Skip to main content
  1. Home
  2. Computing
  3. Legacy Archives

Microsoft Blames Rootkits for Security Update Crashes

Add as a preferred source on Google
MS-DOS
Image used with permission by copyright holder

Earlier this month, Microsoft released a patch for its entire supported line of Windows operating systems—that’d be Windows 2000 all the way through Windows 7—which included a fix for a security vulnerability that had been lurking in its Virtual DOS Machine for some 17 years—a record by almost any standard. The problem was that the security update led to problems on some Windows XP machines: users would install the update, then find themselves faced with the dreaded Blue Screen of Death or an endless cycle of reboots. Some Windows XP users angrily railed against Microsoft for damaging their computers, and Microsoft promptly began looking into the problem. Their verdict? The problems Windows XP users experienced were caused by malware using the Alureon rootkit, not the security update.

“Our investigation has concluded that the reboot occurs because the system is infected with malware, specifically the Alureon rootkit,” wrote Microsoft’s Security Response Center director Mike Reavey, in a blog post. “We were able to reach this conclusion after the comprehensive analysis of memory dumps obtained from multiple customer machines and extensive testing against third party applications and software. The restarts are the result of modifications the Alureon rootkit makes to Windows Kernel binaries, which places these systems in an unstable state.”

Recommended Videos

Microsoft has determined that 64-bit versions of Windows are not vulnerable to the problem, and so has re-enabled Automatic Updates for those systems. However, Microsoft is still holding off on making the update available to 32-bit systems via Automatic Update.

In the meantime, Microsoft is recommending users make sure they’re running up-to-date antivirus and security software to make sure their systems aren’t infected by malware prior to installing any system updates. If users can’t confirm they’ve been able to remove the Alureon rootkit—which does go to a lot of effort to hide itself—Microsoft users back up their important files and data, then completely restore their systems to a re-formatted drive.

Geoff Duncan
Former Contributor
Geoff Duncan writes, programs, edits, plays music, and delights in making software misbehave. He's probably the only member…
AI is finding Apple security flaws faster than Apple can sort through them
Apple has limited how many bug reports researchers can keep open as AI tools produce both genuine Mac vulnerabilities and a flood of questionable submissions
Lighting, Architecture, Building

Apple has capped the number of security reports researchers can keep open at once after AI bug hunting put its review process under pressure, according to the Financial Times.

Some submissions describe hallucinated or purely theoretical risks. Others uncover vulnerabilities serious enough to require patches. Bynario told the FT that it found more than 50 possible macOS flaws in three weeks, including a privilege-escalation chain that could give an attacker full control of a Mac.

Read more
Anthropic is paying $1.5 billion over pirated books, but it can still legally cut up purchased ones
The settlement addressed unauthorized ebook downloads, not the destructive scanning of lawfully bought physical copies, a distinction now alarming booksellers
Book, Publication, Indoors

A federal judge has approved Anthropic’s $1.5 billion settlement over nearly half a million pirated books. The same litigation also protected a more physical method of feeding its AI systems. Anthropic bought print books, removed their bindings, scanned every page and destroyed the originals.

The legal divide came down to acquisition. The settlement covers books downloaded from LibGen and PiLiMi, while the court treated Anthropic’s one-for-one conversion of purchased books into private digital files as fair use. Training AI models on lawfully acquired material was also considered transformative.

Read more
Google Earth’s AI misadventure lasted only a day. It was a tale of dangerous ignorance.
Nuclear reactors, tanks, and historical destruction on a life-like satellite map? Yeah, that's bad.
Nano Banana AI image generator representation.

Technology behemoths are clearly not reading the room, or they are just moving faster than they should when it comes to AI deployment. Google has already stuffed its Gemini AI in every corner of its software stack, from Android to daily productivity tools like Gmail that are used by hundreds of millions of users every day. AI is everywhere. Not all of it is bad, mind you. But in a few places, it just feels forced.

In its latest AI-fication experiment, the company targeted Google Earth. The idea was to let the audience use its Nano Banana 2 AI image generator and make images that can be placed on the map view. On paper, it's a cool idea. What would the Colosseum of Rome look like in your urban neighborhood? Yeah, fun stuff like that.

Read more