Botnets - FBI Begins Disinfecting Coreflood from User PCs - eWeek Security Watch | eWeek

FBI Begins Disinfecting Coreflood from User PCs

Jun 23, 2011
2 minute read
eWeek Le contenu et les recommandations de produits sont indépendants de la rédaction. Nous pouvons gagner de l'argent lorsque vous cliquez sur des liens vers nos partenaires. En savoir plus

The Federal Bureau of Investigation has finally moved ahead with the next step in its fight against the Coreflood botnet: disinfecting compromised machines.

When federal law agents seized servers belonging to the Coreflood botnet in April, they obtained legal permission from the United States District Court of Connecticut to replace them with servers under their own control that pushed out instructions to temporarily disable the malware on the zombie army. The Justice Department also obtained permission to be able to contact individual computer owners to get permission to remove the malware permanently.

That cleanup has begun as the FBI’s programmers has issued some 19,000 uninstall commands to the computers belonging to 24 individuals, Brian Krebs reported on his Krebs on Security blog. The commands effectively purge the systems of the malware and is supposed to have no other impact on the machines.

“FBI has directly notified hundreds of identifiable victims, and that it has provided information to approximately 25 of the largest Internet service providers in the United States, enabling them to notify their infected customers,” Krebs wrote.

FBI Special Agent Kenneth Keller claimed in court documents that the FBI has notified hundreds of additional victims and their internet service providers that the machines were infected. The FBI obtained written consent from each victim before pushing out the uninstall code.

Keller said it will be very difficult to notify and obtain consent from all infected users. However, the dramatic 95 percent decline in the size of the Coreflood botnet is the result of the FBI’s notification efforts.

The FBI also seized control over the 29 domain names that controlled the day-to-day operations of the command and control servers, which allowed it to redirect the zombies to federal servers.

The raid took down servers only in the United States, so Coreflood remains active globally.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Propriété de TechnologyAdvice. © 2026 TechnologyAdvice. Tous droits réservés

Divulgation publicitaire : Certains des produits qui apparaissent sur ce site proviennent d'entreprises dont TechnologyAdvice reçoit une compensation. Cette compensation peut influencer la façon dont les produits apparaissent sur ce site, notamment l'ordre dans lequel ils apparaissent. TechnologyAdvice n'inclut pas toutes les entreprises ou tous les types de produits disponibles sur le marché.