piggy-back ride the free security solution from Microsoft.
Recent Techrights' Posts
- New USPTO Memo Makes Fighting Patent Trolls Even Harder
- The U.S. Patent and Trademark Office (USPTO) just made a move that will protect bad patents at the expense of everyone else
- An "EU OS" Would Need European Components
- There are many European (or Europe-led) distros of GNU/Linux. EU OS developers ought to look at those.
-
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Sunday, March 23, 2025
- IRC logs for Sunday, March 23, 2025
- Critics of IBM's Strategy Aren't Racists, But...
- the situation is saddening as it serves to obscure the severity of the problem
- Mauritania: Windows Falls to All-Time Low of 6% (It Used to be Over 99%)
- Windows is 0% in mobile
- Outline of Open Source Initiative Coverage to Come (Now That Consensus is Changing)
- Policing Wikipedia and attacking critics is not a sustainable strategy
- Gemini Links 23/03/2025: "Connor of the Cats" and CSS Naked Day
- Links for the day
- Links 22/03/2025: Science and Antoine Beaupré on "Losing the War for the Free Internet"
- Links for the day
- We Probably Served Close to 100 Million Gemini Requests
- Many of these requests probably came from bots, but it's hard to distinguish (to block them) ... This coming summer Gemini Protocol will turn 6
- Just Because Microsoft Resents Techrights Doesn't Mean SLAPPs Will Silence Techrights
- To confront lies the best solution is to speak truth
- Windows at New Low Levels in Madagascar (Population About 33 Million)
- Madagascar does not need Microsoft
- Slop Images Are Bad Optics, Including for Perl.org
- Slop devalues one's genuine work
- What Happened to the Open Source Initiative (OSI) Elections: Proprietary Software Companies in Control, the Scandals Cannot be Hidden Anymore
- We'll talk about it later this month and next month
- Slopwatch: Fake News About Security Using LLMs That Make Fake 'Articles' About "Linux" (With Slop for Images)
- This cannot end well
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Saturday, March 22, 2025
- IRC logs for Saturday, March 22, 2025
- Gemini Links 22/03/2025: "Ukay Ukay", Microplastics in Tea, Jujutsu, and More
- Links for the day
- Links 22/03/2025: Johor Flooded, Ador Traps Young Musicians With Contract
- Links for the day
- [Video] Richard Stallman on What Patents Would Have Done to Music (Covered by Copyrights)
- Our WebM version can be played using Free software, independently of the availability of Invidious mirrors
- Our IRC Community Turns 17 Very Shortly
- A few years from now our IRC community will turn 20
- Microsoft Destroys and Exploits, It Does Not Create
- A race to nowhere
- Linux Foundation Buys Misleading Puff Pieces About Itself, Earns Some LLM Slop to Accompany the PR (Openwashing and Propaganda as a Service, With the Brand "Linux" Needlessly Borrowed)
- Isn't it funny that after the "LF" (misusing the brand "Linux") flooded the Web with press releases and fake articles (that it had paid for) it now gets some LLM slop doing the same?
- It's About So Much More Than 2 Microsofters, It's About Freedom to Speak About Crimes at Microsoft
- Suffice to say, if some people related to our professional field attack women and get arrested for it, then there's nothing immoral about relaying this information
- Links 22/03/2025: Social Security Attacks and More Attacks on the Press
- Links for the day
- Gemini Links 22/03/2025: INTERPOL, DDoS by "Hey Hi" Hype, and RSS/Feed Readers
- Links for the day
- Links 22/03/2025: Alzheimer Research and Mega-breaches in the US
- Links for the day
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Friday, March 21, 2025
- IRC logs for Friday, March 21, 2025