My biggest problem with all this media is that with knowledge of how it works, and having control of the C&C software, none of those idiots are just saying "For a day let's spoof all of their update centers and spam suicide signal to anyone who comms during that day." Which would kill a majority if not ALL of the virus out there.
Another option is to not sit around proudly on their C&C centers, but that's an obvious start on reversing them as well as a relay point for data. Finding WHAT data EXACTLY they're hunting is the first step in finding who is doing it.