Australia: Zombie hunters track down hijacked computers

The “Australian Internet Security Initiative” has dedicated itself to the goal of tracking down zombie PCs individually and cleaning them of malicious programs.

Archive notice: This article was originally published on October 11, 2007. Links and embedded videos are preserved as part of the historical record.

The initiative, which was launched two years ago by the regulatory authority “Australian Communication and Media Authority” http://www.acma.gov.au, collects information on infected computers for this purpose and matches it with the IP addresses of the ISPs (Internet Service Providers) involved. If there is a match, the access providers take action, contact their customer and help clean the computer.

From the original five participating ISPs, the number has now grown to 25, Bruce Matthwes, manager of the anti-spam team at ACMA, reports to the news portal AustralianIT. Matthews expects further growth in the coming year and, according to his own statements, can improve the software used and drive forward the expansion of the databases with an increase in budget funds of five million Australian dollars (around 3.2 million euros). The ISPs receive daily information about hijacked computers located in their network. “Experience shows us that, on the one hand, customers are extremely surprised when they are contacted by their provider. On the other hand, they are pleased about it and extremely cooperative when it comes to solving the problem,” says Matthews.

In Austria, the Association of Austrian Internet Service Providers (ISPA) http://www.ispa.at is trying to take action against hijacked computers that send spam with a code of conduct. “Our rules of conduct specify how a provider should proceed if it has a computer in its network that sends spam. The first step is, of course, the request to the customer to initiate countermeasures on their computer,” ISPA Secretary General Kurt Einzinger explains in conversation with pressetext. However, it is not so easy to track down hijacked PCs unless a conspicuously large amount of data traffic emanates from the computer. Then, however, the provider takes action on its own initiative. “Most of the time, however, individual computers account for relatively little traffic; the sum of many computers makes up the problem.”

However, there is no initiative like the one in Australia in this country, says Einzinger. “That is not necessary, since it is in the interest of the ISPs and they therefore strive themselves to prevent spam in their network. They must do that too, otherwise they also run the risk of being placed on a blacklist,” says Einzinger. The problem for the computer owner affected is that they notice hardly anything of the processes on their computer. “Customers often call the provider and ask whether there are problems with the line because their Internet access is very slow. The ISP often ultimately determines that the line to the customer is overloaded because a great deal of data traffic is caused by malware,” Einzinger reports.

According to experts, botnets represent a major, dormant danger in the online world. This is not only about the damage that arises on the infected computers themselves, but about the overall system, which spreads rapidly. With a botnet, hackers have a tool in their hands with which to carry out large attacks on companies or even states. Tracing them back is usually very difficult or not possible at all. According to the security experts at Symantec, as many as a quarter of all computers with Internet access may already belong to a botnet. Expressed in absolute figures, this means that there are 100 to 150 million zombie computers worldwide. Around 64,000 hijacked computers are said to be added every day. With AntiBot, the company has had a software Portfolio since summer that is intended to protect the computer from hostile takeover by Trojans, viruses and other pests http://www.symantec.com/norton/products/overview.jsp?pcid=is&pvid=nab1.