How to Steal a Botnet
catonmat.net
catonmat.net
What can hackers do with your, say, checking account info (name and account number, I'm assuming)? Are you liable for any hacker-related losses, if you've done nothing wrong?
I've been infected by viruses three times. Twice were before this year, and it takes some quick work, but both times it was no real challenge to stabilize my machine, so beyond feeling really stupid for a few hours, it ended up being kind of fun.
In November, though, I infected my machine again. Three days later, it was still phoning home to Russia and the Ukraine. There was literally nothing I could do - even Malwarebytes and the like would clean it up only to a certain extent, and the viruses were still embedded in the system software. Finally I just gave up and bought a new machine so I could start from scratch, only pulling data from the old machine.
A good AV won't let you get infected - you still shouldn't allow actions that look fishy or unexpected, but at least you're in control. But once you're infected, the botnet can respond in realtime to what you're trying to do to stop it. And they're better than you are at it.
I'm not saying it's impossible to clean up a machine that's fallen into their hands - but I am saying that even with some past success in this under my belt, I was unable to do it in any amount of time that was justified (even in terms of fun).
If you can still get the machine to boot, I've had very good luck with ComboFix. (Make sure you get it from bleepingcomputer.com [1], not combofix.org, which is an unauthorized re-distribution.)
Most of the rootkits I'm seeing still aren't working directly on existing system files, a la the computer viruses of old. Instead, they're modifying ini files and then installing some cleverly hidden files in system directories. So, you can use tools like RootKit Revealer [2] to sniff them out. Actually removing any hidden files or hidden registry keys may require some expertise and serious effort -- we have a dedicated diagnostic system set up that we use to handle some of these things, with the drive removed from the client computer.
[1]: http://download.bleepingcomputer.com/sUBs/ComboFix.exe
[2]: http://technet.microsoft.com/en-us/sysinternals/bb897445.asp...
So I did, and didn't regret it.
As an example... I find it very difficult, in general, to install software onto multiple Windows machines. Different versions of DLLs, differing Windows features, differing filesystem layout, etc. The botnet control system seems to reliably install on all sorts of machines, without needing 3 restarts and without asking lots of dumb questsions.
Making installing real programs this easy and reliable would be quite nice.
They don't seem to use keylogging. They only capture HTML form information.