![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
Indestructible botnet?
Home » Forums » Cyber Security Information and Advisories » Code Red – Security/Privacy advisories » Indestructible botnet?
- This topic has 16 replies, 9 voices, and was last updated 13 years, 9 months ago.
AuthorTopicWSJust Plain Fred
AskWoody LoungerJuly 4, 2011 at 3:54 pm #477594Viewing 6 reply threadsAuthorReplies-
browni
AskWoody MVP -
WSBanyarola
AskWoody Lounger -
WSmidnight
AskWoody LoungerJuly 5, 2011 at 6:40 am #1286642There is also an article this week at http://www.ghacks.net/2011/07/01/indestructible-botnet-discovered/ which elaborates a bit more. Says it has been found in porn sites, pirated movie sites and on ‘some’ free photo hosting sites. “THEY” are always out to get us!!
-
WSJust Plain Fred
AskWoody LoungerJuly 5, 2011 at 7:30 am #1286643“THEY” are always out to get us!!
midnight,
Yes it would seem so…Also this is why i use a security system (Norton Internet Security 2011) that performs a “Boot Time Scan” (selectable option) Hopefully keeping the “nasties” out before they have a chance to load with windows.:cheers:Regards Fred
-
-
-
WSmidnight
AskWoody Lounger -
WSJust Plain Fred
AskWoody Lounger
-
-
satrow
AskWoody MVP -
WSJust Plain Fred
AskWoody LoungerJuly 5, 2011 at 10:15 am #1286664A boot time scan is useless if your real-time or passive protection didn’t prevent the initial trigger from happening, this loads and is active before Windows is.
satrow,
Hello… Norton scans for it before your “OS” boot’s …and then deals with it…and hopefully catches it there:cheers: Regards Fred -
WSmidnight
AskWoody Lounger -
satrow
AskWoody MVPJuly 5, 2011 at 11:30 am #1286673satrow,
Hello… Norton scans for it before your “OS” boot’s …and then deals with it…and hopefully catches it there:cheers: Regards FredFred, you say one thing then you illustrate it with a link that contradicts you. Has Norton discovered a way to boot and run from thin air, if so, you’d think they’d be boasting about how the only way to remove it would be to use their products.
Explain please how Norton can operate and detect it without having any ‘OS’ started?
-
WSJust Plain Fred
AskWoody LoungerJuly 5, 2011 at 3:06 pm #1286692Fred, you say one thing then you illustrate it with a link that contradicts you. Has Norton discovered a way to boot and run from thin air, if so, you’d think they’d be boasting about how the only way to remove it would be to use their products.
Explain please how Norton can operate and detect it without having any ‘OS’ started?
satrow,
Hello… There are two actually …
1. Norton has a “Bootable Recovery Tool”… so if something does get past your security and “hoses your OS”…. Load up the CD and boot from it,and it will search for the “infection” and remove it. (before windows loads up) Although i have not used it ( didn’t have a need to yet) I view it as a good “tool” to have.2. If this new ( zero day) “Bot” resides in your MBR…at least Norton will “run” a scan of your entire OS before it boots …and remove it. (presuming that Norton has discovered how) Look I’m not trying to pick a fight just passing along some info… So if I’m wrong I Apologize …ask for your money back:cheers:. Regards Fred
-
satrow
AskWoody MVPJuly 5, 2011 at 3:52 pm #1286698A lot of presumptions there Fred
A guess: number of Norton users with the bootable CD = less than 10%
There must be a reason MSFT are saying that it isn’t guaranteed that it can be successfully removed and that fixing the MBR then wiping/reinstalling is the only way to be sure
Check the link Doc Brown gave.
Bottom line: normal A/V tools can’t touch it.
-
-
-
-
-
WSDoc Brown
AskWoody LoungerJuly 5, 2011 at 9:58 am #1286660So far, the major A/V vendors aren’t detecting this via the normal means. If you suspect you have it, you’ll be tipped off by noticing strange behavior and performance issues. There are several companies that have tools to run from a bootable disk to fix it: http://update.pcantivirusreviews.com/news/bootkit/
-
joep517
AskWoody MVP -
WSsuniljoseph
AskWoody Lounger
-
-
WSMalwarekiller
AskWoody Lounger
Viewing 6 reply threads -

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Two blank icons
by
CR2
56 minutes ago -
Documents, Pictures, Desktop on OneDrive in Windows 11
by
ThePhoenix
3 hours, 20 minutes ago -
End of 10
by
Alex5723
6 hours, 1 minute ago -
End Of 10 : Move to Linux
by
Alex5723
6 hours, 30 minutes ago -
Single account cannot access printer’s automatic duplex functionality
by
Bruce
2 hours, 58 minutes ago -
test post
by
gtd12345
12 hours, 1 minute ago -
Privacy and the Real ID
by
Susan Bradley
2 hours, 9 minutes ago -
MS-DEFCON 2: Deferring that upgrade
by
Susan Bradley
2 hours, 58 minutes ago -
Cant log on to oldergeeks.Com
by
WSJonharnew
16 hours, 23 minutes ago -
Upgrading from Win 10
by
WSjcgc50
3 hours, 47 minutes ago -
USB webcam / microphone missing after KB5050009 update
by
WSlloydkuhnle
11 hours, 28 minutes ago -
TeleMessage, a modified Signal clone used by US government has been hacked
by
Alex5723
1 day, 8 hours ago -
The story of Windows Longhorn
by
Cybertooth
19 hours, 46 minutes ago -
Red x next to folder on OneDrive iPadOS
by
dmt_3904
1 day, 10 hours ago -
Are manuals extinct?
by
Susan Bradley
6 hours, 16 minutes ago -
Canonical ditching Sudo for Rust Sudo -rs starting with Ubuntu
by
Alex5723
1 day, 19 hours ago -
Network Issue
by
Casey H
1 day, 6 hours ago -
Fedora Linux is now an official WSL distro
by
Alex5723
2 days, 7 hours ago -
May 2025 Office non-Security updates
by
PKCano
2 days, 7 hours ago -
Windows 10 filehistory including onedrive folder
by
Steve Bondy
2 days, 9 hours ago -
pages print on restart (Win 11 23H2)
by
cyraxote
1 day, 10 hours ago -
Windows 11 Insider Preview build 26200.5581 released to DEV
by
joep517
2 days, 11 hours ago -
Windows 11 Insider Preview build 26120.3950 (24H2) released to BETA
by
joep517
2 days, 11 hours ago -
Proton to drop prices after ruling against “Apple tax”
by
Cybertooth
2 days, 19 hours ago -
24H2 Installer – don’t see Option for non destructive install
by
JP
1 day, 11 hours ago -
Asking Again here (New User and Fast change only backups)
by
thymej
3 days, 6 hours ago -
How much I spent on the Mac mini
by
Will Fastie
13 hours, 50 minutes ago -
How to get rid of Copilot in Microsoft 365
by
Lance Whitney
1 day, 9 hours ago -
Spring cleanup — 2025
by
Deanna McElveen
3 days, 12 hours ago -
Setting up Windows 11
by
Susan Bradley
2 days, 7 hours ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.