Blue screen reboots after patch could mean malware
- 19 February, 2010 07:45
- Comments
Redmond announced today it has found the cause of reported rebooting problems after some Windows users installed a recent patch: The systems were infected with malware.
Specifically, the Alureon rootkit, a type of stealth malware that's used to hide other malware infections. Rootkits typically change important system files to perform their obfuscation, and in this case Microsoft says those system changes caused major problems after the MS10-015 kernel patch, shipped during the last Patch Tuesday, was installed.
A Microsoft Security Response Center post says that the company first heard of the reboot problems on the 10th, and halted the distribution of MS10-015 via Automatic Updates while it investigated. That research confirmed the problem with the rootkit.
According to the post, the Alureon varieties seen by Microsoft only affect 32-bit systems. Also, problem reports have largely involved Windows XP systems. For that reason, Redmond says it will resume distributing the MS10-015 patch for 64-bit systems via Windows Update.
While I'm more than willing to take Microsoft to task when they screw up, in this case I don't think anyone could hold Redmond at fault here when the root cause is a malware infection. It could even be a good thing, since the only thing worse than dealing with a constantly rebooting system is unknowingly using an infected system and having all your passwords and financial info stolen.
Another post from the Microsoft Malware Protection Center provides some technical details on Alureon, and also notes that the latest varieties of the malware no longer conflict with MS10-015. Also, if your own PC has been constantly rebooting since applying this patch and you think you might be infected with the rootkit, Microsoft says it will provide free technical support at its PC Safety hotline at 1-866-727-2338.
Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.
- Bookmark this page
- Share this article
- Got more on this story? Email CIO
- Follow CIO on twitter
- The Low-down on Low-level Rootkits - PCWorld
- Microsoft Security Bulletin MS10-015 - Important: Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (977165)
- Critical Windows Fixes For DirectShow, Network-based Attacks - PCWorld
- The Microsoft Security Response Center (MSRC)
- Firefox Foils Microsoft's Security Hole - PCWorld
- Microsoft Malware Protection Center
-
The 30 best Safari extensions -- so far
-
Apple and Google disagree over licensing of essential patents
-
Monash Uni reduces IT teams after consolidation project
-
FTC warns makers of background checking apps
-
QLD govt demands answers after pay glitch
-
Cost Effective Security and Compliance with Oracle Database 11g Release 2
Information ranging from trade secrets to privacy related information has become the target of sophisticated attacks from both sides of the firewall. Protecting data now requires a strategy that enables both preventive and detective controls. Read on. -
8 reasons why Citrix NetScaler beats the competition
Application delivery controllers (ADC) are one of the most critical elements of cloud infrastructures and enterprise data centre architectures. ADCs strongly impact performance, scale and security of the entire application environment, so it is extremely important for IT leaders to choose the right one. -
Solid State Storage 101 - An introduction to Solid State Storage
Solid state data storage is gaining significant acceptance today. Storage based on Ram Access Memory (RAM) and Flash chips instead of mechanical hard disk drives is earning much greater attention by meeting the market requirements for reliability, performance, and cost more effectively than ever before. Read on.
-
Macromedia Studio MX 2004 Bible
-
Broadband Bible Desktop Edition
-
JavaScript - a Programmers Companion From Basics Through Dhtml, CSS & Dom
-
Interoperability for Enterprise Software and Applications (Proceedings of the Workshops and the Doctorial Symposium of the Second Ifac/Ifip I-esa Int
-
Beginning ASP.NET 4
-
Jakarta Struts for Dummies
-
Excel 2000 for Windows for Dummies Quick Reference
-
Office 2003 Application Development All-In-One Desk Reference for Dummies
-
Wiley Pathways











Comments
Post new comment