Skip to main content

Microsoft Blames Rootkits for Security Update Crashes

MS-DOS
Image used with permission by copyright holder

Earlier this month, Microsoft released a patch for its entire supported line of Windows operating systems—that’d be Windows 2000 all the way through Windows 7—which included a fix for a security vulnerability that had been lurking in its Virtual DOS Machine for some 17 years—a record by almost any standard. The problem was that the security update led to problems on some Windows XP machines: users would install the update, then find themselves faced with the dreaded Blue Screen of Death or an endless cycle of reboots. Some Windows XP users angrily railed against Microsoft for damaging their computers, and Microsoft promptly began looking into the problem. Their verdict? The problems Windows XP users experienced were caused by malware using the Alureon rootkit, not the security update.

“Our investigation has concluded that the reboot occurs because the system is infected with malware, specifically the Alureon rootkit,” wrote Microsoft’s Security Response Center director Mike Reavey, in a blog post. “We were able to reach this conclusion after the comprehensive analysis of memory dumps obtained from multiple customer machines and extensive testing against third party applications and software. The restarts are the result of modifications the Alureon rootkit makes to Windows Kernel binaries, which places these systems in an unstable state.”

Microsoft has determined that 64-bit versions of Windows are not vulnerable to the problem, and so has re-enabled Automatic Updates for those systems. However, Microsoft is still holding off on making the update available to 32-bit systems via Automatic Update.

In the meantime, Microsoft is recommending users make sure they’re running up-to-date antivirus and security software to make sure their systems aren’t infected by malware prior to installing any system updates. If users can’t confirm they’ve been able to remove the Alureon rootkit—which does go to a lot of effort to hide itself—Microsoft users back up their important files and data, then completely restore their systems to a re-formatted drive.

Editors' Recommendations

Geoff Duncan
Former Digital Trends Contributor
Geoff Duncan writes, programs, edits, plays music, and delights in making software misbehave. He's probably the only member…
Microsoft just teased its next big Windows 11 update
Windows 11 22H2 Tablet Taskbar YouTube screenshot

Microsoft has given us a glimpse of a feature that "Moment 2" may bring as early as January 2023.

Since Windows 11 version 22H2, the Redmond, WA company has dedicated to releasing smaller feature updates, known internally as "Moment." The first one gave us the much-requested tabs in File Explorer (along with its Context IQ tech). The next Windows 11 version 22H2 "Moment" is currently slated for early 2023, according to sources, after it undergoes testing throughout 2022.

Read more
Zoom just fixed a major security flaw on Mac. Here’s why you should update now
The Logitech Brio 4K Pro attached to a Macbook.

If you have Zoom installed on your MacBook, you'll want to update the app right now. Zoom spent the weekend patching a major security flaw in its Mac app, and the update is available right now.

According to The Verge, it all began at Def Con, a computer security and hacker conference in Las Vegas. The founder of the security non-profit Objective-See and an ex-NSA security analyst, Patrick Wardle, took to the stage on Friday and presented a stunning find: a massive security vulnerability in the Zoom installer for MacBooks.

Read more
The latest Windows update is causing major printer problems
A Dell laptop with Windows 10 sitting on a desk.

Microsoft is now offering Windows 10 users a workaround for an issue that has come along with a mid-July update.

The KB5015807 update, which rolled out on July 12 and includes OS Builds 19042.1826, 19043.1826, and 19044.1826 all have a glitch that affects printers connected to computers running Windows 10. After the update is installed, you might see multiple printer listings available when you only have one product.

Read more