ZeroHour
Kaspersky Securelistpublished ()ingested @Securelist

Taking down botnets

highMalwareimportance 42
Full article330 words · extracted from securelist.com · click to collapse

Incidents

Incidents

06 Aug 2008

minute read

Let’s start with a few facts. Last week the Dutch police arrested a 19 year old Dutch man for selling a botnet to a Brazilian, who was also arrested. The ‘Shadow’ botnet is made up of around 100 000 infected machines.

However, the arrest isn’t the end of the story. The Dutch police are working to help the victims. One of the steps they’re taking is informing users that Kaspersky Lab websites include removal instructions (created at the request of the Dutch High Tech Crime Team) on how to get rid of the malware which transformed machines into bots.

The case raises a number of security questions which need to be discussed once the botnet has been dismantled. But in the meantime, if you think your computer might be part of the Shadow botnet, check it with an online scanner such as Kaspersky Online Scanner, and read the removal instructions we’ve posted at http://www.kaspersky.com/shadowbot. The botnet does include machines from around the world, so you’re not automatically safe just because you don’t live in the Netherlands.

Do remember that the removal instructions only apply to the malware which has been used to create the botnet. These programs may have downloaded additonal malware to your machine, so make sure you also scan your computer with an up-to-date antivirus solution.

Latest Webinars
Reports

Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.

Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.

Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.

Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.

Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/taking-down-botnets/30443/